13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not →

We build defense contractors a CUI boundary they can prove to an assessor.

When a prime shares CUI with you, all 110 NIST SP 800-171 requirements come with it. We move that CUI into one enclave and tie every requirement to the evidence behind it.

We run the same enclave for our own CUI and publish what it measures, with dates, open items included. Read our own numbers.

$ claude mcp add --transport http mactech-cmmc https://www.mactechsolutionsllc.com/api/mcp
connected · 13 tools · NIST SP 800-171 Rev 2 · DoD Assessment Methodology Annex A

$ lookup_control 3.5.3
Use multifactor authentication (MFA) for local and network access to privileged accounts and for network access to nonprivileged accounts.
SPRS weight 5 · partial credit -3 when MFA covers privileged and remote access only

$ get_assessment_objectives 3.5.3
[a] determine if privileged accounts are identified.
[b] determine if multifactor authentication is implemented for local access to privileged accounts.
[c] determine if multifactor authentication is implemented for network access to privileged accounts.
[d] determine if multifactor authentication is implemented for network access to non-privileged accounts.
4 objectives · every one must be met for 3.5.3 to be met

Same dataset the CMMC MCP server answers from. Nothing leaves your browser.

Three ways in

Which of these is you?

Frameworks & Alignments

Multiple frameworks. One evidence story.

NISTRMFNIST800-53NISTCSF 2.0FedRAMPModerateSOC 2ISO27001ISO9001ISO17025SPRSMITREATT&CKDISASTIGsNIST800-171ACMMC 2.0Level 2NIST800-171FIPS140-3DFARS7012MacTechTRUST CODEX

CUI Enclave & Trust Codex

One boundary, one evidence map, one handoff

Most Level 2 programmes fail on scope and on evidence archaeology. This is the order that avoids both.

  1. Step 01

    Draw the boundary first

    CUI is allowed to exist in exactly one place: a hardened enclave with its own identity, reached over VPN and then RDP, with USB and clipboard redirection disabled. Everything outside that line - your mail, your file server, your engineering laptops - is out of assessment scope, which is the only dependable way to keep a Level 2 assessment small.

    In the boundary

    • Hardened enclave workstations
    • Enclave identity (separate tenant)
    • Monitored transfer station
    • Enclave audit log store

    Out of scope

    • Corporate mail and calendar
    • Company file server
    • Engineering laptops
    • Everything else you own

    How the boundary is built →

  2. Step 02

    Map every requirement to where the proof lives

    All 110 NIST SP 800-171 Rev 2 requirements are recorded in the Trust Codex against the artifact that proves them, the script that produces that artifact, and the path it lands on. Nothing is marked implemented without a location somebody can open.

    $ mactech-cmmc lookup_control 3.13.11
    3.13.11  System & Communications Protection
    Employ FIPS-validated cryptography when used to
    protect the confidentiality of CUI.
    SPRS weight 5  ·  DoD Assessment Methodology, Annex A
    sliding scale: -5 no encryption, -3 not FIPS-validated
    
    # Trust Codex manifest · 3.13.11 → evidence
    /evidence/crypto/bitlocker-fips-policy.json
    /evidence/crypto/openssl-fips-verify.txt
    /evidence/crypto/Invoke-CuiHardening.ps1
    3 artifacts · hashes recorded in the manifest

    All 110 requirements →

  3. Step 03

    Hand the assessor one thing

    The C3PAO receives a single offline viewer that opens on whichever requirement they ask about, with the artifact, its hash, and the date it was produced. Nothing gets assembled in the week before the assessment, because the same scripts that configure the enclave are the ones that emit the evidence.

    CODEX_VIEWER.html

    3.1.1conditional-access-policies.json
    3.4.2baseline-hardening-report.html
    3.13.11openssl-fips-verify.txt

    + the rest of the 110, each with a hash and a date

    See the Trust Codex as built →

Featured Offerings

Productized capabilities, ready to deploy

New Release

IR Tabletop & AAR Evidence Kit

A productized incident response tabletop and After-Action Review for CMMC 2.0 Level 2. AI-drafted custom scenarios, MITRE ATT&CK overlay, and an immutable evidence bundle - delivered on the same MacTech Training platform that already covers your CMMC Awareness & Training program.

  • AI scenario generator

    Describe an incident in plain English. Get a control-mapped tabletop with injects, TTPs, and objective pass criteria.

  • AI-assisted After-Action Review

    The executive summary, timeline, strengths, gaps, and evidence are drafted from the real inject responses rather than from a blank page.

  • Immutable evidence bundle

    SHA-256 manifest, optional RFC 3161 timestamp, drafter ≠ approver enforced, 6-year retention with legal-hold.

Scenario Composer · IR.L2-3.6.x
Prompt:
“Vendor MSP RMM tool compromised - pushes malicious update to our Windows hosts. Detect, contain, brief contracting officer.”
→ Drafting…
✓7 injects · T+0 → T+90
✓4 MITRE TTPs mapped
✓9 NIST controls validated
Review · Refine · Save to library
3.6.1
IR Capability
3.6.2
Track + Report
3.6.3
Test the Plan
Tools

Automated STIG Compliance

Our Hardening and Validation Suite transforms DISA Security Technical Implementation Guides into production-ready automation artifacts - reducing manual effort and accelerating compliance.

  • Ansible Hardening Playbooks

    Automatically generate idempotent playbooks that apply STIG controls programmatically.

  • Compliance Checker Playbooks

    Validate STIG compliance with automated checker playbooks for continuous monitoring.

  • CTP Documentation

    Generate Certification Test Procedure documents in standardized formats for manual controls.

Hardening and Validation Suite
$python -m app.main --stig-file RHEL_9_STIG.xml
→ Generating artifacts...
✓stig_rhel9_hardening.yml
✓stig_rhel9_checker.yml
✓stig_rhel9_ctp.csv
Production-ready automation artifacts
RHEL 8/9
Linux STIGs
Windows
Windows STIGs
Cisco
Network STIGs

Ready to achieve authorization and audit readiness?

Start with our readiness assessment to understand where you stand.