One Platform forComplete Compliance Readiness

CMMC doesn't just require an assessment; it requires controlled policies, a scoped asset inventory, an SSP, and evidence your assessor can review. Gray Warden delivers all of it in one integrated platform, included in every plan.

Gray Warden tenant dashboard showing active binders, frameworks tracked, users, privileged role holders, a binder overview, a user-breakdown chart, and a recent-changes activity feed

Compliance Manager

Manage framework assessments, evidence collection, POA&M tracking, SPRS scoring, and your assessor's review from a single dashboard. Included in every plan.

Objective-Level Self-Assessments

Work through all 110 NIST 800-171 requirements at the same level of detail your assessor will use: the individual NIST 800-171A assessment objectives behind each requirement.

  • Assessment-objective tracking (Met / Partially Met / Unmet)
  • Plain-English explanations for every control
  • Method of Compliance documented per control
  • Control ownership and assignment

SSP & POA&M Generation

Your System Security Plan and POA&M are built as you complete assessments, then exported in the formats DoD reviewers expect, with your system diagrams embedded in the SSP.

  • SSP export to Word with embedded network & data-flow diagrams
  • POA&M export to Excel for external reporting
  • Evidence packages exported as ZIP with manifest
  • Report history: re-download any prior export

SPRS Scoring & Progress Tracking

Your SPRS score is computed continuously using the DoD Assessment Methodology's weighted 110-point scale, so you see exactly where you stand and which gaps cost you the most points.

  • SPRS score with per-control deduction weights
  • Overall compliance score and control-by-control status
  • Family-level progress views
  • Expiring evidence and open POA&M surfaced on the dashboard

Evidence Management

Organize and store your compliance evidence in one secure place. Link evidence to specific controls and never scramble before an audit again.

  • Evidence linked to specific assessment objectives
  • Every upload scanned for malware before it's accepted
  • Expiration dates tracked so stale evidence gets flagged
  • Secure storage with API-streamed downloads

POA&M Tracking

Close compliance gaps with Plans of Action & Milestones. Track deadlines, ownership, and progress on every unmet control.

  • POA&M creation and tracking
  • Milestone deadlines and ownership
  • Priority, impact, and effort scoring
  • Unmet controls surfaced automatically

Framework Crosswalks

Map controls across multiple frameworks automatically. Satisfy one control and see how it maps to requirements in other standards.

  • Curated mappings across CMMC, 800-171, 800-53, and ISO 27001
  • Satisfy a control once, see it reflected everywhere
  • Reduce duplicate work across frameworks
  • Unified view of overlapping requirements

Assessor & Auditor Portal

Invite your C3PAO or internal auditor into a read-only portal scoped to the engagement. They review controls, evidence, POA&M, and your SSP in one place, with no more emailing folders.

  • Time-boxed engagements with scoped, read-only access
  • MFA enforced for every external auditor
  • Credentials expire automatically when the engagement ends
  • Complete access log of everything your assessor viewed

Custom Frameworks

Track requirements beyond published standards. Clone a base framework or start from scratch, then build your own control families, controls, and objectives, assessed with the same workflow.

  • Clone an existing framework or start from a blank template
  • Author your own families, controls, and objectives
  • Track prime flow-down or internal requirements
  • Same evidence and assessment workflow as published frameworks

Asset Management

Track hardware assets, software licenses, and disposal records throughout their lifecycle, and turn your inventory into an assessment-ready CMMC scoping report. Included in every plan.

Compliance context: NIST 800-171 requires organizations to track and manage all CUI-processing assets. Requirements like 3.4.1 (system inventory), 3.4.2 (security configurations), and 3.8.3 (media sanitization) demand a system of record for hardware and software assets, and CMMC assessments begin with asset scoping.

Hardware Asset Lifecycle

Track hardware assets from procurement through deployment, maintenance, and disposal with full lifecycle visibility.

  • Procurement to disposal tracking
  • Deployment and location management
  • Maintenance scheduling and history
  • Asset assignment to users and locations

CMMC Scoping & Asset Categorization

Your asset inventory becomes your CMMC scoping worksheet. Classify every asset into the official CMMC asset classes and export an assessment-ready scoping report.

  • The five official CMMC asset classes: CUI, Security Protection, Contractor Risk-Managed, Specialized, Out-of-Scope
  • Data classification (CUI / FCI / Internal / Public) per asset
  • Scoping reports exported to Excel or PDF
  • Inventory-gap warnings before your assessment, not during it

Data Wipe & Disposal Tracking

Document media sanitization and asset disposal with certificates that directly satisfy NIST 800-171 3.8.3 requirements.

  • Data wipe certification records
  • NIST 800-171 3.8.3 compliance
  • Disposal method documentation
  • Chain of custody tracking

Software License Management

Track software licenses, monitor seat allocation, and maintain compliance with licensing agreements across your organization.

  • License inventory and tracking
  • Seat allocation and utilization
  • Expiration and renewal alerts
  • License compliance monitoring

License Contract Management

Manage software license contracts with renewal tracking, cost analysis, and vendor relationship oversight in one place.

  • Contract lifecycle management
  • Renewal date tracking and alerts
  • Cost tracking and analysis
  • Vendor management

Custom Fields & Categories

Configure asset tracking to match your organization's specific needs with custom fields, categories, and classification schemes.

  • Tenant-specific asset configurations
  • Custom field definitions
  • Flexible categorization schemes
  • CSV import with validation, Excel export
Gray Warden CMMC scoping report showing assets by CMMC category and data classification, with inventory-gap warnings and Excel/PDF export

The CMMC scoping report: an assessment-ready view of where controlled data lives, with gap warnings before your assessor finds them.

Business Process System

Control the lifecycle of policies, procedures, and operational documents, from draft through review, publication, and employee acknowledgement. Included in every plan.

Compliance context: Nearly every NIST 800-171 control family requires documented policies and procedures. Gray Warden closes the loop: the same controlled document that your team reviews and your staff acknowledges also maps into your SSP as evidence.

Document Lifecycle Management

Manage documents through their full lifecycle from draft to effective to retired, with clear status tracking at every stage.

  • Draft, Review, Effective, Retired states
  • Clear status tracking at every stage
  • Automated state transitions
  • Complete lifecycle audit trail

Version Control & History

Track every change with major and minor versioning. Maintain a complete history of document revisions with change tracking.

  • Major and minor version numbering
  • Complete revision history
  • Word tracked changes and redline artifacts preserved
  • Download any prior version

Review & Approval Workflows

Configure multi-organization review cycles with customizable review periods. Ensure documents are properly reviewed before becoming effective.

  • Multi-organization review cycles
  • Configurable review periods
  • Approval tracking and sign-off
  • Automated review reminders

Document Numbering & Categorization

Organize documents with auto-sequencing numbers and categorization by organization, type, and function.

  • Auto-sequencing document numbers
  • Organizational structure mapping
  • Document type categorization
  • Hierarchical document organization

SSP Locker

Your SSP assembly line. Map controlled documents and system diagrams to the controls they satisfy, see exactly what's missing per control, and export a complete SSP.

  • Policies and diagrams mapped to the controls they satisfy
  • Per-document status: Missing, Uploaded, Validated
  • Controlled documents double as SSP evidence: one artifact, two jobs
  • One-click SSP export to Word with diagrams embedded

Employee Acknowledgements

Publish a policy and require staff to read and acknowledge it. Acknowledgements are tracked per version, per organization, a living evidence trail for awareness requirements.

  • Per-organization notify or acknowledge requirements at publish
  • Version-keyed: a new revision re-opens the requirement
  • Per-user, per-document acknowledgement tracking
  • Supports NIST 800-171 3.2.x awareness & training evidence

Employee Document Portal

Every employee gets a company document portal: search, read, and acknowledge published policies without needing a seat in any module. Compliance reaches your whole workforce.

  • Free for every employee, no module seat required
  • Search and filter published documents by category and type
  • Pending acknowledgements pinned front and center
  • Per-document visibility controls what each person can read

Platform Capabilities

Cross-cutting capabilities that power every module: security, collaboration, dashboards, and multi-framework support.

Team Collaboration

Compliance is a team sport. Assign controls to team members, track who's responsible for what, and keep everyone aligned.

  • Role-based access control
  • Task assignment by control
  • Activity tracking and audit log
  • Unlimited team members on every plan

Enterprise-Grade Security

Your compliance data deserves the best protection. Gray Warden is built with security-first architecture to protect sensitive information.

  • Multi-factor authentication included on every plan
  • Data protected with FIPS 140-3 validated encryption, in transit and at rest (AES-256)
  • Tenant data isolation with three-layer access control
  • SAML 2.0 SSO with just-in-time provisioning (Enterprise)
  • Keysafe: manage your own encryption keys for data at rest (Enterprise, coming soon)

Role-Based Dashboards

Four purpose-built dashboards give every team member the view they need: Tenant overview, Compliance status, BPS activity, and personal task tracking.

  • Tenant-wide overview dashboard
  • Compliance-focused dashboard
  • Business Process System dashboard
  • Personal task dashboard

Activity Audit Trail

Every action is logged. Maintain a complete, searchable record of all platform activity for internal reviews and external audits.

  • Complete action logging
  • User activity tracking
  • Searchable audit records
  • IP and user-agent captured per action

Multi-Framework Support

Support for the compliance frameworks that matter most to DIB suppliers, with crosswalk mapping between them, plus custom frameworks you author yourself.

  • CMMC 2.0 Level 1 & Level 2, NIST 800-171 + 800-171A
  • NIST 800-53, NIST 800-161, NIST CSF 2.0
  • ISO 27001 and UK Cyber Essentials
  • Custom frameworks for prime flow-down requirements

Note: Gray Warden does not offer legal advice or attempt to interpret regulations. You remain responsible for determining how compliance requirements apply to your organization and for engaging a qualified assessor for official certification.

Frameworks We Support

Gray Warden covers the compliance frameworks that matter most to DIB suppliers, with crosswalk mapping between them. Framework coverage varies by plan; every plan includes full CMMC 2.0 and NIST 800-171 support.

CMMC 2.0

Full support for Level 1 & Level 2

NIST 800-171

All 110 requirements, assessed at the 800-171A objective level

NIST 800-53

Comprehensive security control catalog

DFARS 252.204-7012

The standing obligation to safeguard CUI, in force regardless of the CMMC timeline

ISO 27001

International information security standard

NIST CSF 2.0

Cybersecurity Framework for risk-based programs

NIST 800-161

Supply chain risk management

Custom Frameworks

Author your own: prime flow-downs, internal standards, and more

See the Full Platform in Action

Start your free trial and experience how Gray Warden brings compliance, asset management, and document control together in one platform.