Kandji vs Rippling IT for a Federal Contractor's Devices
A contract clause, not a personal preference, sets the bar for device management at a federal or defense contractor. Once controlled unclassified information touches a laptop, the requirements that matter are the ones written into the contract and into NIST SP 800-171, not general best practice, and neither Kandji nor Rippling IT is inherently compliant with either one out of the box.
A contractor new to this space often starts by asking which platform is compliant, which is the wrong first question. The right first question is what your contract actually requires, since that shapes everything else about how either platform gets configured.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Start with what your actual contract requires, not general security practice
Contracts vary. Some require compliance with NIST SP 800-171's security controls, some require CMMC certification at a specific level, and some involve no controlled unclassified information at all despite being government-adjacent work. Read your specific contract's security clauses before evaluating any platform, since the requirement drives the configuration, not the other way around.
If you're unsure which category your work falls into, that's worth resolving with your contracting officer or a compliance specialist before you spend money on a platform configured for a requirement that doesn't actually apply to your contract.
How CMMC and NIST SP 800-171 relate to each other
NIST SP 800-171 defines the security controls themselves. CMMC is the certification framework that verifies a contractor actually meets them, at a level tied to the sensitivity of the information involved. A contract might require a CMMC Level 2 self-assessment or a third-party-assessed Level 2 certification, and which one applies to you is set by the contract, not by general industry practice.
Neither platform is a compliance program by itself
Both Kandji and Rippling IT can enforce useful pieces of a compliance posture: encryption, patch management, access controls, and audit logging. Neither one is a complete NIST SP 800-171 or CMMC compliance program on its own, and treating a platform purchase as the whole solution is a common and costly mistake. A compliance program also covers policy documentation, personnel security, and physical security that no device platform touches at all.
A contractor that buys a device platform and stops there, without the accompanying policy documentation and personnel security practices, tends to discover the gap during an actual assessment, which is a far more expensive time to find it than during initial planning.
Which platform fits your actual fleet
A contractor running an all-Mac engineering and program management team gets real value from Kandji's depth on Apple hardware, including detailed compliance reporting that can feed into an audit. A contractor running Windows, which is still standard in a lot of government-adjacent IT environments and required by some specific contract toolchains, will find Rippling IT the workable option since Kandji doesn't manage Windows at all.
Check this against your specific contract's toolchain requirements before assuming your current hardware preference decides it. Some program requirements specify particular software that's only available on one platform, which can override whatever your team would otherwise choose.
Where subcontractors and consultants fit into your compliance boundary
A prime contractor's compliance boundary often needs to extend to subcontractors and consultants who touch the same controlled information, and your flow-down obligations may require you to confirm their device practices too, not just your own employees'. Build this check into your subcontract onboarding rather than treating it as a formality, since a gap at a subcontractor's laptop is still a gap in your overall compliance posture from an assessor's point of view.
Patch timing as a benchmark, even where it isn't a direct mandate
Federal guidance under CISA's binding operational directives sets specific remediation windows for federal agencies, including a 15-day window for a critical, internet-accessible vulnerability1. Your contract may or may not bind you to that exact standard, but it's a reasonable benchmark to hold your own patch process against when an assessor or a prime contractor asks how quickly you remediate known issues.
Producing evidence for an assessment
An assessor will ask for evidence, not assurances: which devices are enrolled, what their patch status is, and how access is controlled and logged. Whichever platform you choose, confirm early that it can export the specific reports your assessor or your prime contractor's flow-down requirements ask for, since discovering a reporting gap during the assessment itself is far more costly than checking beforehand.
Run a practice export well before any real assessment is scheduled. Pulling the report early, while there's still time to fix a gap, is a very different position than discovering the platform can't produce what's being asked for during the assessment window itself.
An assessor will typically ask you to show:
- Which devices are enrolled in the platform, so the boundary of controlled unclassified information handling is documented rather than assumed.
- The current patch status of each enrolled device, including how quickly critical vulnerabilities get remediated.
- How access to devices and data is controlled and logged, since audit logging is one of the controls a platform can enforce.
- That your chosen platform can export the specific reports your assessor or prime contractor's flow-down requirements call for.
What Good Looks Like
A well-run federal contractor can produce, on request, evidence of device encryption, patch status, and access controls mapped to its actual contract requirements, not just a general security claim.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
For a contractor running Windows across program and engineering staff, Rippling IT covers the fleet from one console and can feed hire and termination events into your access control process.
If cleared or contract staff payroll runs through Gusto, use its hire and termination events as the trigger for provisioning or revoking device access, keeping that record aligned with your compliance documentation.
Frequently Asked Questions
Does a device platform alone make us CMMC compliant?
No. A device platform covers pieces of the technical controls, like encryption and patch management, but CMMC compliance also requires documented policies, personnel security practices, and a broader set of controls that a device management tool doesn't touch. Work with a compliance specialist to map the full requirement, not just the device piece.
Do subcontractors' devices need to meet the same standard as our own employees' devices?
If a subcontractor's device touches controlled unclassified information, generally yes, and your prime contract likely flows that requirement down to them. Confirm the specific flow-down language in your subcontract rather than assuming it doesn't apply.
Should we hire a dedicated compliance and IT security role instead of relying on a platform?
National wage data puts the median salary for a software developer, a reasonable proxy for the kind of technical hire this work often falls to, at $135,980 a year2. Most contractors end up needing both: a platform to enforce the technical controls at scale and a person or outside specialist who understands the full compliance requirement beyond just devices.
Sources
Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.
- Security patch remediation SLAs (CISA federal mandates, used as industry norm). CISA Binding Operational Directives 19-02 and 22-01 (CISA briefing hosted at NIST CSRC), 2022.
- Annual wage, Software Developers (SOC 15-1252), US all industries. BLS OEWS May 2025, 2025.
Related Guides
Justworks vs Rippling for a Federal Contractor's W-2 Team
How a small federal or defense contractor should weigh Justworks against Rippling given Service Contract Act pay rules and cost accounting.
Rippling vs Firstbase for Federal Contractors Handling CUI
Contract-level compliance requirements decide more than either vendor does. Here's what a federal or defense contractor needs to confirm before choosing either.
Rippling vs Gusto for Federal Contractors and SCA Pay
A runbook for setting up Service Contract Act wage determinations and DCAA-compliant timekeeping in Rippling or Gusto for federal contractors.
Make vs Zapier for Federal and Defense Contractors
A data-sensitivity checklist for federal and defense contractors choosing between Zapier, Make and Workato around CUI, DCAA timekeeping and contracts.
Zendesk vs Intercom for a Federal or Defense Contractor
Before comparing features, a defense contractor has to answer where support data lives and who can see it. A question-first guide to that decision.
Notion vs. Slite for a Federal and Defense Contractor
A checklist for federal and defense contractors choosing between Notion and Slite for DCAA-compliant timekeeping and facility clearance procedures.