Most DIB contractors fail CMMC assessments they should pass
The typical defense contractor approaching CMMC Level 2 has the security controls in place. What they're missing is the documentation. Implementation statements tied to specific systems, objective-level evidence mapped to each of the 320+ assessment criteria your C3PAO will examine.
Spreadsheets and manual tracking can't do this at scale. By the time you've mapped all 110 practices to objectives, statuses, evidence, responsible parties, and implementation notes across 14 domains, your data is already stale. And your SPRS score is a guess, not a calculation.
The Requirements Browser is the operational core of 1TEN. It's where all 110 CMMC Level 2 practices live, get assessed, and automatically feed every other module. Your SSP, your POA&M, your SPRS score, your Assessment Guide. Before any other module can do its job, this is where the work happens.
How CMMC requirements tracking works in 1TEN
Every practice maps to its NIST SP 800-171A assessment objectives. The granular statements that define what "met" actually means. For each objective you record status, assessment method (Examine, Interview, or Test), implementation notes, linked evidence files, and responsible party. Nothing is left implicit.
- * Status tracked at the objective level, matching how C3PAO assessors actually evaluate
- * Real-time SPRS score recalculates automatically as you update any objective status
- * Implementation notes, evidence links, and responsible party recorded per objective
- * Filter by domain, status, or practice number to focus on gaps
- * Assessment method captured per NIST SP 800-171A methodology
- * Every determination flows into Assessment Summary, POA&M, and SSP without re-entry
What you see inside the Requirements Browser
Here's the actual software your team will use to work through each domain. Every row is a CMMC practice. Every row expands to the full objective-level detail your assessor will evaluate.
Evidence linked directly to requirements is the difference between a passing assessment and a finding. The Evidence Repository keeps your screenshots, configuration exports, policies, and vendor documents organized and mapped to the specific objectives they satisfy.
Requirements coverage across all 14 domains
The Requirements Browser covers every CMMC Level 2 practice. All 110, across all 14 NIST SP 800-171 domains. No gaps, no optional add-ons.
| Domain | Code | Practices | Objectives |
|---|---|---|---|
| Access Control | AC | 22 | 70 |
| Awareness and Training | AT | 3 | 9 |
| Audit and Accountability | AU | 9 | 28 |
| Configuration Management | CM | 9 | 44 |
| Identification and Authentication | IA | 11 | 27 |
| Incident Response | IR | 3 | 12 |
| Maintenance | MA | 6 | 10 |
| Media Protection | MP | 9 | 15 |
| Personnel Security | PS | 2 | 3 |
| Physical Protection | PE | 6 | 16 |
| Risk Assessment | RA | 3 | 6 |
| Security Assessment | CA | 4 | 13 |
| System and Communications Protection | SC | 16 | 38 |
| System and Information Integrity | SI | 7 | 19 |
Why defense contractors choose 1TEN
Most CMMC compliance tools are cloud-based SaaS products. That creates a problem: your assessment data. Implementation statements, CUI system details, gap analysis. Lives on someone else's server. For a DIB contractor handling sensitive program information, that's a risk most primes and their cybersecurity teams won't accept.
Modules that work with Requirements Browser
Every assessment determination you record in the Requirements Browser automatically feeds these modules. No double-entry, no exports required.
30 minutes on a live 1TEN appliance. We'll walk through your specific domains, show you how SPRS score calculation works, and demonstrate how assessment data flows into your SSP and POA&M automatically.