How does Garde1 take me from scope to a defensible CMMC record?

Answer questions about your company once. Garde1 builds your scope, writes the SSP and 14 policies, reads evidence from your tools, scores all 110 requirements, and hands you the fixes.

One laptop through Garde1. Scope → documents. Evidence → mock assessment. Short fix list. Working guide.
In this guide

Updated September 29, 2026

You answer questions about your company once. Garde1 turns the answers into a scope, writes your security plan and policies from it, reads evidence from the tools you already run, scores you the way an assessor would, and turns every gap into a specific fix.

The reason to do this before the real thing is money and time. CMMC is the Defense Department's cybersecurity certification for contractors, and for most shops handling controlled drawings it means an assessment by a C3PAO (a certified third-party assessment organization: the accredited firm that runs the real exam). DoD estimates that assessment at $101,752 for a small company (final rule, 89 FR 83092). You want to find your gaps on your own schedule, not in the middle of that.

Here is what happens, in the order you'll see it.

Scope: where the sensitive files live

Onboarding asks where your CUI lives and who touches it. CUI is controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive. From those answers Garde1 builds one scope, the list of people, computers, offices, and services that handle CUI or protect the things that do.

Take ENG-07, an engineer's Windows laptop that opens drawings and keeps local copies to work offline. It's in scope, and so are the services that protect it: the sign-in system, the device management that configures it, the logging that records what happens on it. Assessors sort every asset into categories with names like "CUI asset" and "Security Protection Asset." You don't need to learn them. Garde1 records each asset's category for you.

It also records what paperwork usually misses: each office's visitor handling, the printers that handle CUI, how paper copies are stored and destroyed, each cloud service's FedRAMP basis (the government's security authorization for cloud services, with Garde1 flagging evidence that's stale or missing), and which work your MSP (managed service provider, your outside IT company) and your cloud provider do for each requirement, the split a customer responsibility matrix spells out. If two answers contradict each other, say "we're fully remote" alongside a list of office door locks, Garde1 flags it.

Documents: written from that scope

Garde1 writes your System Security Plan (the SSP: the document describing how you protect CUI, and the first thing an assessor reads) and 14 policies, one for each area of the standard, from access control to physical security. Level 1 companies, who handle only basic contract information, get one safeguarding policy instead.

The SSP includes three drawings made from your scope: the boundary diagram, the network map, and how CUI moves through the company. Its appendices are the asset inventory, the configuration baseline, the evidence index, and a plan of action for open items when you need one.

Because the SSP and the evidence come from the same scope, they agree. If the SSP called ENG-07 a browser-only device while the evidence showed local files, the assessor would stop there.

Evidence: read from the tools you already run

Garde1 connects to 39 tools, including Microsoft Entra, Intune, Defender, SharePoint and Purview, Google Workspace, Jamf, CrowdStrike, Okta, AWS, and NinjaOne. From Intune it reads each laptop's disk encryption, its last check-in, and the status of every policy setting the laptop reports. From Entra it reads users, groups, admin roles, and app permissions. A laptop that shows up in three tools is matched by serial number, so it appears once.

Some proof only a person can supply, like a signed quarterly access review. You upload it and pick the requirement it supports. Garde1 writes the evidence index entry for every record either way.

Mock assessment: scored like the real one

A mock assessment worth running reads your systems, not only your documents. The standard has 110 requirements, each broken into smaller checks called objectives. Garde1 scores all 110, objective by objective, against your tool evidence and the records you've added, and computes your SPRS score: the number, from 110 down to −203, that you post in the DoD's Supplier Performance Risk System and that primes check before awarding work.

It also flags anything that would block Conditional status, the result that keeps you eligible for awards while you close a short list of open items within 180 days. Three things block it: a score under 88, any open item worth more than 1 point, and the six requirements the rule says can never be left open (32 CFR 170.21).

Fixes: what to change, and where

Every NOT MET item becomes a fix that names the tool, the setting, and what the setting should be. Fixes that block your status come first, then fixes that are due, then fixes that clear the most findings, each with its point value. That's the same order we'd fix gaps by hand, and it drops straight into a 90-day plan. After you change a setting, recheck that one gap or re-run the affected requirements.

After the score

Scopes change. When yours does, Garde1 flags which document sections went stale, and why, that same day, and you regenerate them. It schedules the recurring work with owners and due dates: the monthly security operations review, the quarterly admin-account review, annual training, the annual incident-response exercise, and the annual risk assessment. Every year it assembles your affirmation record (the score, the date, the signer), reminds you when the next one is due, and compares the score you posted in SPRS with its own.

Most readiness work arrives as a consultant's binder that starts disagreeing with your systems the week it's delivered. This is one scope, and everything else reads from it.

Mock assessment

From scope to a list of named fixes.

Watch one laptop go through scope, documents, evidence, and a scored mock assessment in Garde1.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE