What We're Building
One of the most consistent pain points we hear from defense contractors pursuing CMMC Level 2 is SIEM. The audit and accountability domain (AU) alone carries requirements for event logging, log review, log protection, and audit failure alerting — and many of these requirements have historically forced small DIB companies to purchase and integrate a separate enterprise SIEM tool on top of their compliance platform.
We're changing that. 1TEN is actively integrating Wazuh — a proven, open-source security information and event management platform — directly into the 1TEN compliance environment. When complete, customers will have SIEM capabilities built natively into their on-premises deployment, with no additional vendor contracts, no cloud dependencies, and no data leaving the air-gapped environment.
CMMC Requirements This Addresses
The Wazuh integration directly supports compliance with requirements across four NIST SP 800-171 domains. These are areas where assessors consistently probe for technical evidence — log collection, alerting, and monitoring aren't things you can document your way through. You need a running system.
Audit & Accountability (AU) — 9 Requirements
The AU domain is the primary driver for this integration. Wazuh provides the centralized log collection, review, and protection capabilities that AU requires. This includes AU.L2-3.3.1 (audit event creation), AU.L2-3.3.2 (user action traceability), AU.L2-3.3.5 (audit review and analysis), AU.L2-3.3.6 (reduction and reporting), and AU.L2-3.3.7 (authoritative time source synchronization).
System & Information Integrity (SI) — Selected Requirements
Wazuh's threat detection engine and file integrity monitoring (FIM) module directly supports SI requirements for malicious code protection and security alert monitoring. SI.L2-3.14.6 and SI.L2-3.14.7 — which require monitoring of organizational systems for security alerts and identification of unauthorized use — are addressable through Wazuh's rule-based alerting and anomaly detection.
Incident Response (IR) — Selected Requirements
Wazuh's alerting and notification capabilities support IR.L2-3.6.1 and IR.L2-3.6.2, which require an operational incident-handling capability and tracking, documentation, and reporting of incidents. When Wazuh detects an event that meets an alert threshold, it generates a structured record that feeds directly into 1TEN's incident response workflow.
Security Assessment (CA) — Continuous Monitoring
Wazuh's continuous monitoring posture supports CA.L2-3.12.3, which requires ongoing monitoring of security controls. Rather than point-in-time snapshots, customers will have a live feed of control performance data tied directly to their 1TEN compliance dashboard.
Architecture Approach
1TEN is built on an air-gapped, on-premises architecture specifically because many DIB companies cannot allow CUI-adjacent systems to touch the public internet. The Wazuh integration preserves that architecture completely.
Wazuh will be deployed as an embedded component of the 1TEN stack — running on the same hardware, within the same network boundary, with no external telemetry or cloud sync. Log data, alert data, and monitoring records all remain on-site. The integration will surface Wazuh data through the existing 1TEN dashboard interface, so operators don't need to learn a separate SIEM console to meet their compliance obligations.
| Capability | What It Means for Your Deployment |
|---|---|
| On-premises deployment | Wazuh runs inside your network boundary on the same hardware as 1TEN — no separate server, no external calls, no vendor access to your environment. |
| No cloud dependency | No external licensing servers, no telemetry, no update requirements that touch the internet. Fully functional in a fully air-gapped network. |
| Unified dashboard | SIEM alerts and log data surface inside the existing 1TEN compliance interface. Your team doesn't need to learn a separate SIEM console. |
| Assessment-ready output | Log archives, alert histories, and FIM records are exportable directly from 1TEN in assessor-ready format — no manual compilation before your C3PAO review. |
| Mapped to requirements | Each Wazuh capability is pre-mapped to the specific NIST SP 800-171 requirement it satisfies. Implementing the SIEM automatically updates requirement status in your SSP. |
What This Means for Customers
For companies already on 1TEN or planning to deploy, the Wazuh integration eliminates a significant procurement and integration burden. Instead of evaluating, purchasing, and integrating a separate SIEM — then figuring out how to connect its output to your compliance documentation — SIEM coverage will be part of the base platform.
This matters most for small and mid-size DIB companies that don't have dedicated security engineering staff. Standing up and tuning an enterprise SIEM is a non-trivial project. By embedding Wazuh with pre-configured rules mapped to NIST 800-171 requirements, 1TEN reduces that burden to a configuration step, not an engineering project.
Frequently Asked Questions
When will the Wazuh integration be available?
We are actively working on this integration. We will announce a release timeline as development progresses. If you have a specific deployment timeline or assessment date driving urgency, reach out directly — we want to understand how this affects your program.
Will this add cost to the platform?
Wazuh is open-source. The integration itself does not introduce a licensing cost. 1TEN's engineering effort to embed and maintain the integration is part of the platform roadmap. Pricing details for the integrated offering will be communicated ahead of release.
Can Wazuh replace our existing SIEM?
For most small to mid-size DIB companies, yes — Wazuh as embedded in 1TEN will satisfy the SIEM requirements for CMMC Level 2. Larger organizations with complex multi-site environments or existing SIEM investments may want to evaluate whether to run Wazuh as a primary tool or as a supplementary compliance feed alongside their current platform.
Is Wazuh approved for use in classified environments?
CMMC Level 2 governs CUI, not classified information. Wazuh is appropriate for CUI environments. If you're operating in a classified environment (CUI + classified), different rules apply and you should work with your FSO and security officer before making any tool decisions.
What log sources will Wazuh collect from?
The initial integration will cover Windows event logs, Linux syslog, network device logs (via syslog forwarding), and application logs from common DIB-relevant tools. The pre-configured rule set will be tuned to the specific event types that satisfy NIST 800-171 AU requirements. Additional log sources can be added through standard Wazuh agent configuration.