Metes & Bounds Advisory
CMMC Readiness Portal
Cascade Precision
CMMC Level 2 · CAGE 8CP44

Your path to assessment-ready

Everything your CMMC engagement needs, in one place — where your score stands today, and the specific items we need from you to move it forward.

Where you stand

updated today
Requirements confirmed
56 / 110
56 confirmed 22 under review 21 gaps to close 11 not applicable
SPRS score
-6
of 110 target · rises as each requirement is confirmed
Reachable now
48
if everything under review confirms
On track for
building history
at the current pace — indicative, not a promise
Needs you
83
evidence items open right now

Your score is a defensible floor — it counts only what we've confirmed, so it climbs as evidence comes in and we verify it. Nothing here is submitted to DoD until you decide to.

Only share security-setup information. Policies, procedures, and screenshots or exports of your system settings. Please don't upload anything with CUI, FCI, or actual contract or customer data — if you're unsure, ask us first.

What we need from you

83 open · 85 total

Remote access sessions controlled (VPN)

From Fortinet FortiGate Firewall, the remote-access policy/rule configuration showing which users and destinations are permitted, including the default-deny, so that remote access sessions are controlled rather than open.

Remote access / VPN concentrator within 90 days Owner: Network Operations
Needed

Remote access sessions monitored (VPN)

From Fortinet FortiGate Firewall, the session logging configuration plus a recent log sample showing remote-access sessions are recorded (who, when, from where).

Remote access / VPN concentrator within 30 days Owner: Network Operations
Needed

Remote access confidentiality (VPN encryption)

From Fortinet FortiGate Firewall, the tunnel/cipher configuration showing remote-access sessions are encrypted (protocol and cipher suite), so their confidentiality is cryptographically protected.

Remote access / VPN concentrator within 180 days Owner: Cybersecurity Architecture
Needed

Managed access control points identified (VPN)

From Fortinet FortiGate Firewall, the configuration identifying the managed access control point(s) through which remote access is concentrated (the VPN gateway/concentrator), together with the network diagram placing them.

Remote access / VPN concentrator within 180 days Owner: Cybersecurity Architecture
Needed

Remote access routed through control points (firewall)

From Fortinet FortiGate Firewall, the firewall rules showing remote access is forced through the managed access control point(s) and that other inbound remote paths are denied.

Network firewall within 90 days Owner: Network Operations
Needed

Wireless access protected by authentication

The wireless network configuration showing access requires authentication (e.g. WPA2/WPA3-Enterprise with 802.1X, not a shared passphrase), from the wireless controller or access point management. If there is no wireless, record that as the answer.

Wireless LAN controller / access point management within 90 days Owner: Network Operations
Needed

Wireless access protected by encryption

The wireless configuration showing traffic is encrypted (the WPA2/WPA3 cipher), from the controller or AP management. If there is no wireless, record that.

Wireless LAN controller / access point management within 90 days Owner: Network Operations
Needed

Audit record reduction capability (SIEM)

From Elastic SIEM, evidence the platform provides on-demand analysis over collected logs -- a saved search/query or an analysis view run across a representative period.

SIEM / centralized log management within 90 days Owner: Defensive Cybersecurity
Needed

Report generation capability (SIEM)

From Elastic SIEM, a generated report (scheduled or on-demand) showing the platform can produce audit reports on demand.

SIEM / centralized log management within 90 days Owner: Defensive Cybersecurity
Needed

MFA for network privileged access (MFA platform)

From {{technology}}, the conditional-access/enforcement policy requiring MFA for network access to privileged accounts, with the privileged-user coverage report.

MFA / identity provider console within 90 days Owner: Identity & Access Specialist
Needed

MFA for network non-privileged access (MFA platform)

From {{technology}}, the enforcement policy requiring MFA for network access to non-privileged accounts, with a coverage report across all users showing enrollment and any exceptions.

MFA / identity provider console within 90 days Owner: Identity & Access Specialist
Needed

Diagnostic media checked for malicious code (anti-malware)

From Mazak CNC Controller (OT), evidence that media carrying diagnostic/test programs is scanned before use -- the on-access/removable-media scanning policy showing external media is scanned, or scan records for such media.

Endpoint protection / EDR management console within 30 days Owner: Systems Administration
Needed

MFA for nonlocal maintenance sessions (MFA platform)

From {{technology}}, the policy requiring multifactor authentication to establish nonlocal maintenance sessions over external connections.

MFA / identity provider console within 90 days Owner: Identity & Access Specialist
Needed

Nonlocal maintenance sessions terminated (VPN)

From Fortinet FortiGate Firewall, the session-timeout/termination configuration and a log sample showing nonlocal maintenance sessions are ended when complete.

Remote access / VPN concentrator within 90 days Owner: Network Operations
Needed

Access to CUI on media limited (encryption)

From Engineering Workstation Pool, the media/disk-encryption policy and a coverage report showing CUI-bearing system media is encrypted so access is limited to authorized users holding keys/credentials.

Disk/media encryption management (e.g. full-disk encryption console) within 180 days Owner: Systems Administration
Needed

Media sanitized/destroyed before disposal (sanitization)

From {{technology}} (or the sanitization tool/service), completed sanitization/destruction records for disposed CUI media -- certificates of destruction or per-asset wipe records with method and date.

Media sanitization tool / certificates of destruction within 365 days Owner: IT Asset Management (ITAM) Manager
Needed

Media sanitized before reuse (sanitization)

From {{technology}} (or reimaging/wipe tooling), records showing CUI media was sanitized before reissue, tied to specific assets and dates.

Endpoint reimaging / media wipe tooling within 365 days Owner: Systems Administration
Needed

Backup CUI confidentiality protected (backup platform)

From {{technology}}, the backup-encryption configuration showing backups containing CUI are encrypted at the storage location, with confirmation it applies to the relevant backup sets.

Backup / BCDR console within 180 days Owner: Systems Administration
Needed
+ 67 more requests — grouped by system, shown as your engagement progresses

Your documents

policies & procedures

Upload a policy, procedure, or plan and we'll read it and match it to the requirements it covers — you'll see it reflected here.