Before you start
Sentry171 helps you work out which CMMC requirements apply to you, assess yourself against them, and produce the documents and records that back up your result. It guides the work and keeps the record; you still do the work, and the answers are yours.
What it doesn't do:
- It doesn't certify you. A self-assessment is your company's own statement; a Level 2 certification assessment is done by an authorized assessor (a C3PAO).
- It doesn't file anything for you. You enter your score and affirmation in SPRS yourself; Sentry171 keeps the record behind them.
- It doesn't fix your systems. It tells you what's missing and helps you plan the fixes.
Which level do you need?
- Level 1 if you handle only Federal Contract Information (FCI): contract details that aren't public. 17 practices.
- Level 2 if you handle Controlled Unclassified Information (CUI), or your contracts include DFARS 252.204-7012. 110 requirements.
Not sure? Look for that DFARS clause in your contracts, or for documents marked CUI. Either one means Level 2. You can switch levels during the trial.
Who should do it
Whoever knows how your computers, accounts and files are actually set up: often the IT person or an outside IT provider, working with the owner. You'll also need the name and title of the person who approves your policies, usually the owner or president.
Sign up and set up
- Create your account Go to app.sentry171.com/signup and enter your work email and a password.
- Confirm your email Click the link in the email we send. If it isn't in your inbox within a few minutes, check your spam or junk folder and mark it "not spam".
- Set up your company Your company name, your full legal name as it appears on contracts (it's printed on your policies and SSP), and your CMMC level.
- Say who's responsible Who runs security day to day, and who approves your policies. You can skip this and fill it in later, but policies can't be approved until someone is named.
- Follow the checklist You land on the Overview page. Its Getting Started checklist shows what's done and what to do next, and links straight to each step.
The order of the work
Each step builds on the one before, so it pays to go in order. Your scoping answers decide what the assessment asks; your assessment decides what the policies and SSP say.
- Describe your company Scoping page. A few core questions: who owns security policy, how often it's reviewed, where your CUI or FCI lives.
- Answer the scoping questions Scoping page. One short set of plain-language questions per security area. Your answers settle which requirements apply and pre-fill much of what comes later.
- Assess every practice Self-Assessment page. For each objective, mark it met, not met or not applicable, with suggested wording to start from. Your score updates as you go. This is the longest step; expect to spread it over several sittings.
- Optional Invite your team Settings page. See Your team below.
- Approve your policies Policies page. Policies are generated from your scoping and assessment. Review each one; your named approver approves it, and the approved version is kept.
- Level 2 Issue your System Security Plan System Security Plan page. Built from everything above. Gaps from your assessment go on your POA&M as corrective action plans.
- Affirm your score Score Proof page. A senior official affirms the result, and the signed, dated record is kept with your proof package.
After that, compliance becomes routine. The Calendar lists recurring obligations such as log reviews, training and access reviews, and pages like Training, Personnel and Privileged Accounts hold the records an assessor will ask to see.
Words you'll see
- CMMC
- Cybersecurity Maturity Model Certification: the Department of Defense program that checks contractors protect contract information. It is now written into DoD contracts.
- FCI
- Federal Contract Information. Information about a government contract that isn't meant to be public. Handling it means Level 1.
- CUI
- Controlled Unclassified Information. Sensitive government information that isn't classified, such as technical drawings or specifications. Handling it means Level 2.
- NIST SP 800-171
- The document that lists the 110 security requirements Level 2 is built on.
- Practice / requirement
- One security rule, for example "limit system access to authorized users". Level 1 has 17; Level 2 has 110.
- Objective
- The specific things an assessor checks within a requirement. A requirement is met only when all its objectives are. Level 2 has 320.
- Scoping
- Working out which systems, people and places handle the protected information, so you assess what matters and mark the rest not applicable with a reason.
- SPRS score
- Your Level 2 score, entered in the government's Supplier Performance Risk System. It starts at 110 and loses points for each requirement not met, and can go below zero. Level 1 has no score: all 17 practices must be met.
- SSP
- System Security Plan. Describes your systems and how you meet each requirement. Required for Level 2.
- POA&M
- Plan of Action and Milestones. Your plan for closing the gaps: what will be fixed, by whom and by when.
- Affirmation
- A senior official's statement that your result is accurate. Made after each assessment and every year.
- C3PAO
- An authorized third-party assessment organization. Some Level 2 contracts require one to assess you instead of a self-assessment.
Your team
Invite colleagues from Settings. They get an email with a link that works for seven days, and they sign in with that same email address. Each person has one role:
| Owner | Everything, plus managing owners, exporting all data and closing the account. |
|---|---|
| Administrator | Runs the program: invites people, approves policies, issues the SSP, signs affirmations, deletes records. |
| Member | Does the work: answers scoping and assessment questions, adds records, evidence and action plans, uploads documents. |
| Read-only | Sees everything, changes nothing. Good for a consultant, an assessor or leadership. |
Invitation emails can land in spam too; tell people to look there.
Trial, your data, help
The trial
Your free trial runs for 14 days. No credit card is needed. During the trial you can switch between Level 1 and Level 2 in Settings.
Your data
Each company's records are kept separate from every other company's. An owner can export everything, every record, document and uploaded file, as a zip from Settings at any time, or close the account and delete it all.
Getting help
Stuck, found something wrong, or have an idea? Email support@sentry171.com. A screenshot and the page you were on help a lot.
Ready? Scoping and your first few areas take an afternoon.
Start your free trial