Enterprise GRC platforms adapted for small contractors. SaaS tools that put your compliance data in someone else's cloud. Consultants who charge more than your annual contract margin. 1TEN was built from the ground up for the 80,000+ small contractors in the Defense Industrial Base, not scaled down from something built for someone else.
Most CMMC platforms assume you have a CISO, a compliance manager, and an IT team. 1TEN assumes you have one person wearing all three hats alongside everything else they do. Every workflow is designed for that reality.
Every workflow is designed for the IT manager or owner wearing the CISO, compliance, and IT hats at once, alongside everything else they do.
1TEN guides you through all 110 requirements with plain-language explanations, implementation examples, and the exact questions your C3PAO assessor will ask. You learn the standard by documenting it.
Cloud tools store your SSP, policies, and evidence on vendor infrastructure, which may pull that vendor into your assessment boundary. 1TEN runs on your premises with no external data transmission.
Enterprise CMMC platforms charge $30,000 to $100,000+ annually. 1TEN is priced for contractors where compliance cost is measured against real contract margins.
Every C3PAO assessor question from the CMMC Assessment Guide is embedded directly into each of the 110 requirements. No surprises on assessment day, only confirmation of what you documented.
Certification is valid for 3 years with annual affirmations. 1TEN's Compliance Calendar tracks every recurring obligation so your posture doesn't decay between assessments.
The DoD applies the same NIST SP 800-171 standard to every defense contractor regardless of size. A 12-person machine shop with a CUI-bearing subcontract faces identical requirements to a 5,000-person prime. That is the right policy, adversaries don't attack based on company revenue, but it creates a compliance burden that existing tools weren't built to help small contractors absorb.
The small businesses that form the backbone of the defense supply chain, all facing the same standard.
A 12-person shop faces the identical 110 NIST SP 800-171 requirements as a 5,000-person prime.
Compliance burden is a primary driver of attrition from the defense industrial base.
Mandatory third-party C3PAO assessments begin for most Level 2 CUI contractors. The window is shorter than it looks.
1TEN generates your documentation from your actual environment data, calculates your SPRS score as you work, and covers the three-year certification cycle, not just the assessment milestone.
Guided interview through all 110 requirements produces specific, environment-based implementation statements. All 9 required SSP sections auto-generated and exportable to Word or HTML, C3PAO-ready.
Live SPRS score calculation updates as you document each requirement. Point-weight visibility per requirement and no-POA&M flags let you prioritize remediation by score impact.
Every requirement shows the exact questions from the CMMC Assessment Guide that your assessor will ask, with over 1,000 guided questions across 320 assessment objectives.
14 domain policies auto-generated, role-based AT.L2 training with tracked completion, a Compliance Calendar for recurring tasks, and POA&M tracking with 180-day window flags.
When you use a cloud-based compliance platform, your SSP, policies, and evidence may live on vendor infrastructure, which can extend your CMMC assessment boundary to include that vendor. 1TEN eliminates this by architecture, not by policy. The platform ships as an on-premises appliance. After installation, there is no external data transmission, no vendor infrastructure in your scope, and nothing to assess but your own environment.
The C3PAO assessment fee is fixed, no software or consultant changes what a third-party assessment costs. Everything else is where the right platform changes the calculation. The right software doesn't eliminate the cost of CMMC compliance; it eliminates the costs that don't have to be as high as they are.
| Category | Consultant-Led | 1TEN |
|---|---|---|
| Prep & documentation | $15K to $50K+ | Included |
| Compliance platform | $20K to $50K/yr | $15K |
| Security awareness training | $3K to $10K/yr | Included |
| C3PAO assessment | $30K to $55K+ | $30K to $55K+ |
| Annual maintenance | $5K to $15K/yr | $3,495/yr (optional) |
| 3-yr total (est.) | $130K to $275K+ | From $45K |
CMMC Phase 1 began November 10, 2025. Most Level 2 contractors can currently satisfy requirements via self-assessment. Phase 2 begins November 2026, mandatory third-party C3PAO assessments for the majority of Level 2 contractors handling CUI. The realistic preparation timeline is 6 to 12 months, so the window is shorter than it looks.
Level 1 and Level 2 self-assessments required in select contracts. Begin preparation now, not when Phase 2 arrives.
Third-party assessments required for most Level 2 CUI contractors. The 6 to 12 month prep window starts today.
All phases complete. CMMC required across all applicable DoD contracts and subcontracts.
Straight answers, no consultant-speak.
Software purpose-built for the DIB, not an enterprise GRC platform with a CMMC module bolted on. 1TEN: air-gapped on-premises deployment, guided interview through all 110 requirements, automated SSP from your actual environment data, real-time SPRS scoring, and pricing sized for small contractor budgets.
If your contract includes DFARS clause 252.204-7012 and requires handling of CUI, yes, regardless of company size. The same 110 requirements that apply to a 5,000-person prime apply to a 10-person machine shop. Phase 1 began November 10, 2025. Mandatory C3PAO assessments begin November 2026.
Yes, with the right software. 1TEN guides you through all 110 requirements with built-in C3PAO assessor questions, automates your SSP from your environment data, and tracks your SPRS score in real time. A contractor without dedicated compliance staff can run the full program. The C3PAO assessment itself still requires a third-party assessor.
A platform that runs entirely on your own network, with no cloud, no external servers, and no vendor infrastructure. Your SSP, policies, evidence, and compliance data never leave your premises. This eliminates the risk that your compliance tool's vendor enters your CMMC assessment boundary. 1TEN deploys as an on-premises appliance with no external data transmission after installation.
Most small contractors need 6 to 12 months from start to C3PAO assessment readiness. The timeline depends on how many controls are already in place and how fast gaps can be remediated. Purpose-built software compresses the documentation side significantly, a guided SSP that would take months with a consultant can be completed in weeks with 1TEN.
1TEN is the compliance documentation and management layer: your SSP, policies, evidence, training, and SPRS tracking. Your IT provider implements the security controls. The two work in parallel. 1TEN also offers advisory engagements for contractors who need more than software on the path to certification.
1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.
Request a Demo