Capability matrix
Every capability in the platform, grouped by domain and mapped to the NIST controls it covers. LIVE today unless marked otherwise.
Compliance operations
1117 plain-English questions. Submit and get every CMMC L1 control assessed plus a finished SSP PDF.
Auto-generated System Security Plan PDF rolled up from your evidence, controls, and policies.
Plan of Action & Milestones with owner, due date, evidence linking, and dashboard widgets. AI-suggested title/timeline, vendor-quote extraction, Gantt view, and a 12-month implementation-plan PDF.
Full (110-control) and quick (14-family) modes. Shows points lost and your top-10 gaps by points; stays in sync with the dashboard score.
Status by control family at a glance, with easy-wins mode to surface the fastest points.
14 master policy families with per-control children. Each baseline is the NIST statement plus an on-demand AI draft, version-tracked and exportable to PDF.
110 NIST 800-171 R2 controls mapped from official OSCAL. The NIST 800-172 catalog (24 reqs for CMMC L3) is in active development.
24 starter templates customized per tenant. Generate audit-grade policies grounded in your real state.
Automated control posture tracking with drift alerts and rollup metrics.
Automated quarterly SPRS score submission to DoD with reminder workflow and audit trail.
The 24 enhanced 800-172 requirements for CMMC Level 3, mapped from the official catalog. In active development.
Assessment + audit
8Time-limited (default 14 days), scope-bounded, read-only window into your tenant for an external assessor.
Every user action logged with user, IP, route, and timestamp. Append-only, exportable for an auditor.
Per-control evidence files with version history, control linking, and tagged-by-framework search.
Annual self-attestation cycle with status snapshots and SPRS score history.
Export-ready evidence packages, gap analyses, and control-by-control attestation documents.
Control-by-control gap analysis showing where you stand against every requirement, exportable to PDF.
Board-level posture rollup (score, trend, open POA&Ms, top risks) with a scheduled executive PDF report.
Aggregated assessor activity dashboard: time-on-control, gaps identified, modules reviewed.
Risk management
6NIST SP 800-30 inherent + residual scoring with heatmap visualization.
Per-risk treatment PDF with mitigation steps, residual scoring, and assigned owner.
Spin up a POA&M item from any risk with the gap, owner, and due-date prefilled.
Per-scenario financial impact tied to each risk for boardroom-defensible decisions.
Score history per risk showing how the posture moved during the assessment window.
Supplier inventory with criticality scoring, DFARS flow-down tracking, and SPRS-from-vendors collection.
Training · LMS
5Curated CMMC training library (hybrid: central + tenant-custom courses).
Per-user training assignments with due dates and auto-reminders.
Auto-graded quizzes and downloadable completion certificates per user.
Awareness training to recognize and report insider-threat indicators.
Short, practical how-to guides for using Readyline, available to every logged-in user at its own knowledge-base subdomain.
Architecture + security
5Dedicated MySQL database per tenant. No row-level multi-tenancy. Tenant breach radius = your tenant only.
TOTP-based 2FA required for every user. No bypasses, no exceptions.
AES-256 field-level encryption for sensitive secrets (SSO config, integration keys), TLS 1.2+ in transit, and per-tenant database isolation.
Auto-timeout, IP-pinned sessions with full audit log of every login and elevation.
Deploy Readyline inside your own infrastructure, including air-gapped environments. The path for primes preparing for L3.
Operations
5Incident workflow with a guarded state machine, DFARS 72-hour reporting validators, recipient routing, and promote-to-POA&M.
DR plans with action items, recovery objectives, and one-click promotion of gaps into tracked POA&M items.
Change requests with approval workflow, comments, completion/close states, and a full audit trail.
Record scheduled and performed maintenance with admin-gated controls over removable-media and tooling.
In-app advisory feed with read/unread tracking so your team stays ahead of relevant threats and guidance.
Inventory + assets
5Hardware and asset register that feeds your boundary scoping and SSP, with source-agnostic ingestion.
Installed-software register with license tracking and expiration so unauthorized or stale software surfaces fast.
Live Site → VLAN → Asset topology (vis-network) with a manual overlay for the CUI boundary you draw yourself.
Employee register tied to training assignments and role-based access across the tenant.
AI analysis of installed software for CVEs, license violations, and supply-chain red flags.
Integrations + identity
9Single sign-on via Okta, Azure AD / Entra ID, Google Workspace, or any SAML 2.0 / OIDC IdP, with JIT provisioning.
Auto-ingest sites, VLANs, clients, and devices through the UniFi cloud connector. No agent for cloud-adopted networks.
Stream the audit log to your SIEM in CEF, LEEF, syslog, or JSON, on demand or on a schedule (Splunk, Sentinel, etc.).
Point Readyline's AI at your own Anthropic account and pick the model. Keys are encrypted at rest and no Readyline credits are metered.
Choose OpenAI or other providers as your AI backend, alongside the existing Anthropic bring-your-own-key support.
Real OSCAL parsing from the official DoD methodology v1.2.1, not a custom retrofit.
Per-user locale. App surfaces, emails, policies, and PDFs all render in the recipient's language.
Tenant-branded notifications and reminders via Resend with full deliverability.
Programmatic access to controls, risks, POA&Ms, and evidence. Webhooks for event-driven workflows.