C3PAO Submission Pack Builder

    One click to compile your current Athena data into a sealed, hash-manifested bundle a C3PAO can upload to eMASS. Hashing is SHA-256 per the DoD CMMC Assessment Artifact Hashing Guide.

    Live

    Submission-ready for Level 2 Conditional

    SPRS-equivalent score95 / 110 (86.4%) — floor 80%

    No prohibited items on POA&M. Six L2 requirements remain gated: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5.

    POA&M items must be closed within 180 days of the CMMC Status Date.

    What's in the bundle

    Renderers are pure functions; every file is deterministically ordered so the log-hash is reproducible.

    • pre-assessment.jsoneMASS Pre-Assessment payload (Step 2 upload)
    • assessment-results.jsoneMASS Assessment Results payload (Step 5 upload)
    • ao-matrix.csvOne row per assessment objective with method, status, evidence
    • poam.csvPOA&M items — eligibility-gated per §170.21
    • sprs-entry.csvSPRS entry worksheet (PIEE / DFARS 7020 email)
    • evidence/index.csvEvidence artifact registry with hashes
    • CMMCAssessmentArtifacts.logSHA-256 of every file in the bundle (deterministic order)
    • CMMCAssessmentLogHash.logSHA-256 of the artifact log (the integrity hash to share with QA)
    • bundle-manifest.jsonAthena-internal manifest: bundle id, model version, signing info
    • README.txtWhat each file is + 6-year retention notice
    Ready to seal
    Bundle kind:
    submission