CUI landed in your contract. Now someone has to draw a line around it.
Once a contract puts CUI in your hands, the questions arrive in order: which level applies, what is in scope, who may touch it, what an assessor will ask to see. MacTech answers the second one first, with a CUI vault your program runs inside.
The vault we sell is the enclave we run ourselves; what it carries for you is published per control. Read the responsibility matrix.
Where the CUI lives, and the documents that say so
Turnkey CUI Vault
A fully managed CUI vault with CMMC compliance posture and evidence provisioning handled for you-ready for C3PAO submittal, without the buildout.
- Managed CUI Vault$1,995/month
- Vault + EnclaveWatch$3,450/month
- Vault + EnclaveWatch + Trust Codex$5,950/month
Three tiers by scope, flat monthly - no per-user fees.
What's included
- Fully managed CUI vault with a FIPS-controlled boundary; no CUI outside the enclave.
- CMMC compliance posture built and maintained for your control set.
- C3PAO-ready evidence provisioning, kept current for submittal and internal audits.
Deployable CUI Vault
A FIPS 140-3–controlled boundary and API-first vault you deploy into any app or enclave-reducing scope and cost while meeting DFARS and flow-downs.
What's in the box
- FIPS-controlled boundary with REST API for upload, list, and delete-no CUI leaves the enclave.
- Policy bundle and C3PAO-ready evidence package for your boundary documentation.
How the deployable vault is built: the boundary, the API and the artifact formats.
CMMC L2 Policy & Procedure Library
If your team is doing the work in-house, the documents are where the months go. This is the document set we run our own CMMC program on, written for an assessor to read and for you to tailor in days.
What you receive
- 64 editable policies, procedures, plans and agreements covering every control family.
- A coverage index mapping the documents to all 110 NIST SP 800-171 requirements.
- A tailoring guide: what to change, and what to leave alone.
- Document-control conventions an assessor will recognize.
The library in the market: its price, instant delivery, and what it credits toward.
Inside the Evidence Engine
TrainOS - training & evidence modules a C3PAO can read directly
39 / 46
Statements satisfied directly through training
13
CMMC L2 controls in scope
3 of 4
Families fully covered by training (AT · IR · CA)
v2.13
CMMC L2 Assessment Guide aligned (Sept 2024)
Awareness & Role-Based Training
AT-001 · AT-002Two CMMC L2 awareness courses-CUI/insider-threat and role-based-delivering 30 modules, 50 quiz items, and 17 verbatim attestations across ~21,500 words of teaching prose.
- 9 of 9 AT-family determination statements (AT.L2-3.2.1/2/3 - 100%).
- Deterministic certificate + byte-stable PDF, hash-anchored to the ledger on pass.
- Step-up reverification on course-version approval and certificate revocation.
Incident Response Tabletop
IR.L2-3.6.1/2/3Facilitated tabletop exercises with an 11-file deterministic evidence bundle-plan, facilitator guide, injects, attestation, AAR, CARs, control-mapping matrix, technical evidence, notification log, and canonical snapshot.
- 14 of 14 IR-family determination statements (100%).
- DOCX + XLSX + PDF + JSON in a frozen ZIP-same input, byte-identical bundle hash.
- AAR signing and bundle export both step-up reauth gated.
Annual Risk Assessment
RA.L2-3.11.1Seven-phase wizard producing an 11-file vault zip: scoping, scenarios, NIST SP 800-30 R1 scoring, treatments (Mitigate/Accept/Transfer/Avoid), approvals chain, and live objective evaluator.
- 100% of in-scope control (RA.L2-3.11.1 [a]+[b]) with live MET/NOT MET evaluation per objective.
- HIGH/CRITICAL acceptance, executive approval, and finalize all step-up reauth gated.
- Hard separation of duties enforced at the state machine-approver ≠ assessor.
Continuous Control Assessment
CA.L2-3.12.1/2/3/4Per-objective evidence intake, per-packet adjudication, continuous-monitoring event capture, and a 12-file finalize bundle that drives the next SSP regenerate plus drift-detect.
- 14 of 14 CA-family determination statements (100%, the entire CA family).
- Operational POA&M nomenclature aligned to v2.13 page 204 (no 180-day cap conflation).
- SCTM packet finalize, cycle finalize, and hash-manifest seal all step-up reauth gated.
Vulnerability scan + remediation - RA.L2-3.11.2 + RA.L2-3.11.3 (7 statements)
The remaining 7 statements sit outside the training surface by design-they're continuous machine activity, not human program activity. MacTech covers them through EnclaveWatch + Microsoft Defender: Microsoft Defender Vulnerability Management and Defender for Cloud scanning, config-drift detection, and the vuln_remediation register feeding the same ledger-anchored audit chain that backs the training bundles.
The integrity primitives behind every artifact
Append-only ledger, gap-free
SHA-256 chained EvidenceRecord + LedgerEntry per tenant, peppered with a three-secret bind. Verifiable externally with no app dependency.
Byte-stable bundles
RFC 8785-aligned canonical JSON, frozen-date ZIP, pinned PDF trailers, deterministic DOCX packing-same input, same bytes, same hash.
CUI in Azure Government only
FIPS-aligned .usgovcloudapi.net by default, public access blocked at the storage account, 7-year retention pinned per blob.
ESP designation embedded
Every bundle carries the 32 CFR § 170.4 ESP designation-the OSA names MacTech in the SSP and the C3PAO recognizes the ESP scoring path on v2.13 page 11.
Step-up reauth on every gate
11 reverification gates across the four modules-AAR signing, course approval, cert revocation, RA acceptance, RA approval, finalize, SCTM packet, cycle finalize, hash-manifest seal, and more.
Assessment-objective granularity
Per-objective evidence with the verbatim NIST 800-171A statement, MET-path provenance, and assessment method (examine/interview/test) tagged inline. No aggregation, no false-pass risk.
Coverage and statement counts verified against the CMMC L2 Assessment Guide v2.13 (Sept 2024, DoD-CIO-00003).
Frameworks & Alignments
CMMC at the core. Every framework within reach.
Deep dives
Practitioner guides - go deeper on the parts of CMMC that matter most
CMMC Level 2 compliance
All 110 NIST 800-171 controls, C3PAO assessment path, cost and timeline.
CUI enclave architecture
The boundary-engineering decisions that cut assessment scope by 60–90%.
CMMC 2.0 self-attestation
Who can self-attest, what the affirmation legally commits, False Claims Act exposure.
NIST 800-171 compliance
The underlying control catalog every CMMC L2 program implements.
Incident response tabletops
Methodology, scenarios, and AAR rigor for IR.L2-3.6.1 / 3.6.2 / 3.6.3.
Supply-chain cyber compliance
Sub-tier flowdown management for primes with complex supply chains.
Which level, what is in scope, who may touch it: find out what you can answer today.
The readiness assessment shows where your program stands today and emails you the result; someone from MacTech then reaches out about what to do first.
From MacZine
The program, as it keeps changing
Three issues on the levels, the class deviation, and where a shop floor sits in scope.