Compliance posture · Spear One Solutions
Scores reflect submitted evidence only. Controls marked No Data require evidence upload to be evaluated.
Evidence references and notes are sourced from the uploaded CMMC Level 1 Assessment Workbook. Upload a new workbook to update.
| Req ID | Requirement | Coverage | Evidence Reference | Notes |
|---|---|---|---|---|
Governance Documents
Annual policies and procedures — evaluated by AI and reviewed by your CISO
| Document | AI Eval | Next Review | Status |
|---|---|---|---|
| Relationship | Agreement Review Due | Status | |
|---|---|---|---|
Monthly Evidence
Current = uploaded within the last 30 days
| Evidence Type | Last Upload | Days Since | Last 30d | Status | |
|---|---|---|---|---|---|
| Upload → |
Periodic Evidence
| Evidence Type | Cadence | Last Upload | Days Since | Count | Status | |
|---|---|---|---|---|---|---|
| Upload → |
Gap Reports
· ·
| Report | Period | |
|---|---|---|
|
|
Download links expire in 15 minutes. Refresh the page to generate new links.
Delete Report
This report PDF will be permanently deleted and cannot be recovered.
Governance Document Quality Evaluations
Review each uploaded policy document and record whether it meets NSANE quality standards. Evaluations are recorded in the platform and drive control scoring.
Evidence Quality Evaluations
For each control marked Met, evaluate whether the assessor's evidence notes are sufficient to withstand a DoD audit. The AI pre-screens each control — review the recommendation, then save your final judgment.
Quality Evaluation
AI Pre-Evaluation
Takes ~10 seconds. Result is saved for future opens.
Flagged gaps:
Form pre-filled from AI recommendation. Review and submit your final decision.
Evidence Quality Evaluation
Assessor Evidence
File:
AI Pre-Evaluation
Takes ~5 seconds. Result is saved for future opens.
Evidence gaps:
Form pre-filled from AI recommendation. Review and submit your final decision.
Archive Document
This document will be removed from the portal. It will be retained in storage for 30 days and can be recovered by an administrator if needed.
Edit Document Title
Updates the title in both Quality Eval and Compliance Records.
Download and complete these templates, then upload via the Evidence Upload form. Download links expire in 15 minutes — click the Templates tab to refresh.
How to use the CMMC Level 1 Assessment Workbook
- Download the workbook below and open it in Excel.
- Client_Info tab — fill in Client Name, CAGE Code, Assessor Name, Assessment Date, and FCI Systems in Scope.
- Domain tabs (AC, IA, MP, PE, SC, SI) — for each of the 15 requirements, set the Finding dropdown (MET / NOT MET / N/A), enter the Evidence File Reference (filename or path), and add Evidence Notes explaining what was reviewed.
- Summary tab — auto-calculates from the domain tabs; review before uploading.
- Upload the completed workbook via the Evidence Upload form: select as the environment (this client's CMMC-L1 environment — do not select a different client's environment) and CMMC-L1 Assessment Workbook as the document type.
The parser maps each row to its control in the NSANE database — do not rename tabs or rearrange rows.
Download links expire in 15 minutes. Click the Templates tab again to refresh.
Uploaded Evidence Files
All evidence files uploaded for this environment. Delete misloaded files or correct metadata.
| File | |
|---|---|
|
Archived
|
|
Delete Evidence File
This evidence file and all associated parsed data will be permanently deleted and cannot be recovered.
This archived governance document and its source file will be permanently deleted. This action cannot be undone.
Edit Evidence File
Compliance Event Records
Log workforce, security, and technical compliance events (G-Records). These records provide HIPAA evidence and are retained as audit artifacts.
| Added | ||
|---|---|---|
Delete Record
Delete this entry? This cannot be undone.
Assessment History
All CMMC Level 1 assessment workbooks uploaded for this environment. Click View Findings to inspect any historical assessment.
| Assessment File | |
|---|---|
Assessment Findings
| Control | Finding |
|---|---|
Log a new compliance event record
Subcontractor Flow-Down Tracking
| Vendor Name | CAGE Code | Contract Ref | CMMC Level | Flow-Down Status | Last Verified | Notes | Actions |
|---|---|---|---|---|---|---|---|
| — |
|
CMMC L1 Compliance Checklist
FAR 52.204-21 flow-downPrimary Contact
Delete Vendor?
Remove from the vendor list? This cannot be undone.
Third-Party Vendors
| Name | Service | Data Scope | Agreement Signed | Next Review | Risk | Status | Actions |
|---|---|---|---|---|---|---|---|
| Not assessed |
Manage Documents |
Please describe in the Notes field below.
Annual BA Assessment
Breach / Incident Notification
Archive Vendor
This vendor will be removed from the BA Management list. Assessment history and incident records are retained in the database.
Delete Document
This document will be permanently deleted from S3 and removed from the vendor record. This action cannot be undone.