Documentation & Reporting

Policies. Engineered.

CMMC Level 2 requires a written policy for each of the 14 security domains. 1TEN generates all 14 from the configuration and implementation data you entered during your requirements assessment, so each policy describes your actual environment instead of a blank template.

14 CMMC domain policies generated
Per policy Version history and approvals
Word export Formatted for review and signing
Capability

What Drives Generation

Each policy is built from the implementation data you entered when assessing your requirements: which tools handle each control, how access is provisioned, who owns each domain, and what your incident response procedures actually are. The Policy Generator synthesizes that data into policy language that describes your specific environment, not a hypothetical one.

The difference shows the moment an assessor reads it. A policy that names your MFA platform, describes the enrollment process, and identifies the administrator responsible for exceptions reads as genuine. It answers the follow-up questions before they are asked. A template policy invites them.

Dashboard Requirements Evidence POA&M Reports
1TEN Policy Generator producing CMMC policies covering all 14 domains
Capability

Procedures Alongside Policies

Policies state what your organization does. Procedures describe how it gets done, and CMMC assessors examine both. A policy without supporting procedures is an incomplete documentation package. The Policy Generator produces the domain-level policy and the associated procedures together, keeping the two in sync as your environment changes.

Procedures are generated at the practice level, with step-by-step implementation detail for the controls that require it. When a requirement asks you to document how your organization handles media sanitization or how incident response notifications are made, the procedure output gives assessors the specificity they need to verify the control without an extended interview.

Inside the Module

What You See Inside

14 domain policies
Generated from your requirements-assessment data across every CMMC domain: AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, and SI.
Specific to you
Policy content references your actual tools, systems, and responsible parties, not generic placeholders.
Procedures included
Practice-level procedures generated alongside each domain policy, kept in sync with it.
Versioned and approved
Every regeneration creates a new version with prior versions preserved, plus an approval workflow tracking reviewer, date, and signature.
Word export
Export formatted with policy statement, scope, roles, procedures, and practice references for final review and signing.
In the SSP, regenerated on demand
Policies embed in the SSP Export package, and regenerate when you update an implementation detail in the Requirements Browser.
The problem this solves

Generic policy templates are one of the most reliable ways to fail a C3PAO assessment. Assessors read policies first and use them to set expectations for the rest of the review. A policy that says "the organization will implement multi-factor authentication" without naming the system, the method, or the responsible party describes an aspiration, not an implementation, and any gap between that language and what the assessor observes becomes a finding. No more internet templates lightly edited, no more consultant policies that go stale the next time a tool changes, no more policy language that contradicts what the assessor sees in the environment.

Coverage

All 14 Domain Policies

Access Control Policy
User access provisioning, least privilege, remote access, and CUI access controls.
AC
Awareness and Training Policy
Security awareness training requirements, role-based training, and frequency.
AT
Audit and Accountability Policy
Audit log requirements, retention period, review frequency, and protection.
AU
Configuration Management Policy
Baseline configuration, change control, software restrictions, and least functionality.
CM
Identification and Authentication Policy
Authenticator management, MFA requirements, password policy, and privileged accounts.
IA
Incident Response Policy
Incident reporting, response procedures, notification requirements, and testing.
IR
Maintenance Policy
Authorized maintenance, remote maintenance controls, and maintenance personnel.
MA
Media Protection Policy
Media access, transport, sanitization, disposal, and CUI marking.
MP
Personnel Security Policy
Personnel screening, termination procedures, and transfer controls.
PS
Physical Protection Policy
Physical access controls, visitor management, monitoring, and facility protection.
PE
Risk Assessment Policy
Risk assessment frequency, vulnerability scanning, and risk response.
RA
Security Assessment Policy
Control assessment, POA&M management, and system security plan maintenance.
CA
System and Comms Protection Policy
Boundary protection, encryption, network segmentation, and remote access.
SC
System and Info Integrity Policy
Malware protection, security alerts, patch management, and monitoring.
SI
Practices

Practices Satisfied

Practice IDDescription
All 14 Domains Domain-level policy requirements across Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity, and Awareness and Training.
CA.L2-3.12.4 Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, and how security requirements are implemented.
Connected Modules

Related Modules

Your SPRS score, live.

1TEN maps your documented controls to all 110 NIST SP 800-171 requirements and scores your posture in real time.

Request a Demo