Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
The CMMC Map is a self-assessment tool designed for small defense contractors in the U.S. who lack a dedicated compliance team, incorporating NIST SP 800-171 and CMMC standards. With a quick 15-minute scoping wizard, users can easily identify applicable requirements such as CMMC Level 1, CMMC Level 2 self-assessment, or the SPRS score in accordance with DFARS 252.204-7019, while the application automatically fills in about 40% of the necessary controls. Each of the 110 requirements is thoroughly described in accessible language, accompanied by a checklist for evidence collection, and your SPRS score, weighted by Department of Defense criteria, updates dynamically as you input your answers. Additionally, a single click allows you to produce the System Security Plan, POA&M, and all 14 essential policies based on your responses, along with a Readiness Report that evaluates your submission using a reviewer's checklist. The application establishes a read-only link to either Microsoft 365 or Google Workspace, gathering tenant configuration data such as users, MFA, and device settings to serve as evidence, while ensuring that document content remains confidential. Furthermore, it includes features for interview preparation, an Assessor view, a compliance calendar, a training roster, and multi-factor authentication for enhanced security. Consultants are able to manage various clients from distinct workspaces on a single invoice, streamlining the process for both parties involved. Overall, CMMC Map significantly simplifies the compliance process for small defense contractors.
Description
Investing time and resources to prepare for the Cybersecurity Maturity Model Certification (CMMC) assessment is a significant undertaking for organizations. Those managing Controlled Unclassified Information (CUI) in the defense industrial sector should anticipate a certification from an authorized CMMC 3rd Party Assessment Organization (C3PAO) to validate their adherence to NIST SP 800-171 security standards. Assessors will scrutinize how contractors fulfill each of the 320 objectives related to all relevant assets, which encompass personnel, facilities, and technologies. The evaluation process is likely to include artifact reviews, interviews with essential staff, and examinations of technical, administrative, and physical controls. As they compile their evidence, organizations must create clear connections between the artifacts, the security requirement objectives, and the assets under consideration. This comprehensive approach will not only aid in meeting certification criteria but also enhance overall security posture.
API Access
Has API
No
API Access
Has API
Yes
Screenshots View All
No images available
Integrations
Amazon Web Services (AWS)
No
Mercury One Plus
No
Pricing Details
$149/month
Free Trial
No
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
Yes
Vendor Details
Company Name
Hydromation Corporation
Country
United States
Website
cmmcmap.com
Vendor Details
Company Name
Etactics
Country
United States
Website
etactics.com/cmmc
Product Features
Compliance
Archiving & Retention
No
Artificial Intelligence (AI)
No
Audit Management
No
Compliance Tracking
No
Controls Testing
No
Environmental Compliance
No
FDA Compliance
No
HIPAA Compliance
No
ISO Compliance
No
Incident Management
No
OSHA Compliance
No
Risk Management
No
Sarbanes-Oxley Compliance
No
Surveys & Feedback
No
Version Control
No
Workflow / Process Automation
No