Clear Guidance for
Commonly Asked Questions.

Straightforward answers to the questions that come up most while evaluating AssessrLog. How scoping, evidence, integrity, and the SPRS handoff actually work.

24 Questions · 6 Topics

Scope & FCI

Fig. 01

Follow the FCI, not the org chart. You record every person, device, facility, and outside provider that touches FCI as a scope object, classified and marked for whether it processes, stores, or transmits it. You are not left to do it cold.

  • A guided baseline and a ten-question Coverage Check prefill the places FCI usually hides, so you do not under-scope.
  • The app draws the FCI data-flow diagram an assessor looks for, automatically, from your entries.
  • The AI Scope Advisor re-checks each entry against the 32 CFR 170.19(b) rules and raises cited advisories. A person accepts or dismisses each one.

The finished scope decides which of the 15 requirements apply to which item, every call attributed to a person. You own every determination.

Federal Contract Information is information not intended for public release that is provided by or generated for the Government under a contract. It is not public information, and it is not CUI. Level 1 protects FCI only. CUI and the Level 2 world are a different program and out of scope here.

In AssessrLog everything you scope and store is built around the FCI you handle, and material above FCI is kept out of the product by design.

Two ways, and both keep the decision yours.

  • The ten-question Coverage Check walks where FCI most often hides, from email and cloud storage to file servers, outside IT, personal devices, and backups, and prefills the commonly missed items.
  • For a specific question, the AI Scope Advisor answers one scoping question at a time, grounded in the 32 CFR 170.19(b) rules, and names the rule that applies.

It never gives a yes or no verdict on your specific system. You decide with the rule in front of you.

Under-scoping is the number-one reason Level 1 self-assessments fail, so the product is built to prevent it.

  • Group related components under a parent with a count, so a large fleet stays readable.
  • Category columns and the applicability matrix keep the register organized.
  • The Scope Advisor's Deepen Discovery pass looks for what a big environment tends to miss and flags it as a cited advisory.

A newly added in-scope component starts unresolved on every requirement, so nothing silently passes when your scope grows. You end with an organized register, the data-flow diagram, and any gaps surfaced for a person to resolve.

No. The AI Scope Advisor only ever raises a cited advisory. It reads what you have recorded plus the 32 CFR 170.19(b) rules and returns a Discrepancy, a Question, or a Suggestion, each tied to a verbatim quote from your own material.

  • Accepting one opens a prefilled form that you save. Accepting alone changes nothing.
  • Dismissing one asks you to record a reason.
  • It never changes your scope on its own, never says a system is in or out, and never makes a MET, NOT MET, or N/A determination.

Every determination is made and recorded by a person. A defensible self-assessment requires your organization to own the scope and the calls. The reason is liability.

How the Assessment Works

Fig. 02

You work the 59 assessment objectives one at a time. For each, you record fieldwork, attach the evidence you relied on, and make one determination, either MET, NOT MET, or N/A. Recording it is a deliberate action, never an auto-save.

What makes it hold up is a written basis. NOT MET needs a note on what is left to implement. N/A needs a rationale. A MET saved with no basis is flagged Undocumented until you write one, and it holds up your SPRS readiness until you do. When a requirement applies to several in-scope systems, you evaluate each, so it cannot be called met while a component is unchecked.

Built-in guidance for each objective sits beside the official NIST SP 800-171A procedure, so you always know what the objective is asking. You end with every objective resolved on an attributed, evidence-backed basis.

No. Level 1 has no score, no percentage, no maturity index, and no plan-of-action artifact. Status is a threshold. You need MET on all 15 requirements, with any N/A properly justified.

Progress shows as a count of resolved objectives out of 59, where resolved means MET plus justified N/A, and the separate MET, N/A, NOT MET, and in-progress counts are always shown next to it. What you see is exactly where you stand, never a grade.

Evidence & Your Data

Fig. 03

In AssessrLog, not scattered across laptops, email, and shared drives. Each artifact is stored, versioned, and content-hashed.

Uploading a new version never overwrites the old one. Every prior version stays retrievable, so you can always show the exact file a past determination relied on. One item can back every objective it supports without being uploaded twice, and an evidence chain assembles the full story behind any objective in one view.

A hard ceiling. Every file upload requires a short confirmation that the file contains only FCI or less, nothing needing Level 2 or Level 3 protection, and the app records that attestation with the file version and the person who made it.

On a standard deployment the classification field will not accept CUI, so material above FCI stays out of the product entirely.

Yes. Your evidence lives in AssessrLog, and that evidence can contain FCI. That is the point, to centralize your proof in one protected place instead of leaving it scattered.

It is a shared responsibility. AssessrLog isolates each organization's data, keeps a tamper-evident record of your decisions, and protects finalized cycles from deletion. You control who you invite, each person's role, account strength, and what you upload. Scope stays FCI-only.

Trust & Integrity

Fig. 04

Every decision you record is sealed into an Integrity Ledger. Each entry fixes its content, author, time, and determination when written, and is chained by hash to the one before it, with a SHA-256 fingerprint on the evidence.

Open the ledger and it re-checks the whole chain and states plainly whether the record is intact, naming the first break if there ever is one. There is deliberately no edit and no repair button. A record you could quietly fix would not be tamper-evident.

It proves to your affirming official or an assessor who decided what, when, on what basis, and that nothing was altered after the fact.

A finished determination is never silently overwritten. When something it relied on changes, an implementation control, a workflow, a piece of scope, or a superseded evidence file, the affected objective is flagged for another look in the Revalidation Queue.

The saved finding stays intact next to the flag. A person reviews the change and resolves it deliberately, and both the flag and the resolution are written to the ledger. An unresolved flag holds up next year's carry-forward, so the assessment stays honest between annual cycles instead of drifting stale.

Four roles, each building on the last.

  • Executive views everything, but does not edit.
  • Security Team edits workpapers and evidence, but does not conclude.
  • Assessor does that, plus records determinations.
  • Admin does everything, including managing members.

Only an Assessor or Admin can record a MET, NOT MET, or N/A, and that is enforced on the server, not just hidden in the interface. Guardrails keep a team from locking itself out. The person who signs stands on work with named owners.

The Output & After

Fig. 05

No. AssessrLog assembles the package. It never submits to SPRS and never affirms.

It produces the handoff set for your official. That set includes a SPRS Entry Worksheet that mirrors every SPRS field so a person can enter it line by line, an Affirming Official Readiness Packet, and a per-requirement self-assessment report with evidence fingerprints and ledger references. Every document states in its own body that it is not an official DoD or SPRS form and that no automated submission exists.

Your senior official enters it in SPRS and affirms it. It never submits and never affirms for you. That step stays with your official.

Level 1 repeats every year, and AssessrLog carries your finished cycle forward instead of starting you over.

It freezes last year's assessment as a permanent record, opens the new cycle from a fresh snapshot, and produces a delta report of what changed in your scope, controls, and workflows. Objectives that are unchanged can be confirmed in bulk. Only what actually moved needs fresh work, and each confirmation is attributed in the ledger.

Six years. CMMC requires the artifacts behind a self-assessment to be kept for six years from your status date, and that obligation is yours. While your subscription is active, AssessrLog is built to hold a finalized package for each cycle for that full term.

While your subscription is active, AssessrLog keeps the evidence for each cycle inside its retention window, so the record you affirmed stays complete, and you get a six-year archive manifest describing the package. If you cancel, you can export your records first, and your own six-year retention obligation stays with you.

Choosing Level 1 Software

Fig. 06

CMMC Level 1 is a self-assessment against 15 requirements and 59 assessment objectives, affirmed once a year in SPRS by a senior company official. No rule names a required tool. What the rule does require is a defensible record. Which systems handle FCI, a determination of MET, NOT MET, or N/A for every objective, the evidence behind each one, and six years of retention.

  • A Scope Register. Every person, device, facility, and provider that touches FCI, recorded and classified, with the data-flow diagram an assessor expects.
  • An Objective Workspace. All 59 objectives worked one at a time, each with its determination, its reason, and the evidence that supports it.
  • Evidence Storage. The files themselves, kept as the system of record, versioned, and tied to the objective they prove.
  • An Affirmation Package. The finished assessment frozen as one record the affirming official can read and sign.

AssessrLog is built to do exactly those four things for an FCI-only supplier, and nothing beyond them.

Ask the vendor the questions an assessor would ask you. A tool that cannot answer them cleanly will not help you answer them either.

  • Does it work all 59 objectives from NIST SP 800-171A, or a shortened checklist?
  • Does it store my evidence, or only link to files that live somewhere else?
  • Is every determination attributed to a named person with a timestamp and a reason?
  • Can it show me exactly what changed since last year, so year two is a review rather than a redo?
  • Does it produce a package my affirming official can read before signing in SPRS?
  • Can I export everything if I leave, and does it hold records for the six-year term?
  • Is the price for a single small supplier, with no per-user fees and no implementation charge?

If the demo answers those seven with a yes you can see on screen, the tool is sized for Level 1. If it answers with a roadmap, keep looking.

Yes, and many suppliers start there. A spreadsheet can hold the 59 objectives and a status for each. The trouble arrives in year two, and on the day someone asks you to prove a determination. A spreadsheet holds a status, not a record. Files in a shared drive have no version, no integrity check, and no name attached to the decision they support.

A platform earns its place when it keeps the evidence, ties each file to the objective it supports, names who made each call and when, and freezes the whole thing as a package the affirming official signs. If a tool does not do those four things, a careful spreadsheet is a fair alternative.

Usually. Platforms built for CUI and the 110 controls of Level 2, or for several frameworks at once, carry pricing, onboarding, and monitoring integrations sized for that job. A small FCI-only supplier pays for capacity it never uses and spends weeks configuring controls it does not have.

Level 1 has no score, no POA&M, and no third-party assessor. The right size is a tool that works the 59 objectives, holds the evidence, and produces the affirmation package. If your contracts will move to CUI, plan for Level 2 when that happens. Do not buy for it now.

Keep it, rather than point at it. Evidence is the part of a self-assessment that gets challenged, so the software should pass three tests.

  • System of Record. The file is stored in the platform, versioned, and content-hashed, so the copy you affirmed is the copy that exists.
  • Linked to the Objective. Each file is attached to the objective and determination it supports, so a reviewer moves from finding to proof in one step.
  • Attributed and Sealed. Every upload and every determination carries a name, a time, and a reason, in a trail that cannot be edited afterward.

AssessrLog passes all three and seals every determination and upload in the Integrity Ledger, a hash-chained record a reviewer can verify.

For a single small supplier, a fair price is in the low hundreds of dollars per month, or a little over a thousand per year, with no per-user charges and no implementation fee. Anything priced like an enterprise compliance program is priced for a different buyer.

AssessrLog Practitioner is $99 per month billed annually, or $149 per month billed monthly, for one active environment. Each additional active assessment is $49 per month.

It does not submit to SPRS for you, and it should not claim to. Your affirming official logs in and affirms. What software should do is put a finished package in front of that person. The scope, all 59 determinations with their reasons, the evidence attached, and a record of who did what and when.

AssessrLog freezes each cycle as a permanent package, keeps it through the six-year retention term while your subscription is active, and opens next year's cycle from a snapshot with a report of what changed.

Look for isolation first. Each organization's assessment should be its own environment, with its own evidence and its own affirming official, and nothing summed or averaged across clients. Then look for oversight that reads progress without reading content.

AssessrLog's MSP Portfolio Oversight gives a firm one read-only view across every connected assessor's self-assessment. It sees readiness counts, cycle stage, dates, and assigned reviewers. It never sees evidence, findings, determinations, notes, or FCI scope, and each organization's own Admin grants and can revoke the connection.

Still Have a Question

Talk to Us
About the Platform.

If your question is not here, we will answer it straight, grounded in how the product works.