Skip to main content
← Home
Maryland Compliance Automation

MODPA, CMMC, and NIST 800-171, evidence from a single scan.

Maryland pairs one of the strictest state privacy laws in the country with the densest federal-contractor corridor in it. CISGuard maps continuous CIS benchmark scanning to MODPA security expectations and NIST 800-171/CMMC evidence simultaneously.

Quick Facts

Maryland compliance at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

Privacy law
Maryland Online Data Privacy Act (MODPA), effective October 1, 2025
MODPA character
Strict data minimization and sensitive-data limits
Enforcement
Maryland Attorney General, Consumer Protection Division
Breach notification
Maryland Personal Information Protection Act
Federal overlay
NIST 800-171 and CMMC across the DC-Baltimore contractor corridor
Defense anchor
Fort Meade and federal agency density
Deployment
On-premises, US-region cloud, or air-gapped
Regulatory Landscape

Compliance in Maryland, United States.

Maryland's compliance profile is a two-front problem. The Maryland Online Data Privacy Act (MODPA), enacted in 2024 and effective October 1, 2025, is among the strictest state privacy laws yet passed: it imposes strong data minimization duties and tight limits on sensitive data, alongside the expected requirement for reasonable security practices, with enforcement through the Maryland Attorney General's Consumer Protection Division. Maryland's existing Personal Information Protection Act adds breach notification duties. The second front is federal: the corridor between Washington and Baltimore, anchored by Fort Meade and dozens of federal agencies, hosts one of the highest densities of defense and civilian federal contractors in the country, which means NIST 800-171 obligations for controlled unclassified information and CMMC assessment readiness for the defense industrial base. CISGuard serves both fronts from one scan: continuous CIS benchmark posture mapped to NIST 800-53, with air-gapped deployment for classified-adjacent environments.

Frameworks

Frameworks CISGuard maps for Maryland.

Each scan generates per-framework reports showing satisfied / partial / not-met status.

FrameworkScopeAuthority
Maryland Online Data Privacy Act (MODPA)Comprehensive consumer privacy, effective October 1, 2025Maryland Attorney General (Consumer Protection Division)
Maryland Personal Information Protection ActPersonal information protection and breach notificationMaryland Attorney General
NIST 800-171 / CMMCControlled unclassified information for defense contractorsDoD Cyber-AB
NIST 800-53Federal information systems and contractor environmentsNIST + agency authorizing officials
HIPAA Security RuleMaryland health systems and federal health contractorsHHS OCR
Data Residency

Sovereignty and residency, solved by architecture.

Maryland's federal-contractor density makes deployment boundaries a first-order question. NIST 800-171 environments handling controlled unclassified information restrict where security tooling and its data may live, and many Fort Meade-adjacent programs prohibit outbound connectivity entirely. CISGuard's on-premises deployment keeps all scan data inside the contractor's assessed boundary with no vendor phone-home, and the air-gapped option operates with zero outbound connectivity, with CIS benchmark updates via signed media. For commercial workloads under MODPA, US-region cloud deployment keeps evidence inside US borders for Attorney General enquiries.

Deployment Options

Three ways to deploy in Maryland.

Option 01

On-premises inside the assessed boundary

Single-tenant deployment inside the contractor's NIST 800-171 or CMMC assessment boundary. No external data flow, so the tool does not expand the boundary it evidences.

Option 02

Air-gapped

Zero outbound connectivity for classified-adjacent and high-side-adjacent environments in the Fort Meade corridor. CIS benchmark content updates ship via signed media through approved channels.

Option 03

US-region cloud (AWS / Azure / GCP)

Deployed in US regions for commercial workloads under MODPA and SOC 2, with all scan and evidence data retained inside US borders.

Frequently Asked

Maryland questions, answered directly.

How does CISGuard support MODPA compliance?

MODPA requires reasonable security practices for Maryland consumers' personal data, enforced through the Maryland Attorney General's Consumer Protection Division, and its strict data-minimization posture raises the bar on demonstrable governance. CISGuard evidences the technical layer: continuous CIS benchmark posture, drift detection, and mapping to NIST 800-53 and ISO 27001, producing the documented, continuously operating controls record a MODPA program stands on.

How does CISGuard help Maryland defense contractors with CMMC?

CMMC Level 2 aligns with NIST SP 800-171, which derives from NIST 800-53. CISGuard's NIST 800-53 mapping covers a large share of CMMC Level 2 practice requirements through CIS benchmark scanning, and exception management documents compensating controls for the remainder. Deployed on-premises inside the assessed boundary, it evidences the environment without adding an external service to the assessment scope.

Can CISGuard run in Fort Meade-adjacent air-gapped environments?

Yes. The air-gapped deployment operates with zero outbound connectivity: no SaaS phone-home, no telemetry, no license callbacks. CIS benchmark content updates ship via signed media through the customer's approved transfer channels. This is the standard pattern for classified-adjacent contractor environments in the Maryland corridor where internet-connected security tooling is prohibited.

Can one Maryland organization cover MODPA and NIST 800-171 with one program?

Yes, with scoped instances. The common pattern is one CISGuard deployment inside the CUI boundary producing NIST 800-171/CMMC evidence, and a second covering corporate systems for MODPA and SOC 2, with consolidated executive reporting. Both run the same continuous CIS benchmark scanning across 22 benchmarks and 3,928 controls, so the evidence model is uniform even where the boundaries are not.

Ready to deploy in Maryland?

Our compliance engineers have helped organizations across Maryland achieve regulatory readiness in as little as one business day.