NIST 800-171 · CMMC · ISO 27001

Meet the technical controls before the assessor arrives.

Skans ships meeting the technical controls of NIST 800-171 and CMMC at mandated defaults — FIPS mode, hardware-backed MFA, a CIS/STIG baseline, TLS everywhere — and assembles the evidence pack from live state on one command. The organizational controls stay yours, spelled out per control in a responsibility matrix with any gaps tracked in a POA&M. It supports your certification; no product can grant it.

Skans console · Compliance
The Skans compliance view — a NIST 800-171 security-posture ring with per-control-family status cards for AC, AU, CM, CP, IA, RA and SC.

On by default

The technical controls are set at install — not after a project.

The hard technical controls don't wait for a hardening sprint. From the first boot the appliance runs its cryptography in FIPS approved-mode, admits operators only with hardware-backed MFA, applies a CIS/STIG baseline, and encrypts every device and service. The posture starts compliant and stays enforced — a severed WAN changes none of it.

  • FIPS approved-mode — the appliance runs its cryptography in FIPS 140-3 approved-mode from install (approved-mode, honestly stated — not a per-release CMVP-validated module).
  • Hardware-backed MFA — operator login via PIV / FIDO2 tokens issued from your own CA, satisfying device trust and multi-factor authentication.
  • CIS / STIG baseline — a hardening baseline applied by default at install, with drift detection against directory and network golden config.
  • TLS everywhere — encryption in transit on every device and service, encryption at rest, and default credentials removed.
  • An enforced update baseline — staged patch rings keep Configuration Management controls current with no WSUS and no internet.
Skans console · Updates
The Skans updates view — signature-gated patch rings, a fleet patch-compliance bar chart, a firmware repository and password-baseline tabs.

Measured, not assumed

Every device carries proof — or reads Not Verified.

Compliance is read off the box, device by device, never inferred from a policy that should have applied. Each managed device carries an X.509 identity and an agent-measured scorecard; a control Skans hasn't actually measured stays Not Verified rather than turning green. Agentless devices are marked N/A for agent checks — they never silently count as passing.

  • An identity per device — every managed device carries an X.509 identity from the enclave's own certificate authority.
  • Agent-measured scorecard — BitLocker, host firewall, audit policy, FIPS mode, patch, Defender and certificate posture, all read on the box.
  • Not Verified stays honest — a control that hasn't been measured is never flipped green because a policy was supposed to apply it.
  • Agentless is N/A, not a silent pass — devices without an agent don't quietly inflate the numbers.
Skans console · Devices
The Skans device inventory — cameras, switches and firewalls with certificate status, capability tier and management lane per device.

Live posture

Mapped to the control families, continuously — with an ISO 27001 crosswalk.

Skans maps its live technical checks to the NIST 800-171 control families and reports posture from current appliance state — not a spreadsheet from last quarter. The same measurements crosswalk to all 93 ISO/IEC 27001:2022 Annex A controls via NIST's published OLIR #155 mapping, so every link traces back to a reference standard. It never rolls that crosswalk up to a single "you're compliant" score — that would be a lie over a standard that is mostly organizational — so it reports honest buckets over a fixed denominator instead.

  • Mapped to the families — AC, AU, CA, CM, CP, IA, RA, SC and SI, each evidenced from live appliance state.
  • ISO 27001 crosswalk — the same checks crosswalk to the 93 Annex A controls of ISO/IEC 27001:2022 via NIST OLIR #155.
  • Four honest buckets — supporting-evidence, gaps identified, mapped-not-measured, and customer-responsibility over a fixed denominator — never a single made-up score.
  • Continuous risk assessment — correlated monitoring plus offline CVE and MITRE ATT&CK feeds, matched against live per-host inventory without internet.
Skans console · NOC
The Skans NOC wall — live tiles for fleet health (31 of 42 devices online), open incidents, controls-passing, certificates issued, devices by trust tier, open vulnerabilities, ATT&CK detections and 24-hour events.

Assessment-ready

One command hands the assessor the whole evidence pack.

From the Compliance hub, a single command produces a timestamped, air-gap-friendly .zip assembled entirely from live state — no hand-collation the night before. Inside is the system security plan status, a live POA&M of open gaps, the responsibility matrix, the asset inventory and the audit log, all under a signed manifest. Alongside it, an append-only, hash-linked audit chain lets you prove nothing was edited after the fact.

  • One command, one pack — a timestamped .zip built from live state, suitable for a disconnected site, with no manual assembly.
  • Everything an assessor asks for — SSP control status, a live POA&M of gaps, the responsibility matrix, the asset register and the audit log.
  • Signed manifest — a SHA-256 hash of every file plus a detached signature, so the pack proves it wasn't altered after export.
  • Tamper-evident audit chain — an append-only, hash-linked, signed log that detects after-the-fact modification cryptographically (tamper-evident — not WORM, not immutable).
Skans console · Compliance
The Skans compliance hub — control-family posture cards and the one-command evidence-pack export.

Where the boundary sits

Honest about what a product can and can't do.

Being straight about the edges is part of the point. Skans does the technical heavy lifting and generates the evidence; it never pretends to be your certification.

Technical vs organizational

Roughly a third of NIST 800-171's 110 requirements are organizational — physical, personnel, planning, program, and the process parts of incident response. Those stay yours, spelled out per control in the responsibility matrix.

Supports, never certifies

No product makes you "CMMC compliant in a box." Formal Level 2 standing needs a third-party assessment by a C3PAO; ISO 27001 certifies your ISMS, not an appliance. Skans generates the evidence — it doesn't replace the assessor.

Tamper-evident, not immutable

The audit chain detects modification cryptographically, but it isn't write-once media. We describe it as tamper-evident — never as WORM or immutable — because that's what it is.

FIPS approved-mode, stated plainly

The appliance runs in FIPS 140-3 approved-mode — capable, not the same as a CMVP-validated module. Per-release module pinning is an open item, and an independent penetration test remains yours to run.

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.