ComplyToCMMC Sample Workspace
Back to package Start checkout

Public sample - no sign-in required

See the workspace before you buy.

This sample shows how ComplianceAide organizes CMMC readiness work: evidence, assessment status, gap priorities, chat guidance, and downloadable planning artifacts. The company, files, findings, and messages below are synthetic.

Sample data only. Do not upload CUI, passwords, contract files, or customer evidence into public pages. Paid workspaces use your own account and onboarding path.
18 sample evidence items
7 controls needing attention
3 ready artifacts
42% sample readiness score

Assessment snapshot

The sample assessment turns uploaded evidence into a prioritized remediation plan. It does not certify the organization or replace a C3PAO assessment.

Priority Finding Next action
High MFA policy exists, but admin exception review is missing. Document exception owner, expiry, and quarterly review.
High Asset inventory covers laptops, but not shop-floor systems. Add CNC controller and engineering workstation ownership.
Medium Incident-response plan is drafted but untested. Schedule a tabletop exercise and capture lessons learned.
Ready Backup procedure includes monthly restore testing. Keep latest restore-test evidence with the assessment pack.

Evidence organized for review

In the paid workspace, your team uploads approved evidence after onboarding confirms the right handling path.

Access-control-policy.md Mapped to AC.L2-3.1.1 and AC.L2-3.1.2
Employee-offboarding-checklist.pdf Supports account revocation and access review
Backup-restore-test.csv Supports continuity and recovery evidence

Example chat guidance

Contractor We received DFARS 252.204-7012 language. Are we Level 1 or Level 2?
ComplianceAide DFARS 252.204-7012 and CUI usually point toward Level 2 and NIST SP 800-171 readiness. Start by confirming whether your systems store, process, or transmit CUI, then collect policies, asset inventory, access controls, backup evidence, and incident-response procedures for the assessment.

What a buyer can inspect

This page lets a buyer see the shape of the product before payment without entering their own data.

  • How evidence is grouped and named.
  • How findings become prioritized next actions.
  • How chat answers CMMC scope and timeline questions.
  • What artifact categories the package produces.

Security Assessment Report

Summarizes readiness status, evidence reviewed, and gaps needing attention.

Remediation Roadmap

Turns assessment gaps into practical action items, owners, and timing.

SSP and POA&M Support

Helps organize planning documentation, with POA&M support only where permitted.