Register:Governance5 recordsSHA3-256 chainedSealed head sha3:36218b0add80968e1db1b8a3402c759a30f19ca3cada4cc514093ebf9443150aIntact

CMMC / NIST 800-171 and 800-53 / FedRAMP / SOC 2 / PCI DSS / ISO 27001 / HIPAA

One record. Every framework that matters.

Defense contractors carry CMMC, NIST 800-171, NIST 800-53, FedRAMP, and DFARS at once; commercial enterprises stack SOC 2, PCI DSS 4.0, ISO 27001, and HIPAA. PolicyCortex keeps one hash-chained implementation record and writes the control mapping on every row, so one encryption setting evidences every framework that cites it and the evidence for all of them can be recomputed.

Request verificationBook a call

Read only. Fourteen days. No sales call required.

REC 0000OBLIGATIONsha3-2565be7c23a408d3a7384daa7f64158d34c09f7936a590d99c6295030673bb6679aprev:9b4405416504

What overlapping frameworks ask you to prove

Every framework asks for the same environment through a different vocabulary. CMMC AC.L2-3.1.1, NIST 800-53 AC-3, FedRAMP AC-3, SOC 2 CC6.1, PCI DSS requirement 7, ISO 27001 A.5.15, and HIPAA 164.312(a) are all, in the end, a question about who can reach what. Answering each separately means collecting the same evidence several times and keeping several narratives in step by hand.

The obligation that matters is that the mappings be explicit. An assessor who asks why this row satisfies that control needs to see the mapping written on the record, not inferred by a tool at report time.

gov.frameworks
CMMC Level 2, NIST 800-171 and 800-53, FedRAMP, DFARS, SOC 2, PCI DSS 4.0, ISO 27001, HIPAA, ITAR, CIS benchmarks, MITRE ATT&CK and ATLAS.
gov.mapping
Bidirectional control map: the 110 CMMC Level 2 requirements cross-walked to NIST 800-53 and onward. The mapping is stored on the record, not implied.
gov.policy
Policy evaluation runs inside your tenant; custom rules are first-class beside framework controls and produce the same evidence.
gov.rollout
Policy changes roll out in phases under the trust mode you set; a regression against the compliance baseline rolls back to the prior phase, and the rollback is a row.
REC 0001EVIDENCEsha3-2565927addc2b51ad8a3a6017011853233f57b306f1a369452e7159c6ec4c592e79prev:5be7c23a408d

One implementation record, every framework

One implementation record, many envelopes. Where each proof files:

Access (AC · CC6 · A.5.15 · req. 7)
Proof of state: who could reach what as of any date, one record, with every framework's control identifier written on it.
Change (CM · CC8 · A.8.32 · req. 6)
Proof of change: who or what altered the estate, under what authority, with before and after hashes and a rollback identifier, filed once against every framework that cites it.
Audit (AU · CC7 · A.8.15 · req. 10)
The chain itself: an audit record that cannot be edited without detection, with declared gaps, serving every logging and monitoring control at once.
Machine actions (AC-6 · SI-4 · ATLAS)
Proof of agency: the envelope, the action, and the counterfactual for every autonomous act, with MITRE ATT&CK and ATLAS techniques annotated.
Documents (SSP · POA&M · SAR)
Generated from the one record and exported as OSCAL 1.1.2 where the framework wants it. The document is never the source.
Exhibit SB-9control rows, as shipped
The PolicyCortex control implementation table: CMMC Level 2 controls by family with implementation status and evidence counts

Exhibit SB-9 · the requirement table where evidence files, control by control, with implementation status and artifact counts. Illustrative demo data; the interface is real.

REC 0002VERIFICATIONsha3-2569abaf56b29029b38fc7e8e999bf46b903062418dce1c7179ca1d42d8ba7ffd6cprev:5927addc2b51

How one record is verified for many frameworks

For overlapping frameworks the recomputation is done once: the control mapping is a field on the row, so an assessor for any framework recomputes the same digest and reads the mapping written on it.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

REC 0003EVALUATIONsha3-256fbbc5f2e2747c6712f5ed293852f16b6d882785924c66b16a3010e93914eb466prev:9abaf56b2902

How you evaluate it across your frameworks

The fourteen days capture every row with its mappings written on, so by the end one encryption setting already evidences every framework you selected and none of that evidence needs re-collecting.

Connect read only for fourteen days, in SHADOW mode, inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. At the end of the fourteen days you hold the records and can recompute the chain yourself.

eval.mode
SHADOW. Watch only; nothing executes.
eval.duration
Fourteen days.
eval.location
Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
eval.egress
None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
eval.after
You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
REC 0004QUESTIONSsha3-25636218b0add80968e1db1b8a3402c759a30f19ca3cada4cc514093ebf9443150aprev:fbbc5f2e2747

Questions assessors and buyers ask

How does cross-framework mapping work?

A curated bidirectional control map: the 110 CMMC Level 2 requirements cross-walked to NIST 800-53 and, through it, to the other frameworks. Each row carries its mappings as a field, so one piece of evidence satisfies the matched controls in adjacent frameworks and the reason is written down.

Custom internal policies?

Yes. Custom rules are first-class beside the framework controls: same evidence model, same gating, same record.

Why several policy engines under one layer?

OPA for in-tree rules, Steampipe for live cloud queries, Cloud Custodian for resource lifecycle. The router picks the engine per control; the evidence is the same shape whichever ran.

How is a regression detected during a phased rollout?

Each phase runs against the compliance baseline. Promotion to the next phase requires the same or a better result. A drop rolls back to the prior phase, and the rollback is a row in proof of change.

Does PolicyCortex make us compliant?

No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

What happens when a collector is down?

The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

One record. Every mapping written down.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000OBLIGATION5be7c23a408d9b4405416504
REC 0001EVIDENCE5927addc2b515be7c23a408d
REC 0002VERIFICATION9abaf56b29025927addc2b51
REC 0003EVALUATIONfbbc5f2e27479abaf56b2902
REC 0004QUESTIONS36218b0add80fbbc5f2e2747

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:36218b0add80. The product does the same thing to your evidence.

Photograph: Bill Hrybyk, NASA Goddard Space Flight Center, Public domain (NASA, 17 U.S.C. 105). Source