Practitioner Guide

CMMC Registered Practitioner Software Tools:
What RPs Use to Serve DIB Clients

Most content about CMMC RPs explains what an RP is. This covers what they actually need to do the work — the software that makes an RP engagement efficient, defensible, and repeatable across clients.

Published April 22, 2026

What RPs Do The Tooling Problem Gap Assessment SSP Tools POA&M & SPRS Policy Generation Evidence Ongoing Compliance 1TEN for RPs FAQ

What a CMMC Registered Practitioner Actually Does for a Client

A CMMC Registered Practitioner provides advisory services to help organizations seeking certification (OSCs) prepare for a C3PAO assessment. The Cyber AB defines the role as delivering "non-certified advisory services" — meaning RPs do not conduct formal assessments, but they handle everything that happens before one.

In practice, an RP engagement with a small DIB contractor covers the full compliance journey:

PhaseWhat the RP DoesOutput
Gap Assessment Evaluates current implementation status against all 110 NIST SP 800-171 requirements. Identifies which controls are met, partially met, or not implemented. Gap report, initial SPRS score
Scoping Defines the assessment boundary: which systems, users, and services process, store, or transmit CUI. Determines what is in scope and what can be excluded. System boundary diagram, asset inventory
SSP Development Builds or guides the client through building the System Security Plan — per-requirement implementation statements, user types, CUI data flows, policy references, and POA&M tie-ins. Complete SSP document
POA&M Management Documents unmet requirements with realistic remediation timelines, named owners, and interim mitigations. Tracks progress toward closure within the 180-day window for conditional certification. Active POA&M with milestones
Policy Development Produces or reviews the 14 domain-specific security policies required for CMMC Level 2. Ensures policies reflect the client's actual environment rather than generic templates. 14 domain policy documents
Evidence Organization Collects, organizes, and maps evidence artifacts to the requirements they satisfy. Ensures assessors can find what they need during the C3PAO assessment without searching. Evidence package linked to requirements
Remediation Guidance Advises on how to close specific gaps — which tools satisfy which requirements, what configuration changes are needed, which gaps carry higher SPRS risk. Prioritized remediation roadmap
Ongoing Maintenance Manages the compliance calendar between certification cycles: annual affirmations, training renewals, policy reviews, and recurring assessment tasks. Compliance calendar, audit readiness

The Tooling Problem Most RPs Face

The CMMC ecosystem has a lot of content about what RPs are and how to become one. It has very little about how RPs do the work efficiently across multiple clients. The default approach most practitioners use — spreadsheets, Word documents, and shared folders — creates compounding problems:

Version control and accuracy drift

An SSP written in Word and stored in a shared folder degrades in accuracy within weeks. Every time a client changes a tool, adds a user, or closes a POA&M item, someone has to remember to update the document. In practice, they often do not. The document diverges from reality. By the time the C3PAO assessor reviews it, the SSP describes an organization that no longer exists.

No systematic evidence linkage

Assessors work from an evidence index — they ask for artifacts by requirement ID and expect to receive them quickly. A folder of PDFs, screenshots, and configuration exports with no mapping to specific requirements means searching under pressure on assessment day. That search does not instill confidence in your client's compliance posture.

SPRS scoring errors

Manually calculating an SPRS score from a spreadsheet is error-prone. Point weights are not uniform: 44 requirements carry 5-point deductions, 14 carry 3-point deductions, and the remaining 52 carry 1-point deductions or less (one requirement, the system security plan itself, isn't point-scored at all). MFA (IA.L2-3.5.3) and FIPS encryption (SC.L2-3.13.11) have conditional scoring rules that spreadsheets rarely capture correctly. An inaccurate SPRS submission carries False Claims Act exposure for the client.

No repeatable delivery model

Engagements built on custom documents for each client do not scale. Each new client is a rebuild from scratch. The time spent re-creating structures that could be standardized is time that could be spent on substantive compliance work — or additional client engagements.

Gap Assessment Tools

The first deliverable in any RP engagement is a gap assessment: where does this client stand against all 110 requirements, and what is their current SPRS score. The tool used for this shapes everything that follows.

What a gap assessment tool needs to do

Walk through all 110 NIST SP 800-171 Rev 2 requirements in a structured interview format. Record implementation status (met, not met, partially implemented, not applicable) for each requirement. Apply the correct SPRS point weights automatically. Distinguish which gaps are POA&M eligible (1-point requirements only, plus the SC.L2-3.13.11 FIPS exception) from those that must be fully remediated before assessment. Surface the highest-impact gaps by point value so remediation can be prioritized.

What to avoid

Generic GRC platforms (Vanta, Drata, ServiceNow) map CMMC as a framework overlay on top of SOC 2 or ISO 27001 infrastructure. They do not enforce DoD scoring rules, do not distinguish POA&M-eligible from non-eligible gaps, and do not generate a C3PAO-ready audit package in the format assessors expect. They are compliance automation tools, not CMMC-specific assessment platforms. Using them for CMMC Level 2 preparation produces documentation that looks professional but fails scrutiny at the requirement level.

SSP Generation: The Document That Determines Assessment Outcomes

The System Security Plan is required by CA.L2-3.12.4 and is the first document a C3PAO assessor reads. It must describe your client's actual environment with enough specificity that an independent assessor can verify every claim. An SSP generated from operational data — asset inventory, user roles, implemented controls, evidence artifacts — is fundamentally different from an SSP filled out from a template.

Template-based SSPs and why they fail

Templates circulate widely and are genuinely useful for understanding the document's structure. The problem is that a template is structurally correct and substantively empty. Assessors are trained to distinguish an SSP that describes a real environment from one that was filled out from a form. Generic implementation statements like "the organization uses industry-standard access controls" generate harder scrutiny in interviews, not less. Specificity is what passes. The tool's name, the configuration, the responsible person, the evidence location.

Generated SSPs vs. written SSPs

The most defensible SSPs are generated from the data captured during the gap assessment itself. When an RP walks a client through the 1TEN Requirements Browser — recording how each of the 110 requirements is implemented — those implementation statements become the per-requirement section of the SSP. The asset inventory populates the system boundary section. The user role documentation feeds the user types section. The POA&M tracker feeds the open items. The SSP Export module produces a formatted Word document from all of it. No compilation. No copy-paste. No version drift.

What assessors look for in an SSP
Specific tool names and configurations for each implemented control. Real user roles, not placeholder descriptions. A system boundary that matches the actual infrastructure. Evidence references by artifact name and location. POA&M items with realistic timelines and named owners. The absence of any of these signals to an assessor that the document was not built from actual compliance data.

POA&M and SPRS Scoring Tools

POA&M management and SPRS scoring are closely linked. The POA&M documents which requirements are not yet met. The SPRS score reflects how many points those gaps represent. Both need to be accurate before the client submits to SPRS or enters a C3PAO assessment.

POA&M eligibility — the rule most tools get wrong

Under 32 CFR 170.21, only requirements with a point value of 1 are eligible to appear on a POA&M for conditional CMMC certification. There is one exception: SC.L2-3.13.11 (FIPS-validated encryption) may appear on a POA&M if encryption is employed but not FIPS-validated, even though it carries a 3-point deduction. Any other 3-point or 5-point requirement left in a POA&M disqualifies the client from conditional certification. Many general-purpose compliance tools do not enforce this rule. An RP building a POA&M that includes ineligible items is setting a client up for an assessment failure.

SPRS scoring accuracy

The DoD Assessment Methodology assigns 5 points to 44 requirements, 3 points to 14 requirements, and 1 point to 51 more (the remaining requirement, the system security plan itself, isn't point-scored). MFA (IA.L2-3.5.3) has conditional scoring: 5 points if not implemented for any users, 3 points if implemented for privileged and remote users but not all users. FIPS encryption (SC.L2-3.13.11) has conditional scoring: 5 points if no encryption is used, 3 points if encryption is used but not FIPS-validated. A spreadsheet that does not account for these rules produces an inaccurate score. 1TEN calculates SPRS in real time as requirements are assessed, applies conditional scoring rules automatically, and updates the score when POA&M items are closed.

180-day POA&M closeout tracking

Conditional CMMC certification requires that all POA&M items be closed within 180 days of the assessment date. That timeline starts running on the day the conditional status is granted. An RP managing a client through the closeout period needs a tool that tracks milestones, surfaces approaching deadlines, and documents progress toward closure. A spreadsheet without automatic reminders and a clear view of days remaining is not adequate for managing a 180-day deadline with contract eligibility on the line.

Policy Generation: 14 Domain Policies, Not 14 Generic Templates

CMMC Level 2 requires documented policies covering all 14 domains: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

Generic policy templates pulled from the internet fail the same way generic SSPs fail: they describe a fictional organization, not the client's actual environment. Assessors verify that policies are implemented, not merely documented. A policy that says "the organization enforces MFA for all privileged accounts" is meaningless if the implementation statements in the SSP say MFA is only deployed for remote users.

1TEN's Policy Generator produces all 14 domain policies from the implementation data captured in the Requirements Browser. The policies reference the actual tools, configurations, and procedures the client uses — because they are generated from the same data that drives the SSP. Consistency between the SSP and the policies is automatic, not something the RP has to manually verify and reconcile.

Evidence Management: Linking Artifacts to Requirements

Evidence management is the most labor-intensive part of a CMMC engagement and the area where disorganization does the most damage on assessment day. C3PAO assessors ask for evidence by requirement ID. They expect to receive it quickly. An evidence package that requires searching is a package that looks unprepared.

What an evidence management tool needs to provide

Direct linkage between artifacts and the specific requirement IDs they satisfy. Support for multiple artifact types: screenshots, configuration exports, policy documents, training records, audit logs. Version history so the most current artifact is always what the assessor sees. An evidence index — preferably generated directly into the SSP — that maps every requirement to its supporting artifacts.

What happens without it

Evidence lives in email threads, shared folders with inconsistent naming, and individual laptops. When the assessor asks for evidence of AU.L2-3.3.8 (protecting audit information), someone searches for a screenshot that may or may not have been saved anywhere accessible. The search takes 20 minutes, during which the assessor is forming an impression of the program's maturity. That impression affects findings.

Ongoing Compliance: The Work Between Certifications

CMMC Level 2 certification is valid for three years, but it is not a set-and-forget event. Annual affirmations, recurring training renewals, policy reviews, and the POA&M closeout timeline require active management throughout the certification cycle. RPs who build their client relationships around ongoing compliance support — rather than point-in-time assessment preparation — create recurring revenue and deeper client retention.

That ongoing relationship requires a tool that surfaces recurring tasks, tracks completion, and flags when something is approaching a deadline. A compliance calendar integrated with the requirements data ensures that the annual requirement to review and update the SSP (CA.L2-3.12.4) does not get missed, that security awareness training (AT.L2-3.2.1) renewals are tracked by user, and that POA&M milestone dates are visible before they lapse.

How 1TEN Is Built for RP Engagements

1TEN is a purpose-built CMMC Level 2 compliance platform deployed as an on-premises appliance. It covers all 110 NIST SP 800-171 Rev 2 requirements and produces the documentation required for C3PAO third-party assessments. For RPs, it provides a structured delivery model for the full engagement lifecycle:

RP Need1TEN ModuleWhat It Produces
Gap assessment across all 110 requirements Requirements Browser Implementation status by requirement, C3PAO-level assessment questions embedded, real-time SPRS score
SPRS score with correct point weights SPRS Scoring (built into Requirements Browser) Live score with conditional MFA and FIPS rules applied, score history over time
SSP generation from actual assessment data SSP Export Formatted Word document with all required sections, per-requirement implementation statements, evidence index
POA&M with eligibility enforcement and 180-day tracking POA&M Tracker Structured POA&M with milestone dates, owner assignments, Wazuh automation integration for eligible items
14 domain policies that match the SSP Policy Generator All 14 domain policies generated from Requirements Browser data, consistent with SSP implementation statements
Evidence organization linked to requirements Evidence Manager Artifact upload and direct requirement linkage, evidence index populated into SSP export
Ongoing compliance calendar Compliance Calendar Recurring tasks mapped to CMMC requirements, annual affirmation reminders, training renewal tracking
CUI boundary definition CUI Scoping Wizard + Data Flow Diagrams Guided boundary scoping, visual CUI data flow documentation for SSP and assessor review
Security awareness training records Training Module 10 training modules with completion tracking, satisfying AT domain requirements
SIEM capability on-premises Wazuh Integration (optional) On-premises log collection and alerting, POA&M automation for SI and AU requirements

Because 1TEN is deployed on-premises at the client site, all compliance data — SSPs, policies, evidence, assessment records — stays within the client's network. This matters for two reasons. First, it eliminates the CUI boundary question that arises when using cloud-based compliance tools: if your SSP and evidence artifacts are stored in a vendor's cloud, that infrastructure may fall within your assessment scope. On-premises deployment avoids that entirely. Second, it aligns with the security principle underlying the whole exercise — your compliance documentation for a program designed to protect CUI should not be stored where you cannot control access to it.

1TEN RP Partner Program
1TEN has a dedicated partner program for CMMC Registered Practitioners and RPOs who want to add a software-backed delivery model to their consulting practice. Partner RPs deploy 1TEN at client sites as part of their engagement model, providing clients with a platform that stays active through the three-year certification cycle. If you work with DIB contractors and want to discuss what a 1TEN-backed engagement looks like, the partner contact form is at /partners/contact.

Frequently Asked Questions

What software do CMMC Registered Practitioners actually use?

Most RPs use a mix of tools depending on the engagement: a compliance or GRC platform for tracking the 110 requirements, Word or Excel for SSP and POA&M documentation, and file storage for evidence organization. The problem with this approach is that it does not scale well and creates version drift between documents. RPs who use a purpose-built CMMC platform like 1TEN work from a single system that handles gap assessment, SSP generation, POA&M tracking, SPRS scoring, and evidence management — generating C3PAO-ready output directly from assessment data.

Can an RP conduct a CMMC assessment?

No. RPs provide advisory and preparation services — gap assessments, SSP development, POA&M management, policy development, evidence organization — but they cannot conduct formal CMMC certification assessments. That is reserved for C3PAOs. RPs also cannot participate in the C3PAO assessment for a client they have advised, to prevent conflicts of interest. The intended model is RP prepares the client, C3PAO independently assesses.

What is the biggest mistake RPs make in client engagements?

The most consequential mistake is building documentation — SSPs, POA&Ms, policies — that does not accurately reflect the client's actual environment. Generic implementation statements, incorrect SPRS calculations (especially for the MFA and FIPS conditional scoring rules), and POA&Ms that include non-eligible requirements all create problems at assessment time. The second most consequential mistake is not managing the 180-day POA&M closeout timeline actively. Conditional certification with a missed 180-day window results in status expiration.

Why deploy 1TEN on-premises rather than use a cloud-based CMMC tool?

Two reasons matter most for RPs advising small DIB contractors. First, if a cloud-based compliance tool stores the client's SSP, policies, and evidence — documents that describe and reference CUI handling — that data may qualify as CUI itself, pulling the vendor's cloud infrastructure into the client's assessment boundary. On-premises deployment eliminates that question entirely. Second, small contractors often have concerns about their sensitive compliance documentation residing in a shared cloud environment. An on-premises appliance keeps all data within their own network, which is the right answer for an organization trying to demonstrate control over their information environment.

Does 1TEN have a formal RP partner program?

Yes. 1TEN's RP partner program is designed for CMMC Registered Practitioners and RPOs who want to add a software-backed delivery model to their consulting practice. Partner RPs deploy 1TEN at client sites as part of their engagement, providing clients with a platform that remains active through the three-year certification cycle. For more detail on how the partner program works, visit /partners or contact the partner team directly at /partners/contact.

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo