Register:CMMC Level 26 recordsSHA3-256 chainedSealed Amended head sha3:3701ae4549ddbdcdef2dc62c87ce3de1338d8cb5f608742fda81278807bb3e4dIntact

32 CFR Part 170 / NIST SP 800-171 Rev. 2

CMMC Level 2 compliance and evidence software.

CMMC Level 2 assesses the 110 requirements of NIST SP 800-171 Rev. 2. PolicyCortex records the state of your cloud, every change to it, and every machine action against those requirements, hash chained inside your tenant, and hands your C3PAO a package built to be verified by recomputation rather than believed.

Request AccessBook a call

Access is reviewed. Scope and onboarding are agreed with your team.

REC 0000OBLIGATIONsha3-256e770493b6a3fb97d413446d796a71a80d030499012e09b18878651f0180f684aprev:a5c2da4c4d6d

What a Level 2 assessment asks you to prove

CMMC Phase II is suspended. On July 13, 2026 the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. Phase I self-assessments and DFARS 252.204-7012 safeguarding obligations remain, and the Department has named NIST SP 800-171 Rev. 2 as the interim enforcement baseline: 110 requirements across 14 families, checked through self-assessment and selected government-led assessments.

The obligation is evidence, not narrative. For each requirement the assessor wants the technical state that satisfies it, the record of who or what changed that state and under what authority, and proof that the package handed over is the package that was assessed. The SPRS score you affirm rests on the same rows.

cmmc.baseline
NIST SP 800-171 Rev. 2: 110 requirements, 14 families. The interim baseline named by the Department.
cmmc.phase-ii
Suspended 2026-07-13 pending a 60-day reform review. Phase I self-assessment requirements remain in place.
cmmc.levels
Level 1 self-attestation, Level 2 C3PAO assessment, Level 3 DIBCAC assessment, under 32 CFR Part 170.
cmmc.boundary
The CUI enclave is a declared scope on every record. Azure Government, AWS GovCloud, and GCC High are observed clouds.
cmmc.source
Department of War release, July 13, 2026 (official release); the site's explainer: what changed and what to do.
cmmc.handoff
The eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.
REC 0001EVIDENCEsha3-2569b72cd01aaee0bf20cf52c2cbafdfeac4197ad4603a1b144219252e5c65664f4prev:e770493b6a3f

The evidence a C3PAO receives for the 110 requirements

One evidence base for the 110 requirements, handed to the assessor as generated evidence with the raw payload attached. The families below are where the three proofs file.

AC · IA · SC
Proof of state: point-in-time captures of access control, identification, and system protection settings, content hashed and regenerable to the date the assessor names.
CM · AU
Proof of change: who or what altered a CUI-scope resource, under what authority, with before and after hashes and a rollback identifier, on a chain that cannot be edited without detection.
Machine actions
Proof of agency: the envelope that permitted each autonomous action, the record of what it did, and the counterfactual that would have blocked it one notch different.
SSP · POA&M · SAR
Generated from the one implementation record, not written beside it. Exports as OSCAL 1.1.2 with an eMASS and C3PAO handoff package.
SPRS
SPRS-relevant evidence carried per requirement, so the score you affirm rests on rows you can recompute.
Exhibit SB-3control rows, as shipped
The PolicyCortex control implementation table: CMMC Level 2 controls by family with implementation status and evidence counts

Exhibit SB-3 · the 110-requirement table where evidence files, control by control, with implementation status and artifact counts. Illustrative demo data; the interface is real.

REC 0002VERIFICATIONsha3-2565ca6a79bb04ff9d70da7ff20d0575129fb5a275d2f4a4f5bf05853c7f9241381prev:9b72cd01aaee

How the C3PAO verifies the record

For Level 2 the recomputation is the C3PAO's: the OSCAL 1.1.2 package and the eMASS handoff carry the digests, so the assessor can confirm that the package handed over is the package that was assessed.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

REC 0003EVALUATIONsha3-256d33aa16f6cfa9dffd0391f8aba09adf8ddd53f38a0b869a6fe2ad6a53aeb660dprev:5ca6a79bb04f

Access and onboarding inside a CUI enclave

During agreed read-only onboarding in Azure Government, AWS GovCloud, or GCC High, the CUI enclave boundary is declared on every record and captured evidence is mapped to the 110 requirements.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

eval.mode
SHADOW. Watch only; nothing executes.
eval.onboarding
Access is reviewed. Scope and onboarding are agreed with your team.
eval.location
Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
eval.egress
None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
eval.after
You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
REC 0004DELIVERYsha3-256e8e98976217243cd7ee7a5a3bf5151a712d1532e29b4b7e3eab2e09497410e34prev:d33aa16f6cfa

Delivery, if you want the record stood up for you

If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee: $15,000 flat for the standard scope, one primary cloud environment. A cleared delivery team collects the evidence, writes the policies and assessment documents, coordinates approved technical remediation, prepares control owners, and stays through assessor review for in-scope follow-up at no additional cost. The independent assessor makes the certification decision. No certification is guaranteed.

engagement.price
$15,000 flat for the standard engagement scope. No hourly, no overages.
engagement.scope
30 days. One primary cloud environment. NIST SP 800-171 Rev. 2, 110 requirements.
engagement.package
SSP, POA&M, OSCAL 1.1.2 bundle, and the evidence behind them, organized by control objective.
engagement.review
In-scope assessor follow-up is included. The C3PAO remains independent and makes the decision.

Every term of the engagement, on its own page.

REC 0005QUESTIONSsha3-2563701ae4549ddbdcdef2dc62c87ce3de1338d8cb5f608742fda81278807bb3e4dprev:e8e989762172

Questions assessors and buyers ask

Did the Department of War cancel CMMC?

No. On July 13, 2026, the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. All Phase I self-assessment requirements remain in place.

What remains enforceable during the pause?

The Department says NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments. DFARS 252.204-7012 safeguarding obligations also remain contractually binding.

Does PolicyCortex make us compliant?

No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

Level 2 or Level 3, which do we need?

Most contractors handling CUI need Level 2, assessed by a C3PAO. Level 3 applies to organizations supporting high-priority programs and is assessed by DIBCAC. The evidence base is the same; the control selection differs.

What does the delivery engagement include?

Thirty days, one primary cloud environment, $15,000 flat: the 110-requirement baseline, CUI boundary analysis, coordinated and approved technical remediation, an SSP, POA&M, and OSCAL bundle with the evidence behind them, and support through assessor review. The independent assessor decides; no certification is guaranteed.

Does PolicyCortex submit to CMMC eMASS?

No. Your C3PAO controls the official assessment package and eMASS submission. PolicyCortex prepares the control-mapped evidence, change history, SSP, POA&M, and OSCAL bundle so the assessor can review, select, and submit with less manual cleanup.

Can we use a different C3PAO?

Yes. The output is C3PAO-agnostic: the OSCAL package and evidence bundle work with any C3PAO. We do not lock you to an assessor.

What about CMMC 2.0 versus 3.0?

The current CMMC final rule (32 CFR Part 170) defines three maturity levels: Level 1 self-attestation, Level 2 C3PAO assessment, Level 3 DIBCAC assessment. The record is kept against the requirement text in force; a revision is a new mapping over the same rows, and existing evidence is not relabeled.

What happens when a collector is down?

The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Hand the assessor a package built to be verified.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000OBLIGATIONe770493b6a3fa5c2da4c4d6d
REC 0001EVIDENCE9b72cd01aaeee770493b6a3f
REC 0002VERIFICATION5ca6a79bb04f9b72cd01aaee
REC 0003EVALUATIONd33aa16f6cfa5ca6a79bb04f
REC 0004DELIVERYe8e989762172d33aa16f6cfa
REC 0005QUESTIONS3701ae4549dde8e989762172

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:3701ae4549dd. The product does the same thing to your evidence.

Photograph: Central Intelligence Agency, Public domain (Central Intelligence Agency, 17 U.S.C. 105). Source