CMMC L2 · NIST SP 800-171 · DFARS 252.204-7012

Defensible CMMC self‑assessments, at scale.

Qualense helps consultants and organizations organize approved evidence, review cited mapping suggestions, maintain assessment working records, and generate supporting NIST SP 800-171 deliverables.

Evidence → Verdictlive trace
SSP §3.5 excerptokta_policy.csvvpn_mfa_config.txt3.5.3MultifactorAuthentication3 citations attachedRULES ENGINER1R3R6R9MET · 3 cites−203SPRS SCORE−203+110
The problem

Manual evidence review becomes difficult to trace across clients and reviewers.

Qualense keeps approved evidence, cited suggestions, human decisions, assessment state, and supported exports connected so reviewers can inspect how a working result was produced.

500

files supported in one upload batch, subject to plan and environment limits.

100 MB

maximum supported size for an individual evidence file.

4

individual working deliverables in the current export package.

The pipeline

Four stages. Each one reviewable.

01

Evidence intake

Authorized users upload approved non-CUI, native-text evidence. File, malware, secret-pattern, and CUI-marking checks support — but do not replace — customer classification. Images and scanned files are not currently processed.

02

Cited mapping suggestions

Qualense proposes evidence-to-objective mappings with source excerpts. Reviewers inspect the citation and accept, reject, or request more evidence.

03

Deterministic assessment rules

Rules evaluate approved assessment state for conditions such as evidence quality, scope, conflicts, and selected scoring requirements.

04

Working deliverables

Generate a gap report, POA&M workbook, supporting SPRS summary, evidence index, or a ZIP containing those four outputs.

110maximum supporting score before deductions
R1–R9implemented assessment rule families
4individual working deliverables
2workspace roles: Member and Admin
Who it’s for

Built for the people who do this for a living.

Consultants / RPOs

Organized review per analyst

Bring intake, cited suggestions, reviewer decisions, gaps, and supported exports into one engagement workflow.

MSPs / MSSPs

Compliance as a product line

Organize CMMC self-assessment support across recurring engagements, with supported exports carrying your configured firm branding.

Primes

Evidence-backed visibility

Review subcontractor-provided evidence and supporting self-assessment results without treating them as an independent certification.

What changed · July 2026

Phase 2 is paused. The liability isn’t.

On July 13, 2026, DoD announced suspension of CMMC Phase 2 and later implementation milestones while Phase 1 self-assessment and underlying NIST/DFARS obligations remained. Customers should verify their current solicitation, contract, clauses, and DoD guidance.

STILL LAWDFARS 252.204-7012 and the NIST SP 800-171 requirements remain in force.
CONTRACT-SPECIFICSPRS and affirmation duties depend on the current solicitation, contract, clauses, and DoD guidance.
CUSTOMER-OWNEDThe customer validates scope, evidence, determinations, score, and any government submission.
QUALENSE ROLEOrganize evidence and review history so qualified people can make and support their decisions.

Bring evidence review into one traceable workflow.

Tell us about your assessment workflow and we will walk you through the current evidence, review, and deliverables experience.

Request a walkthrough