CMMC 2.0 / NIST 800-171 Customer Configuration Checklist

CMMC 2.0 / NIST 800-171 Customer Configuration Checklist

CMMC 2.0 / NIST 800-171 Customer Configuration Checklist 

Because Vector GFX operates a Zero-Knowledge model, the responsibility for protecting the data created within our applications falls under the customer's "System Security Plan" (SSP). Use this checklist to satisfy your CMMC Level 2 audit objectives. 

1. Access Control (AC) 

Requirement (3.1.1): Limit system access to authorized users. 

Implementation: Ensure Canvas X Draw is only installed on workstations belonging to users with "Need-to-Know" clearance for the project data being illustrated. 

Requirement (3.1.2): Limit transactions/functions. 

Implementation: Use Windows/macOS Standard User accounts for daily design work. Only use Administrator accounts for the initial installation and updates of Canvas X Draw. 

2. Configuration Management (CM) 

Requirement (3.4.1): Establish baseline configurations. 

Implementation: List Canvas X Draw in your Software Inventory. Record the specific version (e.g., Version N) to prove you are using a version currently supported with security patches. 

Requirement (3.4.7): Restrict non-essential software. 

Implementation: If using the Air-Gapped Edition, disable all network adapters (WiFi/Ethernet) at the OS level to ensure the workstation remains an isolated enclave. 

3. Identification & Authentication (IA) 

Requirement (3.5.3): Use multi-factor authentication (MFA). 

Implementation: Ensure the Windows or macOS host machine requires MFA (e.g., Windows Hello for Business, Smart Cards, or Yubikeys) before a user can launch the application and access technical drawings. 

4. Media Protection (MP) 

Requirement (3.8.3): Sanitize or destroy system media. 

Implementation: When retiring a workstation used for canvasxdraw ensure the local drive is wiped according to NIST 800-88 standards, as the application saves files locally. 

5. System & Information Integrity (SI) 

Requirement (3.14.1): Identify, report, and correct system flaws. 

Implementation: Subscribe to the Vector GFX Security Advisory mailing list to receive immediate notification of "Critical" patches and "Zero-Day" mitigations. 

Security FAQ: Quick Reference for IT Managers 

Q: Where is my data stored when I use Canvas X Draw?  

A: Locally. Vector GFX has no cloud storage components for your drawings. All .cvx files and exported PDFs reside on your local hard drive or your company’s secure file server. 

Q: Does the software "Phone Home" for license checks?  

A: The standard version performs a periodic encrypted handshake for license validation. For DOD customers in high-security environments, the Air-Gapped Edition eliminates this requirement entirely, allowing for 100% offline operation. 

Q: Is the software FIPS-compliant?  

A: As a desktop application, Canvas X Draw utilizes the FIPS 140-2/3 validated cryptographic modules provided by the host Operating System (Windows or macOS) for securing data at rest and in transit. 

Q: How do I verify the integrity of the installer?  

A: All Vector GFX installers are digitally signed. Right-click the .exe (Windows) or check the .dmg (Mac) to verify the "Digital Signature" is from Vector GFX, Inc. 

 

 
    • Recent Articles

    • Comprehensive Feature Guide for canvasxdraw

      Comprehensive Feature Guide The Professional Standard for 2D Technical Illustration & Documentation. 1. Unified Vector & Raster Workflow Unlike many design suites that require switching between different apps for photos and drawings, canvasxdraw ...
    • 2D Illustration Cheat Sheet

      2D Illustration Cheat Sheet for our trial-ers Master the technical edge in minutes. 1. The Power Shortcuts (Must-Knows) > Direct Edit Mode: Double-Click any object to enter edit mode, or press Cmd + E (Mac) / Ctrl + E (Win). > The "Magic" ...
    • 2D Illustration Cheat Sheet

      2D Illustration Cheat Sheet for our trial-ers Master the technical edge in minutes. 1. The Power Shortcuts (Must-Knows) > Direct Edit Mode: Double-Click any object to enter edit mode, or press Cmd + E (Mac) / Ctrl + E (Win). > The "Magic" ...
    • Canvas X Draw Menus

      Canvas X Draw Menus Canvas X Draw File Edit Text Object Path About Canvas X Draw... Preferences... Check for Updates Services Hide Canvas X Draw Hide Others Show All Quit Canvas X Draw New... Open... Open Recent Close Place... Import Images... Symbol ...
    • Privacy at a Glance: Vector GFX Data Handling

      Privacy at a Glance: Vector GFX Data Handling Feature Standard License Air-Gapped License Who can see your files? Only You. Vector GFX has zero access to your drawings or IP. Only You. Vector GFX has zero access to your drawings or IP. What user info ...
    • Related Articles

    • Vector GFX Customer Trust & Security Policy

      Vector GFX Customer Trust & Security Policy Last Updated: February 20, 2026 Overview At Vector GFX, we understand that our technical illustration software—including canvasxdraw—is a mission-critical tool for your engineering and design workflows. ...
    • Vector GFX Customer Trust & Security Policy

      Vector GFX Customer Trust & Security Policy Last Updated: February 20, 2026 Overview At Vector GFX, we understand that our technical illustration software—including canvasxdraw—is a mission-critical tool for your engineering and design workflows. ...
    • Security and Trust: Frequently Asked Questions (FAQ)

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements? Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the foundation ...
    • Frequently Asked Questions (FAQ): Security & Trust

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements?  Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the ...
    • Security and Trust: Frequently Asked Questions (FAQ)

      Frequently Asked Questions (FAQ): Security & Trust 1. CMMC & Government Compliance Does Vector GFX comply with CMMC 2.0 requirements? Yes. Vector GFX aligns its internal operations and secure development lifecycle with NIST SP 800-171, the foundation ...
    • Popular Articles

    • The new macOS Native/Universal app has arrived!

      Exciting news for Mac users! The first universal native app is here! This new version is be compatable with all macOS versions and chipsets. Subscription users can download here Perpetual users looking to upgrade click here Free trials here Thank ...
    • Welcome to Vector GFX!

      Please bear with us as we are busy updating all of our help content. If you need immeadiate assistance submit a ticket at https://vgfxsupport.zohodesk.com/portal/en/newticket or e-mail info@vectorgfx.net. Other important links: New Website: ...
    • Vector GFX: Quality Assurance Program Overview

      Vector GFX: Quality Assurance Program Overview At Vector GFX, we are committed to delivering high-performance, stable desktop solutions. Because our software resides directly on our customers' local environments, our Quality Assurance (QA) program ...
    • How many computers can I put a license on?

      Overview: Each license can only be used to register the program on two computers. If you are looking to get more than one license, we can offer a discount for multiple licenses. Please contact our sales department at sales@vectorgfx.net. Applies To: ...
    • What is the difference between Canvas X Draw and Canvas X Pro (Canvas GFX)?