Register:FAQ8 recordsSHA3-256 chainedSealed Amended head sha3:014eb0882f6b16277c67baf133ce98e6d02f283ce74b12d9ade75e21b1ce3030Intact

REFERENCE / QUESTIONS ON RECORD

Frequently asked questions.

Answers on record for the questions buyers, assessors, and contracting officers ask about PolicyCortex: what it is, who it is for, which frameworks and clouds it covers, how it deploys inside your tenant, how it handles data, how licensing and onboarding work, and how PolicyCortex, Inc. sells to the federal government. 29 entries in 7 categories.

REC 0000CONTENTSsha3-2562da4e6d20b416a1a8cad373283ec4d7ce2630018009d428ef651082024fbb0dcprev:59d3263ee0c0

Contents

Each category is one record in the chain below; each question is one entry. Where an answer and a live page disagree, the page controls. The plain-language twin of this register is llms-full.txt.

REC 0001CMMCsha3-2565d96618e9d180b86bb1c3f49f755df3f1d7b71b3fa525e5e0796b369b51a43eeprev:2da4e6d20b41

CMMC compliance

  1. Q-01

    What changed with CMMC Phase II on July 13, 2026?

    The Department of War suspended the November 10 Phase II transition and pending and future CMMC implementation milestones while it conducts a 60-day reform review. Phase I self-assessment requirements remain in place, and DFARS 252.204-7012 safeguarding duties still apply.

  2. Q-02

    How much does CMMC compliance cost with PolicyCortex?

    The standard 30-day CMMC acceleration engagement is $15,000 flat for one agreed primary cloud environment: evidence collection, documentary work, approved remediation, package preparation, and support through assessor review. PolicyCortex itself is licensed software on an annual license; the customer's tenant owns the evidence. Commercial terms are on the pricing and engagement pages. The independent assessor makes the certification decision, and no certification is guaranteed.

  3. Q-03

    What clearances does the PolicyCortex team hold?

    Founder Leonard Esere holds a DoD Secret clearance and a DoE Q clearance (equivalent to DoD Top Secret). He currently consults at a DOE national laboratory.

REC 0002GENERALsha3-256d19618c1cc91f8a2d51d7a170f4b62789aa1cc409ae9915187afb43267fbd45eprev:5d96618e9d18

General

  1. Q-04

    What is PolicyCortex?

    PolicyCortex is a compliance and assurance platform for regulated cloud and AI systems. It connects requirements, control implementation, remediation, and verifiable evidence in your tenant, helping your organization prepare for self-assessment, independent assessment, and authorization review, and maintain readiness as systems change. Licensed software with access arranged through our team; fixed-scope delivery engagements are optional.

  2. Q-05

    Who is PolicyCortex built for?

    Defense contractors, federal programs, and regulated organizations preparing for CMMC Level 2, NIST SP 800-171, FedRAMP 20x, ATO and continuous authorization, and federal AI obligations such as the OMB M-25-21 minimum practices and the annual AI use-case inventory. If you need a checklist and a score, there are good products for that and we will point you at them. If you are accountable for what an autonomous system does in a regulated environment, and you have already worked out that logs and evidence are different words, this is for you.

  3. Q-06

    How is PolicyCortex different from a traditional GRC tool?

    GRC tools organize compliance records; the evidence is still whatever someone uploaded. PolicyCortex produces the record itself: point-in-time state captured from the provider APIs, changes with their authority and rollback identifiers, and agent actions with the envelope that permitted them, each SHA3-256 hashed and chained. A second party can recompute the chain with no PolicyCortex account or API in the loop. Gaps are declared, not hidden.

  4. Q-07

    What cloud providers does PolicyCortex support?

    Azure, AWS, and GCP, including AWS GovCloud, Azure Government, and GCC High. AWS and Azure boundaries are supported for ATO packaging; GCP support covers governance, remediation, and control-linked evidence, not an ATO workflow. What is not connected is not observed, and the record says so.

REC 0003FRAMEWORKSsha3-2565500c1ea455ec74cdf6140af99570b8c495806310ad8a2f447149d0ced42c617prev:d19618c1cc91

Compliance and frameworks

  1. Q-08

    What compliance frameworks does PolicyCortex support?

    CMMC Levels 1 to 3 (Level 2, the 110 NIST SP 800-171 requirements, is the certification scope PolicyCortex packages), NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 2 and 3, DFARS 252.204-7012, FedRAMP Low, Moderate and High, FISMA, ITAR/EAR, HIPAA, SOX, PCI DSS, CIS Benchmarks for AWS, Azure and GCP, SOC 2 Type II, NIST AI RMF, MITRE ATT&CK and ATLAS. Control implementations are traced to evidence rows once and projected into each framework's artifacts: SSP, POA&M, SAR, and OSCAL 1.1.2.

  2. Q-09

    How does PolicyCortex help with CMMC preparation?

    One evidence base for the 110 requirements of NIST SP 800-171, handed to the assessor as generated evidence with the raw payload attached. The SSP, POA&M, and SAR are generated from that one implementation record, not written beside it. Start with the public ten-question readiness assessment and work the 110-control checklist. Request product access separately to discuss the environment and evidence package with our team.

  3. Q-10

    Does PolicyCortex replace my C3PAO assessment?

    No. PolicyCortex is not a C3PAO and does not certify anything. The C3PAO remains independent and makes the assessment decision. PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe, and stays engaged for in-scope evidence questions during assessor review.

  4. Q-11

    Can PolicyCortex map controls across multiple frameworks?

    Yes. One encryption setting can evidence NIST 800-171 3.13.16 and 800-53 SC-28 at once, and the mapping is written down on the record, not implied. The Multi-Framework Bidirectional Control Map is one of the four U.S. patent applications filed.

  5. Q-12

    How does evidence collection work?

    Collectors read configuration from the cloud provider APIs and write one record per resource per capture: the raw provider response as the proof, a SHA3-256 content hash, the digest of the record before it, and a UTC capture time. Records are append-only and retained seven years. When a collector is down or a scope is unobserved, the chain carries a declared gap with the interval and the reason; evidence never silently has fewer rows. Documentary and interview evidence that software cannot infer is gathered in the delivery engagement.

REC 0004DEPLOYMENTsha3-256b740dbdcaa55cd1031fa0f54de65ca4576863e94a02b6715afbfc830aaa4047dprev:5500c1ea455e

Technical and deployment

  1. Q-13

    How is PolicyCortex deployed?

    Inside the customer's own tenant, including AWS GovCloud, Azure Government, and GCC High. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence. On-premises delivery for air-gapped environments is available.

  2. Q-14

    Does PolicyCortex require agents on my servers?

    No. PolicyCortex operates through the cloud provider APIs (AWS, Azure, GCP) and reads configuration, resource state, and event data with read-only access. Approved remediation uses scoped write permissions that you control, bounded by the autonomy envelope, and every action carries a rollback identifier.

  3. Q-15

    How does remediation work?

    Every action runs inside the Safety Sandwich: detect; pre-check (blast radius bounded, target state pinned by hash, 3 of 3 policy gates required); decision (the reasoning layer proposes and publishes confidence, and cannot execute); execute; verify (a hashed-delta mismatch triggers automatic rollback); rollback identifier. The default trust mode is GATED: a named human approves each action and becomes part of its record.

  4. Q-16

    Can I start with manual approvals before enabling any automation?

    Yes. There are three trust modes: SHADOW (watch only, nothing executes), GATED (the default; a named human approves each action), and AUTONOMOUS (narrow, well-tested action classes, with every gate still run on every act). Read-only onboarding uses SHADOW mode after access is approved and scope is agreed.

  5. Q-17

    What data does PolicyCortex access?

    Cloud configuration data, metadata, and event logs through the cloud provider APIs. It does not access the content of your files, databases, or application data. Because it runs inside your tenant, that metadata does not leave your environment.

  6. Q-18

    Can PolicyCortex work in air-gapped environments?

    Yes. On-premises delivery is available for organizations that operate disconnected or air-gapped environments. The platform runs entirely within your infrastructure with no external connectivity required for core functionality.

REC 0005SECURITYsha3-25607eb1ea33c71afcd3a1b94b7c3b9f5772215fc0b718f7d017bf779554892ad4dprev:b740dbdcaa55

Security and trust

  1. Q-19

    How does PolicyCortex handle my data?

    It processes cloud configuration metadata inside your tenant, not your application data or CUI. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence. Data is encrypted in transit and at rest, and exported evidence packages are AES-256 protected.

  2. Q-20

    Is PolicyCortex pursuing FedRAMP authorization?

    PolicyCortex is built with FedRAMP-aligned controls and exports OSCAL 1.1.2 natively. A FedRAMP Moderate path is planned, not held; SOC 2 Type II is in progress. Current status is on the security page.

  3. Q-21

    Who can see what in PolicyCortex?

    Role-based access control with scoped visibility. CISOs see organization-wide posture. Cloud architects see infrastructure details. ISSOs see evidence and control status. Each role sees only what it needs, without exposing sensitive information across team boundaries.

REC 0006COMMERCIALsha3-2567869f47dfc97d55bb8b8cef99102fd4220774c23cd198cd996b0428a54e612ceprev:07eb1ea33c71

Pricing and getting started

  1. Q-22

    How is PolicyCortex priced?

    An annual license; the customer's tenant owns the evidence. The optional fixed-scope delivery engagement is thirty days at a fixed fee for one agreed primary cloud environment. Commercial terms are on the pricing and engagement pages.

  2. Q-23

    How do we request product access?

    Use Request Access at https://app.policycortex.com/auth?mode=request-access. Our team reviews your request and agrees on scope and onboarding before product access is granted. Public calculators, checklists, and the ten-question readiness assessment do not require product access.

  3. Q-24

    How quickly can I get started?

    We confirm onboarding after reviewing your request, target assessment, timeline, CUI boundary, environments, and existing evidence. The optional delivery engagement runs thirty days within its agreed scope; submitting an access request does not begin that engagement or grant product access.

REC 0007PROCUREMENTsha3-256014eb0882f6b16277c67baf133ce98e6d02f283ce74b12d9ade75e21b1ce3030prev:7869f47dfc97

Federal procurement

  1. Q-25

    Which company is the legal provider of PolicyCortex?

    PolicyCortex, Inc. is the legal contracting and invoicing entity. PolicyCortex is the software product and brand offered by PolicyCortex, Inc. Federal quotes, offers, awards, and payments use the active SAM.gov entity record of PolicyCortex, Inc.

  2. Q-26

    Is PolicyCortex registered to pursue federal awards?

    Yes. PolicyCortex, Inc. is active in SAM.gov for All Awards through July 30, 2027. Its Unique Entity ID is C7L8DKKF5TK5 and its CAGE code is 19CQ3.

  3. Q-27

    Is PolicyCortex currently available through GSA?

    No. PolicyCortex, Inc. has completed the preparation sections for a GSA Multiple Award Schedule offer for PolicyCortex, but final review is pending and the offer has not been submitted or awarded. PolicyCortex will not be described as available on GSA until an award and contract number exist.

  4. Q-28

    Can a government organization request a quote now?

    Yes. PolicyCortex, Inc. can provide a direct commercial quote, W-9, entity identifiers, technical scope, and security documentation. The buying organization's contracting officer determines the authorized purchasing method and competition requirements.

  5. Q-29

    Is PolicyCortex currently available through NASA SEWP?

    No. A future contract-holder partnership is planned, but PolicyCortex is not currently orderable through SEWP.

Ask the people who build the system.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000CONTENTS2da4e6d20b4159d3263ee0c0
REC 0001CMMC5d96618e9d182da4e6d20b41
REC 0002GENERALd19618c1cc915d96618e9d18
REC 0003FRAMEWORKS5500c1ea455ed19618c1cc91
REC 0004DEPLOYMENTb740dbdcaa555500c1ea455e
REC 0005SECURITY07eb1ea33c71b740dbdcaa55
REC 0006COMMERCIAL7869f47dfc9707eb1ea33c71
REC 0007PROCUREMENT014eb0882f6b7869f47dfc97

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:014eb0882f6b. The product does the same thing to your evidence.

Photograph: U.S. Air Force, Public domain (U.S. Air Force, 17 U.S.C. 105). Source