Getting started

Your first hour with Sentry171

What to do first, the order the work goes in, and the handful of CMMC terms you'll keep seeing. About ten minutes to read.

Before you start

Sentry171 helps you work out which CMMC requirements apply to you, assess yourself against them, and produce the documents and records that back up your result. It guides the work and keeps the record; you still do the work, and the answers are yours.

What it doesn't do:

  • It doesn't certify you. A self-assessment is your company's own statement; a Level 2 certification assessment is done by an authorized assessor (a C3PAO).
  • It doesn't file anything for you. You enter your score and affirmation in SPRS yourself; Sentry171 keeps the record behind them.
  • It doesn't fix your systems. It tells you what's missing and helps you plan the fixes.

Which level do you need?

  • Level 1 if you handle only Federal Contract Information (FCI): contract details that aren't public. 17 practices.
  • Level 2 if you handle Controlled Unclassified Information (CUI), or your contracts include DFARS 252.204-7012. 110 requirements.

Not sure? Look for that DFARS clause in your contracts, or for documents marked CUI. Either one means Level 2. You can switch levels during the trial.

Who should do it

Whoever knows how your computers, accounts and files are actually set up: often the IT person or an outside IT provider, working with the owner. You'll also need the name and title of the person who approves your policies, usually the owner or president.

Sign up and set up

  1. Create your account Go to app.sentry171.com/signup and enter your work email and a password.
  2. Confirm your email Click the link in the email we send. If it isn't in your inbox within a few minutes, check your spam or junk folder and mark it "not spam".
  3. Set up your company Your company name, your full legal name as it appears on contracts (it's printed on your policies and SSP), and your CMMC level.
  4. Say who's responsible Who runs security day to day, and who approves your policies. You can skip this and fill it in later, but policies can't be approved until someone is named.
  5. Follow the checklist You land on the Overview page. Its Getting Started checklist shows what's done and what to do next, and links straight to each step.
Your work saves as you go. Stop whenever you like; the checklist picks up where you left off.

The order of the work

Each step builds on the one before, so it pays to go in order. Your scoping answers decide what the assessment asks; your assessment decides what the policies and SSP say.

  1. Describe your company Scoping page. A few core questions: who owns security policy, how often it's reviewed, where your CUI or FCI lives.
  2. Answer the scoping questions Scoping page. One short set of plain-language questions per security area. Your answers settle which requirements apply and pre-fill much of what comes later.
  3. Assess every practice Self-Assessment page. For each objective, mark it met, not met or not applicable, with suggested wording to start from. Your score updates as you go. This is the longest step; expect to spread it over several sittings.
  4. Optional Invite your team Settings page. See Your team below.
  5. Approve your policies Policies page. Policies are generated from your scoping and assessment. Review each one; your named approver approves it, and the approved version is kept.
  6. Level 2 Issue your System Security Plan System Security Plan page. Built from everything above. Gaps from your assessment go on your POA&M as corrective action plans.
  7. Affirm your score Score Proof page. A senior official affirms the result, and the signed, dated record is kept with your proof package.

After that, compliance becomes routine. The Calendar lists recurring obligations such as log reviews, training and access reviews, and pages like Training, Personnel and Privileged Accounts hold the records an assessor will ask to see.

Words you'll see

CMMC
Cybersecurity Maturity Model Certification: the Department of Defense program that checks contractors protect contract information. It is now written into DoD contracts.
FCI
Federal Contract Information. Information about a government contract that isn't meant to be public. Handling it means Level 1.
CUI
Controlled Unclassified Information. Sensitive government information that isn't classified, such as technical drawings or specifications. Handling it means Level 2.
NIST SP 800-171
The document that lists the 110 security requirements Level 2 is built on.
Practice / requirement
One security rule, for example "limit system access to authorized users". Level 1 has 17; Level 2 has 110.
Objective
The specific things an assessor checks within a requirement. A requirement is met only when all its objectives are. Level 2 has 320.
Scoping
Working out which systems, people and places handle the protected information, so you assess what matters and mark the rest not applicable with a reason.
SPRS score
Your Level 2 score, entered in the government's Supplier Performance Risk System. It starts at 110 and loses points for each requirement not met, and can go below zero. Level 1 has no score: all 17 practices must be met.
SSP
System Security Plan. Describes your systems and how you meet each requirement. Required for Level 2.
POA&M
Plan of Action and Milestones. Your plan for closing the gaps: what will be fixed, by whom and by when.
Affirmation
A senior official's statement that your result is accurate. Made after each assessment and every year.
C3PAO
An authorized third-party assessment organization. Some Level 2 contracts require one to assess you instead of a self-assessment.

Your team

Invite colleagues from Settings. They get an email with a link that works for seven days, and they sign in with that same email address. Each person has one role:

OwnerEverything, plus managing owners, exporting all data and closing the account.
AdministratorRuns the program: invites people, approves policies, issues the SSP, signs affirmations, deletes records.
MemberDoes the work: answers scoping and assessment questions, adds records, evidence and action plans, uploads documents.
Read-onlySees everything, changes nothing. Good for a consultant, an assessor or leadership.

Invitation emails can land in spam too; tell people to look there.

Trial, your data, help

The trial

Your free trial runs for 14 days. No credit card is needed. During the trial you can switch between Level 1 and Level 2 in Settings.

Your data

Each company's records are kept separate from every other company's. An owner can export everything, every record, document and uploaded file, as a zip from Settings at any time, or close the account and delete it all.

Getting help

Stuck, found something wrong, or have an idea? Email support@sentry171.com. A screenshot and the page you were on help a lot.

Ready? Scoping and your first few areas take an afternoon.

Start your free trial