You need a CUI boundary an assessor will accept. Here is ours.
When CUI is spread across laptops, drives and email, the assessment has no edge. MacTech delivers one boundary, one evidence story and one C3PAO handoff, pre-built, with the Trust Codex mapping all 110 requirements to their evidence.
We run it ourselves and publish what it measures, with dates, unflattering numbers included. Read our own numbers.
CUI Vault Enclave (VM)
A single, contained environment where all Controlled Unclassified Information is stored and worked on - one clear boundary. No CUI on everyday laptops or file shares. Staff access CUI only by connecting into the vault via VPN and then RDP to a dedicated, hardened virtual machine. There is no public RDP, no USB mass storage, and no clipboard or drive redirection. Every session is logged and time-limited.
Trust Codex - CMMC Acceleration
MacTech's auditor-defensible, executive-readable, engineer-actionable manual for the CUI enclave. The Trust Codex maps all 110 NIST SP 800-171 Rev.2 requirements (CMMC 2.0 Level 2) to control strategy and evidence - so the vault is evidence-ready and assessor-friendly from day one. It ships with the enclave as a single deliverable.
What You Get
Everything required to stand up a defensible CUI enclave and walk into a C3PAO assessment with confidence.
Hardened Enclave VM
Windows Server 2025 Datacenter in Azure, Entra ID with MFA and conditional access, FIPS and TLS 1.2 enforced, no public RDP, no USB or clipboard redirection, RDP session limits (15-min idle, 5-min disconnect, 8-hour maximum).
Trust Codex Manual
Full control mapping for all 110 NIST SP 800-171 requirements across 14 domains, with per-control evidence type, artifact name, owner, location, retention period, and regeneration method.
Governance Bundle
Pre-built policies (MAC-POL series), procedures (MAC-SOP series), incident response plan, configuration management plan, CUI Enclave User Agreement, and MFA guide - all CMMC Level 2–aligned.
C3PAO-Ready Evidence Layout
Automated evidence collection and validation scripts, timestamped evidence bundles, PASS/FAIL validation reports, and a single offline CODEX_VIEWER.html deliverable. An assessor picks a requirement and the artifact proving it is one click away - no interview, no file hunt, no reconstruction.
Technical Stack
Built on proven, auditor-recognized technology - no proprietary lock-in.
| Component | Specification |
|---|---|
| Operating System | Windows Server 2025 Datacenter |
| Cloud Platform | Microsoft Azure (Commercial) |
| Identity & Access | Microsoft Entra ID (cloud-only), Entra-joined VMs, MFA, Conditional Access |
| Network Access | VPN required, then RDP to enclave VM only - no public RDP endpoint |
| Portable Media | USB mass storage disabled; clipboard and drive redirection disabled |
| Hardening Scripts | Invoke-CuiHardening.ps1 - idempotent, FIPS, TLS 1.2, LSA protection, ASR rules, session limits |
| Evidence Collection | Collect-Cui-Evidence.ps1 - timestamped bundles under C:\evidence\, 1-year retention baseline |
| Validation | Test-CuiHardening.ps1 - read-only PASS/FAIL + JSON report; required checks per control |
| Drift Detection | Drift Guard baseline + check scripts to detect configuration regressions |
110 Controls. 14 Domains. One Evidence Story.
The Trust Codex covers every NIST SP 800-171 Rev.2 requirement across all 14 domains.
Class A - system-enforced
System-enforced - OS, identity, network, crypto, logging, and hardening. Evidence is technical and reproducible via scripts, configs, and validation reports.
Class B - governance and inherited
Governance, policy, inherited, or not applicable - policies, SOPs, training records, cloud inheritance, or justified non-applicability.
A CMMC 2.0 Level 2–aligned CUI enclave you receive, rather than assemble.
Pre-hardened VM. All 110 NIST SP 800-171 Rev 2 requirements pre-mapped. Governance bundle included. Evidence runbook ready.
From MacZine
The reasoning behind this build
Three issues on the evidence problem this system was built to solve, and who else says it is real.
Start with a discovery call
We scope your program, recommend the right delivery path, and send a proposal with clear deliverables and C3PAO-ready evidence.