- Client
- An IT services and compliance consultancy
- Level 2 controls, generated from the official catalog
- 110
- SPRS scoring computed to the DoD's own method
- -203 to +110
- Scores typed into a spreadsheet by hand
- Zero
The problem
Almost every CMMC consultant runs assessments in an Excel workbook per client. That works until it does not. The scoring is arithmetic in a formula nobody audits, and the score is submitted to the Department of Defense, where a wrong one is not an embarrassment but a False Claims Act exposure. Around that sit the rest of the problems: the System Security Plan and the POA&M are written by hand and consume most of an engagement's billable hours, evidence is chased through email threads with no index tying an artifact to the control it proves, and answers come from interviewing people about their configuration rather than from the configuration. And because each client lives in a separate workbook, a consultancy carrying twenty of them has no way to see the whole book at once.
What we built
We built a platform where one consultant login manages many client organizations, each in an isolated workspace with access enforced by row-level security at the database rather than in the interface. Assessments run against the official control catalogs, 15 at Level 1 and the 110 of NIST SP 800-171 at Level 2, with verification guidance on each question and a sprint mode for working quickly. SPRS scores are computed live to the DoD's own methodology across its full range, including the edge cases most spreadsheets get wrong, and the catalog itself is generated from the official sources with a test suite asserting the scoring invariants hold. A what-if simulator answers the question every client asks: remediate these six controls and the score moves from here to there. POA&M tracking enforces the eligibility rules, so the tool refuses to let you defer a control the rules say cannot be deferred. Evidence is requested from clients, tracked and indexed against the control it supports, and a Microsoft 365 collector pulls the client's actual tenant configuration so a findings engine answers assessment questions from real data. The deliverables that used to be written by hand fall out of the assessment: the SSP, the gap report, the POA&M, the SPRS report, the shared responsibility matrix, the asset inventory and the evidence index.
The outcome
The number submitted to the government is computed rather than entered, from a catalog generated out of official sources and covered by tests, which is a different category of confidence from a formula in a workbook. Deliverables that used to absorb most of an engagement now come out of the assessment data and get reviewed rather than authored. Evidence is answered from the client's actual tenant configuration instead of from an interview, which is both quicker and considerably easier to defend in front of a third-party assessor. And because every client sits in one system with history and benchmarks, the consultancy can watch a whole book of business at once rather than opening twenty workbooks, which is the difference between selling assessments as projects and selling readiness as an ongoing service.