Now recruiting beta participants
Your compliance assessment never leaves your building.
Desktop software for running regulated security and compliance assessments — CMMC 2.0 Level 2, financial institution examinations, and eight other frameworks. Control testing, evidence, policy generation, attestation, and reviewer-ready deliverables, on one workstation you control. No cloud account, no vendor copy of your data, no telemetry.
Join the beta program Select your industry →
Free during the pilot. Limited to a small number of invited organizations.
The problem
A compliance self-assessment is the most candid document your organization produces all year. It is a written record of exactly where your security program falls short, mapped to the requirements you are measured against.
Nearly every tool built to manage that document is a hosted platform — which means uploading it to a third party, inside their breach exposure, subject to their security posture. For a defense contractor the problem is sharper still: that document describes how you protect CUI, and frequently contains CUI, so the platform holding it becomes another cloud service you have to answer for under DFARS 252.204-7012.
The common alternative is a spreadsheet, which has no audit trail, no evidence handling, nothing that carries forward between cycles, and nothing a reviewer recognizes.
Axiometrik is the third option: assessment software with the data model, evidence handling, and reporting of a platform, that runs entirely on your own machine.
Why local matters
Encrypted at rest, by default
The assessment database is encrypted with AES-256 via SQLCipher. The key is generated on first launch and held in the operating system credential store — Windows Credential Manager, GNOME Keyring, or macOS Keychain. A stolen drive yields nothing readable.
Optional passphrase as a second factor
Add a passphrase required once per session, combined with the machine key using PBKDF2-SHA256. Protects against someone reaching an unattended, logged-in workstation. A recovery key is issued at first launch.
No vendor systems, no telemetry
No vendor-operated account, server, or hosted store. No analytics, crash reporting, or usage tracking transmitted to us. We cannot produce your assessment on request, because we never received it.
Portable, attestable files
An assessment exports as a single portable file that opens on any Axiometrik installation. Once signed and attested it is locked read-only on every installation, not just yours — preserving the integrity of the attested record.
The local-only and no-telemetry statements are contractual, not marketing — they appear in Article 7.1 of the Beta Software License Agreement and in the Privacy Notice.
Select your industry
Ten assessment templates across seven sectors. Each is built against the specific regulation or standard it serves — not a generic control list with the regulation's name on the cover.
Pilot licenses are provisioned individually. We work out which templates your organization actually needs before your license is issued, so you start with what applies to you.
What you do with it, in every sector
1 — Set up the organization
Create the organization being assessed with its industry profile, operational details, and compliance scope. Organizations with branches, divisions, or multiple sites can be structured under a parent. Independent assessors and MSPs can manage several client organizations from a single installation. Banks regulated by the FDIC can optionally auto-fill charter and address details from public regulatory data; every other organization type is entered directly.
2 — Run the assessment
Work control by control with verification guidance, business risk context, a verification checklist, response status, finding summary and detail, verification method, tested date, and responsibility attribution. Attach the policy, screenshot, or configuration export that evidences each control. Unmet controls get a mitigation plan or a formal risk acceptance.
3 — Use a cadence that matches the requirement
Cadence is cumulative — a quarterly review includes the monthly controls, semi-annual includes both. So a short quarterly check is a real scoped review rather than a reduced version of the annual. Prior-cycle responses, findings, and open remediation items carry forward instead of starting from a blank sheet every year.
4 — Generate the policies the controls require
Policy packs produce organization-branded policy documents mapped to the specific controls they satisfy — so your documentation supports your assessment evidence instead of sitting in an unrelated folder.
5 — Sign and attest
Attestation is collected only after the assessment is marked complete. Signing before the work is recorded would misrepresent what is being attested to — which matters under CMMC and FFIEC-supervised frameworks, where an attestation must describe completed work. After attesting, the record locks.
6 — Deliver it in the form your reviewer expects
An executive report with control statuses, findings, framework mappings, and evidence references, in Excel and PDF. The remediation document adapts to the regime you are assessed under — a POA&M for CMMC, an examiner-style Corrective Action Plan for financial institutions, Coast Guard terminology for maritime facilities. Item IDs stay stable across exports, so the same finding can be cited in a submission, in board minutes, in reviewer correspondence, and in next cycle's assessment without renumbering.
Defense Contractors
CMMC 2.0 Level 2 · NIST SP 800-171 Rev 2 · 32 C.F.R. Part 170 · DFARS 252.204-7012
Program status — CMMC Phase II suspended. On July 13, 2026 the Department of War announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect November 10, 2026, and stood up a reform task force to report within 60 days. Phase I self-assessment requirements remain in place. During the interim the Department has stated it will enforce the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments, and that contractors remain obligated to safeguard covered defense information under DFARS clause 252.204-7012.
What that means in practice: the third-party certification track is paused, and the obligation that is unambiguously still in force is the one Axiometrik is built to run — a documented self-assessment against all 110 NIST SP 800-171 Rev 2 controls, with a defensible record behind it. This page reflects the program as of August 2026 and will be updated as the review concludes.
A hosted GRC platform can become its own compliance problem
DFARS 252.204-7012 requires that a cloud service used to store, process, or transmit covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline. Your CMMC assessment artifact is a detailed account of how you protect CUI, and frequently contains CUI itself. Put it in a hosted GRC platform and that platform becomes another cloud service you have to answer for.
Axiometrik runs on your workstation. There is no cloud service in scope, because there is no cloud service.
All 110 controls, plus the GRC set
The full NIST SP 800-171 Rev 2 control set, with additional governance controls enabled where your configuration calls for them — up to 116 in scope. Roughly 10–14 hours for a full assessment.
The three assessment types the regulation defines
Level 2 Self-Assessment (§ 170.16), Level 2 C3PAO Assessment (§ 170.17), and Annual Affirmation (§ 170.22) — each with the attestation structure its section requires.
Gates that actually hold
Designated critical controls block attestation until resolved or formally accepted as not applicable. There is no override, because a self-assessment you can sign around a hard requirement is not worth signing.
POA&M discipline enforced
Plan of Action items are held to the 180-day remediation window — items without a compliant target date cannot be exported into a POA&M. The export follows SPRS-aligned conventions with persistent, stable item IDs.
An SPRS score is produced from the self-assessment for internal planning and self-reporting. The CMMC policy pack generates 28 policies mapped to the fourteen NIST SP 800-171 Rev 2 control families, so the documentation a control requires is tied to the control it satisfies.
A self-assessment is not a third-party assessment. Axiometrik does not perform, and its output does not substitute for, an assessment by a C3PAO. Axiometrik is not a C3PAO or a Registered Practitioner Organization, and is not endorsed by or affiliated with the Department of War or The Cyber AB. Program status above reflects the Department of War announcement of July 13, 2026; confirm current requirements against your own contract terms and with your contracting officer before relying on any of it.
Financial Institutions
FFIEC IT Examination Handbook · GLBA Safeguards Rule · FFIEC BSA/AML Examination Manual · Bank Protection Act
Three separate templates, because examiners treat these as three separate programs — and because most institutions do not need all three at once.
IT examination — 84 controls
Built against the FFIEC IT Examination Handbook and the GLBA Safeguards Rule. An annual comprehensive runs about 8 hours; a quarterly review covering recurring controls runs 60–90 minutes; a semi-annual scan addressing GLBA § 314.4(d)(2) runs 30–45 minutes.
BSA/AML program — 60 controls
Aligned to the FFIEC BSA/AML Examination Manual and FinCEN requirements. Covers ML/TF risk assessment, internal controls, independent testing, BSA officer program management, customer due diligence, transaction monitoring, suspicious activity reporting, OFAC, and training. About 6 hours, with quarterly reviews between annual cycles.
Physical security — 63 controls
Bank Protection Act and FDIC/NCUA guidance — perimeter, access control, surveillance, cash operations, and emergency preparedness. Includes an event-triggered type for out-of-cycle assessment after a robbery, unauthorized access event, or inspection.
Crime data, not assumption
Physical security assessments can incorporate NIBRS crime data, so branch findings rest on what actually happens around a location rather than on a general sense of the neighborhood.
FDIC-regulated banks can auto-fill charter and address details from public regulatory data by searching name and state; credit union details are entered directly. Institutions with branches can structure them under a parent. Corrective Action Plans use examiner-style formatting with GLBA and FFIEC references and column labels following FDIC and NCUA examination conventions.
Policy packs cover all three programs: 35 policies for the information security program across nine domain groups, 19 for BSA/AML, and 15 for physical security.
Utilities & Cooperatives
NERC CIP · SOX ITGC · supply chain risk · OT and field devices
Two templates, split the way utility security teams are actually split — the people responsible for enterprise IT are rarely the people responsible for field devices.
IT systems — 52 controls
Full IT cybersecurity assessment including NERC CIP, SOX ITGC, and supply chain risk. About 10 hours for a full pass. Custom scoping supports targeted reviews of specific domains such as BES Cyber System classification or patch management.
OT & field devices — 50 controls
Operational technology and field device security, including safety instrumented systems, OT endpoint hardening, and anomaly detection. About 10 hours.
Both templates include an event-triggered assessment type for out-of-cycle review following an OT security incident, a grid reliability event, a field device compromise, a safety event, or a NERC CIP compliance finding.
Healthcare
HIPAA Security Rule — administrative, physical, and technical safeguards
A 28-control assessment covering all three HIPAA Security Rule safeguard categories — administrative, physical, and technical — running roughly 6 hours for a full annual pass.
Alongside the annual comprehensive assessment, a custom type supports targeted gap assessments scoped to specific safeguard categories, and an event-triggered type supports out-of-cycle assessment following a reportable breach, an OCR inquiry, or a significant system change — the three moments when an organization most needs a documented, dated, attested record of where it stood.
Because the assessment and its evidence stay on your equipment, PHI referenced in evidence never transits a vendor system. Axiometrik is not a business associate, and does not need to be.
Law Firms
ABA Formal Opinion 477R · applicable Model Rules · SOC 2 monitoring expectations
A 27-control assessment built against ABA Formal Opinion 477R and the applicable Model Rules, running roughly 8 hours for a full annual review.
Quarterly reviews cover recurring controls on a cadence aligned to SOC 2 ongoing monitoring expectations — increasingly what corporate clients ask firms to demonstrate in outside counsel guidelines and security questionnaires. Custom scoping supports targeted reviews.
For a firm, the confidentiality argument is not incidental: an assessment describing where client-confidential systems fall short is itself sensitive. It stays on your machine.
Maritime Facilities
33 C.F.R. Parts 101 and 105 · NVIC 01-20 and 03-03 Change 2 · USCG
Two templates for facility security officers, covering the cyber and physical halves of the Coast Guard's requirements.
Maritime cybersecurity — 68 controls
Ten domains, based on 33 C.F.R. Part 101 Subpart F and NVIC 01-20, for facility owners and operators addressing Coast Guard cybersecurity requirements.
Maritime physical security — 79 controls
Nine domains, based on 33 C.F.R. Part 105 and NVIC 03-03 Change 2 — Facility Security Plan governance, access control, TWIC compliance, restricted areas, cargo and stores security, monitoring, and incident response.
A full assessment runs roughly 8–10 hours and is structured for the annual Facility Security Plan audit required by 33 C.F.R. § 105.415. Corrective action documents use Coast Guard terminology with FSP section references and MARSEC level context. Custom scoping lets an FSO review specific FSP sections on their own cycle.
Small Business — no regulator required
NIST CSF 2.0 — the six core functions
Not every organization that needs to understand its security posture is regulated into it. The general template is a 23-control foundational assessment structured around the six NIST CSF 2.0 functions, running roughly 5 hours.
It suits organizations answering customer security questionnaires, preparing a cyber insurance application or renewal, satisfying a contractual security requirement, doing diligence ahead of an acquisition, or simply wanting a documented, dated baseline that is better than an informal sense of how things are going.
Custom scoping supports gap-focused reviews of individual CSF functions, which is often the sensible starting point for an organization doing this for the first time.
All ten templates
| Template | Controls | Built against |
|---|---|---|
| Defense Contractor — CMMC Level 2 | 110–116 | NIST SP 800-171 Rev 2; 32 C.F.R. Part 170 |
| Community Banking & Credit Unions | 84 | FFIEC IT Examination Handbook; GLBA Safeguards Rule |
| Community Bank & Credit Union — BSA/AML | 60 | FFIEC BSA/AML Examination Manual; FinCEN requirements |
| Physical Security — Financial | 63 | Bank Protection Act; FDIC and NCUA guidance |
| Utility — IT Systems | 52 | NERC CIP; SOX ITGC; supply chain risk |
| Utility — OT & Field Devices | 50 | OT and field device security; safety instrumented systems |
| Healthcare | 28 | HIPAA Security Rule — administrative, physical, technical safeguards |
| Legal — Law Firms | 27 | ABA Formal Opinion 477R and applicable Model Rules |
| Maritime Facility | 68 / 79 | 33 C.F.R. Parts 101 and 105; NVIC 01-20 and 03-03 |
| General Cybersecurity / SMB | 23 | The six NIST CSF 2.0 functions |
Also included, across every profile
Software inventory and vulnerability tracking
Maintain a software inventory, scan it against public vulnerability data, and track remediation or formal risk acceptance against the controls affected. Known-exploited vulnerabilities are surfaced separately from ordinary CVEs.
Policy libraries mapped to controls
28 policies across the fourteen CMMC control families, 35 for community banking, 19 for BSA/AML, 15 for financial physical security — each tied to the controls it satisfies.
In the hands of someone who already knows the framework
Axiometrik does not supply expertise and does not pretend to. It assumes you have it — that you know which control is genuinely met, which finding is material, and where the real risk in your organization sits. What it supplies is everything around that judgment, so your hours go into the judgment instead of the assembly.
Your conclusion, recorded so it holds up
Verification method, tested date, what it was tested with, responsible party, and the evidence attached to the control it supports. You already knew the answer. This is what makes that answer survive a reviewer's question eleven months later, when the reasoning is no longer fresh and the person who did the work may have moved on.
The clerical hours back
A full annual assessment is a day's work. The share of that spent rebuilding a spreadsheet, hunting evidence across a shared drive, renumbering findings, and retyping last year's corrective action plan is not expertise — it's overhead. That's the share this removes.
Last cycle's reasoning is still in front of you
Carry-forward brings prior responses, findings, and open remediation items into the new assessment. Your own earlier judgment stays visible instead of being lost between cycles — which matters, because "what changed since last time, and why" is the question you will actually be asked.
Your name on a record that locks
Attestation is captured only after the work is complete, and the record locks once signed. For a professional whose signature carries weight, the ordering is the point: the signature is tied to a finished body of work, not collected in advance of it.
Policy drafts you edit, not accept
You write better policy than any template does, because you know your organization. You also don't want to write thirty-five of them from a blank page. Control-mapped drafts are a starting point that already knows which control each policy answers to.
A practice, not a project
Independent assessors, consultants, and MSPs can run several client organizations from one installation, each with its own industry persona, compliance scope, and template set — with template lists filtered to the client you actually selected.
The same logic applies to the person who is not a specialist but owns this anyway — the IT director at a 60-person defense supplier, the security officer at a community bank who has five other job titles. The structure carries the parts of the work that don't require your judgment, and asks you for the parts that do.
What Axiometrik is not
Which is why we are equally specific about the boundary. A tool claiming to supply the expertise itself would be a tool you could not responsibly sign behind:
- It is not a compliance guarantee. Using the software does not make an organization compliant with any law, regulation, standard, or framework, and does not guarantee any examination, audit, or certification outcome.
- It is not professional advice. Outputs are for informational and self-assessment purposes. They are not legal, regulatory, cybersecurity, auditing, or accounting advice, and no assessor or auditor relationship is created by using it.
- It is not endorsed by any regulator. Axiometrik is not endorsed by, affiliated with, or approved by the FFIEC, FDIC, OCC, the Federal Reserve, NCUA, FinCEN, the Department of War (formerly the Department of Defense), CISA, NIST, The Cyber AB, the U.S. Coast Guard, the Office for Civil Rights, the PCI Security Standards Council, or any other standards body or regulatory authority.
- A self-assessment is not a third-party assessment. Axiometrik does not perform, and its output does not substitute for, an assessment conducted by a Certified Third-Party Assessment Organization. Axiometrik is not a C3PAO or a Registered Practitioner Organization. Where a contract requires a third-party assessment, this software does not satisfy that requirement. 32 C.F.R. § 170.24 sets out the certification requirement; see the program status note in the defense contractor section for its current implementation.
- It does not replace an assessor. Where an independent assessment is required, an independent assessment is still required.
Join the beta
Axiometrik is in a closed pilot with a small number of invited organizations. Participation is free, and early participants shape what the product becomes.
Vendor due diligence
Reviewing Axiometrik as part of a third-party risk assessment? The license terms, privacy notice, and third-party component notices are published in full, not gated. For questionnaires or anything not answered there, write to legal@axiometrik.net.
Legal entity
| Legal name | Sadler Enterprises LLC |
|---|---|
| Software | Axiometrik |
| Jurisdiction | Louisiana, United States |
| Principal address | 1133 Belgard Bend, Boyce, Louisiana 71409 |
| Contact | legal@axiometrik.net |
This product uses data from the NVD API but is not endorsed or certified by the NVD. See third-party notices.