All 110 NIST SP 800-171 requirements across 14 domains. On-premises appliance. C3PAO-ready documentation generated from your environment. Not a template.
Every metric, every module, every artifact. On your hardware, in your facility. No SaaS dependencies. No third-party access to your CUI environment.
CUI Scoping Wizard defines which systems and assets are in scope before any assessment work begins. Assessors verify scope first. Everything built on a misconfigured boundary is wrong. The Requirements Browser walks all 110 NIST SP 800-171 practices at objective level: document implementation, link evidence, flag gaps. Live SPRS score updates in real time.
SSP generated from your environment data: implementation statements per requirement, responsible entities, security tools inventory, POA&M summary, and full appendices. Policy Generator produces all 14 required domain policies. CUI Data Flow Diagrams generate the visual artifact your C3PAO requires. Built in, not hand-drawn.
Certification is a point in time. The Compliance Calendar schedules and assigns recurring obligations. Change Control documents system changes against CM domain requirements. The Activity Log proves continuous operation. Experienced C3PAO examiners recognize a pre-assessment sprint. The Activity Log doesn't accommodate one.
Every module ships with the platform. Select modules below. Each links to full specification, requirement mapping, and C3PAO evidence output details.
Guided workflow to define your CUI boundary and identify in-scope assets before assessment work begins. Assessors verify scope first. A misconfigured boundary invalidates everything built on top of it.
All 110 CMMC Level 2 practices across 14 domains. Document objective-level assessment status, record implementation findings, link evidence artifacts, and track overall compliance progress. Live SPRS score reflects every change in real time.
Upload and link artifacts directly to specific requirements and assessment objectives. The Evidence Matrix report shows full coverage across the entire control set. See what's documented and what's missing before your assessor does.
Generated from your actual environment data: implementation statements per requirement, responsible entities, security tools inventory, POA&M summary, and a complete appendix set. Exports as HTML and Word. C3PAO-ready on demand.
Produces all required domain policies from your organization-specific questionnaire responses. Fourteen domain policy sets generated from your actual environment data. Not a template library. Policies export in Word format.
Real-time SPRS score derived from your Requirements Browser, with an SPRS Score Analysis report that breaks down your position domain by domain on the −203 to 110 scale. See exactly what's costing points and prioritize remediation by impact.
Plan of Action and Milestones tracking with 180-day closeout tracking, risk level tagging, and SPRS impact weighting. Open items linked directly to the requirements they affect. Remediation progress documented continuously.
Visual diagramming tool maps how CUI enters, moves through, and exits your environment. Required C3PAO artifact. Built into the platform. Not a separate tool. Not hand-drawn the night before the assessor arrives.
Every C3PAO assessment question from the official CMMC Assessment Guide embedded directly into every requirement. The same questions your assessor will ask, with your documented evidence mapped to each one. No surprises on assessment day.
Calendar view for scheduling and tracking recurring compliance activities: vulnerability scans, access reviews, audit log reviews, backup verification, and regulatory deadlines. Assign by owner, flag overdue items, maintain documented evidence of continuous activity.
Document system and configuration changes against CM domain requirements. Change records link to the specific controls affected, maintaining an auditable record of how your environment evolves and how compliance posture is preserved through changes.
End-to-end incident lifecycle: detection, containment, eradication, recovery, and closure, with automated mapping to IR domain objectives. IR Exercises captures tabletop scenario records and participation logs. Satisfies IR.L2-3.6.1, 3.6.2, and 3.6.3.
Built-in course delivery including CUI-101, role-based training assignments, completion record tracking, and phishing awareness program support. No separate LMS required. Verifiable records your C3PAO assessor can review on-site.
Configurable approval workflows for onboarding, offboarding, and other compliance processes. Sign-off tracking and role-based access controls tied to NIST requirements. Personnel changes generate the compliance documentation they're supposed to, automatically.
Vendor and supplier records with risk level ratings, CAGE codes, CUI flow-down requirement linkages, and assessment date tracking. Supports supply chain risk management across the SR domain and DFARS subcontractor flow-down obligations.
Self-service kiosk with NDA acknowledgment and escort assignment. Pre-registered visitor approval workflows and recurring visitor tracking. PE domain documentation generated automatically.
Annual Affirmation tracks the senior official affirmation required by 32 CFR Part 117. DIB Compliance Tracker covers SAM.gov registration, SPRS score posting, ECA certificates, DIBNET enrollment, and C3PAO assessment status. All in one place.
Tamper-evident, timestamped record of every platform action: user, module, and timestamp. Proves continuous compliance operation across the full lifecycle. Experienced C3PAO examiners know what a pre-assessment sprint looks like. The Activity Log doesn't lie.
Every architecture decision traces to a single requirement: pass a real C3PAO assessment and sustain compliance between cycles.
Complete CMMC Level 2 coverage across every domain. Click any domain for full requirement breakdown, SPRS point values, and C3PAO assessment criteria.
| Domain | Code | Requirements | 1TEN Coverage |
|---|---|---|---|
| Access Control | AC | 22 | ✓ All 22 covered |
| Awareness & Training | AT | 3 | ✓ All 3 covered |
| Audit & Accountability | AU | 9 | ✓ All 9 covered |
| Configuration Management | CM | 9 | ✓ All 9 covered |
| Identification & Authentication | IA | 11 | ✓ All 11 covered |
| Incident Response | IR | 3 | ✓ All 3 covered |
| Maintenance | MA | 6 | ✓ All 6 covered |
| Media Protection | MP | 9 | ✓ All 9 covered |
| Personnel Security | PS | 2 | ✓ All 2 covered |
| Physical Protection | PE | 6 | ✓ All 6 covered |
| Risk Assessment | RA | 3 | ✓ All 3 covered |
| Security Assessment | CA | 4 | ✓ All 4 covered |
| System & Comms Protection | SC | 16 | ✓ All 16 covered |
| System & Info Integrity | SI | 7 | ✓ All 7 covered |
| Total | 14 | 110 | ✓ Complete coverage |
1TEN tracks your control implementation, calculates your live SPRS score, and organizes your evidence package. On-premises, air-gapped.
Request a Demo