Capability matrix

Capability matrix

Every capability in the platform, grouped by domain and mapped to the NIST controls it covers. LIVE today unless marked otherwise.

Compliance operations

7
L1 Auto-Pilot Wizard

17 plain-English questions. Submit and get every CMMC L1 control assessed plus a finished SSP PDF.

L1 L2 L3 CMMC control 3.12.4 LIVE
SSP Generator

Auto-generated System Security Plan PDF rolled up from your evidence, controls, and policies.

L1 L2 L3 CMMC control 3.12.4 LIVE
POA&M Manager

Plan of Action & Milestones with owner, due date, evidence linking, and dashboard widgets.

L1 L2 L3 CMMC control 3.12.2 LIVE
Control mapping (110 R2 live)

110 NIST 800-171 R2 controls mapped from official OSCAL. The NIST 800-172 catalog (24 reqs for CMMC L3) is in active development.

L1 L2 L3 CMMC control 3.12.1 LIVE
AI policy drafting

24 starter templates customized per tenant. Generate audit-grade policies grounded in your real state.

L1 L2 L3 CMMC control 3.15.1 LIVE
Continuous monitoring dashboard

Automated control posture tracking with drift alerts and rollup metrics.

L1 L2 L3 CMMC control 3.12.3 COMING
Quarterly SPRS submission

Automated quarterly SPRS score submission to DoD with reminder workflow and audit trail.

L1 L2 L3 CMMC control 3.12.1 COMING

Assessment + audit

6
C3PAO assessor mode

Time-limited (default 14 days), scope-bounded, read-only window into your tenant for an external assessor.

L1 L2 L3 CMMC control 3.12.5 LIVE
Immutable audit log

Every user action logged with user, IP, route, and timestamp. Append-only, exportable for an auditor.

L1 L2 L3 CMMC control 3.3.1, 3.3.2 LIVE
Evidence vault

Per-control evidence files with version history, control linking, and tagged-by-framework search.

L1 L2 L3 CMMC control 3.12.4 LIVE
Self-assessment workflow

Annual self-attestation cycle with status snapshots and SPRS score history.

L1 L2 L3 CMMC control 3.12.1 LIVE
Assessor report PDFs

Export-ready evidence packages, gap analyses, and control-by-control attestation documents.

L1 L2 L3 CMMC control 3.12.4 LIVE
C3PAO assessor analytics

Aggregated assessor activity dashboard: time-on-control, gaps identified, modules reviewed.

L1 L2 L3 CMMC control 3.12.5 COMING

Risk management

6
Risk Register · 5×5

NIST SP 800-30 inherent + residual scoring with heatmap visualization.

L1 L2 L3 CMMC control 3.11.1 LIVE
Risk treatment plans

Per-risk treatment PDF with mitigation steps, residual scoring, and assigned owner.

L1 L2 L3 CMMC control 3.11.1 LIVE
Risk → POA&M (one-click)

Spin up a POA&M item from any risk with the gap, owner, and due-date prefilled.

L1 L2 L3 CMMC control 3.12.2 LIVE
USD impact quantification

Per-scenario financial impact tied to each risk for boardroom-defensible decisions.

L1 L2 L3 CMMC control 3.11.1 LIVE
90-day risk trend chart

Score history per risk showing how the posture moved during the assessment window.

L1 L2 L3 CMMC control 3.11.1 LIVE
Vendor risk management (VRM)

Supplier inventory with criticality scoring, DFARS flow-down tracking, and SPRS-from-vendors collection.

L1 L2 L3 CMMC control DFARS 7019 COMING

Training · LMS

4
Course catalog

Curated CMMC training library (hybrid: central + tenant-custom courses).

L1 L2 L3 CMMC control 3.2.1 LIVE
Assignments + due dates

Per-user training assignments with due dates and auto-reminders.

L1 L2 L3 CMMC control 3.2.2 LIVE
Quizzes + certificates

Auto-graded quizzes and downloadable completion certificates per user.

L1 L2 L3 CMMC control 3.2.2 LIVE
Insider threat module

Awareness training to recognize and report insider-threat indicators.

L1 L2 L3 CMMC control 3.2.3 LIVE

Architecture + security

6
Per-tenant DB isolation

Dedicated MySQL database per tenant. No row-level multi-tenancy. Tenant breach radius = your tenant only.

L1 L2 L3 CMMC control 3.13.5 LIVE
2FA mandatory

TOTP-based 2FA required for every user. No bypasses, no exceptions.

L1 L2 L3 CMMC control 3.5.3 LIVE
Encryption & isolation

AES-256 field-level encryption for sensitive secrets (SSO config, integration keys), TLS 1.2+ in transit, and per-tenant database isolation.

L1 L2 L3 CMMC control 3.13.11 LIVE
Session management

Auto-timeout, IP-pinned sessions with full audit log of every login and elevation.

L1 L2 L3 CMMC control 3.5.10 LIVE
Air-gapped self-hosted

Deploy Readyline inside your own infrastructure, including air-gapped environments. The path for primes preparing for L3.

L1 L2 L3 CMMC control 3.13.1 LIVE
AI software risk investigation

AI analysis of installed software for CVEs, license violations, and supply-chain red flags.

L1 L2 L3 CMMC control 3.14.1 COMING

Integrations + identity

5
SAML SSO

Single sign-on via Okta, Azure AD, Google Workspace, or any SAML 2.0 IdP.

L1 L2 L3 CMMC control 3.5.2 LIVE
OSCAL ingestion

Real OSCAL parsing from the official DoD methodology v1.2.1, not a custom retrofit.

L1 L2 L3 CMMC control 3.12.1 LIVE
Bilingual EN/ES

Per-user locale. App surfaces, emails, policies, and PDFs all render in the recipient's language.

L1 L2 L3 CMMC control n/a LIVE
Branded email notifications

Tenant-branded notifications and reminders via Resend with full deliverability.

L1 L2 L3 CMMC control 3.13.13 LIVE
REST API + Webhooks

Programmatic access to controls, risks, POA&Ms, and evidence. Webhooks for event-driven workflows.

L1 L2 L3 CMMC control 3.13.13 COMING