AxiometrikSecurity Assessment & Remediation
Axiometrik

Now recruiting beta participants

Your compliance assessment never leaves your building.

Desktop software for running regulated security and compliance assessments — CMMC 2.0 Level 2, financial institution examinations, and eight other frameworks. Control testing, evidence, policy generation, attestation, and reviewer-ready deliverables, on one workstation you control. No cloud account, no vendor copy of your data, no telemetry.

Join the beta program Select your industry →

Free during the pilot. Limited to a small number of invited organizations.

The problem

A compliance self-assessment is the most candid document your organization produces all year. It is a written record of exactly where your security program falls short, mapped to the requirements you are measured against.

Nearly every tool built to manage that document is a hosted platform — which means uploading it to a third party, inside their breach exposure, subject to their security posture. For a defense contractor the problem is sharper still: that document describes how you protect CUI, and frequently contains CUI, so the platform holding it becomes another cloud service you have to answer for under DFARS 252.204-7012.

The common alternative is a spreadsheet, which has no audit trail, no evidence handling, nothing that carries forward between cycles, and nothing a reviewer recognizes.

Axiometrik is the third option: assessment software with the data model, evidence handling, and reporting of a platform, that runs entirely on your own machine.

Why local matters

Encrypted at rest, by default

The assessment database is encrypted with AES-256 via SQLCipher. The key is generated on first launch and held in the operating system credential store — Windows Credential Manager, GNOME Keyring, or macOS Keychain. A stolen drive yields nothing readable.

Optional passphrase as a second factor

Add a passphrase required once per session, combined with the machine key using PBKDF2-SHA256. Protects against someone reaching an unattended, logged-in workstation. A recovery key is issued at first launch.

No vendor systems, no telemetry

No vendor-operated account, server, or hosted store. No analytics, crash reporting, or usage tracking transmitted to us. We cannot produce your assessment on request, because we never received it.

Portable, attestable files

An assessment exports as a single portable file that opens on any Axiometrik installation. Once signed and attested it is locked read-only on every installation, not just yours — preserving the integrity of the attested record.

The local-only and no-telemetry statements are contractual, not marketing — they appear in Article 7.1 of the Beta Software License Agreement and in the Privacy Notice.

Select your industry

Ten assessment templates across seven sectors. Each is built against the specific regulation or standard it serves — not a generic control list with the regulation's name on the cover.

Defense ContractorsCMMC 2.0 Level 2 · NIST SP 800-171 Rev 2 · 32 C.F.R. Part 170 Financial InstitutionsFFIEC · GLBA · BSA/AML · Bank Protection Act Utilities & Co-opsNERC CIP · SOX ITGC · OT and field devices HealthcareHIPAA Security Rule Law FirmsABA Formal Opinion 477R · SOC 2 Maritime Facilities33 C.F.R. Parts 101 and 105 · NVIC Small BusinessNIST CSF 2.0 — no regulator required

Pilot licenses are provisioned individually. We work out which templates your organization actually needs before your license is issued, so you start with what applies to you.

What you do with it, in every sector

1 — Set up the organization

Create the organization being assessed with its industry profile, operational details, and compliance scope. Organizations with branches, divisions, or multiple sites can be structured under a parent. Independent assessors and MSPs can manage several client organizations from a single installation. Banks regulated by the FDIC can optionally auto-fill charter and address details from public regulatory data; every other organization type is entered directly.

2 — Run the assessment

Work control by control with verification guidance, business risk context, a verification checklist, response status, finding summary and detail, verification method, tested date, and responsibility attribution. Attach the policy, screenshot, or configuration export that evidences each control. Unmet controls get a mitigation plan or a formal risk acceptance.

3 — Use a cadence that matches the requirement

Cadence is cumulative — a quarterly review includes the monthly controls, semi-annual includes both. So a short quarterly check is a real scoped review rather than a reduced version of the annual. Prior-cycle responses, findings, and open remediation items carry forward instead of starting from a blank sheet every year.

4 — Generate the policies the controls require

Policy packs produce organization-branded policy documents mapped to the specific controls they satisfy — so your documentation supports your assessment evidence instead of sitting in an unrelated folder.

5 — Sign and attest

Attestation is collected only after the assessment is marked complete. Signing before the work is recorded would misrepresent what is being attested to — which matters under CMMC and FFIEC-supervised frameworks, where an attestation must describe completed work. After attesting, the record locks.

6 — Deliver it in the form your reviewer expects

An executive report with control statuses, findings, framework mappings, and evidence references, in Excel and PDF. The remediation document adapts to the regime you are assessed under — a POA&M for CMMC, an examiner-style Corrective Action Plan for financial institutions, Coast Guard terminology for maritime facilities. Item IDs stay stable across exports, so the same finding can be cited in a submission, in board minutes, in reviewer correspondence, and in next cycle's assessment without renumbering.

Defense Contractors

CMMC 2.0 Level 2 · NIST SP 800-171 Rev 2 · 32 C.F.R. Part 170 · DFARS 252.204-7012

Program status — CMMC Phase II suspended. On July 13, 2026 the Department of War announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect November 10, 2026, and stood up a reform task force to report within 60 days. Phase I self-assessment requirements remain in place. During the interim the Department has stated it will enforce the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments, and that contractors remain obligated to safeguard covered defense information under DFARS clause 252.204-7012.

What that means in practice: the third-party certification track is paused, and the obligation that is unambiguously still in force is the one Axiometrik is built to run — a documented self-assessment against all 110 NIST SP 800-171 Rev 2 controls, with a defensible record behind it. This page reflects the program as of August 2026 and will be updated as the review concludes.

A hosted GRC platform can become its own compliance problem

DFARS 252.204-7012 requires that a cloud service used to store, process, or transmit covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline. Your CMMC assessment artifact is a detailed account of how you protect CUI, and frequently contains CUI itself. Put it in a hosted GRC platform and that platform becomes another cloud service you have to answer for.

Axiometrik runs on your workstation. There is no cloud service in scope, because there is no cloud service.

All 110 controls, plus the GRC set

The full NIST SP 800-171 Rev 2 control set, with additional governance controls enabled where your configuration calls for them — up to 116 in scope. Roughly 10–14 hours for a full assessment.

The three assessment types the regulation defines

Level 2 Self-Assessment (§ 170.16), Level 2 C3PAO Assessment (§ 170.17), and Annual Affirmation (§ 170.22) — each with the attestation structure its section requires.

Gates that actually hold

Designated critical controls block attestation until resolved or formally accepted as not applicable. There is no override, because a self-assessment you can sign around a hard requirement is not worth signing.

POA&M discipline enforced

Plan of Action items are held to the 180-day remediation window — items without a compliant target date cannot be exported into a POA&M. The export follows SPRS-aligned conventions with persistent, stable item IDs.

An SPRS score is produced from the self-assessment for internal planning and self-reporting. The CMMC policy pack generates 28 policies mapped to the fourteen NIST SP 800-171 Rev 2 control families, so the documentation a control requires is tied to the control it satisfies.

A self-assessment is not a third-party assessment. Axiometrik does not perform, and its output does not substitute for, an assessment by a C3PAO. Axiometrik is not a C3PAO or a Registered Practitioner Organization, and is not endorsed by or affiliated with the Department of War or The Cyber AB. Program status above reflects the Department of War announcement of July 13, 2026; confirm current requirements against your own contract terms and with your contracting officer before relying on any of it.

↑ Back to all industries

Financial Institutions

FFIEC IT Examination Handbook · GLBA Safeguards Rule · FFIEC BSA/AML Examination Manual · Bank Protection Act

Three separate templates, because examiners treat these as three separate programs — and because most institutions do not need all three at once.

IT examination — 84 controls

Built against the FFIEC IT Examination Handbook and the GLBA Safeguards Rule. An annual comprehensive runs about 8 hours; a quarterly review covering recurring controls runs 60–90 minutes; a semi-annual scan addressing GLBA § 314.4(d)(2) runs 30–45 minutes.

BSA/AML program — 60 controls

Aligned to the FFIEC BSA/AML Examination Manual and FinCEN requirements. Covers ML/TF risk assessment, internal controls, independent testing, BSA officer program management, customer due diligence, transaction monitoring, suspicious activity reporting, OFAC, and training. About 6 hours, with quarterly reviews between annual cycles.

Physical security — 63 controls

Bank Protection Act and FDIC/NCUA guidance — perimeter, access control, surveillance, cash operations, and emergency preparedness. Includes an event-triggered type for out-of-cycle assessment after a robbery, unauthorized access event, or inspection.

Crime data, not assumption

Physical security assessments can incorporate NIBRS crime data, so branch findings rest on what actually happens around a location rather than on a general sense of the neighborhood.

FDIC-regulated banks can auto-fill charter and address details from public regulatory data by searching name and state; credit union details are entered directly. Institutions with branches can structure them under a parent. Corrective Action Plans use examiner-style formatting with GLBA and FFIEC references and column labels following FDIC and NCUA examination conventions.

Policy packs cover all three programs: 35 policies for the information security program across nine domain groups, 19 for BSA/AML, and 15 for physical security.

↑ Back to all industries

Utilities & Cooperatives

NERC CIP · SOX ITGC · supply chain risk · OT and field devices

Two templates, split the way utility security teams are actually split — the people responsible for enterprise IT are rarely the people responsible for field devices.

IT systems — 52 controls

Full IT cybersecurity assessment including NERC CIP, SOX ITGC, and supply chain risk. About 10 hours for a full pass. Custom scoping supports targeted reviews of specific domains such as BES Cyber System classification or patch management.

OT & field devices — 50 controls

Operational technology and field device security, including safety instrumented systems, OT endpoint hardening, and anomaly detection. About 10 hours.

Both templates include an event-triggered assessment type for out-of-cycle review following an OT security incident, a grid reliability event, a field device compromise, a safety event, or a NERC CIP compliance finding.

↑ Back to all industries

Healthcare

HIPAA Security Rule — administrative, physical, and technical safeguards

A 28-control assessment covering all three HIPAA Security Rule safeguard categories — administrative, physical, and technical — running roughly 6 hours for a full annual pass.

Alongside the annual comprehensive assessment, a custom type supports targeted gap assessments scoped to specific safeguard categories, and an event-triggered type supports out-of-cycle assessment following a reportable breach, an OCR inquiry, or a significant system change — the three moments when an organization most needs a documented, dated, attested record of where it stood.

Because the assessment and its evidence stay on your equipment, PHI referenced in evidence never transits a vendor system. Axiometrik is not a business associate, and does not need to be.

↑ Back to all industries

A 27-control assessment built against ABA Formal Opinion 477R and the applicable Model Rules, running roughly 8 hours for a full annual review.

Quarterly reviews cover recurring controls on a cadence aligned to SOC 2 ongoing monitoring expectations — increasingly what corporate clients ask firms to demonstrate in outside counsel guidelines and security questionnaires. Custom scoping supports targeted reviews.

For a firm, the confidentiality argument is not incidental: an assessment describing where client-confidential systems fall short is itself sensitive. It stays on your machine.

↑ Back to all industries

Maritime Facilities

33 C.F.R. Parts 101 and 105 · NVIC 01-20 and 03-03 Change 2 · USCG

Two templates for facility security officers, covering the cyber and physical halves of the Coast Guard's requirements.

Maritime cybersecurity — 68 controls

Ten domains, based on 33 C.F.R. Part 101 Subpart F and NVIC 01-20, for facility owners and operators addressing Coast Guard cybersecurity requirements.

Maritime physical security — 79 controls

Nine domains, based on 33 C.F.R. Part 105 and NVIC 03-03 Change 2 — Facility Security Plan governance, access control, TWIC compliance, restricted areas, cargo and stores security, monitoring, and incident response.

A full assessment runs roughly 8–10 hours and is structured for the annual Facility Security Plan audit required by 33 C.F.R. § 105.415. Corrective action documents use Coast Guard terminology with FSP section references and MARSEC level context. Custom scoping lets an FSO review specific FSP sections on their own cycle.

↑ Back to all industries

Small Business — no regulator required

NIST CSF 2.0 — the six core functions

Not every organization that needs to understand its security posture is regulated into it. The general template is a 23-control foundational assessment structured around the six NIST CSF 2.0 functions, running roughly 5 hours.

It suits organizations answering customer security questionnaires, preparing a cyber insurance application or renewal, satisfying a contractual security requirement, doing diligence ahead of an acquisition, or simply wanting a documented, dated baseline that is better than an informal sense of how things are going.

Custom scoping supports gap-focused reviews of individual CSF functions, which is often the sensible starting point for an organization doing this for the first time.

↑ Back to all industries


All ten templates

TemplateControlsBuilt against
Defense Contractor — CMMC Level 2110–116 NIST SP 800-171 Rev 2; 32 C.F.R. Part 170
Community Banking & Credit Unions84 FFIEC IT Examination Handbook; GLBA Safeguards Rule
Community Bank & Credit Union — BSA/AML60 FFIEC BSA/AML Examination Manual; FinCEN requirements
Physical Security — Financial63 Bank Protection Act; FDIC and NCUA guidance
Utility — IT Systems52 NERC CIP; SOX ITGC; supply chain risk
Utility — OT & Field Devices50 OT and field device security; safety instrumented systems
Healthcare28 HIPAA Security Rule — administrative, physical, technical safeguards
Legal — Law Firms27 ABA Formal Opinion 477R and applicable Model Rules
Maritime Facility68 / 79 33 C.F.R. Parts 101 and 105; NVIC 01-20 and 03-03
General Cybersecurity / SMB23 The six NIST CSF 2.0 functions

Also included, across every profile

Software inventory and vulnerability tracking

Maintain a software inventory, scan it against public vulnerability data, and track remediation or formal risk acceptance against the controls affected. Known-exploited vulnerabilities are surfaced separately from ordinary CVEs.

Policy libraries mapped to controls

28 policies across the fourteen CMMC control families, 35 for community banking, 19 for BSA/AML, 15 for financial physical security — each tied to the controls it satisfies.

In the hands of someone who already knows the framework

Axiometrik does not supply expertise and does not pretend to. It assumes you have it — that you know which control is genuinely met, which finding is material, and where the real risk in your organization sits. What it supplies is everything around that judgment, so your hours go into the judgment instead of the assembly.

Your conclusion, recorded so it holds up

Verification method, tested date, what it was tested with, responsible party, and the evidence attached to the control it supports. You already knew the answer. This is what makes that answer survive a reviewer's question eleven months later, when the reasoning is no longer fresh and the person who did the work may have moved on.

The clerical hours back

A full annual assessment is a day's work. The share of that spent rebuilding a spreadsheet, hunting evidence across a shared drive, renumbering findings, and retyping last year's corrective action plan is not expertise — it's overhead. That's the share this removes.

Last cycle's reasoning is still in front of you

Carry-forward brings prior responses, findings, and open remediation items into the new assessment. Your own earlier judgment stays visible instead of being lost between cycles — which matters, because "what changed since last time, and why" is the question you will actually be asked.

Your name on a record that locks

Attestation is captured only after the work is complete, and the record locks once signed. For a professional whose signature carries weight, the ordering is the point: the signature is tied to a finished body of work, not collected in advance of it.

Policy drafts you edit, not accept

You write better policy than any template does, because you know your organization. You also don't want to write thirty-five of them from a blank page. Control-mapped drafts are a starting point that already knows which control each policy answers to.

A practice, not a project

Independent assessors, consultants, and MSPs can run several client organizations from one installation, each with its own industry persona, compliance scope, and template set — with template lists filtered to the client you actually selected.

The same logic applies to the person who is not a specialist but owns this anyway — the IT director at a 60-person defense supplier, the security officer at a community bank who has five other job titles. The structure carries the parts of the work that don't require your judgment, and asks you for the parts that do.

What Axiometrik is not

Which is why we are equally specific about the boundary. A tool claiming to supply the expertise itself would be a tool you could not responsibly sign behind:


Join the beta

Axiometrik is in a closed pilot with a small number of invited organizations. Participation is free, and early participants shape what the product becomes.

See the beta program details

Vendor due diligence

Reviewing Axiometrik as part of a third-party risk assessment? The license terms, privacy notice, and third-party component notices are published in full, not gated. For questionnaires or anything not answered there, write to legal@axiometrik.net.

Legal entity

Legal nameSadler Enterprises LLC
SoftwareAxiometrik
JurisdictionLouisiana, United States
Principal address1133 Belgard Bend, Boyce, Louisiana 71409
Contactlegal@axiometrik.net

This product uses data from the NVD API but is not endorsed or certified by the NVD. See third-party notices.