Athena Consulting Group, LLC
    New · Productized assessment workflow

    Build your CMMC Level 2 Assessment Pack in days, not months.

    Turn your gap analysis into a scoped SSP, POA&M, objective-level evidence checklist, and a hashed export ZIP that holds up under assessor review.

    Live
    0 of 6 steps complete0%
    Step 1

    Scope your environment

    Document CUI assets, SPAs, CRMAs, Specialized Assets, and Out-of-Scope justification with a network diagram. Required input for every downstream artifact.

    Step 2

    Walk the 110 controls at the objective level

    Athena drafts your stance on every Level-2 assessment objective. One NOT MET objective fails a requirement — so we score at the AO unit, not just the practice.

    Step 3 Sprint

    Collect objective-level evidence

    Generate an Evidence Request List by AO. Drop artifacts in once — Athena maps each one to the specific objectives it satisfies.

    Step 4 Sprint

    Generate the SSP draft

    A scoped System Security Plan written from your real answers — flagged "MISSING DETAIL" where evidence is thin, never invented.

    Step 5 Sprint

    Auto-draft your POA&M

    Every failing or partial objective becomes a POA&M entry with a weakness statement, milestone, owner, and closure-evidence target.

    Step 6 Sprint

    Export a hashed Assessment Pack

    One-click ZIP: scoped SSP, POA&M, AO matrix, evidence index, eMASS-ready JSON skeleton, and a SHA-256 manifest per the CMMC Hashing Guide.

    What an objective looks like inside the pack

    IA.L2-3.5.3 · Multifactor Authentication

    "Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts."

    Assessment objectives
    • 3.5.3[a] privileged-account MFA enforced
    • 3.5.3[b] network-access MFA enforced
    • 3.5.3[c] MFA mechanisms identified — evidence pending
    Missing-evidence checklist
    • Entra Conditional Access export (CSV)
    • Screenshot: privileged-role MFA registration
    • SHA-256 hash will be auto-generated on upload
    Scoped asset inventory + diagram
    Draft SSP mapped to all 110 controls
    POA&M starter for every gap
    AO-level Evidence Request List
    SHA-256 manifest per Hashing Guide
    One-click assessor-ready ZIP