sha3:7f507f75d754d8a89851ccef434f515344af6ed3dbda698bfb7315f5df73e759IntactFEDERAL / PROGRAM OFFICE
ATO, FedRAMP 20x,
800-53, 800-171, CMMC.
The same record, in the shape your program office expects. One implementation record, hash chained inside your tenant, projects into every artifact indexed below.
9f838bdaa8f02d9506cee0a186ecc5e79f8e45846667dc608efc162e8be0997aprev:01230ec20849How this page relates to the proofs
Everything below is a projection of three records: proof of state (what your cloud was, as of any timestamp), proof of change (what changed it, append only and hash chained), and proof of agency (what your machines were allowed to do, and what they actually did).
The SSP, POA&M, and SAR are generated from that one implementation record, not written beside it. OSCAL 1.1.2 export, SPRS-relevant evidence for the 110 requirements of NIST 800-171, and continuous authorization records are the same rows in a different envelope. When a collector was down or a scope was unobserved, the projection says so: a declared gap with interval and reason, never silently fewer rows.
- NIST 800-53
- Control implementations traced to evidence rows; SSP and SAR generated, not authored.
- NIST 800-171
- All 110 requirements mapped, with SPRS-relevant evidence carried per requirement.
- CMMC Level 2
- Assessment objectives linked to rows a C3PAO can verify by hash.
- FedRAMP 20x
- OSCAL 1.1.2 native; continuous authorization as machine-readable records.
- MITRE ATT&CK / ATLAS
- Techniques annotated on detections and agent actions, including AML.T0048 and AML.T0051.
- NIST AI RMF
- GOVERN, MAP, MEASURE, MANAGE tied to the proof of agency record.
d03901d4cfcfddc82f09f01c2cae23eee2abbea185b680cb22a1590ab3c0138eprev:9f838bdaa8f0ATO and continuous authorization
An authorization decision is a claim about a system as of a date. The record regenerates to any historical timestamp, so the package your authorizing official signed and the package you hold today differ only by rows you can enumerate. Chain verification tells both of you whether anything was edited after the fact.
- platform.ato
- ATO and continuous authorization: SSP, POA&M, and SAR generated from one implementation record, regenerable as of any timestamp.

Exhibit F-1 · one authorization package from scope to 3PAO assessment: passing controls, family coverage, next action. Illustrative demo data; the interface is real.
a85df88da083cc52276c3c41345e1efb074f614a40fcbfe6f95765853b7e5cc3prev:d03901d4cfcfGovernance and compliance monitoring
Monitoring against NIST 800-53, NIST 800-171, and CIS benchmarks, written as evidence: every observation content hashed with SHA3-256, timestamped, appended to the chain, retained seven years. A control that stopped being observed produces a declared gap, not a stale green.
- platform.governance
- Governance and compliance monitoring: 800-53, 800-171, and CIS, recorded as chained evidence inside your tenant.
59f9749ade3a8f5a713e08d8b615a551f826f0ffce45c86a9f741ce83797048fprev:a85df88da083CMMC Level 2
CMMC Level 2 assesses the 110 requirements of NIST 800-171. Start with the self-serve assessment: read only, fourteen days, running inside your tenant. Work the 110-control checklist requirement by requirement, then hand the assessor a package built to be verified rather than believed.
- cmmc.assessment
- Self-serve CMMC Level 2 assessment: read-only evaluation of your own tenant, fourteen days, no egress.
- cmmc.checklist
- The 110-control checklist: every requirement, the evidence it wants, and where that evidence comes from.
- cmmc.handoff
- eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.
- cmmc.glossary
- The glossary: terms as assessors use them, not as vendors do.

Exhibit F-2 · open gaps by family and severity, each with an owner and a remediation path. Declared, not hidden. Illustrative demo data; the interface is real.
13780dd1a47b6090ae2b0ebf715930a133cc3adc6f7c5779cc4bb72d4dca927eprev:59f9749ade3aCalculators and tools
Two questions a program office asks early: what will this cost, and how much calendar remains. The calculators exist so both answers arrive before the first conversation.
- tools.cost
- CMMC cost calculator: an estimate you can argue with, line by line.
- tools.deadline
- CMMC deadline calculator: the calendar between today and your clause.
- tools.index
- All calculators and tools: the full set.
e45d6e398d58098f17162c07e7189d8d2e0247782eaa2c37c06813b9798e1349prev:13780dd1a47bFramework solution briefs
One brief per framework or mission context: what the record contributes to that obligation, and what remains yours to do.
- brief.cmmc
- CMMC compliance: Level 2, from scoping to assessment day.
- brief.nist-800-171
- NIST 800-171: the 110 requirements and the evidence each one wants.
- brief.fedramp
- FedRAMP: 20x and continuous authorization as machine-readable records.
- brief.dfars
- DFARS compliance: 252.204-7012 obligations and the flowdown.
- brief.itar
- ITAR compliance: export-controlled data boundaries and evidence of enforcement.
- brief.defense
- Defense contractors: prime and subcontractor evidence posture.
- brief.federal-rd
- Federal R&D: labs and research computing under federal data obligations.
62c8534846ffeb73b0e76f1484abb6d8a5594f7b31f9ba5af6e3b3161556f495prev:e45d6e398d58The engagement and procurement
If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee, run on the same software indexed on this page. The procurement facts your contracting office asks for are published, not emailed on request.
- engagement
- The delivery engagement: 30 days, fixed fee, one agreed environment.
- procurement
- Procurement facts: PolicyCortex, Inc. SAM active. CAGE 19CQ3. Dallas-Fort Worth, Texas.
14339fbbeb8a3e885920bd6049bcdebae1bed701382ee47464fead8aaa13cb9dprev:62c8534846ffThe delivery engine
The pages above describe outputs. The software that produces them runs inside your tenant with no telemetry pipeline back to PolicyCortex, and every autonomous action is bounded by an envelope: blast radius, cost ceiling, change windows, an andon cord. The delivery team uses the same software; there is no internal edition.
- platform
- The delivery engine: the software the delivery team uses.
7f507f75d754d8a89851ccef434f515344af6ed3dbda698bfb7315f5df73e759prev:14339fbbeb8aWhat this page is not
Bring your program office. We speak OSCAL.
Request verification