Assessment & Evidence

CMMC Requirements Tracking Software

All 110 NIST SP 800-171 practices. All 14 domains. Every assessment objective tracked at the granular level your C3PAO assessor will actually evaluate. With your SPRS score updating in real time as you work.

110 Practices tracked
320+ Assessment objectives
−203 to +110 SPRS range
14 CMMC domains
The Problem How It Works What You See Inside Requirements Coverage Why 1TEN

Most DIB contractors fail CMMC assessments they should pass

The typical defense contractor approaching CMMC Level 2 has the security controls in place. What they're missing is the documentation. Implementation statements tied to specific systems, objective-level evidence mapped to each of the 320+ assessment criteria your C3PAO will examine.

Spreadsheets and manual tracking can't do this at scale. By the time you've mapped all 110 practices to objectives, statuses, evidence, responsible parties, and implementation notes across 14 domains, your data is already stale. And your SPRS score is a guess, not a calculation.

The Requirements Browser is the operational core of 1TEN. It's where all 110 CMMC Level 2 practices live, get assessed, and automatically feed every other module. Your SSP, your POA&M, your SPRS score, your Assessment Guide. Before any other module can do its job, this is where the work happens.

How CMMC requirements tracking works in 1TEN

Every practice maps to its NIST SP 800-171A assessment objectives. The granular statements that define what "met" actually means. For each objective you record status, assessment method (Examine, Interview, or Test), implementation notes, linked evidence files, and responsible party. Nothing is left implicit.

Dashboard Requirements Evidence POA&M Reports
1TEN Requirements Browser showing all 110 NIST SP 800-171 requirements with implementation status and live SPRS score
  • * Status tracked at the objective level, matching how C3PAO assessors actually evaluate
  • * Real-time SPRS score recalculates automatically as you update any objective status
  • * Implementation notes, evidence links, and responsible party recorded per objective
  • * Filter by domain, status, or practice number to focus on gaps
  • * Assessment method captured per NIST SP 800-171A methodology
  • * Every determination flows into Assessment Summary, POA&M, and SSP without re-entry

What you see inside the Requirements Browser

Here's the actual software your team will use to work through each domain. Every row is a CMMC practice. Every row expands to the full objective-level detail your assessor will evaluate.

Requirements Browser: Live Interface HTML source coming

Evidence linked directly to requirements is the difference between a passing assessment and a finding. The Evidence Repository keeps your screenshots, configuration exports, policies, and vendor documents organized and mapped to the specific objectives they satisfy.

Requirements Browser: Live Interface HTML source coming

Requirements coverage across all 14 domains

The Requirements Browser covers every CMMC Level 2 practice. All 110, across all 14 NIST SP 800-171 domains. No gaps, no optional add-ons.

Domain Code Practices Objectives
Access ControlAC2270
Awareness and TrainingAT39
Audit and AccountabilityAU928
Configuration ManagementCM944
Identification and AuthenticationIA1127
Incident ResponseIR312
MaintenanceMA610
Media ProtectionMP915
Personnel SecurityPS23
Physical ProtectionPE616
Risk AssessmentRA36
Security AssessmentCA413
System and Communications ProtectionSC1638
System and Information IntegritySI719
SPRS Score Impact
Not all 110 practices carry equal weight. Point values range from −1 to −5 per unmet practice, with a perfect score of 110 and a floor of −203. 1TEN calculates your exact weighted score as you work. So you know your self-attestation number before you submit to SPRS.

Why defense contractors choose 1TEN

Most CMMC compliance tools are cloud-based SaaS products. That creates a problem: your assessment data. Implementation statements, CUI system details, gap analysis. Lives on someone else's server. For a DIB contractor handling sensitive program information, that's a risk most primes and their cybersecurity teams won't accept.

What makes 1TEN different
Air-gapped, on-premises appliance. Your assessment data never leaves your network. The 1TEN appliance ships pre-configured and deploys in your facility. No cloud dependency, no SaaS subscription, no data leaving your control.
All 23 modules ship together. Requirements Browser, Evidence Manager, Policy Generator, POA&M Tracker, SSP Export, Risk Register, Training. Everything on one appliance. No per-module pricing, no integrations to configure.
Built by veterans for the DIB. 1TEN is a veteran-owned company founded specifically to solve CMMC compliance for defense contractors. We understand DFARS 252.204-7012, 32 CFR Part 117, and what a C3PAO assessor actually looks for.
Assessment-ready from day one. The platform is structured around NIST SP 800-171A assessment methodology. The same framework your C3PAO uses. Every field, every status, every evidence link is designed to produce the artifact package assessors expect.

Modules that work with Requirements Browser

Every assessment determination you record in the Requirements Browser automatically feeds these modules. No double-entry, no exports required.

See the Requirements Browser running with real data.

30 minutes on a live 1TEN appliance. We'll walk through your specific domains, show you how SPRS score calculation works, and demonstrate how assessment data flows into your SSP and POA&M automatically.

Request a demo