SSPARC
A self-assessment workspace for managed service providers who look after defense contractors. One baseline, many clients.
What it does
- Tracks CMMC Level 1 (15 FAR 52.204-21 requirements) and Level 2 (110 NIST SP 800-171 Rev 2 controls) per client organisation.
- Shares one implementation baseline across clients, with per-client overrides.
- Records where evidence lives and flags attestations that have expired.
- Produces a System Security Plan and a POA&M from the recorded state.
- Computes the SPRS score using the DoD Assessment Methodology.
What it does not do
SSPARC never stores your CUI — there is no upload anywhere in the product, and evidence is recorded as a pointer to where the artifact lives in your own environment. It is a preparation tool: it does not certify anything, does not assess anything, and is not legal advice.