News

UC San Diego’s Sherlock Secure Cloud Advances Trusted Computing for Higher Education and Defense Research

Published September 21, 2026

By Kimberly Mann Bruch

Digital blue shield with a checkmark floating over glowing binary code on a dark background.

Credit: iStock

The San Diego Supercomputer Center's (SDSC) Sherlock Secure Cloud has achieved FedRAMP Moderate equivalency, making the University of California San Diego the only known higher education institution to pair that achievement with Cybersecurity Maturity Model Certification (CMMC) Level 2 certification. This achievement positions Sherlock to help universities, researchers, and defense organizations work with federally sensitive information in a secure, compliant environment.

With this milestone, higher education institutions, research organizations and members of the Defense Industrial Base (DIB) can leverage an already assessed and compliant computing environment at SDSC, precluding the need to build such an environment from ground up in order to meet the cybersecurity guidelines set by the Department of War (DoW).

“Achieving both CMMC Level 2 and FedRAMP Moderate equivalency represents a significant milestone not only for Sherlock and SDSC, but for higher education.”

— Sandeep Chandra, SDSC Stack Science Director

“Achieving both CMMC Level 2 and FedRAMP Moderate equivalency represents a significant milestone not only for Sherlock and SDSC, but for higher education,” said Sandeep Chandra, director of the Stack Science Division at SDSC, which is based at the UC San Diego Halıcıoğlu School of Data Science and Computing. “To our knowledge, UC San Diego is the only higher education institution in the country to have achieved both milestones. That gives Sherlock a unique opportunity to make the investments we have made in security and compliance available to universities, research institutions and DIB organizations across the nation.”

A New Model for Higher Education CMMC Compliance

For higher education institutions, achieving CMMC compliance independently can require substantial investments in infrastructure, technical and cybersecurity personnel, documentation, monitoring, policy development, procedures and ongoing assessment activities.

Sherlock offers a different model: Inherit rather than build.

Under Sherlock’s shared-services model, partnering institutions can inherit the vast majority of required CMMC controls from Sherlock’s assessed cloud enclave. Instead of independently implementing and managing an entire compliant environment, institutions can leverage Sherlock’s established infrastructure, operational controls, security processes, documentation templates, procedures and compliance expertise.

Partnering organizations will remain responsible for institution-specific requirements, such as applicable personnel security and cybersecurity awareness training, as well as other responsibilities defined within the shared responsibility framework. Sherlock provides the underlying compliant infrastructure and the operational and compliance capabilities within its defined scope.

This approach significantly reduces the number of controls that institutions must implement and manage locally, minimizing implementation complexity and reducing the effort required to prepare for their CMMC assessment.

Lowering the Barrier to CMMC Compliance

Building and maintaining a CMMC-compliant environment independently can be a significant undertaking, particularly for research universities and smaller DIB organizations that may not have the resources to assemble and sustain the necessary infrastructure and specialized expertise.

Through Sherlock’s shared-services model, participating organizations can access a mature CMMC-compliant platform, established compliance processes, assessment-ready documentation and expert guidance without having to develop a comparable capability independently.

Sherlock brings together a multidisciplinary team of security professionals, cloud architects, systems engineers, compliance specialists and project managers. This allows participating institutions to leverage a deep pool of specialized expertise and proven operational practices without having to recruit and maintain an equivalent team locally.

For many institutions, the annual cost of participating in Sherlock’s shared-services model may be comparable to the cost of adding only a limited number of staff, while providing access to an entire compliance platform and a broad team of experienced practitioners.

The result is a practical pathway to CMMC compliance that can substantially reduce the time, complexity and financial investment traditionally associated with establishing and operating a compliant environment.

Extending UC San Diego’s Investment to the National Research Community

Sherlock’s evolution from an internal UC San Diego capability to a national service provider reflects SDSC’s broader mission of making advanced cyberinfrastructure and specialized expertise available to the research community.

Universities and research institutions increasingly participate in federally funded programs involving Controlled Unclassified Information (CUI), Federal Contract Information (FCI) and other sensitive information. Yet many institutions face significant challenges in developing the infrastructure and expertise necessary to meet federal cybersecurity requirements.

Sherlock provides an opportunity to leverage an environment that has already undergone rigorous assessment and certification, allowing participating organizations to focus their resources on their research and mission rather than duplicating the substantial investments required to establish an equivalent capability.

Potential applications include:

  • Federally funded research involving CUI, FCI and other sensitive information.
  • Secure workflows involving defense, scientific and clinical research data.
  • Collaborative research programs spanning universities, government agencies, national laboratories and industry.
  • Research software development and data analysis requiring controlled computing environments.
  • Defense-related research and development conducted by higher education institutions and DIB organizations.
  • Organizations seeking a practical pathway toward CMMC compliance without building a dedicated environment from the ground up.

Sherlock’s model is intended to complement — not replace — the responsibilities of each customer to understand and satisfy the cybersecurity and contractual requirements applicable to its own organization and information systems.

“As the demand for secure AI, federally supported research and defense collaboration continues to grow, we believe higher education should not have to choose between rigorous cybersecurity and the open, collaborative research environment that enables scientific innovation.”

— Sandeep Chandra, SDSC Stack Science Director

“Ultimately, Sherlock’s approach is about changing the conversation around CMMC in higher education,” Chandra said. Rather than viewing compliance as a costly, multi-year undertaking that requires building a program from the ground up, institutions can leverage a proven framework that dramatically reduces the effort required to achieve certification. Our goal is to help organizations reach the CMMC finish line quickly, confidently, and affordably, ensuring that CMMC becomes an enabler of research opportunities rather than a barrier to participation.”

From Secure Research to Secure AI

SDSC has long supported data-intensive science through high-performance computing, advanced data management and research cyberinfrastructure. Sherlock extends that mission into environments where security, compliance and controlled access are essential.

The combination of secure cloud services and advanced research computing creates opportunities for organizations to conduct secure AI, machine learning, scientific computing and data-intensive research involving federally sensitive information.

“As the demand for secure AI, federally supported research and defense collaboration continues to grow, we believe higher education should not have to choose between rigorous cybersecurity and the open, collaborative research environment that enables scientific innovation,” Chandra said. “Sherlock is designed to provide that bridge — giving institutions and organizations access to a trusted, compliant foundation while allowing them to focus on solving complex scientific and national challenges.”

Archive

Media Contact

Kimberly Mann Bruch
SDSC Communications