ALC - Ascera

test

Posts about Blog:

Is Excel Slowing Down Your CMMC Program?

Is Excel Slowing Down Your CMMC Program?

If you manage CMMC compliance, there's a good chance Excel is somewhere in your process.

This is understandable. Spreadsheets are familiar. They're flexible. They don't require a lengthy onboarding process, and nearly everyone on your team already knows how to use one. When organizations first start tackling CMMC or NIST 800-171 compliance, Excel often becomes the default tool for tracking controls, logging evidence, and monitoring status. And in the early stages, it actually works.

But as your compliance program grows, so do its demands — and that's where Excel starts to show its limits.

What Excel Gets Right

Before we talk about the problems, let's give credit where it's due. Excel has earned its place in the CMMC world for a reason.

It's customizable, widely accessible, and requires no vendor relationship or licensing complexity. Teams can build their own control trackers, color-code compliance statuses, and generate reports that look exactly the way they want them to. For organizations just beginning their CMMC journey, a well-built spreadsheet can provide a useful snapshot of where things stand.

That visibility — even if manual — is genuinely valuable. The impulse to reach for Excel makes sense.

Where Excel Falls Short

The problem isn't that Excel is a bad tool. The problem is that compliance — especially CMMC and NIST 800-171 — has outgrown what any spreadsheet can realistically handle.

You're constantly re-entering the same information

With 110 controls across NIST 800-171, teams spend enormous time copying and pasting the same implementation statements, notes, and evidence references into multiple places. One update often means updating a dozen cells across several tabs or documents — and hoping nothing gets missed.

Spreadsheets offer no guidance

Excel can tell you a control is "Not Met," but it can't tell you what "Met" actually looks like, what evidence an assessor will expect, or how one control relates to another. Teams are left to figure that out on their own, often learning the hard way during an assessment.

Human error is inevitable

Manual data entry means manual mistakes. A miscategorized control, an outdated status, a missed cell — any one of these can misrepresent where you actually stand.

Spreadsheets go stale the moment you close them

Your CMMC status isn't static. The second a user changes a setting, a patch fails to apply, or a new device connects to your network, your actual compliance posture shifts — and your spreadsheet has no way of knowing. It only reflects the last time someone updated it.

Evidence collection is a full-time job

For a CMMC Level 2 assessment, you need proof for all 110 controls. That means pulling data from systems, interviewing stakeholders, documenting configurations, and uploading files. Excel can track it, but it can't do it.

−113
Average point drop between self-assessment and official DIBCAC review Some of that gap comes from spreadsheets giving teams false confidence about where they actually stand.

What ASCERA Does Differently

ASCERA was built to solve exactly these problems. And because every organization's compliance journey looks a little different, ASCERA offers three tiers — each one a meaningful step beyond what Excel can provide.

ASCERA
CUIComply

Purpose-built for CMMC. It eliminates the copy-paste grind by letting you enter information once and automatically mapping it across all 110 controls. Generates System Security Plans (SSPs) automatically, tracks your SPRS score over time with a color-coded dashboard, and includes assessor-created video explanations for every control. If Excel is a blank canvas, CUIComply is a structured, guided workflow designed specifically for CMMC.

ASCERA
Advanced

Builds on everything in CUIComply and extends it across multiple DoD security frameworks within a single platform. For organizations managing more than just NIST 800-171, or RPOs supporting clients across several frameworks, ASCERA Advanced eliminates the need for separate spreadsheets per requirement set. Upload evidence once, and it automatically maps across every applicable control in every framework you're tracking.

ASCERA
ConMon

Adds automated evidence collection and continuous controls monitoring. ConMon pulls system data directly from your environment, compares it against NIST standards and your own security policies, and flags the moment a control shifts from Met to Not Met. For teams that need to maintain and defend compliance continuously, ConMon is the answer.

There's a Tier for Where You're At

Not every organization needs the same solution on day one. What matters is that no matter where you are in your compliance journey — just getting started with CMMC, managing multiple frameworks, or maintaining continuous readiness — there's an ASCERA tier designed for that stage. And every tier is a significant improvement over managing compliance in a spreadsheet.

Excel will always have a place on your desktop. But your compliance program deserves a purpose-built platform.

Ready to see how ASCERA fits your organization?

Get a personalized walkthrough and see how it maps to your current compliance program.

Schedule a Free Demo →

Customer Interview: Shifting from Point-in-Time CMMC Compliance to ConMon

Customer Interview: Shifting from Point-in-Time CMMC Compliance to ConMon

As organizations across the Defense Industrial Base (DIB) work toward CMMC certification, many struggle to keep compliance programs current without relying on tedious manual tracking and spreadsheets. 

MRIGlobal — a scientific research organization supporting U.S. Government defense and national security missions — faced similar challenges. While the organization could meet requirements, its existing approach made it harder to maintain visibility and confidence as expectations increased. 

That changed after adopting ASCERA. Time spent managing scattered documentation was reduced, and the team could focus more directly on control implementation and assessment readiness. 

This interview highlights how ASCERA’s centralized Cyber GRC platform simplified MRIGlobal’s CMMC efforts through structured evidence management, continuous controls monitoring (ConMon), enhanced visibility, and more. 

Background Overview 

What types of contracts or work does your organization handle within the Defense Industrial Base (DIB)?

MRIGlobal operates within the Defense Industrial Base primarily as a scientific research, development, test, and evaluation (RDT&E) organization supporting U.S. Government defense and national security missions.

Our work is largely focused on chemical, biological, radiological, nuclear, and explosive (CBRNE) defense, including threat detection, diagnostics, biosurveillance, and warfighter protection technologies. We support the Department of Defense and related agencies through applied research, independent laboratory testing, system evaluation, and advanced analytics that inform operational and acquisition decisions.

MRIGlobal also designs and supports deployable and mobile laboratory capabilities, provides unbiased scientific assessments, and executes mission-aligned research under established federal contract vehicles. Overall, our role in the DIB is that of a trusted, non-profit scientific partner delivering objective, high-consequence technical solutions in support of defense readiness and national security.

Before ASCERA, how were you managing your CMMC or cybersecurity compliance requirements?

Before ASCERA, our CMMC and broader cybersecurity compliance efforts were managed through a combination of internally developed processes, policy documents, spreadsheets, and shared repositories. We relied heavily on manual control tracking, narrative documentation, and point-in-time evidence collection to support assessments and audits.

While this approach allowed us to remain compliant, it required significant coordination and discipline to maintain consistency, version control, and visibility across control families, enclaves, and stakeholders. Preparing for CMMC Level 2 amplified those challenges, as the need for structured traceability, repeatability, and ongoing readiness increased substantially. We recognized that sustaining compliance at scale would require moving beyond ad-hoc tools toward a more centralized, purpose-built platform.

Challenges Before ASCERA 

What challenges or pain points were you facing prior to using ASCERA? 

Prior to using ASCERA, our primary challenges centered around scale, visibility, and sustainability. Managing CMMC-aligned controls across multiple environments required extensive manual effort to track implementation status, maintain supporting evidence, and ensure documentation remained current and consistent. In other words, spreadsheet nightmares!

Evidence collection and validation were largely point-in-time activities, which made it difficult to maintain continuous awareness of control effectiveness. Additionally, mapping controls to policies, procedures, and technical artifacts required careful coordination and introduced risk around version control and traceability.

As we prepared for CMMC Level 2, it became clear that relying on spreadsheets and distributed documentation increased the operational burden on the team and limited our ability to quickly assess gaps, demonstrate maturity, or pivot as requirements evolved.

How were these challenges impacting your organization’s ability to stay compliant or prepare for CMMC certification?

These challenges didn’t prevent us from meeting requirements, but they did introduce inefficiencies and risk as we moved toward CMMC Level 2. A manual, point-in-time approach to compliance made it harder to quickly assess our readiness posture, prioritize remediation efforts, or confidently demonstrate consistency across control families.

As expectations around evidence quality, traceability, and repeatability increased, more time was spent validating documentation and reconciling artifacts rather than focusing on risk reduction and control improvement. Preparing for certification required significant effort to ensure accuracy and alignment, and it became clear that sustaining compliance over time would be increasingly resource-intensive without a centralized system to support continuous readiness.

The challenge wasn’t achieving compliance — it was sustaining confidence and readiness as the rigor of CMMC Level 2 increased.

Why You Chose ASCERA

What stood out to you about ASCERA compared to other solutions you evaluated?

What stood out about ASCERA was that it was clearly built with the right functionality at its core. The platform isn’t surface-level or cosmetic — it’s designed to directly support the intent of NIST 800-171 and the realities of maintaining compliance over time.

Rather than focusing on static, point-in-time assessments that begin to age the moment they’re completed, ASCERA’s Cyber GRC is structured around continuous visibility and control alignment. Each control is mapped in a way that supports ongoing validation, evidence traceability, and day-to-day operational use, which is exactly what CMMC Level 2 demands.

That depth and intentionality set ASCERA apart. It was evident that the platform was purpose-built to help organizations sustain compliance in real time, not just prepare for an audit.

Your Experience Using ASCERA

How has ASCERA helped you simplify or accelerate your CMMC compliance efforts?

ASCERA has simplified our CMMC compliance efforts by centralizing control management, documentation, and evidence into a single, structured Cyber GRC platform. Instead of coordinating across multiple tools and repositories, our team can quickly understand the status of each control, identify gaps, and see how policies, procedures, and technical evidence align.

From an acceleration standpoint, ASCERA reduces the time spent on manual tracking and reconciliation, allowing the team to focus on control implementation and risk reduction rather than administrative overhead. The platform enables us to move more efficiently from assessment to remediation, while maintaining confidence that documentation and evidence remain current and defensible.

Most importantly, ASCERA supports a continuous-readiness mindset. That shift has made preparation for CMMC Level 2 more predictable, repeatable, and sustainable over time.

ASCERA shifted us from managing compliance as an event to operating in a state of continuous readiness.

What specific features or capabilities have been the most valuable for your team? (e.g., Continuous Controls Monitoring (ConMon), POA&M tracking, automated evidence collection, policy mapping, reporting dashboard, etc.).

One of ASCERA’s most valuable features is its control matrix, which we often joke looks like a scientific periodic table of evidence. That visual structure makes it easy to understand the status of each NIST 800-171 control and easy to navigate about the platform, which is incredibly helpful for both day-to-day operations and assessment preparation.

ASCERA’s ability to catalog, identify, and manage evidence has also been a major strength. In some cases, the platform itself becomes part of the evidence simply by using it to support and document control implementation. Beyond that, the built-in evidence repository makes it easy to upload, organize, and maintain artifacts in a centralized and defensible way.

When it came time to submit our body of evidence to our C3PAO assessor, ASCERA’s custom export capability was a standout. The platform generated a structured export with evidence organized by control in a single package, which significantly streamlined the review process. In fact, our assessor specifically commented on how easy the body of evidence was to navigate.

How has ASCERA improved your visibility into compliance or risk posture?

ASCERA has significantly improved our visibility into compliance by providing a real-time, centralized view of control implementation, evidence status, and risk areas. Instead of relying on fragmented updates or manual rollups, we can quickly understand where we stand across NIST 800-171 control families at any given time through ConMon.

From a risk perspective, the platform allows us to identify gaps earlier, track remediation efforts through POA&Ms, and prioritize work based on impact and maturity. That level of visibility enables more informed decision-making and reduces uncertainty as we prepare for assessments.

Perhaps most importantly, ASCERA provides confidence. It allows us to move from reactive compliance management to proactive oversight, ensuring we maintain awareness of our posture rather than discovering issues late in the process.

Have you seen measurable results or improvements since implementing ASCERA? (Examples: reduced audit prep time, better documentation, faster gap closure, etc.).

Yes, we’ve seen clear and measurable improvements since implementing ASCERA, particularly in how efficiently we prepare for assessments and manage documentation. The time and effort required to validate evidence, confirm control alignment, and assess readiness has been significantly reduced.

Documentation quality and consistency have improved as well. With controls, policies, and evidence managed in a centralized platform, we spend less time reconciling artifacts and more time closing gaps and strengthening implementations.

ASCERA has reduced the overall friction associated with audit preparation. Readiness activities are more predictable, progress is easier to track, and the team can approach assessments with greater confidence and less last-minute effort.

Partnership and Support Experience

How would you describe your experience working with the ASCERA team?

Working with the ASCERA team has been an extremely positive experience. They bring a deep level of expertise around CUI and CMMC requirements, but they communicate it in a way that is patient, practical, and approachable. At times, the experience feels less like working with a vendor and more like collaborating with professors who genuinely want to teach, mentor, and see you succeed.

What’s been especially valuable is their continued engagement even after certification. The team remains invested in helping us maintain our posture, refine our processes, and ensure that compliance is sustained over time rather than treated as a one-time achievement. That ongoing partnership has reinforced confidence and kept us moving forward in the right direction.

How responsive or helpful has our customer support been when you’ve had questions or requests?

ASCERA’s customer support has been consistently responsive and highly effective. Questions are addressed promptly, and when deeper discussion is needed, the team takes the time to ensure we fully understand both the issue and the solution.

Support interactions feel collaborative rather than transactional, and the guidance provided is always grounded in a strong understanding of CMMC and CUI requirements. We’ve had zero concerns regarding responsiveness or helpfulness, which has made a meaningful difference throughout the compliance process.

How do you feel about the way ASCERA listens to customers and evolves the product?

ASCERA does an excellent job of actively listening to its customers and incorporating real-world feedback into the platform. We have recurring meetings with the ASCERA team where we can openly discuss user experience, functionality, and feature ideas, and those conversations routinely translate into meaningful product improvements.

That collaborative approach reinforces confidence that ASCERA is evolving alongside its customers and staying aligned with the needs of organizations operating within the Defense Industrial Base.

Impact and Outcomes

What impact has ASCERA had on your overall compliance process or confidence heading into CMMC certification?

ASCERA has fundamentally changed how we approach compliance and readiness. The evolution it has enabled in our compliance capabilities is comparable to the shift from pen and paper to modern, intelligent tooling. It’s not just faster, but categorically more effective.

Heading into CMMC certification, ASCERA provided a level of confidence that came from knowing our controls, evidence, and documentation were aligned, current, and defensible. Compliance stopped being something we prepared for and became something we actively maintained.

 

Looking Ahead

How do you see ASCERA fitting into your long-term compliance and cybersecurity strategy?

ASCERA is now a foundational component of our long-term compliance and cybersecurity strategy. We have leveled up our cybersecurity capabilities for the organization with ASCERA and it supports how we continuously manage, monitor, and mature our security posture over time.

From a strategic standpoint, ASCERA helps ensure that compliance scales with the organization and remains aligned with mission delivery. It allows us to move forward with confidence, knowing that our approach to CMMC and cybersecurity is durable, defensible, and built for the long term.

Can you share a short story or example of a time ASCERA made a big difference for your team? 

 

The technology itself is excellent, and ASCERA has proven to be one of the best investments I’ve made as Director of Cybersecurity at MRIGlobal. But for me and my team, that’s not the biggest difference.

 

The real difference has been the people behind the platform. The ASCERA team has consistently shown up as true partners — working alongside us, ensuring expectations were met, and helping us prepare thoroughly for our assessment. They were willing to comb through large volumes of evidence with us, validate that every detail was addressed, and take the time to walk through controls repeatedly until everything was clearly understood.

 

That level of commitment, patience, and shared ownership is what ultimately made the difference. It wasn’t just about using a tool — it was about having experienced professionals on our side who were genuinely invested in our success.

 

If you had to describe ASCERA in one sentence to another organization, what would you say? 

ASCERA turns CMMC compliance from a point-in-time exercise into a sustainable, continuously managed discipline.

Which ASCERA Tier is Right for You?

Which ASCERA Tier is Right for You?

Choosing the right CMMC software can be a challenge.

With compliance needs varying from one organization to the next, it’s easy to end up with a tool that’s either too lightweight or far more complex than you actually need. What works for a small organization preparing for CMMC, for instance, looks very different from what a larger DIB organization needs to maintain ongoing compliance with multiple security frameworks. 

ASCERA was built to scale with you. From organizations focused solely on CMMC to teams managing multiple frameworks and continuous monitoring, each ASCERA tier is designed to meet your organization where it’s at. 

To help you quickly identify the best fit, we put together a short quiz below. Answer a few questions about your organization, your environment, and your compliance goals, and we’ll point you to the ASCERA tier that aligns best with where you are today. 

Checklist: How to Evaluate an AI Tool for CMMC

Checklist: How to Evaluate an AI Tool for CMMC

Every GRC tool is now boasting AI functionality, but what exactly does this mean? And how can you evaluate one tool against another? 

This checklist gives you the key questions to ask when evaluating an AI tool for CMMC, so you can separate hype from software that will actually help you pass your C3PAO assessment. 

 

What is AI for CMMC? 

 

AI for CMMC can include any artificial intelligence feature that uses machine learning, natural language processing, or other automated intelligence to help with compliance tasks. 

One of the most common forms of AI for CMMC is a chat-based AI assistant that lets you type a question and get an instant answer. In a compliance context, that might mean asking for a plain-language explanation of a control, drafting an implementation statement, or clarifying which evidence to submit. 

But not all of these tools are created equal. Some are built on generic internet data and offer advice that’s outdated or inaccurate. Others don’t protect your CUI or integrate with your existing workflows, which can create new risks instead of reducing them. 

Keep reading for a closer look at how to evaluate AI tools for CMMC so you can reduce risk  and get the best return on your investment.

How to Evaluate an AI Tool for CMMC: 7 Key Factors

 

1. Data Security

 

Question to ask: How does the tool handle sensitive information? 

CMMC involves Controlled Unclassified Information (CUI), which must be protected at all times. Uploading parts of your SSP, logs, or evidence into a public AI model is a compliance risk in itself. A trustworthy tool will have a layered defense strategy, combining multiple security measures — such as access control, encryption, monitoring, and user training — to ensure the confidentiality, integrity, and availability of your data. The tool’s website should clearly spell out how your data is stored and processed.

Look for: 

  • Assurances that data is never sent to public AI models or used for training 
  • Encryption in transit and at rest 
  • Hosting options that meet government security standards, like AWS GovCloud 
  • Clear documentation on how prompts and outputs are handled

 

2. CMMC Training

 

Question to ask: Is the AI trained specifically on CMMC/NIST data? 

Generic AI tools are trained on broad internet data, which means they can pull in outdated or unverified information. They can also “hallucinate,” giving responses that sound plausible but aren’t accurate. A reliable CMMC AI tool should be built on expert-vetted content and clearly disclose its sources. 

Look for: 

  • AI models trained specifically on CMMC and NIST 800-171 content 
  • Disclosure of what sources the model draws from 
  • Assurance that the materials used for training were chosen by CMMC experts 

3. Seamless Integration & Grounding

 

Question to ask: Does the AI tool integrate with your compliance data and ground into your environment?

An AI assistant isn’t useful if you have to constantly copy and paste material into a chat box or if it sits outside your everyday processes. The best tools allow you to workshop your own SSPs, POA&Ms, and implementation statements in real time — securely, without leaving your environment — while presenting an intuitive interface your team will actually want to use. 

An AI tool should be grounded in context. This means that when users ask a question, the tool uses techniques like Retrieval Augmented Generation (RAG) to automatically retrieve the relevant policies, parameters, and live operational data to return an answer tailored to the user’s environment. Here’s a deeper look at RAG in CMMC AI tools.

Look for: 

  • Ability to interact directly with your existing compliance documentation 
  • Secure, private processing of your data without exposing CUI externally 
  • A user-friendly interface that minimizes training and speeds adoption 
  • Integration with your existing compliance workflows  

4. Practical Value

 

 

Question to ask: What tasks does the AI actually make easier? 

AI should do more than rephrase definitions. The best tools help you move compliance work forward in concrete ways. 

Look for: 

  • Drafting implementation statements 
  • Identifying the right evidence for each control 
  • Clarifying overlapping requirements 
  • Breaking down complex controls into plain English 
  • Highlighting gaps in existing documentation 

5. Vendor Credibility

 

Question to ask: Was the AI tool created by people who actually know CMMC? 

A vendor’s credibility matters. Tools built by general software teams with no CMMC experience can miss key requirements or misinterpret controls. Look for a product team with assessor credentials, a history of working with DoD contractors, and a proven track record in compliance. 

Look for: 

  • Clear involvement of Certified CMMC Assessors or other recognized experts 
  • Published credentials or partnerships that show domain expertise 
  • References or case studies from organizations like yours 

6. Vendor Transparency

 

Question to ask: Does the vendor explain how their AI works? 

You don’t need a technical whitepaper, but you do need enough clarity to know the AI is built responsibly. Be cautious of vendors that market “black box” AI without explaining what sources it relies on. 

Look for: 

  • Clear explanation of data sources (preferably assessor-vetted) 
  • Details on where your data goes 
  • Commitment that customer prompts won’t be used to train public models 

7. Ability to Try a Demo

 

Question to ask: Can you request a demo or trial? 

A reputable vendor should be confident enough to let you see the tool in action with your own use cases. Demos or trial access give you a chance to test features, see how your data is handled, and evaluate the user experience before committing. 

Look for: 

  • The ability to book a live demo with product experts 
  • Trial environments or sandbox access 
  • Opportunities to test real CMMC scenarios 

Conclusion 

AI can be a game-changer for CMMC, but only if it’s secure, framework-aware, and built for assessment readiness. By asking the right questions up front, you can avoid the risks of public or generic AI tools and choose a platform that actually helps your team succeed. 

With ASCERA’s ComplyAI, you get an AI assistant designed exclusively for CMMC — secure by design, assessor-created, and practical for the real tasks contractors face every day. Try it for free to see if ComplyAI is right for you.

ASCERA Customer Interview: Replacing Spreadsheets with Continuous Monitoring for CMMC

ASCERA Customer Interview: Replacing Spreadsheets with Continuous Monitoring for CMMC

As organizations across the Defense Industrial Base (DIB) work toward CMMC certification, many face the same challenge: keeping their compliance programs accurate and up to date without drowning in spreadsheets and manual tracking.

One ASCERA customer — a cybersecurity and technology contractor supporting the Army, Air Force, SOCOM, and DIA — was no exception. The company faced a number of challenges that prevented them from confidently preparing for their C3PAO assessment.

After adopting ASCERA, however, the game changed. Less time was spent managing scattered documentation and outdated templates and instead actual progress toward control implementation was made.

This interview with the company’s CTO/CISO gives insight into how ASCERA’s automated evidence collection and continuous monitoring streamlined the company’s CMMC process.

Background Overview 

What types of contracts or work does your organization handle within the Defense Industrial Base (DIB)?

Our company operates in three value segments – Defense/Civilian, Health, and Clean Energy. Most of the DoD work is performed by the Defense/Civilian value segment but there is cross-over in the other two segments with DoD contracts.

Most of our DIB contracts are with the Army, Air Force, U.S. Special Operations Command (SOCOM), and Defense Intelligence Agency (DIA), where we provide unclassified and classified support specializing in enterprise IT modernization, cybersecurity, health IT, systems integration, and digital engineering. 

Before ASCERA, how were you managing your CMMC or cybersecurity compliance requirements?

I inherited an environment previously assessed against CMMC v1 by a consulting firm that produced an unrealistic SPRS score and relied on incomplete and inaccurate templates. We had separate ISO 27001 and CMMC documentation sets, an SSP lacking detail, and no continuous monitoring plan to sustain compliance. 

Challenges Before ASCERA 

What challenges or pain points were you facing prior to using ASCERA? 

Our challenges and pain points were:

  • Having separate documentation sets for ISO and CMMC compliance
  • Using a spreadsheet to track control compliance
  • An outdated SSP template in Word format
  • Cumbersome linking of evidence to assessment objectives
  • No executable continuous monitoring plan.

Our asset list was not accurate, assets were not categorized in accordance with the CMMC scoping guide, we hadn’t performed a scoping exercise to find our CUI data flows and were attempting to achieve compliance at the enterprise level at CMMC Level 1 where CMMC Level 2 made more sense with a separate enclave for the limited personnel handling CUI. 

How were these challenges impacting your organization’s ability to stay compliant or prepare for CMMC certification?

The SSP was not defendable, I had no confidence in our SPRS score, and we had limited activities planned to demonstrate the ability to sustain compliance. 

Why You Chose ASCERA

What stood out to you about ASCERA compared to other solutions you evaluated?

Many things stood out. When I evaluate solutions, I cast a wide net and schedule meetings and demonstrations with several vendors and follow the decision analysis and resolution process we developed through our CMMI compliance program.

ASCERA stood out because it focuses on solving one problem exceptionally well—automated evidence collection and continuous control monitoring. Unlike most tools that only evaluate configuration data, ASCERA analyzes log data to validate whether controls are truly met. That cross-check gave me confidence that when I marked a control ‘met,’ ASCERA would confirm it with real data. 

Your Experience Using ASCERA

How has ASCERA helped you simplify or accelerate your CMMC compliance efforts?

I spent much less time formatting my SSP and organizing evidence.

As my approach to writing policy, plan, and procedure documentation was to answer control implementation questions, I was able to very easily cut/paste content from my documents into ASCERA. I found it very intuitive to manage evidence by dragging/dropping files into the repository and tag them to a control family, control(s), or assessment objective(s). And when my C3PAO assessment was complete, I simply exported all the evidence from ASCERA, ran the hashing scripts, and provided the results to the assessors. 

What specific features or capabilities have been the most valuable for your team? (e.g., Continuous Controls Monitoring, POA&M tracking, automated evidence collection, policy mapping, reporting dashboard, etc.).

Both the ACE and CCM were the most valuable as these functions were continuously running while I worked on control implementation and I could see things go from red to green as compliant configurations were put in place and reflected in the logs analyzed by ASCERA.  

How has ASCERA improved your visibility into compliance or risk posture?

We incorporated viewing of the ASCERA “periodic table of controls” (the compliance view) into our weekly information security management system technical review meetings. ASCERA has become an integral part of our continuous monitoring solution supporting the RA (Risk Assessment) and CA (Security Assessment) control families. 

Have you seen measurable results or improvements since implementing ASCERA? (Examples: reduced audit prep time, better documentation, faster gap closure, etc.).

Using ASCERA to manage our SSP, POA&Ms, and evidence management reduced our audit preparation time and simplified our engagement with the C3PAO. ASCERA allowed us to simply enter our control implementation statements, attach evidence, and create POA&M items without having to deal with templates, document management, or any formatting issues.

By providing our C3PAO access to ASCERA, it freed us from having to send any documents to them and ensured they were always seeing the most up-to-date information.  

Partnership and Support Experience

How would you describe your experience working with the ASCERA team?

The ASCERA team has been a pleasure to work with. Everyone on the ASCERA team has been enthusiastic, responsive, and very collaborative in responding to any issues we reported and incorporating our feedback and feature requests.

I really enjoyed and appreciated the deeper technical discussions with the development team and compliance experts around the interpretation of control and assessment objective requirements and how ACE and CCM are implemented to evaluate criteria to ensure we can confidently say they are met or not met. 

How responsive or helpful has our customer support been when you’ve had questions or requests?

The customer support team has been very responsive. We had very few issues, but when reported they were corrected quickly. We submitted several feature requests, most of which were received positively and promptly implemented. 

How do you feel about the way ASCERA listens to customers and evolves the product?

We had very productive weekly sessions with the ASCERA team which not only helped us fully realize the benefit of the product but also helped everyone more thoroughly understand CMMC requirements and compliant control implementations. For anyone new to CMMC or not well-versed in compliance, I recommend engagement with the ASCERA professional services team for guidance. 

Impact and Outcomes

What impact has ASCERA had on your overall compliance process or confidence heading into CMMC certification?

As our assessment date approached, seeing a full set of green controls and a 110 score in ASCERA gave me complete confidence that our integrated ISO 27001:2022 and CMMC Level 2 ISMS would pass—and, more importantly, that it was sustainable through continuous monitoring. 

 

Looking Ahead

How do you see ASCERA fitting into your long-term compliance and cybersecurity strategy?

Now that we have a CMMC Level 2 compliant enclave, I’d like to use ASCERA to perform a CMMC Level 1 self-assessment of our enterprise environment. And if ASCERA continues to evolve to support other compliance frameworks, I’d like to use it for our next ISO 27001 assessment and internal audits.