The Platform

CMMC.
Platform.

All 110 NIST SP 800-171 requirements across 14 domains. On-premises appliance. C3PAO-ready documentation generated from your environment. Not a template.

110
NIST SP 800-171 requirements covered
14
CMMC Level 2 domains, complete coverage
26
Platform modules, no add-ons
Air-gapped
On-premises appliance. CUI never leaves your facility.
Dashboard How It Works Modules Architecture Coverage

Every requirement tracked.
Nothing in the cloud.

Every metric, every module, every artifact. On your hardware, in your facility. No SaaS dependencies. No third-party access to your CUI environment.

Dashboard Requirements Evidence POA&M Documents
Dashboard
Last refreshed: Jun 23, 2026 8:14 AM
SPRS Score
0
Range: -203 to 110
Compliance
0%
106 of 110 met
Open POA&M
10
Action items
!
Open Risks
3
2 high
Compliance HealthView All →
96% of requirements met
96%
met
106
Met
4
Not Met
0
Not Assessed
0
N/A
POA&M SummaryView All →
7
Open
3
In Progress
0
Overdue
0
Closed
Compliance Progress (90 days)
Requirements met remained stable near 100 from June 4 to June 23.
TrainingView All →
My completion100%
3 of 3 complete

Organization-wide64%
9 of 14 assignments complete
Last Snapshot
June 23, 2026
✅ 100 requirements met
📋 10 POA&M open
🛡 3 active risks

First login to C3PAO-ready. Three stages.

01. SCOPE & ASSESS

Define your CUI boundary and document every control

CUI Scoping Wizard defines which systems and assets are in scope before any assessment work begins. Assessors verify scope first. Everything built on a misconfigured boundary is wrong. The Requirements Browser walks all 110 NIST SP 800-171 practices at objective level: document implementation, link evidence, flag gaps. Live SPRS score updates in real time.

CUI Scoping Wizard Requirements Browser Evidence Manager POA&M Tracker Risk Register
02. DOCUMENT

Generate your SSP, policies, diagrams, and assessment package

SSP generated from your environment data: implementation statements per requirement, responsible entities, security tools inventory, POA&M summary, and full appendices. Policy Generator produces all 14 required domain policies. CUI Data Flow Diagrams generate the visual artifact your C3PAO requires. Built in, not hand-drawn.

SSP Export Policy Generator CUI Data Flow Diagrams Assessment Guide Evidence Matrix
03. MAINTAIN

Stay compliant between assessment cycles

Certification is a point in time. The Compliance Calendar schedules and assigns recurring obligations. Change Control documents system changes against CM domain requirements. The Activity Log proves continuous operation. Experienced C3PAO examiners recognize a pre-assessment sprint. The Activity Log doesn't accommodate one.

Compliance Calendar Change Control Activity Log Annual Affirmation DIB Compliance Tracker

26 modules. No add-ons. No per-module pricing.

Every module ships with the platform. Select modules below. Each links to full specification, requirement mapping, and C3PAO evidence output details.

Scoping

CUI Scoping Wizard

Guided workflow to define your CUI boundary and identify in-scope assets before assessment work begins. Assessors verify scope first. A misconfigured boundary invalidates everything built on top of it.

All 14 Domains
Requirements

Requirements Browser

All 110 CMMC Level 2 practices across 14 domains. Document objective-level assessment status, record implementation findings, link evidence artifacts, and track overall compliance progress. Live SPRS score reflects every change in real time.

All 14 DomainsLive SPRS
Evidence

Evidence Manager + Evidence Matrix

Upload and link artifacts directly to specific requirements and assessment objectives. The Evidence Matrix report shows full coverage across the entire control set. See what's documented and what's missing before your assessor does.

CAAll Domains
Documentation

System Security Plan (SSP)

Generated from your actual environment data: implementation statements per requirement, responsible entities, security tools inventory, POA&M summary, and a complete appendix set. Exports as HTML and Word. C3PAO-ready on demand.

CAAll 14 Domains
Documentation

Policy Generator

Produces all required domain policies from your organization-specific questionnaire responses. Fourteen domain policy sets generated from your actual environment data. Not a template library. Policies export in Word format.

All 14 Domain Policies
Scoring

SPRS Score + Score Analysis

Real-time SPRS score derived from your Requirements Browser, with an SPRS Score Analysis report that breaks down your position domain by domain on the −203 to 110 scale. See exactly what's costing points and prioritize remediation by impact.

All 14 Domains
Tracking

POA&M Tracker

Plan of Action and Milestones tracking with 180-day closeout tracking, risk level tagging, and SPRS impact weighting. Open items linked directly to the requirements they affect. Remediation progress documented continuously.

CAAll Domains
Documentation

CUI Data Flow Diagrams

Visual diagramming tool maps how CUI enters, moves through, and exits your environment. Required C3PAO artifact. Built into the platform. Not a separate tool. Not hand-drawn the night before the assessor arrives.

SCCA
Assessment

Assessment Guide

Every C3PAO assessment question from the official CMMC Assessment Guide embedded directly into every requirement. The same questions your assessor will ask, with your documented evidence mapped to each one. No surprises on assessment day.

All 110 Requirements
Ongoing Compliance

Compliance Calendar

Calendar view for scheduling and tracking recurring compliance activities: vulnerability scans, access reviews, audit log reviews, backup verification, and regulatory deadlines. Assign by owner, flag overdue items, maintain documented evidence of continuous activity.

CAAUMARA
Change Management

Change Control

Document system and configuration changes against CM domain requirements. Change records link to the specific controls affected, maintaining an auditable record of how your environment evolves and how compliance posture is preserved through changes.

CM
Incident Response

Incident Response + IR Exercises

End-to-end incident lifecycle: detection, containment, eradication, recovery, and closure, with automated mapping to IR domain objectives. IR Exercises captures tabletop scenario records and participation logs. Satisfies IR.L2-3.6.1, 3.6.2, and 3.6.3.

IR
Training

Training Management

Built-in course delivery including CUI-101, role-based training assignments, completion record tracking, and phishing awareness program support. No separate LMS required. Verifiable records your C3PAO assessor can review on-site.

AT
Workflows

Compliance Workflows

Configurable approval workflows for onboarding, offboarding, and other compliance processes. Sign-off tracking and role-based access controls tied to NIST requirements. Personnel changes generate the compliance documentation they're supposed to, automatically.

PSACIA
Supply Chain

Supplier Management

Vendor and supplier records with risk level ratings, CAGE codes, CUI flow-down requirement linkages, and assessment date tracking. Supports supply chain risk management across the SR domain and DFARS subcontractor flow-down obligations.

SRDFARS
Physical Security

Visitor Log & Registered Visitors

Self-service kiosk with NDA acknowledgment and escort assignment. Pre-registered visitor approval workflows and recurring visitor tracking. PE domain documentation generated automatically.

PE
Coming Soon
Regulatory

Annual Affirmation + DIB Compliance Tracker

Annual Affirmation tracks the senior official affirmation required by 32 CFR Part 117. DIB Compliance Tracker covers SAM.gov registration, SPRS score posting, ECA certificates, DIBNET enrollment, and C3PAO assessment status. All in one place.

32 CFR 117DFARS
Audit

Activity Log

Tamper-evident, timestamped record of every platform action: user, module, and timestamp. Proves continuous compliance operation across the full lifecycle. Experienced C3PAO examiners know what a pre-assessment sprint looks like. The Activity Log doesn't lie.

AU

Engineered for the Defense Industrial Base.

Every architecture decision traces to a single requirement: pass a real C3PAO assessment and sustain compliance between cycles.

Air-Gapped Deployment
Dedicated on-premises appliance. CUI never traverses the public internet. No cloud dependencies, no external APIs, no data leaving your facility. This is not a "private cloud." It is your hardware, your network, your control.
Single-Tenant Architecture
Each organization receives a dedicated appliance. No shared infrastructure, no co-mingled data, complete organizational isolation. Your system boundary stays yours. Exactly what assessors expect and what CMMC requires.
Tamper-Evident Audit Log
Every platform action logged: user, module, timestamp. Immutable. Proves continuous compliance operation across the full assessment lifecycle. C3PAO examiners recognize a pre-assessment sprint. The Activity Log doesn't accommodate one.
Live SPRS Score + Domain Analysis
Real-time SPRS score derived directly from your Requirements Browser. Domain-by-domain breakdown on the −203 to 110 scale. Pinpoints exactly what's costing points so remediation effort maps to score impact, not guesswork.
C3PAO-Ready Exports
SSP, policies, evidence matrix, assessment guide, and SPRS analysis export in Word and HTML. Formatted for on-site C3PAO review. No reformatting, no conversion, no cleanup between export and assessor arrival.
MSP Multi-Tenant Option
MSPs and Registered Practitioners deploy 1TEN across multiple DIB clients. Each client receives a dedicated appliance: full isolation, separate audit trails, independent compliance posture. No per-seat pricing, no shared infrastructure.

All 14 domains. All 110 requirements.

Complete CMMC Level 2 coverage across every domain. Click any domain for full requirement breakdown, SPRS point values, and C3PAO assessment criteria.

Domain Code Requirements 1TEN Coverage
Access Control AC 22 All 22 covered
Awareness & Training AT 3 All 3 covered
Audit & Accountability AU 9 All 9 covered
Configuration Management CM 9 All 9 covered
Identification & Authentication IA 11 All 11 covered
Incident Response IR 3 All 3 covered
Maintenance MA 6 All 6 covered
Media Protection MP 9 All 9 covered
Personnel Security PS 2 All 2 covered
Physical Protection PE 6 All 6 covered
Risk Assessment RA 3 All 3 covered
Security Assessment CA 4 All 4 covered
System & Comms Protection SC 16 All 16 covered
System & Info Integrity SI 7 All 7 covered
Total 14 110 Complete coverage

Engineered for the DIB.

1TEN tracks your control implementation, calculates your live SPRS score, and organizes your evidence package. On-premises, air-gapped.

Request a Demo