REDACTED — Demo data, real format

    See what Athena actually delivers

    Most CMMC vendors hide their output behind a sales demo. We don't. These are real Athena deliverables, redacted from a fictional ACG assessment, in the exact format your C3PAO will see them.

    Want the full bundle, not just samples?
    Seal your live data into a hash-manifested C3PAO Submission Pack — eMASS JSON, AO matrix, SPRS worksheet, SHA-256 log.
    Open Submission Pack Builder

    Deliverable

    System Security Plan — Excerpt

    How Athena writes an SSP control implementation: scope, narrative, objective-level status, evidence references, and enduring exceptions.

    SYSTEM SECURITY PLAN — EXCERPT (REDACTED)
    Organization: ACG (Athena Consulting Group)
    System: CUI Enclave — Production
    CMMC Level: 2 (Self-Assessment, Conditional)
    SSP Version: 4.2 — Sealed 2026-05-14
    Affirming Official: Doug Majewski, ACG Operations
    
    §3.1.1  AC.L2-3.1.1 — Limit system access to authorized users
    Implementation:
      Identity is federated through Microsoft Entra ID. All workforce accounts
      are provisioned via the ACG HR-to-IT joiner workflow (ticket SVC-INT-42).
      Privileged role assignment is gated by PIM with a 2-hour activation
      window and approver review. Service accounts use managed identities and
      cannot interactively log in. Quarterly access reviews are performed by
      the Security Operations team; the prior review attested 41 active
      accounts with zero exceptions on 2026-04-30.
    
    Assessment Objective Status:
      3.1.1[a] authorized users identified                    MET
      3.1.1[b] processes acting on behalf of users identified MET
      3.1.1[c] devices authorized to connect identified       MET
      3.1.1[d] system access limited to authorized users      MET
    
    Enduring Exceptions: none.
    Evidence: EV-3.1.1-01 (PIM policy export, sha256 1f3a...),
              EV-3.1.1-02 (Quarterly access review attestation).
    

    Ready for this in your own assessment?

    Every deliverable above is generated automatically from your own data — no copy-paste, no consultants in the loop.

    "REDACTED — DEMO" data shown above. No customer data is used in these samples. Sealing, hash verification, and 6-year retention follow DoD CAP §4.3 in real bundles.