sha3:3701ae4549ddbdcdef2dc62c87ce3de1338d8cb5f608742fda81278807bb3e4dIntact32 CFR Part 170 / NIST SP 800-171 Rev. 2
CMMC Level 2 compliance and evidence software.
CMMC Level 2 assesses the 110 requirements of NIST SP 800-171 Rev. 2. PolicyCortex records the state of your cloud, every change to it, and every machine action against those requirements, hash chained inside your tenant, and hands your C3PAO a package built to be verified by recomputation rather than believed.
e770493b6a3fb97d413446d796a71a80d030499012e09b18878651f0180f684aprev:a5c2da4c4d6dWhat a Level 2 assessment asks you to prove
CMMC Phase II is suspended. On July 13, 2026 the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. Phase I self-assessments and DFARS 252.204-7012 safeguarding obligations remain, and the Department has named NIST SP 800-171 Rev. 2 as the interim enforcement baseline: 110 requirements across 14 families, checked through self-assessment and selected government-led assessments.
The obligation is evidence, not narrative. For each requirement the assessor wants the technical state that satisfies it, the record of who or what changed that state and under what authority, and proof that the package handed over is the package that was assessed. The SPRS score you affirm rests on the same rows.
- cmmc.baseline
- NIST SP 800-171 Rev. 2: 110 requirements, 14 families. The interim baseline named by the Department.
- cmmc.phase-ii
- Suspended 2026-07-13 pending a 60-day reform review. Phase I self-assessment requirements remain in place.
- cmmc.levels
- Level 1 self-attestation, Level 2 C3PAO assessment, Level 3 DIBCAC assessment, under 32 CFR Part 170.
- cmmc.boundary
- The CUI enclave is a declared scope on every record. Azure Government, AWS GovCloud, and GCC High are observed clouds.
- cmmc.source
- Department of War release, July 13, 2026 (official release); the site's explainer: what changed and what to do.
- cmmc.handoff
- The eMASS and C3PAO handoff package: what the assessor receives and how they verify it by hash.
9b72cd01aaee0bf20cf52c2cbafdfeac4197ad4603a1b144219252e5c65664f4prev:e770493b6a3fThe evidence a C3PAO receives for the 110 requirements
One evidence base for the 110 requirements, handed to the assessor as generated evidence with the raw payload attached. The families below are where the three proofs file.
- AC · IA · SC
- Proof of state: point-in-time captures of access control, identification, and system protection settings, content hashed and regenerable to the date the assessor names.
- CM · AU
- Proof of change: who or what altered a CUI-scope resource, under what authority, with before and after hashes and a rollback identifier, on a chain that cannot be edited without detection.
- Machine actions
- Proof of agency: the envelope that permitted each autonomous action, the record of what it did, and the counterfactual that would have blocked it one notch different.
- SSP · POA&M · SAR
- Generated from the one implementation record, not written beside it. Exports as OSCAL 1.1.2 with an eMASS and C3PAO handoff package.
- SPRS
- SPRS-relevant evidence carried per requirement, so the score you affirm rests on rows you can recompute.

Exhibit SB-3 · the 110-requirement table where evidence files, control by control, with implementation status and artifact counts. Illustrative demo data; the interface is real.
5ca6a79bb04ff9d70da7ff20d0575129fb5a275d2f4a4f5bf05853c7f9241381prev:9b72cd01aaeeHow the C3PAO verifies the record
For Level 2 the recomputation is the C3PAO's: the OSCAL 1.1.2 package and the eMASS handoff carry the digests, so the assessor can confirm that the package handed over is the package that was assessed.
Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.
A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.
d33aa16f6cfa9dffd0391f8aba09adf8ddd53f38a0b869a6fe2ad6a53aeb660dprev:5ca6a79bb04fAccess and onboarding inside a CUI enclave
During agreed read-only onboarding in Azure Government, AWS GovCloud, or GCC High, the CUI enclave boundary is declared on every record and captured evidence is mapped to the 110 requirements.
Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.
- eval.mode
- SHADOW. Watch only; nothing executes.
- eval.onboarding
- Access is reviewed. Scope and onboarding are agreed with your team.
- eval.location
- Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- eval.egress
- None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- eval.after
- You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
e8e98976217243cd7ee7a5a3bf5151a712d1532e29b4b7e3eab2e09497410e34prev:d33aa16f6cfaDelivery, if you want the record stood up for you
If you want the record stood up for you, the delivery engagement is 30 days at a fixed fee: $15,000 flat for the standard scope, one primary cloud environment. A cleared delivery team collects the evidence, writes the policies and assessment documents, coordinates approved technical remediation, prepares control owners, and stays through assessor review for in-scope follow-up at no additional cost. The independent assessor makes the certification decision. No certification is guaranteed.
- engagement.price
- $15,000 flat for the standard engagement scope. No hourly, no overages.
- engagement.scope
- 30 days. One primary cloud environment. NIST SP 800-171 Rev. 2, 110 requirements.
- engagement.package
- SSP, POA&M, OSCAL 1.1.2 bundle, and the evidence behind them, organized by control objective.
- engagement.review
- In-scope assessor follow-up is included. The C3PAO remains independent and makes the decision.
3701ae4549ddbdcdef2dc62c87ce3de1338d8cb5f608742fda81278807bb3e4dprev:e8e989762172Questions assessors and buyers ask
Did the Department of War cancel CMMC?
No. On July 13, 2026, the Department suspended the Phase II transition and pending and future implementation milestones while a reform task force conducts a 60-day review. All Phase I self-assessment requirements remain in place.
What remains enforceable during the pause?
The Department says NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments. DFARS 252.204-7012 safeguarding obligations also remain contractually binding.
Does PolicyCortex make us compliant?
No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.
Level 2 or Level 3, which do we need?
Most contractors handling CUI need Level 2, assessed by a C3PAO. Level 3 applies to organizations supporting high-priority programs and is assessed by DIBCAC. The evidence base is the same; the control selection differs.
What does the delivery engagement include?
Thirty days, one primary cloud environment, $15,000 flat: the 110-requirement baseline, CUI boundary analysis, coordinated and approved technical remediation, an SSP, POA&M, and OSCAL bundle with the evidence behind them, and support through assessor review. The independent assessor decides; no certification is guaranteed.
Does PolicyCortex submit to CMMC eMASS?
No. Your C3PAO controls the official assessment package and eMASS submission. PolicyCortex prepares the control-mapped evidence, change history, SSP, POA&M, and OSCAL bundle so the assessor can review, select, and submit with less manual cleanup.
Can we use a different C3PAO?
Yes. The output is C3PAO-agnostic: the OSCAL package and evidence bundle work with any C3PAO. We do not lock you to an assessor.
What about CMMC 2.0 versus 3.0?
The current CMMC final rule (32 CFR Part 170) defines three maturity levels: Level 1 self-attestation, Level 2 C3PAO assessment, Level 3 DIBCAC assessment. The record is kept against the requirement text in force; a revision is a new mapping over the same rows, and existing evidence is not relabeled.
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
Hand the assessor a package built to be verified.