Incident Response & Operations

Continuity. Engineered.

Passing your C3PAO assessment is the beginning, not the end. The Compliance Calendar tracks every recurring obligation (audit log reviews, access reviews, vulnerability scans, training renewals) so your posture stays current and your annual affirmation is supportable with a real activity trail.

Recurring Task scheduling by interval
Per owner Named accountability
Logged Dated completion history
Capability

Recurring Tasks and Scheduling

The Compliance Calendar works from pre-configured task categories that map to the recurring requirements embedded in CMMC practices: daily backup verification, weekly audit log reviews, monthly access reviews, quarterly vulnerability scans, annual risk assessments, annual training renewals, and annual affirmation submission. Each task can be assigned to a named individual, given a recurrence interval, and set with advance notification.

Tasks appear in the calendar view by due date, and overdue items escalate visually: they show highlighted on the calendar and as open items on the Assessment Summary dashboard. The combination of a due-date view and an overdue indicator means nothing falls through the gap between assessment cycles.

Dashboard Requirements Evidence POA&M Reports
1TEN Compliance Calendar scheduling recurring compliance activities and deadlines
Evidence

Completion History and Assessment Evidence

Every completed task is logged with the completion date, the completing user, and any notes entered at completion. This history is the evidence that ongoing compliance is actually happening, not just scheduled to happen.

When a C3PAO assessor asks for evidence that audit log reviews are occurring periodically, the completion log provides a dated, named record of every review completed during the assessment period. The same applies to access reviews, vulnerability scans, and every other recurring control CMMC requires be performed on an ongoing basis rather than once at certification time.

Inside the Module

What You See Inside

Calendar view
Upcoming and overdue tasks organized by due date, with overdue items highlighted.
Pre-configured task categories
Audit log review, access review, vulnerability scan, backup verification, risk assessment, training renewal, media sanitization, baseline review, and annual affirmation.
Flexible recurrence
Daily, weekly, monthly, quarterly, semi-annual, or annual scheduling per task.
Named ownership
Each task has a single responsible owner and advance notification before it is due.
Completion log
Date, completing user, and optional notes captured for every completed task.
Domain mapping and escalation
Each task links to the CMMC practices it satisfies, and overdue items surface on the Assessment Summary dashboard.
The problem this solves

CMMC is not a one-time certification. It requires that controls are maintained on an ongoing basis: audit logs reviewed regularly, access lists reviewed periodically, vulnerability scans run on schedule, training renewed annually. When an assessor asks to see your last six months of audit log reviews, the answer needs to be a dated completion log, not a policy that says reviews should happen. No more reminders scattered across personal inboxes, no more policies that claim reviews happen with nothing to prove it, no more recurring tasks with no named owner accountable for them.

Reference

Pre-Configured Recurring Tasks

Audit Log Review
Weekly by default · AU domain.
AU.L2-3.3.1
Privileged Access Review
Quarterly by default · AC domain.
AC.L2-3.1.6
User Access Review
Semi-annual by default · AC domain.
AC.L2-3.1.1
Vulnerability Scan
Monthly by default · RA domain.
RA.L2-3.11.2
Backup Verification
Weekly by default · SI domain.
SI.L2-3.14.1
Risk Assessment Review
Annual by default · RA domain.
RA.L2-3.11.1
Security Awareness Training
Annual by default · AT domain.
AT.L2-3.2.1
Media Sanitization Log Review
Monthly by default · MP domain.
MP.L2-3.8.3
Configuration Baseline Review
Quarterly by default · CM domain.
CM.L2-3.4.1
Annual SPRS Affirmation
Annual by default · CA domain.
32 CFR Part 117
Practices

Practices Satisfied

Practice IDDescription
CA.L2-3.12.3 Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
AU.L2-3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
RA.L2-3.11.1 Periodically assess the risk to organizational operations, assets, and individuals. Periodic review scheduling and completion logging satisfies the frequency requirement.
AT.L2-3.2.1 Ensure that organizational personnel are aware of the security risks associated with their activities. Annual training renewal tracking satisfies the ongoing awareness requirement.
MA.L2-3.7.1 Perform maintenance on organizational systems.
Connected Modules

Related Modules

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo