eMASS Submission

    eMASS Submission for CMMC and NIST SP 800-171

    eMASS submission is the last mile of the CMMC assessment — the bundle a C3PAO or DIBCAC reviewer actually ingests. Athena assembles an eMASS-ready package containing your SSP, SAR, POA&M, and supporting evidence, shaped for the Enterprise Mission Assurance Support Service and exported alongside OSCAL JSON, with a SHA-256 chain-of-custody hash and snapshot-frozen provenance on every artifact.

    What is an eMASS-ready CMMC package?

    eMASS is the DoD's Enterprise Mission Assurance Support Service — the authorization repository where assessment artifacts land. An eMASS-ready CMMC package is the bundle of documents and evidence shaped to ingest directly into eMASS workflows: the System Security Plan, the Security Assessment Report, the Plan of Action & Milestones, and the supporting evidence — in the schemas eMASS accepts, with the metadata DIBCAC and C3PAO reviewers expect, and with chain-of-custody hashes so the reviewer can verify nothing changed between export and ingest.

    Why eMASS-ready matters

    A platform that generates a great SSP but exports it as a PDF leaves the eMASS-shaping work on your team. That work is non-trivial: the SSP has to be sectioned and tagged correctly, the POA&M has to follow the prescribed milestone format, the SAR has to map findings to objectives in the order the reviewer expects, and the supporting evidence has to be referenced consistently across all three documents. Manual reformatting between platform export and eMASS ingest is rework you do every quarter, and rework that introduces inconsistencies the reviewer will surface.

    eMASS-ready output eliminates the reformatting step entirely. The package the platform produces is the package the reviewer ingests.

    What Athena's eMASS submission delivers

    • Full package assembly. SSP, SAR, POA&M, supporting evidence — bundled in eMASS-shaped form.
    • OSCAL JSON output. Machine-readable export for systems that accept the OSCAL schema.
    • Cryptographic provenance. SHA-256 hash on every artifact; immutable chain of custody back to source evidence and approving reviewer.
    • Snapshot freezing. Export creates an immutable point-in-time snapshot — the package the reviewer sees six months later is the package you submitted.
    • Defensibility trace. Every SAR line carries a "Why?" trace the reviewer can click to walk back through reviewer sign-off, AI draft, source evidence, and originating telemetry.
    • Affirming Official attestation. The package includes the attestation trail 32 CFR Part 170 requires.

    How eMASS submission ties into the workflow

    The eMASS package is the final output of the workflow that begins with evidence intake and runs through SSP automation, POA&M management, SPRS scoring, and C3PAO assessment prep. Because every artifact draws from the same evidence ledger and carries the same provenance, the package is internally consistent by construction — see the workflow automation pillar.

    Buyer checklist for eMASS submission

    • eMASS-shaped export, not just PDF.
    • OSCAL JSON alongside human-readable artifacts.
    • SHA-256 chain-of-custody hash per artifact.
    • Snapshot freezing for immutable assessor-bound packages.
    • Clickable provenance trace per SAR line.
    • Affirming Official attestation trail included.

    Frequently asked questions

    What goes into an eMASS-ready CMMC package?

    The System Security Plan, the Security Assessment Report, the Plan of Action & Milestones, and the supporting evidence — in eMASS-shaped schemas with metadata DIBCAC and C3PAO reviewers expect, plus OSCAL JSON for machine-readable ingestion, plus SHA-256 hashes for chain-of-custody verification.

    Is OSCAL required for eMASS submission?

    OSCAL is not yet universally required, but the DoD acquisition stack is moving toward OSCAL-native ingestion. Submitting OSCAL alongside human-readable artifacts future-proofs the package against the next round of DIBCAC tooling and prime contractor portals. Athena emits both by default.

    What does snapshot freezing do?

    Snapshot freezing captures the immutable state of every artifact at export time — the SSP, SAR, POA&M, evidence, hashes, and provenance trace. Six months later a reviewer auditing the submission sees exactly what was submitted, not the live system state. It is the defense against "the system changed after we submitted."

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.