ADEPTIO Logo
Secure Access Portal

Sign in to ADEPTIO

Access your CMMC readiness workspace, evidence, reports, and Compass AI guidance.

Compliance with Clarity. Readiness with Confidence.

Command Center

AI-Powered Compliance Readiness

Turn CMMC, DFARS, CUI, FAR, NIST, and OT requirements into a guided readiness journey.

ADEPTIO helps customers scope their environment, answer plain-English compliance questions, organize evidence, identify gaps, create POA&Ms, and prepare for reporting.

Overall Readiness 0% Advisory readiness score only
Compliance0%

Controls answered and implemented.

Evidence0%

Evidence notes and uploads tracked.

Documentation0%

Organization, scope, and system details.

Operational0%

Assets, gaps, and remediation planning.

Evidence Intelligence

AI-scored evidence gaps and controls that need proof before assessment.

SPRS Readiness Dashboard

DoD Assessment Methodology weighted scoring (5 / 3 / 1 point deductions). SSP prerequisite 3.12.4 required for a score.

SPRS Score0

DoD weighted score out of 110.

Implemented0

Level 2 controls implemented.

Open Gaps0

Controls not yet complete.

Blockers0

Items that may block assessment.

Domain Heat Map

Top Point Deductions

Assessment Blockers

Connected CMMC Workflow

This layer does not change ADEPTIO's modules. It shows how the current data connects across the assessment lifecycle.

Production Readiness Audit

Quality check before connecting OpenAI, Supabase, GitHub, and PowerShell.

CMMC Level 1

FCI Foundation

Focuses on FCI and the foundational 17 controls. These controls establish the baseline that carries forward into Level 2.

0%Level 1 Progress
CMMC Level 2

CUI Expansion

Builds on Level 1 and expands into CUI-focused requirements. Applicable Level 1 information can carry forward into the Level 2 build.

0%Level 2 Progress
Level 1 → Level 2 Growth: ADEPTIO treats Level 1 as the FCI foundation. Level 2 includes applicable Level 1 data and expands the assessment for CUI protection.

Recommended User Workflow

Use ADEPTIO in this order to avoid jumping across too many tools.

Next Recommended Actions

    Risk Snapshot

    Organization Profile

    Customers fill this out first. These answers feed scoping, reporting, SSP content, and AI guidance.

    Scoping Center

    Guided questions help determine FCI, CUI, cloud, third-party, and assessment boundary considerations.

    Do you handle Federal Contract Information?
    Do you handle Controlled Unclassified Information?
    Do you use external cloud providers?
    Do you use MSPs, MSSPs, or third-party IT providers?
    Do remote users access systems containing FCI or CUI?

    Asset Intelligence Center

    Track hardware, software, cloud assets, government property, and OT assets.

    Asset Inventory Fields

    Track unique identifier, asset type, asset name, serial number, owner, location, data type, system role, and assessment relevance for SSP generation and evidence mapping.

    CMMC Level 1 Guided Assessment

    Plain-English questions tied to the 15 Level 1 safeguards. Customers answer, add notes, and identify evidence.

    Domain Progress

    Track Level 1 implementation by domain family.

    Controls

    Select a practice

    Choose a safeguard to begin.

    Assessable Practices / Sub-Functions

    Assess each objective underneath the selected practice.

    Upload Evidence Files

    Attach screenshots, policies, procedures, logs, diagrams, training records, or inventory files to this safeguard.

    Saving a Level 1 safeguard automatically updates the matching Level 2 requirement.

    AI Adeptio Compass

    Evaluate completeness, gaps, and readiness for the selected practice.

    CMMC Level 2 Build

    Level 2 expands the platform toward NIST SP 800-171-style requirements, SSP narratives, evidence mapping, and POA&M development.

    L2 Readiness0%

    Based on completed Level 2 requirements.

    Answered0

    Requirements with selected status.

    Evidence Files0

    File records attached to L2 requirements.

    SSP Narratives0

    Implementation narratives drafted.

    Domain Progress

    Track implementation by NIST family and prioritize open 5-point SPRS gaps.

    Controls

    Select a Level 2 requirement

    Choose a requirement to begin.

    Assessable Practices / Sub-Functions

    Assess each objective underneath the selected Level 2 requirement.

    Upload Level 2 Evidence Files

    Attach evidence files to this safeguard. Files upload to cloud storage when signed in.

    AI Adeptio Compass

    Evaluate completeness, gaps, and readiness for the selected requirement.

    Evidence Vault

    Upload proof, store files in the cloud when signed in, and use AI to map evidence to controls with quality scoring.

    Upload Evidence Files

    Upload screenshots, PDFs, policies, procedures, logs, exports, diagrams, and training records. Signed-in users store files in Supabase; use AI Analyze to suggest control mappings.

    Document Review Queue

    Low-confidence mappings, unmapped uploads, and auto-mapped items awaiting analyst confirmation.

    Consultant Review

    Consultant-style review queue, findings, and evidence requests — additive to OSC workflows. Uses existing review status bubbles on Level 1 and Level 2 controls.

    Pending Review0

    Controls not yet approved.

    Open Findings0

    Documented consultant findings.

    Evidence Requests0

    Open artifact requests.

    Approved0

    Controls marked reviewed and approved.

    Review Queue

    Findings Register

    Evidence Requests

    Consultant Share Link

    Generate a read-only link for external consultants or C3PAO assessors. Snapshot includes SPRS score, review queue, findings, and executive summary. Links expire automatically.

    Integrations Hub

    Connect cloud platforms, security tools, and workflow systems. Integration signals feed the organization digital twin, evidence mapping, and continuous compliance monitoring.

    Available Connectors

    Compass AI — Virtual C3PAO

    Your AI compliance consultant. Ask about readiness, evidence gaps, interview questions, mock assessments, and remediation priorities using your live organization data.

    POA&M Studio

    Findings are generated from incomplete practices and can be assigned owners and due dates.

    Reporting Center

    Generate assessment-ready exports for SSP, POA&M, executive summary, and evidence packages. PDF uses direct download when available, otherwise print-to-PDF.

    Resource Repository

    Central reference library for ADEPTIO source documents, templates, regulations, and planning materials.

    Add Resource Files

    Upload files, documents, spreadsheets, presentations, images, videos, or other reference materials. You can remove added resources if uploaded by mistake.

    Static prototype note: uploaded resource records are saved in this browser only. Production storage will use Supabase Storage.

    SSP Studio

    Generate a System Security Plan draft from organization data, scope, assets, CMMC responses, evidence, and POA&Ms.

    Assessment Readiness Center

    Shows whether each control is assessment-ready based on implementation status, narrative, evidence notes, and file attachments.

    Overall Readiness0%

    Live from L1 + L2 assessment records.

    Level 1 Readiness0%

    FCI / Level 1 practices.

    Level 2 Readiness0%

    CUI / Level 2 requirements.

    Approved Controls0

    Review status Approved.

    In Progress0

    Active assessment work.

    Unreviewed0

    Not yet reviewed.

    Needs Remediation0

    Deficient or open gaps.

    Missing Evidence0

    Status set without proof.

    Ready for Review0

    Queued for consultant/OSC review.

    Not Applicable0

    Scoped out controls.

    Open POA&Ms0

    Outstanding remediation items.

    Control Completion0%

    Implemented or N/A controls.

    Evidence Matrix

    One-click view of controls, status, evidence notes, attached files, and assessor confidence.

    Policy Builder

    Create usable policy and procedure documents tied to assessment level, domain, control, and practices.

    Flow: Select assessment level → select domain → select control/practice → generate policy/procedure → edit → export.

    Gap Remediation Engine

    Turns incomplete controls into actionable remediation tasks with priority, effort, owner, and expected readiness impact.

    Boundary Diagram Builder

    Describe your environment in text and generate a CUI/FCI assessment boundary and data flow diagram.

    1Describe Your Environment

    Describe users, systems/assets in scope, data flows, cloud providers, vendors, remote access, out-of-scope items, and any FCI/CUI handling.

    0 / 4000
    Advanced Options (Optional)
    How it works

    Enter a plain-language description. Each description generates a fresh diagram. ADEPTIO creates the boxes, labels, and arrows from the systems, users, vendors, data flows, and scope described in the text.

    Saved Diagrams

    2Generated Boundary Diagram
    Not generated yet
    In-Scope Data Flow Out-of-Scope / Internet 🔒 Encrypted / Secure

    Vendor Risk Management

    Track MSPs, MSSPs, cloud providers, subcontractors, and vendors that may touch FCI, CUI, systems, or evidence.

    ESP / Cloud Provider Risk Check

    Use this to verify whether an External Service Provider or cloud provider is actually FedRAMP Moderate/High authorized with supporting documentation, rather than only FedRAMP eligible.

    AI Governance Center

    Inventory, classify, assess, approve, and monitor AI systems that may interact with FCI, CUI, company data, or the CMMC environment. This is a governance and exposure-management capability — not a certification tool.

    Compliance Calendar

    Track policy reviews, risk assessments, vulnerability scans, training, incident exercises, SSP reviews, and evidence refreshes.

    Collaboration Center

    Secure internal messaging between customer users, organization admins, assessors, and ADEPTIO support. All messages stay inside ADEPTIO for auditability.

    Conversations

    Recent Notifications

    Multi-Framework Center

    Prepare ADEPTIO to scale beyond CMMC into NIST, CIS, ISO, SOC 2, HIPAA, and CJIS.

    Risk Analysis Center

    Analyzes scope, assets, vendors, CMMC responses, evidence, POA&Ms, policies, and remediation tasks to generate an executive risk assessment.

    Overall Risk0

    Weighted risk score.

    Risk LevelLow

    Current business risk rating.

    Critical Risks0

    Immediate leadership attention.

    Maturity0%

    Cybersecurity maturity estimate.

    Risk Heat Map

    Executive Risk Brief

    Risk Register

    Functional risk register generated from current ADEPTIO data. You can adjust likelihood, impact, owner, and treatment status.

    Practice Assessment Workspace

    Work one practice at a time — capture status, narrative, notes, and sub-functions, then explore Related Practices without leaving the workspace.

    Assessable Sub-Functions

    Related Practices

    CMMC Level 2 related-practice mappings for the selected control. Expand a related practice without losing your primary workspace context.

    Readiness Timeline

    Customize phases, milestones, and tasks with due dates, owners, dependencies, and linked controls to match your assessment strategy.

    Awareness & Training Builder

    Generate training outlines and PowerPoint-ready content for CMMC awareness, cybersecurity awareness, CUI handling, insider threat, and recurring training.

    App Help & Navigation Guide

    How to navigate ADEPTIO, use each module, and get the most from Compass AI. Download the branded PDF for training and customer onboarding.

    Download PDF Guide

    Loading navigation guide…

    ADEPTIO Setup Guide

    Step 1 of 5