Shipbuilding sub-tiers, marine systems integrators, and hull and propulsion component manufacturers are embedded in programs that span decades. A compliance gap doesn't just create a finding. It ends a supplier relationship that took years to build.
Naval architecture drawings, combat system interface control documents, and ship repair specifications don't just describe your component. They describe the platform it integrates with. Interface data, installation constraints, and performance specifications received from primes capture whole-ship characteristics that are export-controlled and CUI. The systems where that data lives, the engineers who work with it, and the networks connecting them are all within your CMMC assessment boundary. Assessors in naval supplier environments consistently find that organizations have underestimated how far their scope extends.
Hull form data, structural analyses, and compartmentation drawings for active and future programs are CUI and frequently Export Controlled. Restricted to U.S. persons with documented need-to-know.
ICDs describe the external behavior of combat systems. A single supplier may receive ICDs from multiple system suppliers, together providing a near-complete view of the combat system architecture.
Repair specifications generated during scheduled availabilities describe the current configuration and condition of an operational naval vessel. CUI from the moment they are created.
Technical data for naval communications systems describes frequencies, signal characteristics, and system architecture that is operationally sensitive and subject to strict handling requirements.
A compliance gap doesn't pause a long-cycle naval program. It replaces the supplier. Talk to us about where your organization stands and what it takes to protect the relationships you've built.
Naval and maritime defense suppliers cannot use cloud-hosted compliance tools. Ship system data, architectural drawings, combat system ICDs, and propulsion plant specifications, is exactly the category of information that must not leave the facility. 1TEN is deployed as an on-premises appliance inside your network. No internet connection required. The compliance program lives where the CUI lives, inside the boundary it is meant to protect.
On-premises appliance with no external connectivity. Ship system CUI never leaves your network to reach a compliance platform.
System boundary definition tools for complex environments where commercial maritime and naval defense data must be segmented and documented clearly.
Documentation for need-to-know access controls and citizenship screening requirements that apply to export-controlled naval technical data.
Complete assessment documentation generated from your actual implementation, ready for C3PAO assessment and prime review.
1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.
Request a Demo