Five steps from “do we even need this?” to a C3PAO who finds nothing new.
Garde1 scopes your boundary, connects to your systems, writes your policies and SSP, fixes what it can, and grades you against every objective before an assessor does. Works on your existing Microsoft 365, Google Workspace or AWS environment.*
* Your environment has to meet FedRAMP Moderate for CUI. ITAR and EAR data also need a government partition with US-person handling. Garde1 tells you whether yours does.
Scope
Maps where CUI lives, and flags where your answers contradict what your tools show, before an assessor finds it.
YouAnswer plain questionsConnect
Pulls evidence from 23 connectors, including Microsoft 365, Google Workspace, AWS, CrowdStrike and Okta, into the controls it proves.
YouSign in once per systemFix
Checks your settings against DISA STIG and CIS baselines, credits what Microsoft 365 and Google Workspace cover under their published responsibility matrices, and applies supported fixes once you approve them.
YouClick approve*Document
Writes your 14 domain policies and the SSP from your real environment. A fact it does not have is marked for you to fill, not filled in.
YouReview and signProve
Scores all 320 objectives against your evidence, builds the POA&M, and opens a portal for your assessor (Professional and up) once you reach SPRS 88.
YouBook the C3PAO
*Supported settings only, on Professional and up, subject to the vendor's API availability. Everything else comes with step-by-step instructions. See exactly what's left to you →
What's truly left to you. We'd rather you hear it from us.
Software can't sign for your company, lock your doors or sit your interview. Here is everything Garde1 handles, and the short list it can't.
Training by role is inside the subscription. Background checks run inside Garde1 through your own Checkr account, billed by Checkr at cost.
What you get at each step.
The documents, the evidence, the score and the answers, as they look inside Garde1.
Documents generated from your environment.
Policies first, from a guided onboarding and your scope. The System Security Plan writes itself once your mock reaches SPRS 88, so it describes what was measured, not what you hope.
- Upfront14 policies and assessment artifacts from guided onboarding
- At SPRS 88System Security Plan grounded in measured evidence
Evidence collected from the systems you already run.
23 connectors and a Windows agent pull live evidence into the controls it proves. No screenshots. No “where is that PDF” at 2am.
- IdentityMicrosoft Entra · Okta · Google Workspace · Duo
- CloudAWS · Azure · GCP
- EndpointCrowdStrike · SentinelOne · Defender · Intune
Continuous evaluation against real evidence.
Every objective is scored against the configuration of your stack, not the policy text. When a control slips, your next mock catches it. Not your C3PAO.
- CadenceMock assessments run Tuesdays on Starter; Monday, Tuesday, Thursday and Friday on Professional; any day on Enterprise. Each takes about 12 minutes.
- ScoringSPRS out of 110 · 110 is Final · 88+ is Conditional, with open items closed within 180 days
Garde1 Consultant.Answers from your own evidence.
Ask about a control or a gap in plain English. It answers from your scope and your evidence, not the open internet, and shows which control and which evidence the answer rests on.
- SourcesThe CMMC and NIST 800-171 text · your scope · your evidence · outside lookups only on NIST, FedRAMP and vendor sites
- CitationsAnswers point to the control, the objective and the evidence they rest on
Every tool the DIB runs, with the CRM your assessor wants.
23 connectors pull evidence directly from the vendor API, and 30 curated Customer Responsibility Matrices say what each vendor covers. Vendors without a connector (PreVeil, Virtru, Brivo) get a curated CRM plus evidence upload. Anything else in your stack gets a CRM inferred from that product's profile in our catalog.
