CMMC. Engineered.

The all-in-one CMMC readiness platform built for small defense manufacturers.

Learn more about 1TEN

CMMC Phase 2 enforcement begins November 2026. What is your SPRS Score?

What you need to know

Built with Purpose. Engineered for Compliance.

1TEN Compliance Manager covers every NIST SP 800-171 requirement your C3PAO assessor will check. On-premises, air-gapped, and built specifically for small manufacturers in the DIB.

Watch a platform demo
Evidence Management
POA&M Management
Dashboard Metrics
Document Management
Policy Management
Live SPRS Scoring
SSP Generation
Asset Tracking

Every requirement. Mapped. Scored. Documented.

1TEN maps your live environment against every NIST SP 800-171 control. It calculates your SPRS score in real time, generates your SSP automatically, and builds a C3PAO-ready evidence package.

Access Control
AC — Access Control
Demo Defense Contractors Inc. 🔔 Demo Admin
AC

Access Control

Limit system access to authorized users, processes, and devices.

22 Requirements
All Met Not Met Pending
Code Requirement Objectives Status Progress
AC.L2-3.1.1 Authorized Access Control 6 Met
6/6
AC.L2-3.1.2 Transaction & Function Control 2 Met
1/2
AC.L2-3.1.3 Control CUI Flow 5 Met
1/5
AC.L2-3.1.4 Separation of Duties 3 Met
1/3
AC.L2-3.1.5 Least Privilege 4 Met
1/4
AC.L2-3.1.6 Non-Privileged Account Use 2 Met
1/2
AC.L2-3.1.7 Privileged Functions 4 Met
1/4
AC.L2-3.1.8 Unsuccessful Logon Attempts 2 Met
1/2
AC.L2-3.1.20 External System Connections 6 Not Met
0/6
AC.L2-3.1.21 Portable Storage Use 3 Not Met
0/3

Engineered for the Defense Industrial Base.

Every contractor handling CUI faces the same 110 requirements. 1TEN was engineered to meet every one without building a compliance department around it. The platform does the work so your team can stay focused on the mission.

DoD Contractor
NAICS 336413
C3PAO Ready
DFARS Compliant
Air-Gapped
On-Premises
SPRS Scoring
SSP Generator

The Latest

Guides, assessments, and regulatory updates for defense contractors navigating CMMC Level 2.

Recent
Assessment Readiness
SPRS & Scoring
Documentation
Regulation
News
CMMC

DoD Suspends CMMC Phase 2: What Changed, What Didn't, What to Do

On July 13, 2026 the DoD immediately suspended CMMC Phase 2 third-party certification and stood up a 60-day reform task force. The certification mechanism is under review. DFARS 252.204-7012, NIST 800-171, self-assessment, and SPRS scores are not. Here is exactly what changed and what contractors should do.

Read the article →
CM

CMMC Specialized Assets: OT, IoT, GFE & Test Equipment Explained

The five CMMC Level 2 Specialized Asset types (OT, IoT/IIoT, GFE, Restricted Information Systems, and Test Equipment): how they are scoped, documented in the SSP, and why they are not assessed against all 110 requirements.

Read the article →
CMMC

The Phase 2 Deadline Is a Queue, Not a Date: The C3PAO Capacity Math

Phase 2 is a scheduling problem, not a calendar problem. The real assessment-capacity numbers from the February 2026 Cyber AB Town Hall, the working-backwards timeline, the conditional certification path, and what to do this quarter.

Read the guide →
REGCA

CMMC Is Becoming the New SOC 2 — And That's Bigger Than Defense

CMMC Level 2 is more prescriptive than SOC 2, independently verified, and increasingly recognized by cyber insurance underwriters. Here is why that matters even if you never touch a DoD contract.

Read the analysis →
“Our SPRS score went from -67 to +98 in four months. Having every requirement mapped to evidence in one place made the difference — our assessor commented on how organized the documentation was.”
Program Manager · Defense Electronics Contractor

Stay in the fight.

Request a demo