13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not →

CUI landed in your contract. Now someone has to draw a line around it.

Once a contract puts CUI in your hands, the questions arrive in order: which level applies, what is in scope, who may touch it, what an assessor will ask to see. MacTech answers the second one first, with a CUI vault your program runs inside.

The vault we sell is the enclave we run ourselves; what it carries for you is published per control. Read the responsibility matrix.

Where the CUI lives, and the documents that say so

Turnkey CUI Vault

A fully managed CUI vault with CMMC compliance posture and evidence provisioning handled for you-ready for C3PAO submittal, without the buildout.

Three tiers by scope, flat monthly - no per-user fees.

What's included

  • Fully managed CUI vault with a FIPS-controlled boundary; no CUI outside the enclave.
  • CMMC compliance posture built and maintained for your control set.
  • C3PAO-ready evidence provisioning, kept current for submittal and internal audits.

Deployable CUI Vault

A FIPS 140-3–controlled boundary and API-first vault you deploy into any app or enclave-reducing scope and cost while meeting DFARS and flow-downs.

What's in the box

  • FIPS-controlled boundary with REST API for upload, list, and delete-no CUI leaves the enclave.
  • Policy bundle and C3PAO-ready evidence package for your boundary documentation.

How the deployable vault is built: the boundary, the API and the artifact formats.

CMMC L2 Policy & Procedure Library

If your team is doing the work in-house, the documents are where the months go. This is the document set we run our own CMMC program on, written for an assessor to read and for you to tailor in days.

What you receive

  • 64 editable policies, procedures, plans and agreements covering every control family.
  • A coverage index mapping the documents to all 110 NIST SP 800-171 requirements.
  • A tailoring guide: what to change, and what to leave alone.
  • Document-control conventions an assessor will recognize.

The library in the market: its price, instant delivery, and what it credits toward.

Inside the Evidence Engine

TrainOS - training & evidence modules a C3PAO can read directly

39 / 46

Statements satisfied directly through training

13

CMMC L2 controls in scope

3 of 4

Families fully covered by training (AT · IR · CA)

v2.13

CMMC L2 Assessment Guide aligned (Sept 2024)

Awareness & Role-Based Training

AT-001 · AT-002

Two CMMC L2 awareness courses-CUI/insider-threat and role-based-delivering 30 modules, 50 quiz items, and 17 verbatim attestations across ~21,500 words of teaching prose.

  • 9 of 9 AT-family determination statements (AT.L2-3.2.1/2/3 - 100%).
  • Deterministic certificate + byte-stable PDF, hash-anchored to the ledger on pass.
  • Step-up reverification on course-version approval and certificate revocation.

Incident Response Tabletop

IR.L2-3.6.1/2/3

Facilitated tabletop exercises with an 11-file deterministic evidence bundle-plan, facilitator guide, injects, attestation, AAR, CARs, control-mapping matrix, technical evidence, notification log, and canonical snapshot.

  • 14 of 14 IR-family determination statements (100%).
  • DOCX + XLSX + PDF + JSON in a frozen ZIP-same input, byte-identical bundle hash.
  • AAR signing and bundle export both step-up reauth gated.

Annual Risk Assessment

RA.L2-3.11.1

Seven-phase wizard producing an 11-file vault zip: scoping, scenarios, NIST SP 800-30 R1 scoring, treatments (Mitigate/Accept/Transfer/Avoid), approvals chain, and live objective evaluator.

  • 100% of in-scope control (RA.L2-3.11.1 [a]+[b]) with live MET/NOT MET evaluation per objective.
  • HIGH/CRITICAL acceptance, executive approval, and finalize all step-up reauth gated.
  • Hard separation of duties enforced at the state machine-approver ≠ assessor.

Continuous Control Assessment

CA.L2-3.12.1/2/3/4

Per-objective evidence intake, per-packet adjudication, continuous-monitoring event capture, and a 12-file finalize bundle that drives the next SSP regenerate plus drift-detect.

  • 14 of 14 CA-family determination statements (100%, the entire CA family).
  • Operational POA&M nomenclature aligned to v2.13 page 204 (no 180-day cap conflation).
  • SCTM packet finalize, cycle finalize, and hash-manifest seal all step-up reauth gated.
Extended by MacTech toolkit

Vulnerability scan + remediation - RA.L2-3.11.2 + RA.L2-3.11.3 (7 statements)

The remaining 7 statements sit outside the training surface by design-they're continuous machine activity, not human program activity. MacTech covers them through EnclaveWatch + Microsoft Defender: Microsoft Defender Vulnerability Management and Defender for Cloud scanning, config-drift detection, and the vuln_remediation register feeding the same ledger-anchored audit chain that backs the training bundles.

The integrity primitives behind every artifact

Append-only ledger, gap-free

SHA-256 chained EvidenceRecord + LedgerEntry per tenant, peppered with a three-secret bind. Verifiable externally with no app dependency.

Byte-stable bundles

RFC 8785-aligned canonical JSON, frozen-date ZIP, pinned PDF trailers, deterministic DOCX packing-same input, same bytes, same hash.

CUI in Azure Government only

FIPS-aligned .usgovcloudapi.net by default, public access blocked at the storage account, 7-year retention pinned per blob.

ESP designation embedded

Every bundle carries the 32 CFR § 170.4 ESP designation-the OSA names MacTech in the SSP and the C3PAO recognizes the ESP scoring path on v2.13 page 11.

Step-up reauth on every gate

11 reverification gates across the four modules-AAR signing, course approval, cert revocation, RA acceptance, RA approval, finalize, SCTM packet, cycle finalize, hash-manifest seal, and more.

Assessment-objective granularity

Per-objective evidence with the verbatim NIST 800-171A statement, MET-path provenance, and assessment method (examine/interview/test) tagged inline. No aggregation, no false-pass risk.

Coverage and statement counts verified against the CMMC L2 Assessment Guide v2.13 (Sept 2024, DoD-CIO-00003).

Frameworks & Alignments

CMMC at the core. Every framework within reach.

NISTRMFNIST800-53NISTCSF 2.0FedRAMPModerateSOC 2ISO27001ISO9001ISO17025SPRSMITREATT&CKDISASTIGsNIST800-171ACMMC 2.0Level 2NIST800-171FIPS140-3DFARS7012MacTechTRUST CODEX

Which level, what is in scope, who may touch it: find out what you can answer today.

The readiness assessment shows where your program stands today and emails you the result; someone from MacTech then reaches out about what to do first.