Register:Federal9 recordsSHA3-256 chainedhead sha3:7f507f75d754d8a89851ccef434f515344af6ed3dbda698bfb7315f5df73e759Intact

FEDERAL / PROGRAM OFFICE

ATO, FedRAMP 20x,
800-53, 800-171, CMMC.

The same record, in the shape your program office expects. One implementation record, hash chained inside your tenant, projects into every artifact indexed below.

REC 0000PROJECTIONsha3-2569f838bdaa8f02d9506cee0a186ecc5e79f8e45846667dc608efc162e8be0997aprev:01230ec20849

How this page relates to the proofs

Everything below is a projection of three records: proof of state (what your cloud was, as of any timestamp), proof of change (what changed it, append only and hash chained), and proof of agency (what your machines were allowed to do, and what they actually did).

The SSP, POA&M, and SAR are generated from that one implementation record, not written beside it. OSCAL 1.1.2 export, SPRS-relevant evidence for the 110 requirements of NIST 800-171, and continuous authorization records are the same rows in a different envelope. When a collector was down or a scope was unobserved, the projection says so: a declared gap with interval and reason, never silently fewer rows.

NIST 800-53
Control implementations traced to evidence rows; SSP and SAR generated, not authored.
NIST 800-171
All 110 requirements mapped, with SPRS-relevant evidence carried per requirement.
CMMC Level 2
Assessment objectives linked to rows a C3PAO can verify by hash.
FedRAMP 20x
OSCAL 1.1.2 native; continuous authorization as machine-readable records.
MITRE ATT&CK / ATLAS
Techniques annotated on detections and agent actions, including AML.T0048 and AML.T0051.
NIST AI RMF
GOVERN, MAP, MEASURE, MANAGE tied to the proof of agency record.
REC 0001ATO / CONTINUOUS AUTHORIZATIONsha3-256d03901d4cfcfddc82f09f01c2cae23eee2abbea185b680cb22a1590ab3c0138eprev:9f838bdaa8f0

ATO and continuous authorization

An authorization decision is a claim about a system as of a date. The record regenerates to any historical timestamp, so the package your authorizing official signed and the package you hold today differ only by rows you can enumerate. Chain verification tells both of you whether anything was edited after the fact.

platform.ato
ATO and continuous authorization: SSP, POA&M, and SAR generated from one implementation record, regenerable as of any timestamp.
Exhibit F-1ato collection, as shipped
A PolicyCortex ATO collection overview: passing controls, six-stage lifecycle from scope to 3PAO assessment, control family coverage, and package readiness

Exhibit F-1 · one authorization package from scope to 3PAO assessment: passing controls, family coverage, next action. Illustrative demo data; the interface is real.

REC 0002GOVERNANCE / MONITORINGsha3-256a85df88da083cc52276c3c41345e1efb074f614a40fcbfe6f95765853b7e5cc3prev:d03901d4cfcf

Governance and compliance monitoring

Monitoring against NIST 800-53, NIST 800-171, and CIS benchmarks, written as evidence: every observation content hashed with SHA3-256, timestamped, appended to the chain, retained seven years. A control that stopped being observed produces a declared gap, not a stale green.

platform.governance
Governance and compliance monitoring: 800-53, 800-171, and CIS, recorded as chained evidence inside your tenant.
REC 0003CMMC LEVEL 2sha3-25659f9749ade3a8f5a713e08d8b615a551f826f0ffce45c86a9f741ce83797048fprev:a85df88da083

CMMC Level 2

CMMC Level 2 assesses the 110 requirements of NIST 800-171. Start with the self-serve assessment: read only, fourteen days, running inside your tenant. Work the 110-control checklist requirement by requirement, then hand the assessor a package built to be verified rather than believed.

cmmc.assessment
Self-serve CMMC Level 2 assessment: read-only evaluation of your own tenant, fourteen days, no egress.
cmmc.checklist
The 110-control checklist: every requirement, the evidence it wants, and where that evidence comes from.
cmmc.handoff
eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.
cmmc.glossary
The glossary: terms as assessors use them, not as vendors do.
Exhibit F-2gap analysis, as shipped
The PolicyCortex gap analysis: open compliance gaps stacked by control family and severity, each with framework, environment, days open, and owner

Exhibit F-2 · open gaps by family and severity, each with an owner and a remediation path. Declared, not hidden. Illustrative demo data; the interface is real.

REC 0004CALCULATORSsha3-25613780dd1a47b6090ae2b0ebf715930a133cc3adc6f7c5779cc4bb72d4dca927eprev:59f9749ade3a

Calculators and tools

Two questions a program office asks early: what will this cost, and how much calendar remains. The calculators exist so both answers arrive before the first conversation.

tools.cost
CMMC cost calculator: an estimate you can argue with, line by line.
tools.deadline
CMMC deadline calculator: the calendar between today and your clause.
tools.index
All calculators and tools: the full set.
REC 0005SOLUTION BRIEFSsha3-256e45d6e398d58098f17162c07e7189d8d2e0247782eaa2c37c06813b9798e1349prev:13780dd1a47b

Framework solution briefs

One brief per framework or mission context: what the record contributes to that obligation, and what remains yours to do.

brief.cmmc
CMMC compliance: Level 2, from scoping to assessment day.
brief.nist-800-171
NIST 800-171: the 110 requirements and the evidence each one wants.
brief.fedramp
FedRAMP: 20x and continuous authorization as machine-readable records.
brief.dfars
DFARS compliance: 252.204-7012 obligations and the flowdown.
brief.itar
ITAR compliance: export-controlled data boundaries and evidence of enforcement.
brief.defense
Defense contractors: prime and subcontractor evidence posture.
brief.federal-rd
Federal R&D: labs and research computing under federal data obligations.
REC 0006ENGAGEMENT / PROCUREMENTsha3-25662c8534846ffeb73b0e76f1484abb6d8a5594f7b31f9ba5af6e3b3161556f495prev:e45d6e398d58

The engagement and procurement

If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee, run on the same software indexed on this page. The procurement facts your contracting office asks for are published, not emailed on request.

engagement
The delivery engagement: 30 days, fixed fee, one agreed environment.
procurement
Procurement facts: PolicyCortex, Inc. SAM active. CAGE 19CQ3. Dallas-Fort Worth, Texas.
REC 0007DELIVERY ENGINEsha3-25614339fbbeb8a3e885920bd6049bcdebae1bed701382ee47464fead8aaa13cb9dprev:62c8534846ff

The delivery engine

The pages above describe outputs. The software that produces them runs inside your tenant with no telemetry pipeline back to PolicyCortex, and every autonomous action is bounded by an envelope: blast radius, cost ceiling, change windows, an andon cord. The delivery team uses the same software; there is no internal edition.

platform
The delivery engine: the software the delivery team uses.
REC 0008STATED LIMITsha3-2567f507f75d754d8a89851ccef434f515344af6ed3dbda698bfb7315f5df73e759prev:14339fbbeb8a

What this page is not

Bring your program office. We speak OSCAL.

Request verification
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000PROJECTION9f838bdaa8f001230ec20849
REC 0001ATO / CONTINUOUS AUTHORIZATIONd03901d4cfcf9f838bdaa8f0
REC 0002GOVERNANCE / MONITORINGa85df88da083d03901d4cfcf
REC 0003CMMC LEVEL 259f9749ade3aa85df88da083
REC 0004CALCULATORS13780dd1a47b59f9749ade3a
REC 0005SOLUTION BRIEFSe45d6e398d5813780dd1a47b
REC 0006ENGAGEMENT / PROCUREMENT62c8534846ffe45d6e398d58
REC 0007DELIVERY ENGINE14339fbbeb8a62c8534846ff
REC 0008STATED LIMIT7f507f75d75414339fbbeb8a

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word anywhere above and every digest after it changes. Head of chain: sha3:7f507f75d754. The product does the same thing to your evidence.