Five steps from “do we even need this?” to a C3PAO who finds nothing new.

Garde1 scopes your boundary, connects to your systems, writes your policies and SSP, fixes what it can, and grades you against every objective before an assessor does. Works on your existing Microsoft 365, Google Workspace or AWS environment.*

* Your environment has to meet FedRAMP Moderate for CUI. ITAR and EAR data also need a government partition with US-person handling. Garde1 tells you whether yours does.

  1. Scope

    Maps where CUI lives, and flags where your answers contradict what your tools show, before an assessor finds it.

    YouAnswer plain questions
  2. Connect

    Pulls evidence from 23 connectors, including Microsoft 365, Google Workspace, AWS, CrowdStrike and Okta, into the controls it proves.

    YouSign in once per system
  3. Fix

    Checks your settings against DISA STIG and CIS baselines, credits what Microsoft 365 and Google Workspace cover under their published responsibility matrices, and applies supported fixes once you approve them.

    YouClick approve*
  4. Document

    Writes your 14 domain policies and the SSP from your real environment. A fact it does not have is marked for you to fill, not filled in.

    YouReview and sign
  5. Prove

    Scores all 320 objectives against your evidence, builds the POA&M, and opens a portal for your assessor (Professional and up) once you reach SPRS 88.

    YouBook the C3PAO

*Supported settings only, on Professional and up, subject to the vendor's API availability. Everything else comes with step-by-step instructions. See exactly what's left to you →

No fine print

What's truly left to you. We'd rather you hear it from us.

Software can't sign for your company, lock your doors or sit your interview. Here is everything Garde1 handles, and the short list it can't.

Garde1 doesYou do
ScopeMaps your boundary, cross-checked against what your systems showAnswer the questions, confirm the boundary
EvidencePulls evidence from every system you connectSign in once per system. Upload what no system can show: visitor logs, signed agreements, DD 254s
FixesApplies supported fixes in your tools, with step-by-step instructions for the restApprove them. Handle what software can’t: locks, badges, hardware
DocumentsWrites your 14 policies, the SSP and the POA&M from your scopeRead and sign. They’re your company’s commitments
ReviewsQueues access and software reviews from your live systemsKeep or revoke
TrainingWorks out who owes which training, and delivers it in Garde1Get your people through it, and their policy acknowledgments
AssessmentRuns the whole Security Assessment (CA) family, grades all 320 objectives, and hands your package to the assessorHire the C3PAO and sit the interviews
Sign-offKeeps the record ready for the day you affirmReport real incidents to the DoD within 72 hours. A senior official affirms in SPRS; no one else can

Training by role is inside the subscription. Background checks run inside Garde1 through your own Checkr account, billed by Checkr at cost.

Up close

What you get at each step.

The documents, the evidence, the score and the answers, as they look inside Garde1.

Document

Documents generated from your environment.

Policies first, from a guided onboarding and your scope. The System Security Plan writes itself once your mock reaches SPRS 88, so it describes what was measured, not what you hope.

  • Upfront14 policies and assessment artifacts from guided onboarding
  • At SPRS 88System Security Plan grounded in measured evidence
policies & documents · sample tenantlive
⋮
Media Protection Policy
Policy
Governs how CUI is protected on physical and digital media (e.g. USB drives, backups, printouts), including sanitization and disposal.
PolicyApproved
⋮
Physical Protection Policy
Policy
The "locks and keys" policy. Defines how you control physical access to buildings, server rooms, and areas where CUI is located.
PolicyApproved
⋮
Risk Assessment Policy
Policy
The framework for how your organization identifies, analyzes, and responds to cybersecurity risks.
PolicyIn review
⋮
Identification & Auth Policy
Policy
The "digital ID" policy. Defines how users and devices are uniquely identified and verified before they can access anything.
PolicyIn review
⋮
Personnel Security Policy
Policy
Defines security processes tied to people, such as background screening, transfers, and termination, to mitigate insider risks.
PolicyApproved
⋮
Maintenance Policy
Policy
Sets the rules for how system maintenance is performed securely, ensuring that CUI isn't exposed during repairs or updates.
PolicyDraft
Connect

Evidence collected from the systems you already run.

23 connectors and a Windows agent pull live evidence into the controls it proves. No screenshots. No “where is that PDF” at 2am.

  • IdentityMicrosoft Entra · Okta · Google Workspace · Duo
  • CloudAWS · Azure · GCP
  • EndpointCrowdStrike · SentinelOne · Defender · Intune
integrations · 23 connectors · sample tenantlive
Workspace (2)Cloud Security (3)Identity (4)Endpoint (4)SIEM (1)Vulnerability Mgmt (1)Network (4)Dev, ticketing & training (4)
Available Connectors (23)
Configured Integrations (3)
Cloud Security
Microsoft Azure
Cloud Security
Subscriptions, resources, IAM, policy, networking, logging and Defender for Cloud evidence.
Amazon Web Services
Cloud Security
IAM, compute, storage, networking, logging, Security Hub and infrastructure evidence.
Google Cloud
Cloud Security
Projects, IAM, compute, storage, networking, organization policy, logging and Security Command Center evidence.
Prove

Continuous evaluation against real evidence.

Every objective is scored against the configuration of your stack, not the policy text. When a control slips, your next mock catches it. Not your C3PAO.

  • CadenceMock assessments run Tuesdays on Starter; Monday, Tuesday, Thursday and Friday on Professional; any day on Enterprise. Each takes about 12 minutes.
  • ScoringSPRS out of 110 · 110 is Final · 88+ is Conditional, with open items closed within 180 days
compliance status by domain · sample tenantlive
Access Control
22 Controls
Limit information system access and protect against unauthorized access to CUI
Compliance73%
16 Compliant1 Partial3 Non-Compliant2 Need Evidence
Awareness & Training
3 Controls
Ensure personnel are trained to recognize and respond to cybersecurity threats
Compliance67%
2 Compliant1 Need Evidence
Audit and Accountability
9 Controls
Create, maintain, and protect audit records to enable monitoring and investigation
Compliance67%
6 Compliant1 Partial1 Non-Compliant1 Need Evidence
Configuration Management
9 Controls
Establish and maintain baseline configurations and inventories of systems
Compliance56%
5 Compliant1 Partial2 Non-Compliant1 Need Evidence
Identification & Authentication
11 Controls
Verify the identities of users, processes, and devices
Compliance36%
4 Compliant1 Partial4 Non-Compliant2 Need Evidence
Incident Response
3 Controls
Detect, respond to, and recover from cybersecurity incidents
Compliance33%
1 Compliant1 Non-Compliant1 Need Evidence
Ask

Garde1 Consultant.Answers from your own evidence.

Ask about a control or a gap in plain English. It answers from your scope and your evidence, not the open internet, and shows which control and which evidence the answer rests on.

  • SourcesThe CMMC and NIST 800-171 text · your scope · your evidence · outside lookups only on NIST, FedRAMP and vendor sites
  • CitationsAnswers point to the control, the objective and the evidence they rest on
Garde1 consultant · sample tenantonline
What's the requirement for IA.L2-3.5.3, and where am I failing it?
Garde1
It requires multifactor authentication for every privileged account, and for network access by everyone else. You fail it because 3 global admins are excluded from the conditional-access policy that enforces MFA in Entra ID.
RequirementNIST SP 800-171 rev 2, §3.5.3 · 5 points
EvidenceEntra ID conditional access · synced 12 seconds ago
Assign the fixSteps for Entra included · re-checked at your next assessment
Integrations & CRMs

Every tool the DIB runs, with the CRM your assessor wants.

23 connectors pull evidence directly from the vendor API, and 30 curated Customer Responsibility Matrices say what each vendor covers. Vendors without a connector (PreVeil, Virtru, Brivo) get a curated CRM plus evidence upload. Anything else in your stack gets a CRM inferred from that product's profile in our catalog.

Demo

See your SPRS score this week.

Give us 30 minutes. We'll show you where you stand against all 110 requirements, what's missing, and what it costs to close the gap, using your own environment instead of a slide deck.

Only handle FCI? See Level 1, $150 a monthOr start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE
readiness · sample tenantlive
61%
Ready
Pass67
Partial5
Fail19
None19
SPRS SCORE
39
CONNECTED
3
CADENCE
4 days a week
TREND
↑ improving