CMMC is now in DoD contracts. Most small shops aren't staffed for it.
If you handle contract information for the Department of Defense, you need a current self-assessment, a score on file, and the documents to back it up.
110 requirements, 320 objectives
NIST SP 800-171 is long, and written for people who already speak it. Knowing where to start is half the battle.
Paperwork that has to agree
Your score, your SSP, your policies and your POA&M all have to tell the same story. Spreadsheets drift apart.
It never ends
Log reviews, training, access reviews, the annual affirmation. Compliance is a calendar, not a project.
How it works
Plain-language questions first. The paperwork follows from your answers, so nothing contradicts anything else.
Scope
Answer short questions about how your company works: where CUI lives, how accounts are managed, what you use. Your answers decide which requirements apply.
Assess
Mark each objective met, not met or not applicable, with suggested wording to start from. Your SPRS score updates as you go.
Prove it
Generate policies and your System Security Plan, plan fixes for the gaps, and keep signed, dated records of every affirmation.
What you get
Everything a small contractor needs for a self-assessment, in one place, with no consultant hours.
Guided scoping
Questions that settle what applies to your environment, so the assessment only asks about what's relevant.
Objective-level self-assessment
All 320 assessment objectives, with N/A justifications and suggested narratives.
SPRS score, with proof
Your score as of any date, rebuilt from history, and a proof package for an assessor or prime.
Policies from your answers
14 policy families, generated from your scoping and assessment, approved and versioned.
System Security Plan
An SSP built from everything above. Issue versions with a named approver.
POA&M as action plans
Turn gaps into corrective action plans with ready-made steps, owners and due dates.
Compliance calendar
22 recurring obligations, from log reviews to training, with evidence attached when done.
Records in one place
Assets, privileged accounts, personnel, training, incidents, maintenance, media disposal and changes.
Your team, your assessor
Invite colleagues as members, and give a consultant or assessor read-only access.
Level 1 or Level 2
Pick the level your contracts call for. During the trial you can switch.
You handle FCI only
Federal Contract Information: contract details that aren't public, but no CUI.
- 17 practices from FAR 52.204-21
- Annual self-assessment and affirmation
- Policies and records to back it up
You handle CUI
Controlled Unclassified Information, or DFARS 252.204-7012 in your contracts.
- 110 requirements from NIST SP 800-171
- SPRS score, System Security Plan and POA&M
- Ready for self-assessment, or to prepare for a C3PAO
Built by a defense contractor, for defense contractors
Sentry171 was built inside a small defense contractor working through CMMC itself, because the tools we found were made for companies with a compliance department. It does what we needed: tells you what applies, walks you through it, and keeps the record straight.
See where you stand in an afternoon.
Start with scoping and the first few domains. Your score updates as you go. Free for 14 days, no credit card.
Start your free trial