From signup to audit-ready, in one platform.
Seven phases. Four distinct roles. Every control, evidence file, and policy decision sealed in a tamper-evident audit log.

The contractor journey
- 1
Sign up & onboard
Contractor adminPick a plan, add company profile (CAGE, UEI, industry, headcount), invite teammates by role.
- 2
Scope the assessment
Contractor adminAnswer 8 scoping questions, inventory in-scope assets, define the CUI boundary.
- 3
Run the 110-control wizard
Contractor + contributorsGuided NIST 800-171 assessment with live SPRS score, domain completion %, auto-generated POA&M for any 'no' or 'partial'.
- 4
Collect evidence
ContributorsPer-control evidence slots with SHA-256 hashing, malware scan, and review states (pending → approved → audit-ready).
- 5
Author policies
Contractor adminAI-drafted 14-policy library tailored to scope. E-sign, version, and require staff acknowledgement.
- 6
Submit & invite auditor
Contractor adminMark SPRS submitted in supplier portal, generate the audit package, invite your C3PAO with a scoped, expiring token.
- 7
Continuous compliance
Contractor adminTrack findings remediation, annual affirmation, quarterly POA&M reviews — Cincra reminds you 90/60/30/14/7 days out.
Four roles, four logins
Cincra enforces strict separation. The Cincra team never sees your assessment data; auditors only see what you grant, when you grant it.
Contractor
The defense company pursuing CMMC. Owns the data, runs the assessment, submits to DoD.
MSP / Reseller
Manages a portfolio of contractor clients. Switches context per client; every action is audit-logged.
Auditor (C3PAO)
Invited per engagement with a time-boxed token. Reviews evidence, files CAT I/II/III findings, issues final determination.
Cincra
Platform operator. Never sees contractor assessment data. Manages control library, partner approvals, billing.
Ready to start your assessment?
Free 10-question scoping quiz, no card required.