V5 Ultimate
CMMC 2.0 · NIST SP 800-171 · DFARS 7012 · CUI · On-Prem

CMMC software with all 110 NIST 800-171 practices as live controls, not a Word SSP.

CMMC 2.0 Level 2 assessment prep collapses when access control, audit, configuration management, incident response and system integrity are enforced by the platform — not documented in a System Security Plan nobody re-reads. Cloud or on-premises, CUI-aware, DFARS 252.204-7012 aligned by construction.

Start a free trial See access + audit controls
CMMC 2.0 L2
All 110 practices mapped
NIST 800-171 r2
Native
DFARS 7012
Aligned
CUI-aware
Object tagging
On-prem / cloud
Available
If any of these sound familiar

You're shopping for CMMC software because a C3PAO assessment is 12 months out and your SSP is a Word file the assessor won't accept.

SSP and POA&M live in Word and Excel, not the systems being described

Audit log evidence is stitched together from six tools at assessment time

CUI-tagged objects have no system enforcement — just a policy PDF

Access reviews are a spreadsheet dance, not an automated report

Incident response tabletops don't produce evidence a C3PAO will accept

Configuration baselines drift and nobody notices until assessment

What's in the box

CMMC controls that are live, not documented.

Access Control (AC) family

RBAC with least-privilege enforcement, session lock, remote access logging, and separation of duties enforced by role — not by policy. AC-1 through AC-22 evidenced live.

Audit & Accountability (AU)

Signed, hash-chained audit trail on every controlled object. Non-repudiation, event review reports, and audit storage capacity monitoring — all AU-family practices mapped.

Configuration Management (CM)

Baseline configurations, change control workflow with impact analysis, least-functionality enforcement and software-inventory tracking — CM-1 through CM-11 native.

Incident Response (IR)

Incident workflow with 72-hour reporting clock, evidence preservation, tabletop exercise records and post-incident review — IR-1 through IR-6 evidenced end-to-end.

System & Information Integrity (SI)

Flaw remediation tracking, malicious code protection integration, security alerts monitoring and information handling — SI-family practices produce live evidence.

CUI object tagging

Every controlled object carries a CUI category tag (Basic, Specified, or none). Access, transmission and storage controls fire off the tag automatically — not off a spreadsheet.

What changes the day this goes live

What changes when CMMC is a system, not an SSP.

  • C3PAO assessment prep drops from 6+ months to weeks
  • SSP becomes a report extract, not a hand-maintained Word file
  • POA&M items close when the control does — not when someone updates a spreadsheet
  • Prime contractor supplier questionnaires answer themselves
  • Configuration drift surfaces at commit, not at assessment
  • Access reviews run on schedule and produce their own evidence
Regulatory anchor

Every CMMC assessor's checklist.

CMMC 2.0 Level 2

All 110 NIST SP 800-171 rev 2 practices across 14 families mapped to platform controls with live evidence. Level 1 (17 practices) covered by construction.

NIST SP 800-171 rev 2

AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, SI families — evidenced through platform behaviour, not through documentation.

DFARS 252.204-7012

Adequate security expectations met natively; 72-hour cyber incident reporting workflow, media protection, encryption at rest and in transit.

NIST SP 800-172 (Level 3 aware)

Enhanced-security practices for APT-resistant environments — advanced audit correlation, threat hunting hooks, deception controls.

21 CFR Part 11 (dual-use suppliers)

Defence-medical suppliers get bound e-signatures and hash-chained records on top of the CMMC control layer.

Questions buyers actually ask

CMMC software, answered.

What is CMMC software?

CMMC software is a platform that enforces and evidences the 110 NIST SP 800-171 rev 2 practices required for CMMC 2.0 Level 2 as live system behaviour — access control, audit trails, configuration baselines, incident response, media protection, system integrity — rather than documenting them in a System Security Plan (SSP) that has to be manually re-verified at every assessment.

Does V5 cover all 110 practices?

Yes. Every NIST SP 800-171 rev 2 practice has a mapped V5 control with live evidence generation. The platform is not itself a C3PAO — you still need an accredited assessor for certification — but assessment prep collapses because the evidence is already produced.

Cloud or on-premises?

Both. V5 Ultimate Cloud runs in FedRAMP-adjacent posture for most Level 2 scenarios. V5 Ultimate On-Premises is containerised, air-gap capable and CUI-boundary friendly for cases where CUI cannot leave your facility.

How does CUI tagging work?

Every object (drawing, routing, batch record, measurement data, procedure) carries an explicit CUI category tag. Access, transmission, storage-at-rest and audit controls fire off the tag automatically — so CUI never ends up in a non-CUI system by accident.

Is V5 also DFARS 7012 compliant?

V5 supports the DFARS 252.204-7012 adequate-security expectations natively — the 110 practices, 72-hour incident reporting workflow, cyber incident information preservation and self-assessment evidence. Full DFARS compliance always requires a customer-owned SSP; V5 provides the platform controls and evidence that populate it.

How long does implementation take?

Most DoD suppliers stand up Level 1 controls within 30 days and Level 2 assessment-ready posture within 8–16 weeks depending on scope of the Assessment Boundary and CUI footprint.

Turn CMMC assessment prep into a report extract — not another year of Word-file archaeology.

Free trial (cloud) or on-prem evaluation. No sales gate.