We build defense contractors a CUI boundary they can prove to an assessor.
When a prime shares CUI with you, all 110 NIST SP 800-171 requirements come with it. We move that CUI into one enclave and tie every requirement to the evidence behind it.
We run the same enclave for our own CUI and publish what it measures, with dates, open items included. Read our own numbers.
$ claude mcp add --transport http mactech-cmmc https://www.mactechsolutionsllc.com/api/mcp connected · 13 tools · NIST SP 800-171 Rev 2 · DoD Assessment Methodology Annex A $ lookup_control 3.5.3 Use multifactor authentication (MFA) for local and network access to privileged accounts and for network access to nonprivileged accounts. SPRS weight 5 · partial credit -3 when MFA covers privileged and remote access only $ get_assessment_objectives 3.5.3 [a] determine if privileged accounts are identified. [b] determine if multifactor authentication is implemented for local access to privileged accounts. [c] determine if multifactor authentication is implemented for network access to privileged accounts. [d] determine if multifactor authentication is implemented for network access to non-privileged accounts. 4 objectives · every one must be met for 3.5.3 to be met
claude mcp add --transport http mactech-cmmc https://www.mactechsolutionsllc.com/api/mcpSame dataset the CMMC MCP server answers from. Nothing leaves your browser.
- CMMC 2.0 L2
- Self-Attested
- GSA HACS
- Eligible
- 75 → 89SPRS, measured on evidence that flows weekly
- 1,869Findings remediated, each with a root cause
- 110 / 320Controls and objectives, each bound to an evidence source
Three ways in
Which of these is you?
A flow-down clause just landed in my inbox
Your prime sent DFARS 252.204-7012 down the chain and asked when you will be CMMC Level 2. Start with what the clause actually obliges you to do, which of the 110 requirements you already meet, and how small the boundary can be.
I am the prime, and my subs are my exposure
The CUI you are accountable for is sitting on a sub-tier network you have never seen. Flow the clause down so it holds, monitor posture instead of collecting attestations, and be able to show the programme office what you know.
I am a consultant or C3PAO deciding whether MacTech is the real thing
You are a consultant, a C3PAO, or the person who has to recommend someone. Read the enclave and Trust Codex work as built, then run our reference servers yourself against your own questions rather than taking a claim on trust.
Frameworks & Alignments
Multiple frameworks. One evidence story.
CUI Enclave & Trust Codex
One boundary, one evidence map, one handoff
Most Level 2 programmes fail on scope and on evidence archaeology. This is the order that avoids both.
Step 01
Draw the boundary first
CUI is allowed to exist in exactly one place: a hardened enclave with its own identity, reached over VPN and then RDP, with USB and clipboard redirection disabled. Everything outside that line - your mail, your file server, your engineering laptops - is out of assessment scope, which is the only dependable way to keep a Level 2 assessment small.
In the boundary
- Hardened enclave workstations
- Enclave identity (separate tenant)
- Monitored transfer station
- Enclave audit log store
Out of scope
- Corporate mail and calendar
- Company file server
- Engineering laptops
- Everything else you own
Step 02
Map every requirement to where the proof lives
All 110 NIST SP 800-171 Rev 2 requirements are recorded in the Trust Codex against the artifact that proves them, the script that produces that artifact, and the path it lands on. Nothing is marked implemented without a location somebody can open.
$ mactech-cmmc lookup_control 3.13.11 3.13.11 System & Communications Protection Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. SPRS weight 5 · DoD Assessment Methodology, Annex A sliding scale: -5 no encryption, -3 not FIPS-validated # Trust Codex manifest · 3.13.11 → evidence /evidence/crypto/bitlocker-fips-policy.json /evidence/crypto/openssl-fips-verify.txt /evidence/crypto/Invoke-CuiHardening.ps1 3 artifacts · hashes recorded in the manifest
Step 03
Hand the assessor one thing
The C3PAO receives a single offline viewer that opens on whichever requirement they ask about, with the artifact, its hash, and the date it was produced. Nothing gets assembled in the week before the assessment, because the same scripts that configure the enclave are the ones that emit the evidence.
CODEX_VIEWER.html
3.1.1 conditional-access-policies.json 3.4.2 baseline-hardening-report.html 3.13.11 openssl-fips-verify.txt + the rest of the 110, each with a hash and a date
Featured Offerings
Productized capabilities, ready to deploy
IR Tabletop & AAR Evidence Kit
A productized incident response tabletop and After-Action Review for CMMC 2.0 Level 2. AI-drafted custom scenarios, MITRE ATT&CK overlay, and an immutable evidence bundle - delivered on the same MacTech Training platform that already covers your CMMC Awareness & Training program.
AI scenario generator
Describe an incident in plain English. Get a control-mapped tabletop with injects, TTPs, and objective pass criteria.
AI-assisted After-Action Review
The executive summary, timeline, strengths, gaps, and evidence are drafted from the real inject responses rather than from a blank page.
Immutable evidence bundle
SHA-256 manifest, optional RFC 3161 timestamp, drafter ≠ approver enforced, 6-year retention with legal-hold.
Automated STIG Compliance
Our Hardening and Validation Suite transforms DISA Security Technical Implementation Guides into production-ready automation artifacts - reducing manual effort and accelerating compliance.
Ansible Hardening Playbooks
Automatically generate idempotent playbooks that apply STIG controls programmatically.
Compliance Checker Playbooks
Validate STIG compliance with automated checker playbooks for continuous monitoring.
CTP Documentation
Generate Certification Test Procedure documents in standardized formats for manual controls.
- 110Requirements, each with its own reference page
- 320Assessment objectives, published and checklistable
- 2,029DISA STIG rules, searchable with check and fix text
- 10Things you can run right now, no sign-in
Ready to achieve authorization and audit readiness?
Start with our readiness assessment to understand where you stand.