Compliance with Clarity. Readiness with Confidence.
Command Center
AI-Powered Compliance Readiness
Turn CMMC, DFARS, CUI, FAR, NIST, and OT requirements into a guided readiness journey.
ADEPTIO helps customers scope their environment, answer plain-English compliance questions, organize evidence, identify gaps, create POA&Ms, and prepare for reporting.
Controls answered and implemented.
Evidence notes and uploads tracked.
Organization, scope, and system details.
Assets, gaps, and remediation planning.
Evidence Intelligence
AI-scored evidence gaps and controls that need proof before assessment.
SPRS Readiness Dashboard
DoD Assessment Methodology weighted scoring (5 / 3 / 1 point deductions). SSP prerequisite 3.12.4 required for a score.
DoD weighted score out of 110.
Level 2 controls implemented.
Controls not yet complete.
Items that may block assessment.
Domain Heat Map
Top Point Deductions
Assessment Blockers
Connected CMMC Workflow
This layer does not change ADEPTIO's modules. It shows how the current data connects across the assessment lifecycle.
Production Readiness Audit
Quality check before connecting OpenAI, Supabase, GitHub, and PowerShell.
FCI Foundation
Focuses on FCI and the foundational 17 controls. These controls establish the baseline that carries forward into Level 2.
CUI Expansion
Builds on Level 1 and expands into CUI-focused requirements. Applicable Level 1 information can carry forward into the Level 2 build.
Recommended User Workflow
Use ADEPTIO in this order to avoid jumping across too many tools.
Next Recommended Actions
Risk Snapshot
Organization Profile
Customers fill this out first. These answers feed scoping, reporting, SSP content, and AI guidance.
Scoping Center
Guided questions help determine FCI, CUI, cloud, third-party, and assessment boundary considerations.
Asset Intelligence Center
Track hardware, software, cloud assets, government property, and OT assets.
Track unique identifier, asset type, asset name, serial number, owner, location, data type, system role, and assessment relevance for SSP generation and evidence mapping.
CMMC Level 1 Guided Assessment
Plain-English questions tied to the 15 Level 1 safeguards. Customers answer, add notes, and identify evidence.
Domain Progress
Track Level 1 implementation by domain family.
Controls
Select a practice
Choose a safeguard to begin.
Assessable Practices / Sub-Functions
Assess each objective underneath the selected practice.
Attach screenshots, policies, procedures, logs, diagrams, training records, or inventory files to this safeguard.
Saving a Level 1 safeguard automatically updates the matching Level 2 requirement.
AI Adeptio Compass
Evaluate completeness, gaps, and readiness for the selected practice.
CMMC Level 2 Build
Level 2 expands the platform toward NIST SP 800-171-style requirements, SSP narratives, evidence mapping, and POA&M development.
Based on completed Level 2 requirements.
Requirements with selected status.
File records attached to L2 requirements.
Implementation narratives drafted.
Domain Progress
Track implementation by NIST family and prioritize open 5-point SPRS gaps.
Controls
Select a Level 2 requirement
Choose a requirement to begin.
Assessable Practices / Sub-Functions
Assess each objective underneath the selected Level 2 requirement.
Attach evidence files to this safeguard. Files upload to cloud storage when signed in.
AI Adeptio Compass
Evaluate completeness, gaps, and readiness for the selected requirement.
Evidence Vault
Upload proof, store files in the cloud when signed in, and use AI to map evidence to controls with quality scoring.
Upload screenshots, PDFs, policies, procedures, logs, exports, diagrams, and training records. Signed-in users store files in Supabase; use AI Analyze to suggest control mappings.
Document Review Queue
Low-confidence mappings, unmapped uploads, and auto-mapped items awaiting analyst confirmation.
Consultant Review
Consultant-style review queue, findings, and evidence requests — additive to OSC workflows. Uses existing review status bubbles on Level 1 and Level 2 controls.
Controls not yet approved.
Documented consultant findings.
Open artifact requests.
Controls marked reviewed and approved.
Review Queue
Findings Register
Evidence Requests
Consultant Share Link
Generate a read-only link for external consultants or C3PAO assessors. Snapshot includes SPRS score, review queue, findings, and executive summary. Links expire automatically.
Integrations Hub
Connect cloud platforms, security tools, and workflow systems. Integration signals feed the organization digital twin, evidence mapping, and continuous compliance monitoring.
Available Connectors
Compass AI — Virtual C3PAO
Your AI compliance consultant. Ask about readiness, evidence gaps, interview questions, mock assessments, and remediation priorities using your live organization data.
POA&M Studio
Findings are generated from incomplete practices and can be assigned owners and due dates.
Reporting Center
Generate assessment-ready exports for SSP, POA&M, executive summary, and evidence packages. PDF uses direct download when available, otherwise print-to-PDF.
Resource Repository
Central reference library for ADEPTIO source documents, templates, regulations, and planning materials.
Upload files, documents, spreadsheets, presentations, images, videos, or other reference materials. You can remove added resources if uploaded by mistake.
Static prototype note: uploaded resource records are saved in this browser only. Production storage will use Supabase Storage.
SSP Studio
Generate a System Security Plan draft from organization data, scope, assets, CMMC responses, evidence, and POA&Ms.
Assessment Readiness Center
Shows whether each control is assessment-ready based on implementation status, narrative, evidence notes, and file attachments.
Live from L1 + L2 assessment records.
FCI / Level 1 practices.
CUI / Level 2 requirements.
Review status Approved.
Active assessment work.
Not yet reviewed.
Deficient or open gaps.
Status set without proof.
Queued for consultant/OSC review.
Scoped out controls.
Outstanding remediation items.
Implemented or N/A controls.
Evidence Matrix
One-click view of controls, status, evidence notes, attached files, and assessor confidence.
Policy Builder
Create usable policy and procedure documents tied to assessment level, domain, control, and practices.
Gap Remediation Engine
Turns incomplete controls into actionable remediation tasks with priority, effort, owner, and expected readiness impact.
Boundary Diagram Builder
Describe your environment in text and generate a CUI/FCI assessment boundary and data flow diagram.
Describe users, systems/assets in scope, data flows, cloud providers, vendors, remote access, out-of-scope items, and any FCI/CUI handling.
Advanced Options (Optional)
Enter a plain-language description. Each description generates a fresh diagram. ADEPTIO creates the boxes, labels, and arrows from the systems, users, vendors, data flows, and scope described in the text.
Saved Diagrams
Vendor Risk Management
Track MSPs, MSSPs, cloud providers, subcontractors, and vendors that may touch FCI, CUI, systems, or evidence.
ESP / Cloud Provider Risk Check
Use this to verify whether an External Service Provider or cloud provider is actually FedRAMP Moderate/High authorized with supporting documentation, rather than only FedRAMP eligible.
AI Governance Center
Inventory, classify, assess, approve, and monitor AI systems that may interact with FCI, CUI, company data, or the CMMC environment. This is a governance and exposure-management capability — not a certification tool.
Compliance Calendar
Track policy reviews, risk assessments, vulnerability scans, training, incident exercises, SSP reviews, and evidence refreshes.
Collaboration Center
Secure internal messaging between customer users, organization admins, assessors, and ADEPTIO support. All messages stay inside ADEPTIO for auditability.
Assessment Notes
Legacy comment threads tied to assessment areas — separate from internal messaging.
Organization Activity Log
Supabase audit trail for uploads, exports, and assessor actions when signed in.
Multi-Framework Center
Prepare ADEPTIO to scale beyond CMMC into NIST, CIS, ISO, SOC 2, HIPAA, and CJIS.
Risk Analysis Center
Analyzes scope, assets, vendors, CMMC responses, evidence, POA&Ms, policies, and remediation tasks to generate an executive risk assessment.
Weighted risk score.
Current business risk rating.
Immediate leadership attention.
Cybersecurity maturity estimate.
Risk Heat Map
Executive Risk Brief
Risk Register
Functional risk register generated from current ADEPTIO data. You can adjust likelihood, impact, owner, and treatment status.
Practice Assessment Workspace
Work one practice at a time — capture status, narrative, notes, and sub-functions, then explore Related Practices without leaving the workspace.
Assessable Sub-Functions
Related Practices
CMMC Level 2 related-practice mappings for the selected control. Expand a related practice without losing your primary workspace context.
Global Search
Search across controls, sub-functions, evidence, assets, vendors, risks, POA&Ms, resources, policies, SSP data, and notes.
Readiness Timeline
Customize phases, milestones, and tasks with due dates, owners, dependencies, and linked controls to match your assessment strategy.
Awareness & Training Builder
Generate training outlines and PowerPoint-ready content for CMMC awareness, cybersecurity awareness, CUI handling, insider threat, and recurring training.
App Help & Navigation Guide
How to navigate ADEPTIO, use each module, and get the most from Compass AI. Download the branded PDF for training and customer onboarding.
Loading navigation guide…