The assessor packet, line by line.
Pre-sale buyers should start at /security. New to CMMC? Start with the plain-English explainer → This page is for the CMMC assessor and the customer compliance team documenting Garde1 in an OSC's scope. 32 CFR §170.19 places Garde1 in the Security Protection Asset (SPA) lane and names a single regulatory deliverable: a published Customer Responsibility Matrix. Below, in reading order: the §170.19 framing, the per-feature data taxonomy, the CRM itself, the no-CUI policy, pasteable SSP boilerplate, and the regs we track to.
A Security Protection Asset under 32 CFR §170.19. Documented, scoped, accounted for in your CRM.
The DoD framework that governs Garde1's customers — CMMC Level 2 under 32 CFR Part 170 — defines a specific lane for External Service Providers that process, store, or transmit Security Protection Data without touching CUI. §170.19 places those ESPs in the OSC's assessment scope as Security Protection Assets and asks the ESP for a service description and a customer responsibility matrix. We've read the regulation closely — the DoD CMMC Level 2 Scoping Guide v2 is the assessor-facing companion — and built Garde1 to land cleanly in that lane. The CRM below is what your assessor will ask for.
Four facts your assessor can rely on. One, Garde1 doesn't ask for, accept, or store CUI (see the published No-CUI Policy). Two, customers document Garde1 in their SSP as the CMMC-relevant ESP supporting readiness and reference the CRM below. Three, the regulation doesn't require Garde1 to hold its own CMMC certification or FedRAMP authorization — under §170.19(c)(2), an ESP that handles security protection data but not CUI is assessed as part of the OSC's scope, documented by a service description and a customer responsibility matrix, not by independent certification of the provider. Hosted on FedRAMP Moderate authorized AWS services in us-east-2. Garde1 itself is not FedRAMP authorized. GovCloud is on the roadmap. Our GovCloud tenancy and FedRAMP 20x roadmap commitments are voluntary — we're pursuing them because serious DIB buyers eventually ask, not because §170.19 requires them. Four, we don't make claims we can't back — “out of CMMC scope”, “CMMC certified”, “FedRAMP compliant”, “performs assessments” are all phrases you will never see on this site.
Why Garde1 is not FedRAMP authorized, and why that is the correct answer.
DFARS 252.204-7012(b)(2)(ii)(D) requires FedRAMP Moderate, or equivalent, of a cloud service that stores, processes or transmits CUI. 32 CFR 170.19(c)(2) says an external service provider that does not process CUI needs no CMMC certification of its own; it owes you a service description and a customer responsibility matrix. Garde1 does not accept CUI. It holds Security Protection Data: your scope, your SSP drafts, configuration posture pulled from your tenants, and evidence summaries. So the FedRAMP Moderate requirement does not attach to Garde1, and the §170.19 obligation does. Both documents are on this page.
We built to the higher bar anyway. Hosted on FedRAMP Moderate authorized AWS services in us-east-2. Garde1 itself is not FedRAMP authorized. GovCloud is on the roadmap. Customer-managed KMS, tenant isolation and a seven-year audit log sit on top. Saying Garde1 is FedRAMP authorized would be false, so we do not. GovCloud tenancy is next on the roadmap, and FedRAMP 20x after it, for contractors who want Garde1 inside a CUI-capable environment. Until then, CUI stays in your tenant, where your assessor expects it. The roadmap, with dates as they are set.
Platform function, data category, CMMC implication.
Per-feature accounting. Each platform function maps to the data category it produces and the CMMC consequence of using it.
| Platform function | Data category | CMMC implication |
|---|---|---|
| Generates SSP drafts | SPD / security-sensitive | Customer owns the final SSP; Garde1 must protect drafts. |
| Stores SSPs and document packages | SPD / possibly sensitive business | Needs retention, deletion, access controls, auditability. |
| Generates POA&M / remediation items | SPD | Customer owns remediation decisions. |
| Pulls connector configuration and security posture | SPD | Read-only / default scopes; documented connector scope matrix. |
| Produces evidence summaries | SPD | Customer validates final evidence. |
| Produces SPRS self-assessment packet | Assessment support data | Customer / Affirming Official submits. Garde1 does not affirm. |
| Interview prep | Assessor-prep only | Cannot satisfy controls on its own. |
| Mock assessment / readiness scoring | Advisory | Not a C3PAO assessment. No certification outcome. |
| AI recommendations | Advisory | Customer reviews and applies. Garde1 does not make changes autonomously. |
The CRM, line by line.
Most assessors expect this matrix on file before they accept Garde1 in the scope discussion. Paste it verbatim into your CRM or adapt to match your environment.
Garde1 uses read-only integrations for assessment and recommendation workflows by default. Write-capable scopes are opt-in per connector for remediation and baseline workflows only; they use a separate credential per connector that you grant, and each action is checked against the permissions you granted. Garde1 does not make autonomous changes to customer environments — see connector scopes for the per-category breakdown.
Garde1 does not require, ask for, or accept CUI.
Pasteable boilerplate. Drop it in. Adjust to your scope.
Two paragraphs your assessor expects. The first describes Garde1's role under §170.19; the second states the no-CUI / SPD-handling posture explicitly.
Garde1, operated by ComplAI Solutions, LLLP, is a mock-assessment and CMMC readiness platform used by the OSC as an External Service Provider. Garde1 is not a C3PAO and does not issue CMMC certifications or determine official CMMC status. Under 32 CFR §170.19, Garde1 is treated as a Security Protection Asset within this OSC's CMMC assessment scope because the service processes and stores Security Protection Data on the OSC's behalf. As an external service provider (cloud service) that handles security protection data, not CUI, Garde1 is not required under §170.19 to obtain its own CMMC certification; Garde1 provides a service description and a customer responsibility matrix (§170.19(c)(2)(ii)) at garde1.com/compliance. Garde1 does not require customers to provide CUI to generate SSPs or readiness artifacts. Garde1 may process security-sensitive information, including SSP drafts, assessment metadata, configuration data, evidence summaries, and Security Protection Data.
Regs and DoD guidance this page tracks to.
- 32 CFR §170.4 — CMMC definitions (ESP, SPA, SPD, CUI, FCI).
- 32 CFR §170.19 — CMMC Level 2 scoping. SPA treatment of ESPs that process / store / transmit SPD without CUI.
- DoD CMMC Level 2 Scoping Guide v2 — assessor-facing reference.
Topic-specific deep dives.
- No-CUI Policy →What we don't take, and what to do if it lands.
- Connector scopes →Read-only by default; write authorization audit.
- AI data use →Azure OpenAI and Document Intelligence, no training, what we send.
- Subprocessors →All vendors, data classes, DPAs.