{"schema_version":"1","site":"https://decosa.ai","id":"cmmc-evidence-map","num":"65","name":"CMMC / NIST 800-171 evidence map","tool_name":"Map evidence to NIST 800-171","short":"CMMC evidence map","blurb":"For small defence contractors and the consultants who prepare them for CMMC Level 2. Send the SSP's statements and the evidence behind them: policies, config exports, logs, records, scans, screenshots and verified test runs. For each NIST SP 800-171 Rev 2 requirement and each of its NIST SP 800-171A objectives it says evidence present, partial or missing, quotes the lines, and flags artefacts that cannot count: drafts, stale exports, systems outside the scope. Gaps come first. Out come a gap map, a draft POA&M marking what may never go on one, and a signed evidence index an assessor can check. An evidence-gap map, never a certification or a score.","status":"live","labels":{"industry":["compliance-trust","public-sector"],"job":["review","attest"],"input":["text","files"],"deploy":["selfhost"],"status":"live","output":["record","data"],"data":["confidential"],"hardware":"gpu-96","licence":"permissive"},"industries":["compliance-trust","public-sector"],"runs_in":["selfhost"],"part_of":[],"built_from":["typed-judgment","grounding","signed-record","flight-recorder"],"models":"Qwen3.8-27B reads the evidence (lines per objective, typed judgment, grounding) and transcribes screenshots; the catalog, point values, POA&M rules and artefact checks are plain code","where":"Self-host for real SSPs (CUI stays on your box); the hosted demo takes synthetic sets only and refuses marked CUI","hardware":"1× RTX PRO 6000 (96 GB) or 1× RTX 5090 (32 GB) for Qwen3.8-27B; the catalog, artefact checks, POA&M rules and signed record run on CPU","final_artifact":"Per NIST SP 800-171A objective evidence present, partial or missing with quotes, a draft POA&M with 32 CFR 170.21 eligibility, a Markdown gap map and a signed decosa.record.v1 evidence index.","self_host_first":true,"verification":{"receipt_coverage":"full","summary":"Receipt per model call; every quote is a line of an artefact you sent; test-run certificates verified; signed hash-chained evidence index with no artefact text","manual_qa":{"hosted":{"date":"2026-09-26","result":"pass","p50_ms":149546,"p95_ms":null,"runs":null,"receipts_per_run":33,"cost_per_run_usd":0.0078},"selfhost":{"date":"2026-09-26","result":"pass","method":"fresh clone, compose up, sample against local model servers","notes":"A fresh clone of a decosa-api pre-release build (not yet merged), the api image built from it with DECOSA_CMMC_SYNTHETIC_ONLY=0, run against the already-running local Qwen3.8-27B vLLM on the direct route. The rehearsal bundle passed 21 of 21 checks in 19.8 s, the smoke module passed in 5.3 s with 18 attested receipts, unmarked and CUI-marked sets were accepted as real-data mode should, and the 10 held-out test companies scored 235 of 286 with no false present. Model-server startup itself not re-verified."},"known_limits":["Synthetic only on the hosted demo, and every number here comes from our own synthetic companies over 14 of the 110 requirements; not run on real SSPs or against an assessor's labels.","Reads text, config exports and single screenshots; the hosted demo reads only the bundled sample screenshot. Scanned PDFs and Word binders are not read.","It errs down: recall of 'present' is 72% on the test set, so some evidenced objectives come back partial.","'Missing' means not in what was sent. It does not interview, test or examine systems as an assessor does.","No SPRS score. A self-assessed estimate appears only when all 110 requirements are mapped in one run (self-hosted), labelled as an estimate.","NIST SP 800-171 Rev 2 and CMMC Level 2 only; no Level 1, Level 3 or Rev 3."],"nightly_covers":null},"nightly":"https://api.decosa.ai/verify/status"},"eval_summary":{"metrics":[{"name":"Objective status, 3 classes","value":"237 / 286","unit":null,"n":286,"split":"test","note":"10 synthetic companies, 80 requirements; present, partial, missing."},{"name":"Partial or missing objectives called present (false present)","value":"0 / 121","unit":null,"n":121,"split":"test","note":null},{"name":"Requirements called fully evidenced that are not","value":"0 / 59","unit":null,"n":59,"split":"test","note":null},{"name":"Present objectives called present (recall)","value":"119 / 165","unit":null,"n":165,"split":"test","note":"It errs down: 47 of 49 errors call an objective less evidenced than its label."},{"name":"Quotes verbatim from the input","value":"446 / 446","unit":null,"n":446,"split":"test","note":null},{"name":"Present or partial calls quoting a planted evidence line","value":"204 / 209","unit":null,"n":209,"split":"test","note":null},{"name":"Requirement roll-up accuracy","value":"64 / 80","unit":null,"n":80,"split":"test","note":null},{"name":"Objective status, self-hosted direct route","value":"235 / 286","unit":null,"n":286,"split":"test","note":"Log-probabilities instead of votes; false present 0 / 121. One rule change made on the self-hosted dev set first."},{"name":"Objective status, 3 classes (dev)","value":"238 / 299","unit":null,"n":299,"split":"dev","note":"215 / 299 before the dev changes; false present on dev 3 / 102."}],"dataset":"Synthetic small defence contractors from the vertical's own generator (invented companies, people and systems): 8 requirements each from a pool of 14 NIST SP 800-171 Rev 2 requirements (51 objectives), each with at most one planted gap (evidence missing, planned, stale, out of scope, draft, shown in part, contradicted, one line dropped). Dev 10 companies (299 objectives, one phrasing), test 10 companies (286 objectives, every evidence line worded differently), run once after the dev work was frozen.","held_out":true,"caveats":["Everything is synthetic, from templates written by the same agent that wrote the prompts and rules: evidence the mechanisms work, not accuracy on real SSPs.","No RPO or assessor labels; 14 of the 110 requirements are exercised.","Labels count only a requirement's own artefacts; the model sometimes uses evidence filed under another requirement.","Screenshot reading is shown on one bundled image, not measured.","Measured on a gateway shared with other workloads, so the latencies are high and vary."],"date":"2026-09-26","doc_url":"https://decosa.ai/metrics/evals/cmmc-evidence-map"},"stack":{"summary":"For small defence contractors preparing for CMMC Level 2, and the consultants (RPOs, MSPs) who prepare them. Send the SSP's statements and the evidence behind them: policies, config exports, logs, records, scans, a screenshot, a verified Decosa test run. Code loads the 110 NIST SP 800-171 Rev 2 requirements and 320 NIST SP 800-171A objectives from NIST's own files, with the 32 CFR 170.24 point values and the 170.21 POA&M rules, and checks every artefact: final or draft, dated and fresh, from a system in the SSP's scope, and, for test runs, the certificate's signature and assertions. Qwen3.8-27B transcribes screenshots, lists the lines that bear on each objective, gives a typed judgment (present, partial, contradicted, missing), and the grounding judge checks that the quotes carry a 'present'. Rules in code decide, and every doubt goes down: the SSP counts only for objectives about something being defined or identified, and a draft, stale or out-of-scope artefact makes an objective partial at most. Out come a gap map (gaps first), a draft POA&M that marks what may never go on one, and a signed evidence index with each artefact's SHA-256 that an assessor can check. It never says MET and never states an SPRS score.","tagline":"Each NIST SP 800-171 objective checked against the evidence you send: present, partial or missing, with quotes. A gap map, never a score.","deployment":"self-host-first","regulatory_note":"Checked 26 Sep 2026 against primary sources (links under Tools). 32 CFR Part 170 (the CMMC Program rule, 89 FR 83092, effective 16 Dec 2024) sets Level 2 as the 110 requirements of NIST SP 800-171 Rev 2, assessed per NIST SP 800-171A (June 2018), both incorporated by reference in 170.2; NIST's Rev 3 (May 2024) is not what CMMC assesses. 170.24 defines MET, NOT MET and N/A, requires evidence in final form (no drafts or unapproved policies), and sets the point values (5, 3, 1; 3.5.3 and 3.13.11 variable). 170.21 limits a POA&M: a score of at least 0.8 of 110, only 1-point requirements (3.13.11 at 3 points when encryption is employed but not FIPS-validated), never 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 or 3.12.4, closed out within 180 days. The DFARS rule (DFARS Case 2019-D041, 90 FR 43560) put CMMC into DoD contracts from 10 Nov 2025 (Phase 1). A pause of the move to Phase 2 (Level 2 C3PAO certification in new contracts from 10 Nov 2026) for a 60-day review from 13 Jul 2026 (DoD memo 26-P-1023) is reported by secondary sources; we did not find the memo itself, so that is unverified here, and we do not know the review's outcome. NIST's 800-171A CSV labels 3.10.1 as Personnel Security; the catalog takes the family from the section number. An SSP and its evidence are often CUI: self-host first; the hosted demo takes synthetic sets only and refuses marked CUI. This is not legal advice, an assessment or a certification: an assessor decides MET, and the senior official affirms in SPRS. Model licence: Apache-2.0 (Qwen3.8-27B). NIST publications and 32 CFR are US government works.","components":[{"id":"map","role":"Catalog, point values and POA&M rules, artefact checks, CUI guard, status rules, gap map, POA&M draft, evidence index and signed record (no model; CPU)","name":"decosa-api CMMC evidence map (decosa_api/verticals/cmmc), importing the grounding judge (17), the typed-judgment engine (24) and the test-run certificate verifier (27)","hf_repo":null,"license":"AGPL-3.0-or-later","params":null,"quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"Python 3.12; NIST SP 800-171 Rev 2 and SP 800-171A CSVs (110 requirements, 320 objectives) with SHA-256, 32 CFR 170.24 point values and 170.21 POA&M rules written out and unit-tested","receipt_coverage":"partial","in_hosted_demo":null,"tiers":["lite","standard"],"alternative_to":null},{"id":"model","role":"Screenshot transcription, lines per objective, the typed judgment per objective, and the grounding judge","name":"Qwen3.8-27B (NVFP4)","hf_repo":"nvidia/Qwen3.8-27B-NVFP4","license":"Apache-2.0","params":"27.8B","quant":"NVFP4 (MLP NVFP4, GDN/attention FP8) + FP8 KV cache; MTP head, 3 draft tokens","vram_gb":20,"memory_gb_estimate":null,"engine":"vLLM 0.29.0, temperature 0 (plus 2 votes at temperature 1 for the typed judgment on the gateway route; log-probabilities on the direct route), thinking off, prefix caching; image input for screenshots","receipt_coverage":"strong","in_hosted_demo":true,"tiers":["standard"],"alternative_to":null},{"id":"ocr","role":"Scanned PDF and evidence-binder reader (wanted)","name":"A licence-clean document OCR and layout model (not chosen)","hf_repo":null,"license":"unknown","params":null,"quant":null,"vram_gb":null,"memory_gb_estimate":null,"engine":null,"receipt_coverage":"none","in_hosted_demo":false,"tiers":["alternates"],"alternative_to":null}],"tiers":[{"id":"lite","label":"Lite · catalog and artefact checks only, no GPU","summary":"GET /cmmc/catalog gives every requirement's objectives, points and POA&M rule; POST /cmmc/check flags draft, stale, undated and out-of-scope artefacts and verifies test-run certificates. No reading of the evidence, so no statuses.","components":["map"],"hardware":"Any CPU","quality_evidence":[{"metric":"Catalog against NIST's CSVs and 32 CFR 170","value":"110 requirements, 320 objectives; 42 five-point, 14 three-point, 2 variable, 52 one-point; the six never-POA&M requirements; unit-tested","source":"tests/test_cmmc.py, 26 Sep 2026"},{"metric":"Artefact-check accuracy on real evidence","value":"not measured yet","source":"not measured yet"}],"latency_note":"no model call; milliseconds on CPU (not separately timed)","in_hosted_demo":true,"receipt_coverage":"none","receipt_note":"No model call, so no receipts; the checks are deterministic code.","hosting":null},{"id":"standard","label":"Standard · one GPU for the model (hosted demo)","summary":"Qwen3.8-27B reads the evidence per requirement and objective (lines, typed judgment, grounding) and transcribes screenshots; the catalog, artefact checks, status rules, POA&M rules and signed index are code. This is what the hosted demo runs, on synthetic sets only.","components":["map","model"],"hardware":"1x RTX PRO 6000 96 GB (measured) or 1x RTX 5090 32 GB (estimate)","quality_evidence":[{"metric":"Objective status, 3 classes (10 held-out synthetic companies, 286 objectives)","value":"237 / 286","source":"docs/evals/cmmc-evidence-map.md, test split, 26 Sep 2026"},{"metric":"Partial or missing objectives called present (false present)","value":"0 / 121","source":"docs/evals/cmmc-evidence-map.md, test split"},{"metric":"Requirements called fully evidenced that are not","value":"0 / 59","source":"docs/evals/cmmc-evidence-map.md, test split"},{"metric":"Present objectives called present (recall)","value":"119 / 165","source":"docs/evals/cmmc-evidence-map.md, test split"},{"metric":"Quotes verbatim from the input","value":"446 / 446","source":"docs/evals/cmmc-evidence-map.md, test split"},{"metric":"Objective status, self-hosted direct route (same 286 test objectives)","value":"235 / 286, false present 0 / 121","source":"docs/evals/cmmc-evidence-map.md, self-hosted test run"}],"latency_note":"measured: under a minute per company self-hosted on the direct route; minutes per company under a heavily shared gateway, and from under a minute to several minutes for the demo and smoke samples.","in_hosted_demo":true,"receipt_coverage":"strong","receipt_note":"Every model call is a separate gateway call with a gateway-signed receipt; the signed index lists them all.","hosting":null}],"alternates":[{"id":"ocr-lane","label":"Evidence binders as PDFs (document reader)","components":["ocr"],"hardware":"1x RTX PRO 6000 96 GB (estimate)","use":"Read SSPs and evidence binders as PDF or Word with page references in quotes. Waits on the document reader block (page 48); not built.","status":"not built"}],"services":[{"name":"decosa-api","port":8445,"image":"${DECOSA_REGISTRY}/decosa-api:<tag>","purpose":"GET /cmmc/info, /cmmc/catalog, /cmmc/samples; POST /cmmc/map (SSE or JSON), /cmmc/check; POST /record/verify. Keeps no artefact text."},{"name":"vLLM (model)","port":8114,"image":"vllm/vllm-openai@sha256:c2914767605584b6d8f45686b82de173ecc99e781897aa3d0a66dacd72c51ae1","purpose":"Qwen3.8-27B NVFP4 behind our gateway (hosted) or called directly (self-host)."}],"tools":[{"name":"32 CFR Part 170, CMMC Program (final rule, 89 FR 83092, 15 Oct 2024)","url":"https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170","license":"US federal regulation (public domain)","purpose":"170.24 scoring (MET, NOT MET, N/A; final-form evidence; point values) and 170.21 POA&M rules, read on eCFR 26 Sep 2026."},{"name":"DFARS Case 2019-D041 (final rule, 90 FR 43560, 10 Sep 2025)","url":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","license":"US federal regulation (public domain)","purpose":"CMMC in DoD contracts from 10 Nov 2025 (Phase 1)."},{"name":"NIST SP 800-171A assessment procedures (CSV)","url":"https://csrc.nist.gov/pubs/sp/800/171/a/final","license":"US government work (public domain)","purpose":"The 320 assessment objectives. Rebuilt by scripts/cmmc_build_catalog.py; CSV SHA-256 in GET /cmmc/info."},{"name":"NIST SP 800-171 Rev 2 security requirements (CSV)","url":"https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final","license":"US government work (public domain)","purpose":"The 110 requirements and their basic or derived designation."},{"name":"Secureframe, CMMC final rule overview (secondary source)","url":"https://secureframe.com/hub/cmmc/proposed-final-rule","license":"third-party article","purpose":"The reported 13 Jul 2026 pause of Phase 2 (memo 26-P-1023, 60-day review). Unverified against a primary source."},{"name":"Decosa test runs (27)","url":null,"license":"AGPL-3.0-or-later","purpose":"Signed certificates of an end-to-end test (here: a sign-in page refusing a locked-out account and an unauthenticated visit) as evidence that a control works; verified before they are read."},{"name":"scripts/eval_cmmc.py and docs/evals/cmmc-evidence-map.md","url":null,"license":"Apache-2.0","purpose":"The synthetic company generator, the dev and test runs and every result row."},{"name":"GET /cmmc/catalog, POST /cmmc/check and POST /record/verify","url":null,"license":"Apache-2.0","purpose":"Look up requirements, objectives, points and POA&M rules, and run the artefact checks, with no model call; verify a signed evidence index anywhere."}],"hardware":[{"tier":"1x RTX PRO 6000 Blackwell 96 GB","fits":true,"notes":"Measured on our server: the hosted demo, the eval and the smoke test ran through the shared gateway on this card."},{"tier":"1x RTX 5090 32 GB","fits":true,"notes":"Estimate: Qwen3.8-27B NVFP4 needs about 20 GB of weights plus KV cache; not run for this tool."},{"tier":"CPU only","fits":true,"notes":"The lite tier (GET /cmmc/catalog, POST /cmmc/check: catalog, POA&M rules, artefact checks) needs no GPU."}],"latency":[{"lane":"one company, 8 requirements, hosted gateway route","typical_ms":236700,"source":"measured on our server 2026-09-26: mean over the 10 test companies, 3 in parallel, gateway shared with other workloads"},{"lane":"harbor-precision sample, 9 requirements with a screenshot, hosted gateway route","typical_ms":354720,"source":"measured on our server 2026-09-26 while recording the Watch run under heavy gateway load; an earlier run of the same sample took 25.8 s"},{"lane":"bluefin-clean sample, 3 requirements (the smoke test), hosted gateway route","typical_ms":149546,"source":"measured on our server 2026-09-26 by scripts/smoke/run_all.py under load; 16.2 s in an earlier, quieter run"},{"lane":"one company, 8 requirements, self-hosted direct route","typical_ms":24100,"source":"measured on our server 2026-09-26 in the self-host check: mean over the 10 test companies, 3 in parallel, typed judgment by log-probabilities"},{"lane":"catalog and artefact checks only (GET /cmmc/catalog, POST /cmmc/check)","typical_ms":null,"source":"no model call; milliseconds on CPU (not separately timed)"}],"benchmark":null,"notes":["On 10 held-out synthetic companies (80 requirements, 286 objectives, worded differently from the dev set) it gave the labelled status for 237 objectives. It called none of the 121 partial or missing objectives present, and no requirement fully evidenced that was not (0 of 59).","It errs down: 47 of its 49 test errors call an objective less evidenced than its label (recall of 'present' is 119 of 165). A preparer re-checks some objectives that were in fact evidenced.","Every quote is a line of an artefact sent (446 of 446 on test), picked by id; 204 of 209 present or partial calls quote a planted evidence line.","Draft, stale, undated and out-of-scope artefacts are caught in code, not by the model, and a test-run certificate that fails verification is not read at all.","Everything is measured on synthetic companies written by the agent that built the checker, over 14 of the 110 requirements. It has not been run on real SSPs or against an assessor's labels."]},"buyer_facts":[{"label":"Data retention","value":"Nothing stored: the SSP and artefacts live in memory for the request. The signed index holds hashes, statuses and receipt ids, never artefact text; logs carry counts only."},{"label":"What leaves the box","value":"Hosted: every model call goes through our gateway to the GPU serving Qwen3.8-27B, and only synthetic sets are accepted (marked CUI is refused before any call). Self-hosted on the direct route: nothing leaves the box, and in real-data mode the service refuses to run if model calls would."},{"label":"What it will not do","value":"Say MET, certify, score or affirm. It maps evidence to objectives, lists the gaps first, and leaves MET to the assessor and the affirmation to the senior official."},{"label":"POA&M rules","value":"Every draft row carries its 32 CFR 170.21 eligibility: 1-point requirements only (3.13.11 conditionally), never 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 or 3.12.4."},{"label":"Input formats","value":"JSON: the system in scope (name, assessment date, scope list), SSP statements (or the SSP pasted as text), and up to 30 artefacts of up to 20,000 characters (120,000 in total), plus screenshots and Decosa test-run certificates. Up to 12 requirements per hosted run, 110 self-hosted."},{"label":"Typical run","value":"The clean sample: a few dozen model calls and a fraction of a cent at the gateway list price, from under a minute to a few minutes on the shared gateway; self-hosted, seconds. Each run shows its own measured cost."}],"data_handling":{"page":"/data#cmmc-evidence-map","self_host":{"level":"confidential","leaves":"nothing","summary":"Runs on your machine; nothing is sent to Decosa or a third party by default."},"hosted":{"level":"operator-processed","demo_only":true,"summary":"Hosted demo on sample or public data only; self-host for real data.","gpus":"operator-contracted","third_parties":[],"retention":"Nothing stored: the SSP and artefacts live in memory for the request. The signed index holds hashes, statuses and receipt ids, never artefact text; logs carry counts only.","used_for_training":false,"encrypted_while_processed":false},"sealed_tier":{"applies":false,"note":"The sealed tier (raw chat only, never use-case pipelines) is paused at launch (/docs/sealed-tier)."},"external_calls":[]},"console":{"href":"/tools/finance/cmmc-evidence-map","input":"cmmc","lanes":[{"id":"map","title":"Gap map: per requirement and objective, gaps first","kind":"list"},{"id":"artefacts","title":"Artefact checks","kind":"list"},{"id":"poam","title":"Draft POA&M with 32 CFR 170.21 eligibility","kind":"list"},{"id":"record","title":"Gap map, POA&M and signed evidence index","kind":"json"}],"samples":[{"n":1,"id":"harbor-precision","title":"Harbor precision","deep_link":"/tools/finance/cmmc-evidence-map?sample=1&autorun=0"},{"n":2,"id":"bluefin-clean","title":"Bluefin clean","deep_link":"/tools/finance/cmmc-evidence-map?sample=2&autorun=0"},{"n":3,"id":"tern-valley-pasted","title":"Tern valley pasted","deep_link":"/tools/finance/cmmc-evidence-map?sample=3&autorun=0"}],"deep_link_params":{"sample":"1-based index into samples, or a sample id","autorun":"1 = start the run once the sample is loaded; 0 (default) = only preselect","reduce-motion":"1 = turn off animations"}},"api":{"base":"https://api.decosa.ai","contract":"/api/contract.json","contract_markdown":"/api/contract.md","reference":"/docs/api","keys":"/account/keys"},"prompts":{"hosted":"/prompts/cmmc-evidence-map-hosted.md","selfhost":"/prompts/cmmc-evidence-map-selfhost.md","assemble":"/prompts/cmmc-evidence-map-assemble.md","mac":"/prompts/cmmc-evidence-map-mac.md"},"rehearsal":{"bundle":"/samples/cmmc-evidence-map.zip","bundle_url":"https://decosa.ai/samples/cmmc-evidence-map.zip","folder":"/samples/cmmc-evidence-map/","expected":"/samples/cmmc-evidence-map/expected.json","files":["/samples/cmmc-evidence-map/expected.json","/samples/cmmc-evidence-map/inputs/artefacts.json","/samples/cmmc-evidence-map/inputs/ssp.json","/samples/cmmc-evidence-map/inputs/system.json"],"bytes":67272,"checks":["encryption is only planned in the SSP, so 3.13.11 has no evidence","3.1.8 has a planted gap, so it is not fully evidenced","3.3.1 has a planted gap, so it is not fully evidenced","3.5.3 has a planted gap, so it is not fully evidenced","3.5.7 has a planted gap, so it is not fully evidenced","3.10.3 has a planted gap, so it is not fully evidenced","3.13.11 has a planted gap, so it is not fully evidenced","3.14.2 has a planted gap, so it is not fully evidenced","3.10.3 (escort visitors) can never go on a POA&M","3.13.11 may go on a POA&M only when encryption is employed but not FIPS-validated","the two-year-old audit log export is flagged stale","the password standard is flagged as a draft","the anti-malware export from a system outside the scope is flagged","the Decosa test-run certificate verifies","the screenshot was read by the vision model","some objectives have evidence present","no score or estimate is shown for 9 of 110 requirements","the gap map lists the draft POA&M","the signed record verifies","a record with its status changed no longer verifies","every model call has a signed receipt"],"licence":"Synthetic: the company, people, systems and evidence are invented (decosa_api/verticals/cmmc/synth.py and pool.py); the screenshot is drawn by scripts/cmmc_make_sample_png.py; the test-run certificate is a real Decosa run against saucedemo.com, Sauce Labs' public test site. NIST SP 800-171 and 800-171A are US government works. Part of decosa-api, AGPL-3.0-or-later.","about":"A fictional 38-person machine shop preparing for a CMMC Level 2 self-assessment. The SSP claims every requirement is implemented except 3.13.11 (planned). Planted: a lockout setting that never locks (3.1.8), a year-old audit log export (3.3.1), MFA shown only in a screenshot where the all-users policy is report-only (3.5.3), a draft password standard (3.5.7), a visitor log with no escort column (3.10.3, which can never go on a POA&M), encryption planned (3.13.11) and an anti-malware export from a system outside the scope (3.14.2). 3.1.1 and 3.11.2 are fully evidenced, 3.1.1 with a verified Decosa test run. The run must never call a planted gap fully evidenced, flag the stale, draft and out-of-scope artefacts, verify the test run, mark 3.10.3 as never on a POA&M, show no score, and sign a record that verifies and fails when changed. (The hosted service's refusals of unmarked and CUI-marked sets are covered by the smoke test and the unit tests, since a self-hosted box in real-data mode accepts both.)","run":{"containers":"docker compose exec api python scripts/rehearse.py cmmc-evidence-map","checkout":"python scripts/rehearse.py cmmc-evidence-map --bundle cmmc-evidence-map.zip --base-url http://127.0.0.1:8445","mac":".venv/bin/python scripts/rehearse.py cmmc-evidence-map"},"guidance":"Set up with a coding agent (we recommend Claude Code with Claude Opus 5.5; any capable coding agent works) on mock data only, run the rehearsal until every check passes, then run your own data locally yourself. Never give the agent real data during setup."},"hardware_fit":{"check":"/self-host/hardware?use=cmmc-evidence-map","data":"/api/hardware.json","tiers":[{"id":"lite","gpu_gb":0,"basis":null,"unknown":[]},{"id":"standard","gpu_gb":57.6,"basis":"stack","unknown":[]},{"id":"alternate-ocr-lane","gpu_gb":0,"basis":null,"unknown":["ocr"]}],"mac":{"fit":"full","memory_gb":32}},"links":{"page":"/tools/finance/cmmc-evidence-map","json":"/use-cases/cmmc-evidence-map.json","metrics":"/metrics/cmmc-evidence-map","console":"/tools/finance/cmmc-evidence-map","console_sample":"/tools/finance/cmmc-evidence-map?sample=1&autorun=0","stack":"/tools/finance/cmmc-evidence-map#stack","try_live":"/tools/finance/cmmc-evidence-map","watch":"/tools/finance/cmmc-evidence-map","build":"/tools/finance/cmmc-evidence-map#build","self_host":"/tools/finance/cmmc-evidence-map#self-host","prompts":{"hosted":"/prompts/cmmc-evidence-map-hosted.md","selfhost":"/prompts/cmmc-evidence-map-selfhost.md","assemble":"/prompts/cmmc-evidence-map-assemble.md","mac":"/prompts/cmmc-evidence-map-mac.md"}}}