About

CMMC, without the consulting tax.

Garde1 was built by two people who've watched the CMMC ecosystem from the inside — and got tired of watching defense contractors pay six figures for binders that drift the day they're signed. We're software, not a consulting engagement. And we'll tell you the truth even when it costs us the sale.

The problem

Traditional CMMC is a binder, not a system.

The default path to a CMMC Level 2 certification is a 6–18 month consulting engagement that typically costs $50K–$200K. It ends with a stack of policies that don't reflect what your environment actually does. Three months later your stack has drifted, your evidence is stale, and the next assessment starts from scratch.

The 110 security practices in CMMC Level 2 are deterministic. The 320 assessment objectives are deterministic. The work of mapping a real environment to them, generating the documents, and keeping evidence fresh — that work belongs in software.

Our approach

Automate what you can. Simplify what you can't.

Three things we do that the binder-and-consultant model can't:

  • AI-generated policies. Answer a guided onboarding; Garde1 generates the 14 domain policies, SSP, and POA&M tailored to your scope. Not boilerplate — deep, control-specific prose grounded in your real environment.
  • API evidence collection. Connect Microsoft 365, Google Workspace, AWS, Okta, your SIEM — Garde1 pulls live evidence and maps it to the controls automatically. Stop chasing screenshots. Stop emailing PDFs at 2am.
  • Bring-your-own evidence, read for you. The controls software can't observe directly — physical security walk-throughs, training records, signed acknowledgments, hand-written logs — you upload the artifact your C3PAO accepts (photo, PDF, screenshot, log export). Garde1 reads uploaded files (text extraction) and has AI check them against the control objective, flagging what's missing before the assessor sees it. A daily digest reminds you what's coming due. No attestation shortcuts — C3PAOs don't take them.

When a control slips, your next scheduled mock assessment catches it. When the C3PAO arrives, you hand them a tamper-evident export, not a fire drill.

Where we sit

The practice room. The C3PAO is the real test. We're built for the run-through.

Garde1 runs internal mock assessments so you find every gap before paying for the real one with a C3PAO. The DoD designed the readiness lane and the certification lane as separate roles for a reason — the room where you fix things sits separate from the room where you get certified. That's the lane Garde1 is built for. Garde1 is pursuing Registered Provider Organization (RPO) authorization. Hosted on FedRAMP Moderate authorized AWS services in us-east-2. Garde1 itself is not FedRAMP authorized. GovCloud is on the roadmap.

We don't adjudicate our own customers' controls. If the evidence says fail, the system says fail. The remediation path is “upload more evidence” — not a button to mark something satisfied.

The team

Two people. Enough scar tissue between them to know what to build.

Andrew Erne
Andrew Erne
CEO

Twenty-five years in federal cybersecurity, six as a Vice President and Solutions Architect, and a part-owner of one of the first C3PAOs the Cyber AB authorized. He has watched contractors pay six figures for a binder and fail the assessment anyway. Garde1 is what he built against that. Independence: Garde1 does not perform, influence or receive information from that C3PAO's assessments of any customer.

Kyle Fahey
Kyle Fahey
CTO

Shipping production software since he was thirteen; twenty years of leading distributed engineering teams, including SOC 2 and ABAC security at Litehouse, 1,000+ PRs at the Anaheim Ducks' technology arm, and a 2M-MAU search service at AbbVie. At Garde1 he learned CMMC from the 110 controls up and built the platform around the work the framework actually imposes. The goal: software a contractor opens on Monday, not a dashboard they find the day before the assessment.

Why we’re building this

We've seen, first-hand, how painful CMMC has become when it doesn't have to be.

Both of us have watched smart contractors burn out their best people on screenshots and spreadsheets. Watched six-figure engagements end with binders that diverge from reality the day they're signed. Watched well-intentioned compliance programs collapse the moment the consultant's contract ends.

We didn't start Garde1 to add another vendor to the ecosystem. We started it to take a stack of work that has been served by consultants for fifteen years and finally move it into software — where it should have been the whole time.

Get started

See how Garde1 maps your scope, generates your documents, and gets you assessment-ready.

Or start a 14-day trial