Home / Products / Deka-Forge

Deka-Forge · CMMC engagement platform

Assessors don't check 110 boxes.
They assess 320 objectives.

Every requirement, every assessment objective, every piece of evidence, tracked in verbatim regulatory language, with a live SPRS score and an audit trail that holds up. Built by a CMMC Certified Professional, for Level 2 certification and Level 1 self-assessment work.

A 24-second tour: dashboard → controls → one objective → inheritance reality check → responsibility matrix. All screens show a fictional example engagement (“Northwind Defense Systems”): real product, invented data, no client information.

The premise

A requirement is only met when every objective under it is.

Most compliance tools track 110 requirements. Assessors don't. They assess 320 objectives, and a requirement is met only when every one of its objectives is. Deka-Forge is built on that reality.

Control text, objective text, and discussion sections are parsed verbatim from the official CMMC Assessment Guides, with programmatic count verification, so what you read in the app is what the assessor reads in the guide. On top of that sit scoping across the five asset categories, cloud-provider inheritance derived from real FedRAMP CRM workbooks, evidence with hashes and staleness tracking, a live SPRS score, and an append-only audit trail, for one engagement or for a whole book of clients.

What makes it different

Six things a spreadsheet cannot do.

Verbatim regulatory text

Control text, all 320 Level 2 objectives, all 59 Level 1 objectives, and the guides' Discussion sections are machine-parsed from the official CMMC Assessment Guide v2.13 PDFs. Parsers anchor exactly on control IDs, so 3.1.1 can never match 3.1.12, and they fail loudly unless the counts come out exactly right. Nothing is summarized, "improved," or rewritten.

Objective-level tracking with hard gates

Every objective carries its own status, owner, notes, implementation statement, and evidence. A requirement's status is derived from its objectives, never typed in, so a control cannot be marked done while an objective underneath it isn't. Marking an objective Met requires per-asset applicability decisions and implementation statements first.

Cloud inheritance that stays honest

Upload a provider's FedRAMP Appendix J CRM workbook, or paste rows for providers like Microsoft 365 GCC High that publish shared responsibility differently. Inheritance is derived per objective through the NIST SP 800-53 Rev 5 crosswalk, and every part of a control aggregates. Critically, inheritance never changes an objective's status: a provider's CRM is evidence to confirm, not an automatic pass.

A single assessment objective in Deka-Forge: the verbatim guide text for AC.L2-3.1.2 objective [a], its Met status, owner, and the approval stamp recording who approved it and when.
One objective, in the guide's own words: status, owner, implementation statement, and the approval stamp.

"Fully inherited" gets a reality check

When a provider claims full inheritance, the platform says the quiet part out loud: that claim covers the provider's own authorization boundary, never your endpoints, facilities, or tenant-side configuration. Every fully inherited objective surfaces a shared per-control caveat, an objective-specific delta, and an editable per-asset engagement note, carried through into the responsibility matrix.

Decision engines that can't drift

The scoping worksheet's dispositions and the External Connections register's suggested dispositions are derived live from their inputs and never stored. Change an input and the disposition, enforcement method, and next action update everywhere at once. The same discipline governs control status, percent complete, and the SPRS score: derived values are always computed, never saved and left to go stale.

CUI-aware by architecture

Every evidence upload must be classified Contains CUI: Yes / No / Unsure. In hosted mode the platform blocks uploads marked Yes or Unsure and shows a persistent warning, because commercial hosting is not FedRAMP authorized, and storing CUI there conflicts with DFARS 252.204-7012 flow-down expectations. Full evidence repositories belong on a local install.

The CRM Inheritance panel with the expanded reality check for AU.L2-3.3.1, spelling out what the OSA still owns despite the provider's fully-inherited claim: tenant-side audit configuration, endpoint log collection, and deciding which events are logged.
The reality check: what a “fully inherited” claim does not cover, spelled out per objective.
The Shared Responsibility Matrix filtered to the Audit domain: fully-inherited dots for the M365 GCC High tenant, each carrying an asterisk marker linking to its OSA reality check.
The responsibility matrix carries the markers. Every full-inheritance dot links back to its reality check.
The data-flow register with CUI decisions, and the URL / cloud service disposition register where Block URL, Network Block Required, and Needs Info dispositions are derived live from three inputs.
Decision engines at work: dispositions derived live from their inputs. Change an input and everything updates; nothing is stored to go stale.

By the numbers

The scope it actually covers.

0
Level 2 assessment objectives tracked individually
0
Level 1 assessment objectives for annual self-assessment
0
Level 2 asset categories in the scoping worksheet
0
Objectives shipping with a worked implementation example
Specifications
ItemValue
Level 2 domains / requirements / objectives14 / 110 / 320
Level 1 domains / practices / objectives6 / 15 / 59
SPRS score range−203 to 110
Evidence integritySHA-256 hash on every file
Evidence staleness default365 days (configurable)
Second factorRequired: passkey or authenticator app
Client data isolationSeparate database and evidence store per client

Regulatory basis: 32 CFR Part 170; CMMC Assessment Guides Level 1 & Level 2 v2.13; CMMC Scoping Guides L1/L2 v2.13; NIST SP 800-171 R2 / 800-171A; NIST SP 800-53 Rev 5 (crosswalk); FAR 52.204-21; DFARS 252.204-7012.

The Deka-Forge Level 2 dashboard: a 91% objectives-met gauge, SPRS score of 91, status breakdown by objective, evidence coverage of 205 of 320 objectives, per-domain progress bars, and a recent-activity feed.
The Level 2 dashboard of the example engagement: live SPRS score, objective status breakdown, evidence coverage, and per-domain progress. Example data, not a customer result.

The compliance workspace

Everything an assessment asks for, in one place.

Dual-level: L2 and L1

A sidebar switcher flips the whole application between Level 2 and Level 1. Work at each level is fully isolated: statuses, evidence, scoping, registers, and dashboards are all level-scoped.

Controls & objectives workspace

Browse by domain, drill into a requirement, expand it into its objectives. Verbatim Discussion and Further Discussion in context, with the five regulatory statuses worded exactly as 32 CFR Part 170 words them.

Review & approval workflow

A Needs Approval status for finished-but-unreviewed work that scores identically to In Progress, so review discipline never inflates a score. Approving records who and when, and the stamp clears automatically if the state changes.

Evidence management

Uploads validated by magic-byte inspection rather than file extension, so a renamed executable is rejected. SHA-256 on every file, random storage keys, and one file can satisfy many objectives instead of being uploaded eleven times.

Staleness & coverage

An optional evidence date drives an automatic staleness flag (365 days by default), so year-old screenshots don't quietly pass as current. A coverage matrix shows exactly where proof is missing.

Scoping worksheet

The five Level 2 asset categories in the Scoping Guide's own words, a working/final asset inventory, a data-flow register with CUI/FCI decision tracking, and a URL and cloud-service disposition register. Full XLSX round-trip.

External Connections register

The approved external systems list required by FAR 52.204-21(b)(1)(iii) at Level 1 and AC.L2-3.1.20 at Level 2. Approval requires a documented control method and a named approver, and every transition is audited.

Shared responsibility matrix

Per-provider CRM manager with version history, derived per-objective inheritance, a "copy into statement" helper that turns provider language into your documentation, and a full SRM matrix with XLSX export: the MSP deliverable.

Implementation examples

All 320 objectives ship with a worked example describing how they could be satisfied using native Microsoft tooling: Entra ID, Intune, Defender, Sentinel, Purview. Marked in-product as a generated suggestion to validate, and editable per objective.

Live SPRS score

The DoD Assessment Methodology per 32 CFR 170.24: starts at 110, subtracts 5 / 3 / 1 per unmet requirement, range −203 to 110. Both partial-credit cases handled, and a missing SSP is flagged on the dashboard.

Dashboard

Overall progress gauge, per-domain progress bars, objective status breakdown, evidence coverage and inheritance chips, recent activity feed, and the SPRS card at Level 2 or a Practices-MET card at Level 1.

Operational plans of action

A working plans-of-action module (CA.L2-3.12.2) for tracking remediation as engagement work, scoped per level.

The evidence coverage matrix: all 110 Level 2 controls as colored chips per domain. Green means all objectives covered, yellow partially covered, red no evidence yet.
Evidence coverage by control: exactly where proof is missing, at a glance.

Platform & operations

Built for a book of clients.

Structural client isolation

Every client gets its own database and its own evidence store. Isolation is structural, not a filter on a shared table. A client user sees no other client's name, data, or even the fact that others exist.

Engagement switching

Super admins create clients and switch between engagements at will; regular accounts land directly in their assigned instance. Access to additional instances is granted one checkbox at a time.

Mandatory two-factor

Two-step sign-in with no exceptions: a correct password alone creates no session. The second factor is a passkey (WebAuthn) or an authenticator app (TOTP); only the public half of a passkey is ever stored, and TOTP secrets are AES-256-GCM encrypted at rest.

Account administration

Roles enforced server-side on every action. Temporary passwords, forced password change, forced re-enrolment of second factors, per-account rename, and a last sign-in timestamp on every row.

Backup & restore

One zip per client with a write-safe database snapshot, every evidence binary, and a manifest of SHA-256 hashes and row counts. Restores validate everything before touching anything, and the swap is all-or-nothing with automatic rollback.

Append-only audit trail

Authentication, status changes, approvals, evidence add and delete, scoping, register transitions, settings, and backup events, each with actor, action, entity, detail, and timestamp.

The Deka-Forge sign-in screen. A password alone creates no session; every account then presents a passkey or authenticator-app second factor.
Two-step sign-in, no exceptions. A correct password alone never creates a session.

Your data, your infrastructure

One codebase runs two ways. Local: SQLite and evidence files on your own disk, where nothing leaves the building. Hosted: managed database and blob storage, or containerized on your own platform. Behavior is identical except for the deliberate CUI restrictions in hosted mode. Backup archives are plain zips holding a standard SQLite file: no proprietary format, no vendor lock-in on your own data.

Who it's for

Three kinds of teams, one platform.

Defense contractors & manufacturers

Organizations Seeking Assessment pursuing Level 2 certification or running the Level 1 annual self-assessment.

Consultants, RPOs & advisors

Anyone running multiple client engagements side by side and needing each one fully isolated from the others.

MSPs & MSSPs

Providers who must show clients exactly which responsibilities are shared, inherited, or entirely theirs.

How you get it

The platform behind our engagements.

Deka-Forge is the platform CyberDeka builds and runs its own CMMC engagements on. It isn't licensed off a shelf; when you work with us, your engagement lives in it from day one, in your own fully isolated instance, and your team works alongside ours in the same tool the whole way to assessment.

Built on assessors' logic, not a generic GRC template.

See it the way our clients do: ask for a walkthrough as part of a CMMC readiness conversation.

Request a Walkthrough