Everything your CMMC engagement needs, in one place — where your score stands today, and the specific items we need from you to move it forward.
Your score is a defensible floor — it counts only what we've confirmed, so it climbs as evidence comes in and we verify it. Nothing here is submitted to DoD until you decide to.
From Fortinet FortiGate Firewall, the remote-access policy/rule configuration showing which users and destinations are permitted, including the default-deny, so that remote access sessions are controlled rather than open.
From Fortinet FortiGate Firewall, the session logging configuration plus a recent log sample showing remote-access sessions are recorded (who, when, from where).
From Fortinet FortiGate Firewall, the tunnel/cipher configuration showing remote-access sessions are encrypted (protocol and cipher suite), so their confidentiality is cryptographically protected.
From Fortinet FortiGate Firewall, the configuration identifying the managed access control point(s) through which remote access is concentrated (the VPN gateway/concentrator), together with the network diagram placing them.
From Fortinet FortiGate Firewall, the firewall rules showing remote access is forced through the managed access control point(s) and that other inbound remote paths are denied.
The wireless network configuration showing access requires authentication (e.g. WPA2/WPA3-Enterprise with 802.1X, not a shared passphrase), from the wireless controller or access point management. If there is no wireless, record that as the answer.
The wireless configuration showing traffic is encrypted (the WPA2/WPA3 cipher), from the controller or AP management. If there is no wireless, record that.
From Elastic SIEM, evidence the platform provides on-demand analysis over collected logs -- a saved search/query or an analysis view run across a representative period.
From Elastic SIEM, a generated report (scheduled or on-demand) showing the platform can produce audit reports on demand.
From {{technology}}, the conditional-access/enforcement policy requiring MFA for network access to privileged accounts, with the privileged-user coverage report.
From {{technology}}, the enforcement policy requiring MFA for network access to non-privileged accounts, with a coverage report across all users showing enrollment and any exceptions.
From Mazak CNC Controller (OT), evidence that media carrying diagnostic/test programs is scanned before use -- the on-access/removable-media scanning policy showing external media is scanned, or scan records for such media.
From {{technology}}, the policy requiring multifactor authentication to establish nonlocal maintenance sessions over external connections.
From Fortinet FortiGate Firewall, the session-timeout/termination configuration and a log sample showing nonlocal maintenance sessions are ended when complete.
From Engineering Workstation Pool, the media/disk-encryption policy and a coverage report showing CUI-bearing system media is encrypted so access is limited to authorized users holding keys/credentials.
From {{technology}} (or the sanitization tool/service), completed sanitization/destruction records for disposed CUI media -- certificates of destruction or per-asset wipe records with method and date.
From {{technology}} (or reimaging/wipe tooling), records showing CUI media was sanitized before reissue, tied to specific assets and dates.
From {{technology}}, the backup-encryption configuration showing backups containing CUI are encrypted at the storage location, with confirmation it applies to the relevant backup sets.
Upload a policy, procedure, or plan and we'll read it and match it to the requirements it covers — you'll see it reflected here.