Built for Small Defense Contractors

Most CMMC software wasn't built for you.

Enterprise GRC platforms adapted for small contractors. SaaS tools that put your compliance data in someone else's cloud. Consultants who charge more than your annual contract margin. 1TEN was built from the ground up for the 80,000+ small contractors in the Defense Industrial Base, not scaled down from something built for someone else.

80K+ small contractors in the DIB needing CMMC Level 2
110 NIST SP 800-171 requirements, the same for every contractor
40% decline in small DIB businesses over the past decade
Nov '26 Phase 2 mandatory third-party assessment deadline

What "built for small contractors" actually means.

Most CMMC platforms assume you have a CISO, a compliance manager, and an IT team. 1TEN assumes you have one person wearing all three hats alongside everything else they do. Every workflow is designed for that reality.

One person can run the entire program

Every workflow is designed for the IT manager or owner wearing the CISO, compliance, and IT hats at once, alongside everything else they do.

You don't need to already know NIST 800-171

1TEN guides you through all 110 requirements with plain-language explanations, implementation examples, and the exact questions your C3PAO assessor will ask. You learn the standard by documenting it.

Your compliance data never leaves your building

Cloud tools store your SSP, policies, and evidence on vendor infrastructure, which may pull that vendor into your assessment boundary. 1TEN runs on your premises with no external data transmission.

Pricing reflects what small contractors earn

Enterprise CMMC platforms charge $30,000 to $100,000+ annually. 1TEN is priced for contractors where compliance cost is measured against real contract margins.

Know what your assessor will ask

Every C3PAO assessor question from the CMMC Assessment Guide is embedded directly into each of the 110 requirements. No surprises on assessment day, only confirmation of what you documented.

Compliance doesn't end at the assessment

Certification is valid for 3 years with annual affirmations. 1TEN's Compliance Calendar tracks every recurring obligation so your posture doesn't decay between assessments.

Same 110 requirements. A fraction of the resources.

The DoD applies the same NIST SP 800-171 standard to every defense contractor regardless of size. A 12-person machine shop with a CUI-bearing subcontract faces identical requirements to a 5,000-person prime. That is the right policy, adversaries don't attack based on company revenue, but it creates a compliance burden that existing tools weren't built to help small contractors absorb.

80K+
Small contractors needing CMMC Level 2

The small businesses that form the backbone of the defense supply chain, all facing the same standard.

110
Requirements, same for every contractor

A 12-person shop faces the identical 110 NIST SP 800-171 requirements as a 5,000-person prime.

40%
Decline in small DIB businesses over 10 years

Compliance burden is a primary driver of attrition from the defense industrial base.

Nov '26
Phase 2 mandatory assessment deadline

Mandatory third-party C3PAO assessments begin for most Level 2 CUI contractors. The window is shorter than it looks.

A real SSP, live SPRS scoring, and the full lifecycle.

1TEN generates your documentation from your actual environment data, calculates your SPRS score as you work, and covers the three-year certification cycle, not just the assessment milestone.

A real SSP, not a template

Guided interview through all 110 requirements produces specific, environment-based implementation statements. All 9 required SSP sections auto-generated and exportable to Word or HTML, C3PAO-ready.

Know your SPRS score before you submit it

Live SPRS score calculation updates as you document each requirement. Point-weight visibility per requirement and no-POA&M flags let you prioritize remediation by score impact.

Embedded C3PAO assessor questions

Every requirement shows the exact questions from the CMMC Assessment Guide that your assessor will ask, with over 1,000 guided questions across 320 assessment objectives.

Policies, training, and ongoing compliance

14 domain policies auto-generated, role-based AT.L2 training with tracked completion, a Compliance Calendar for recurring tasks, and POA&M tracking with 180-day window flags.

Air-gapped. On-premises. By design.
When you use a cloud-based compliance platform, your SSP, policies, and evidence may live on vendor infrastructure, which can extend your CMMC assessment boundary to include that vendor. 1TEN eliminates this by architecture, not by policy. The platform ships as an on-premises appliance. After installation, there is no external data transmission, no vendor infrastructure in your scope, and nothing to assess but your own environment.

What CMMC compliance actually costs.

The C3PAO assessment fee is fixed, no software or consultant changes what a third-party assessment costs. Everything else is where the right platform changes the calculation. The right software doesn't eliminate the cost of CMMC compliance; it eliminates the costs that don't have to be as high as they are.

CategoryConsultant-Led1TEN
Prep & documentation$15K to $50K+Included
Compliance platform$20K to $50K/yr$15K
Security awareness training$3K to $10K/yrIncluded
C3PAO assessment$30K to $55K+$30K to $55K+
Annual maintenance$5K to $15K/yr$3,495/yr (optional)
3-yr total (est.)$130K to $275K+From $45K
The fixed cost
The C3PAO assessment fee is identical in both scenarios. It cannot be reduced by any software or consultant. What a purpose-built platform reduces is everything around it: prep, documentation, the compliance tool itself, training, and ongoing maintenance.

November 2026. The window is now.

CMMC Phase 1 began November 10, 2025. Most Level 2 contractors can currently satisfy requirements via self-assessment. Phase 2 begins November 2026, mandatory third-party C3PAO assessments for the majority of Level 2 contractors handling CUI. The realistic preparation timeline is 6 to 12 months, so the window is shorter than it looks.

Nov 2025
Phase 1 — Active Now

Level 1 and Level 2 self-assessments required in select contracts. Begin preparation now, not when Phase 2 arrives.

Nov 2026
Phase 2 — Mandatory C3PAO

Third-party assessments required for most Level 2 CUI contractors. The 6 to 12 month prep window starts today.

Nov 2028
Full Enforcement

All phases complete. CMMC required across all applicable DoD contracts and subcontracts.

Start now

Common questions from small defense contractors.

Straight answers, no consultant-speak.

What CMMC software is best for small defense contractors?

Software purpose-built for the DIB, not an enterprise GRC platform with a CMMC module bolted on. 1TEN: air-gapped on-premises deployment, guided interview through all 110 requirements, automated SSP from your actual environment data, real-time SPRS scoring, and pricing sized for small contractor budgets.

Do small defense contractors need CMMC Level 2?

If your contract includes DFARS clause 252.204-7012 and requires handling of CUI, yes, regardless of company size. The same 110 requirements that apply to a 5,000-person prime apply to a 10-person machine shop. Phase 1 began November 10, 2025. Mandatory C3PAO assessments begin November 2026.

Can a small contractor do CMMC without a consultant?

Yes, with the right software. 1TEN guides you through all 110 requirements with built-in C3PAO assessor questions, automates your SSP from your environment data, and tracks your SPRS score in real time. A contractor without dedicated compliance staff can run the full program. The C3PAO assessment itself still requires a third-party assessor.

What is an air-gapped CMMC compliance platform?

A platform that runs entirely on your own network, with no cloud, no external servers, and no vendor infrastructure. Your SSP, policies, evidence, and compliance data never leave your premises. This eliminates the risk that your compliance tool's vendor enters your CMMC assessment boundary. 1TEN deploys as an on-premises appliance with no external data transmission after installation.

How long does CMMC Level 2 certification take?

Most small contractors need 6 to 12 months from start to C3PAO assessment readiness. The timeline depends on how many controls are already in place and how fast gaps can be remediated. Purpose-built software compresses the documentation side significantly, a guided SSP that would take months with a consultant can be completed in weeks with 1TEN.

Where does 1TEN fit if we already have an IT provider?

1TEN is the compliance documentation and management layer: your SSP, policies, evidence, training, and SPRS tracking. Your IT provider implements the security controls. The two work in parallel. 1TEN also offers advisory engagements for contractors who need more than software on the path to certification.

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo