13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not

Trust Codex · public demo

See the whole program before you talk to anyone.

Northwind Defense Components is a fictional aerospace parts maker with CUI drawings, a partly hardened enclave and an assessment coming. Everything below is its Trust Codex tenant, read-only, no sign-in, synthetic data run through the real code.

Every page in the demo carries a synthetic-data banner. The download is rate-limited.

Seven stops, in assessment order

  1. 01

    The company and its number

    Northwind Defense Components, a fictional aerospace parts maker mid-journey. Its SPRS score is computed by the real scorer from the evidence on record, not typed in.

    Open the overview
  2. 02

    The System Security Plan

    Versioned sections with control narratives that cite evidence by hash. This is the document an assessor reads first.

    Read the SSP
  3. 03

    All 110 controls

    Every NIST SP 800-171 requirement resolved to its assessment objectives, each MET, NOT MET or N/A with the evidence that justifies it.

    Browse the controls
  4. 04

    One control, end to end

    Control 3.13.16 (CUI at rest) failed a monitoring run, became a POA&M, was fixed, and the regenerated evidence closed it. The whole loop is on one page.

    Walk 3.13.16
  5. 05

    The POA&M

    Open items with milestones, each marked eligible or not under 32 CFR 170.21, and the one that closed with dual sign-off.

    Open the POA&M
  6. 06

    The evidence ledger

    Evidence as metadata: run id, path, SHA-256, freshness. Three items are about to expire, which is what the dashboard would nag about.

    See the evidence
  7. 07

    The assessor package

    The ZIP a C3PAO would receive the night before: SSP, SCTM, POA&M, evidence index, asset inventory, responsibility matrix, attestations.

    Download the package

Questions people ask first

Is any of this real?
No. Northwind Defense Components is fictional, every person and host is invented, and the evidence is metadata with synthetic hashes. The scoring, the objective resolution, the POA&M rules and the package export are the real code paths, run on the synthetic data.
Why can I see it without signing in?
Because a buyer should be able to inspect the product before a sales call. The demo tenant is read-only and pinned to the fictional organization at the middleware; nothing you do there changes anything, and no real tenant is reachable from it.
What would my version look like?
The same screens with your controls, your evidence flowing in weekly from EnclaveWatch in your vault, and your assessor package one click away. That is the Vault + EnclaveWatch + Trust Codex tier on the market.