REFERENCE // FAQ

Frequently asked questions.

Everything about PolicyCortex — compliance frameworks, deployment options, security model, pricing. Jump to a category or scroll the lot.

01 · CMMC COMPLIANCE

CMMC Compliance

What is the November 6 deadline?

DFARS 252.204-7021 enforcement begins November 6, 2026. All defense contractors handling Controlled Unclassified Information (CUI) must hold a CMMC Level 2 certification or risk losing their DoD contracts.

How much does CMMC compliance cost with PolicyCortex?

The 30-day CMMC pilot is $15,000 flat. This includes baseline assessment, automated gap closure, SSP, POA&M, and a C3PAO-ready evidence package. Traditional consultants charge $70K-$300K and take 6-18 months.

What clearances does the PolicyCortex team hold?

Founder Leonard Esere holds a DoD Secret clearance and a DoE Q clearance (equivalent to DoD Top Secret). He currently consults at a DOE national laboratory.

02 · GENERAL

General

What is PolicyCortex?

PolicyCortex is an autonomous cloud governance platform that replaces disconnected compliance, security, cost, and AI governance tools with a single system. It continuously monitors your cloud infrastructure, detects misconfigurations and policy violations, and remediates issues automatically - all while collecting compliance evidence in real time.

Who is PolicyCortex built for?

PolicyCortex is designed for defense contractors preparing for CMMC assessments, national laboratories and federal agencies managing complex multi-cloud environments, and any organization that needs continuous compliance monitoring across AWS, Azure, and GCP.

How is PolicyCortex different from a traditional GRC tool?

Traditional GRC tools manage policies and risk registers but don't connect to your cloud infrastructure. PolicyCortex reads your actual cloud configuration via API, continuously monitors compliance posture, and can automatically remediate issues - closing the gap between documented policies and actual infrastructure state.

What cloud providers does PolicyCortex support?

PolicyCortex supports AWS, Microsoft Azure, and Google Cloud Platform. It provides unified governance across all three providers from a single dashboard, with provider-specific policy engines that understand each platform's native services.

03 · COMPLIANCE & FRAMEWORKS

Compliance & Frameworks

What compliance frameworks does PolicyCortex support?

PolicyCortex supports CMMC (Levels 1-3), NIST 800-171, NIST 800-53, FedRAMP, CIS Benchmarks, DFARS 252.204-7012, MITRE ATT&CK, and MITRE ATLAS. Controls are mapped across frameworks so you don't duplicate effort when meeting multiple requirements simultaneously.

How does PolicyCortex help with CMMC preparation?

PolicyCortex continuously monitors your cloud environment against all 110 NIST 800-171 practices (CMMC Level 2). It automatically collects evidence for each control, generates System Security Plans (SSPs) and POA&Ms, and alerts you when your compliance posture drifts. This transforms CMMC preparation from a months-long manual process into continuous readiness.

Does PolicyCortex replace my C3PAO assessment?

No. You still need a Certified Third-Party Assessor Organization (C3PAO) for your formal CMMC assessment. PolicyCortex helps you prepare by maintaining continuous compliance and assembling the evidence your assessor will need, significantly streamlining the assessment process.

Can PolicyCortex map controls across multiple frameworks?

Yes. PolicyCortex maintains a cross-framework control mapping so that a single security implementation can satisfy requirements across CMMC, NIST, FedRAMP, CIS, and other frameworks simultaneously. This eliminates duplicate evidence collection and provides a unified compliance dashboard.

How does evidence collection work?

PolicyCortex continuously monitors your cloud configuration and automatically collects evidence as it detects compliant (or non-compliant) states. Each evidence artifact is timestamped, versioned, and mapped to the relevant control. When assessment time comes, your evidence is already assembled and current.

04 · TECHNICAL & DEPLOYMENT

Technical & Deployment

How is PolicyCortex deployed?

PolicyCortex offers multiple deployment models: SaaS (multi-tenant), single-tenant cloud, GovCloud (AWS GCC/GCC-High, Azure Government), and on-premises for air-gapped environments. Every deployment model runs the same platform with the same capabilities.

Does PolicyCortex require agents on my servers?

No. PolicyCortex operates agentlessly via cloud provider APIs (AWS, Azure, GCP). It reads your configuration, resource state, and event data through standard cloud APIs using read-only access where possible. Remediation actions use scoped write permissions that you control.

How does autonomous remediation work?

When PolicyCortex detects a policy violation or misconfiguration, it analyzes the root cause and determines the appropriate remediation action. Depending on your configuration, it can execute the fix automatically or present it for human approval. Every action includes a rollback ID so changes can be reversed if needed.

Can I start with manual approvals before enabling full automation?

Yes. Most organizations start in gated mode where every remediation action requires human approval. As confidence builds, you can gradually enable autonomous remediation for specific action types and resource categories while keeping human approval for higher-risk changes.

What data does PolicyCortex access?

PolicyCortex accesses cloud configuration data, metadata, and event logs through cloud provider APIs. It does not access the content of your files, databases, or application data. For CUI environments, the platform can be deployed within your own boundary so that metadata never leaves your environment.

Can PolicyCortex work in air-gapped environments?

Yes. PolicyCortex supports on-premises deployment for organizations that operate disconnected or air-gapped environments. The platform runs entirely within your infrastructure with no external connectivity required for core functionality.

05 · SECURITY & TRUST

Security & Trust

How does PolicyCortex handle my data?

PolicyCortex processes cloud configuration metadata - not your application data or CUI. Data is encrypted in transit and at rest. For the most sensitive environments, single-tenant and on-premises deployments ensure your data never leaves your boundary.

Is PolicyCortex pursuing FedRAMP authorization?

PolicyCortex is designed with FedRAMP-aligned security controls. Contact us for current authorization status and available deployment options for federal customers.

Who can see what in PolicyCortex?

PolicyCortex implements role-based access control with scoped visibility. CISOs see organization-wide posture. Cloud architects see infrastructure details. ISSOs see evidence and control status. Each role sees only what they need - without exposing sensitive information across team boundaries.

06 · PRICING & GETTING STARTED

Pricing & Getting Started

How is PolicyCortex priced?

Pricing depends on your deployment model, cloud footprint size, and the modules you need. We offer flexible models that scale with your infrastructure. Contact us for a tailored quote based on your specific requirements.

Is there a free trial?

We offer guided evaluations where you can see PolicyCortex operating against your actual cloud environment. Contact us to schedule a technical evaluation.

How quickly can I get started?

SaaS deployments can be connected to your cloud accounts within hours. Initial compliance posture assessment is typically available within the first day. Full policy configuration and remediation setup varies by environment complexity but typically takes days, not weeks.

STILL HAVE QUESTIONS

Talk to the team directly.

Cleared consultant responds within one business day. Or skip the queue and book a 30-min scoping call with the founder.

SYS: ONLINE
FOCUSCMMC L2 / L3
BUILD0aed52
CMMC DEADLINET-d
©2026 POLICYCORTEX, INC.