110 controls, continuously. Not at audit time.
NIST SP 800-171 r3 is the underlying standard for CMMC. 110 controls across 14 families, all continuously validated, evidence captured, drift remediated. PolicyCortex turns r3 into a runtime contract instead of a quarterly spreadsheet.

- CAP-0114 families coveredAC · AT · AU · CM · IA · IR · MA · MP · PE · PS · RA · CA · SC · SI.
- CAP-02r3 control deltas trackedRev 2 → Rev 3 mappings auto-applied; nothing manual.
- CAP-03Auto-SSP narrativesGenerated from live state. Always current, never stale.
- CAP-04CUI scope respectedControls only enforced where CUI lives.
- CAP-05Auto-remediationDrift fixed with rollback-safe actions. Type-checked.
- CAP-06POA&M liveFindings open → closed with closure evidence.
- 01ScopeCUI boundary defined. Resources mapped to control families.
- 02BaselineAll 110 controls validated. SSP narratives auto-drafted.
- 03MaintainContinuous validation. POA&M updates as findings cycle.
- DOE National LabActive consultant
- MITRECybersecurity engineering
- USAAFinancial-grade ops
- FrontierProduction cloud architecture
Founder runs every engagement personally. 4 U.S. patent applications filed.
Rev 2 vs Rev 3?
Rev 3 (May 2024) introduced 17 new requirements and reorganized families. PolicyCortex tracks both — cross-walks Rev 2 evidence to Rev 3 controls automatically.
Connection to CMMC?
CMMC L2 directly references NIST 800-171 r3. Same controls, same evidence. PolicyCortex outputs serve both regimes.
Self-assessment vs C3PAO?
Both supported. Self-attestation uses the same evidence; C3PAO assessment uses the OSCAL bundle and auditor ZIP.
What about NIST 800-172?
Enhanced security requirements for high-value assets. Mapped as an L3-overlay on top of the 110 baseline controls.
Run r3 as a runtime. Not a spreadsheet.
$15,000 flat for the 30-day pilot. 110 controls baselined and continuously validated, with the package C3PAOs already accept.
