The all-in-one CMMC readiness platform built for small defense manufacturers.
Learn more about 1TEN1TEN Compliance Manager covers every NIST SP 800-171 requirement your C3PAO assessor will check. On-premises, air-gapped, and built specifically for small manufacturers in the DIB.
Watch a platform demoAccess Control
Limit system access to authorized users, processes, and devices.
| Code | Requirement | Objectives | Status | Progress | |
|---|---|---|---|---|---|
| AC.L2-3.1.1 | Authorized Access Control | 6 | Met |
|
› |
| AC.L2-3.1.2 | Transaction & Function Control | 2 | Met |
|
› |
| AC.L2-3.1.3 | Control CUI Flow | 5 | Met |
|
› |
| AC.L2-3.1.4 | Separation of Duties | 3 | Met |
|
› |
| AC.L2-3.1.5 | Least Privilege | 4 | Met |
|
› |
| AC.L2-3.1.6 | Non-Privileged Account Use | 2 | Met |
|
› |
| AC.L2-3.1.7 | Privileged Functions | 4 | Met |
|
› |
| AC.L2-3.1.8 | Unsuccessful Logon Attempts | 2 | Met |
|
› |
| AC.L2-3.1.20 | External System Connections | 6 | Not Met |
|
› |
| AC.L2-3.1.21 | Portable Storage Use | 3 | Not Met |
|
› |
Every contractor handling CUI faces the same 110 requirements. 1TEN was engineered to meet every one without building a compliance department around it. The platform does the work so your team can stay focused on the mission.
Guides, assessments, and regulatory updates for defense contractors navigating CMMC Level 2.
On July 13, 2026 the DoD immediately suspended CMMC Phase 2 third-party certification and stood up a 60-day reform task force. The certification mechanism is under review. DFARS 252.204-7012, NIST 800-171, self-assessment, and SPRS scores are not. Here is exactly what changed and what contractors should do.
Read the article →The five CMMC Level 2 Specialized Asset types (OT, IoT/IIoT, GFE, Restricted Information Systems, and Test Equipment): how they are scoped, documented in the SSP, and why they are not assessed against all 110 requirements.
Read the article →Phase 2 is a scheduling problem, not a calendar problem. The real assessment-capacity numbers from the February 2026 Cyber AB Town Hall, the working-backwards timeline, the conditional certification path, and what to do this quarter.
Read the guide →CMMC Level 2 is more prescriptive than SOC 2, independently verified, and increasingly recognized by cyber insurance underwriters. Here is why that matters even if you never touch a DoD contract.
Read the analysis →“Our SPRS score went from -67 to +98 in four months. Having every requirement mapped to evidence in one place made the difference — our assessor commented on how organized the documentation was.”Program Manager · Defense Electronics Contractor