CMMC 2.0 · NIST SP 800-171 Rev 2
The technical evidence for your CMMC assessment—collected, hashed, and ready to hand over.
TenantSentinel Proof reads your Microsoft 365 tenant and evaluates it against all 110 NIST SP 800-171 Rev 2 controls. It produces three things an assessor or a cyber-insurer can actually use: a tamper-evident evidence ledger, a full assessor report, and an SSP-ready evidence packet containing the underlying data for every control.
It is a technical-evidence engine, not a compliance platform. Proof does not certify you, and it does not decide whether you pass. It gathers what your tenant can prove, states plainly what it cannot, and shows its work.
Windows desktop application, read-only. Every paid plan includes a 14-day free trial; a free Level 1 quick check is available too.
Why This Exists
Assessors and insurers do not want your assurances. They want artifacts—the actual configuration, the date it was read, and a way to tell whether it was altered afterward.
Most organizations answer a CMMC assessment by assembling screenshots into a spreadsheet, weeks before the assessor arrives. The evidence is stale by the time it is reviewed, nobody can verify it was not edited, and the controls that Microsoft 365 genuinely cannot answer get quietly glossed over. Proof replaces that scramble with a repeatable scan that produces evidence with a verifiable chain of custody, and that is honest about the boundary of what a tenant scan can and cannot establish.
All 110 Controls. Nothing Hidden.
Every control appears in the output, every time—including the ones your tenant cannot evidence.
72 controls in Microsoft 365's orbit
These are the controls where tenant configuration is meaningful evidence. Proof evaluates them with 45 read-only checks across Microsoft Graph, Exchange Online, and Purview—classifying each control as fully evidenceable, partially evidenceable, or requiring human confirmation.
38 organizational controls, listed with reasons
Policy, training, physical security, and personnel controls cannot be read from a tenant, and Proof never pretends otherwise. Each one is printed in the report with an explicit statement of why it falls outside a technical scan, so the assessor sees the full 110 and knows exactly where the boundary is.
Nine controls inherited from Microsoft
A handful of controls are satisfied by the platform itself under Microsoft's shared-responsibility model. Proof marks these as implemented and labels them as Microsoft-inherited, evidenced by Microsoft's own shared-responsibility attestation rather than by your configuration.
It will not fail you by accident
When a check cannot run—an unlicensed workload, a permission not granted, an API that did not answer—Proof degrades that control to needs manual review rather than marking it failed. A control is only reported as not implemented when a check actually ran and actually found it missing. Honest degradation is a design principle here, not a fallback.
A Tamper-Evident Ledger
Every scan writes a cryptographically chained record. If an entry is altered or reordered after the fact, verification fails and tells you where.
Each scan appends entries to a hash chain, and each entry carries a SHA-256 hash of the evidence it describes plus the hash of the entry before it. That means the ledger can be independently verified at any time—a broken link identifies the exact entry where the chain diverges. This is the difference between handing an assessor a folder of screenshots and handing them a record whose integrity can be checked.
Because the ledger persists across scans, Proof also reports what changed since the last one. Controls that regressed, controls that improved, and evidence that changed underneath an unchanged verdict are all surfaced in a "changes since last scan" section, so drift between assessments is visible instead of silent.
What You Hand Over
One scan produces three deliverables, each aimed at a different reader.
Assessor Report
A self-contained HTML file covering all 110 controls, each with its status, the checks that produced it, and the evidence behind them. Filter by status or control family, search, and print to PDF. This is the document you give a C3PAO or an internal assessor.
Summary Report
A short executive version for a cyber-insurer or leadership: the score, status tiles, control-family breakdown, and a prioritized list of gaps. It omits the full 110-row table so the reader sees posture rather than a control inventory.
Evidence Packet
A single zip containing a folder for every one of the 110 controls—each with a plain-language note on what was checked and why it satisfies the objective, plus the judged evidence and its SHA-256 hash. It also carries the raw API responses the scan was built from, and a manifest tying every hash together.
Reports are generated locally on your Windows machine. The only network calls a scan makes are read-only requests to Microsoft.
Where a Human Signs
Some controls can only be established by a person. Proof lets an operator attest to those—and keeps that testimony in a separate lane, forever.
Roughly twenty controls need human confirmation, and thirty-eight are organizational by nature. For these, an authorized operator can record an attestation: their name, their role, a written justification, and a supporting file. The file's SHA-256 hash is recorded in the ledger alongside the attestation itself, so the claim and its proof travel together.
What an operator cannot do is override the tool. Attestation is permitted only on controls the scan marked as needing manual review or as organizational. If a check actually ran and found a control not implemented, no attestation can turn that into a pass. Tool-verified findings and self-attested findings are reported as two distinct lanes and are never merged into a single number—because an assessor needs to know which is which.
Read-Only, by Construction
Zero write permissions
- The application registration requests read-only Microsoft Graph and Exchange scopes and holds no write scopes at all.
- A check that would require write access is treated as a defect in the check, not a feature.
Certificate-based authentication
- Authentication uses a certificate rather than a stored client secret.
- Consent is granted once by your Global Administrator and can be revoked at any time from your tenant.
Who It's For
Defense contractors
Organizations in the defense industrial base preparing for a CMMC Level 2 assessment who need to know where their Microsoft 365 tenant actually stands, and to produce evidence an assessor will accept.
Assessors and consultants
Practitioners who want the technical evidence gathered, hashed, and organized by control before the engagement begins—so the assessment is spent on judgment rather than on collection.
Cyber-insurance applicants
Companies whose underwriter wants documented security posture. The summary report answers that question without handing an insurer a 110-control inventory.
About the Score
Proof reports a scoring estimate as a range, and labels it plainly.
The DoD Assessment Methodology assigns point values to the 800-171 controls, and Proof computes what those points imply for the controls it was able to assess. Because a technical scan cannot assess every control, the result is presented as a ceiling and a floor rather than a single certain number, with the unassessed controls forming the band between them. The headline figure is the ceiling, and it is labeled every time it appears as an estimate, not a certified SPRS score. Your official score comes from your assessment, not from this tool.
Ready to see your evidence?
Choose a plan and start a 14-day free trial—no charge until it ends. Consultants and RPOs can run assessments across their whole client book; a single organization can evidence its own tenant.
Important
TenantSentinel is not a CMMC Third-Party Assessment Organization (C3PAO) and does not perform certifications. TenantSentinel Proof produces technical evidence and analysis intended to support assessment preparation. Control mappings, coverage classifications, scoring estimates, and remediation guidance are informational and do not constitute legal, regulatory, audit, or compliance advice. Determining whether your organization satisfies CMMC 2.0, NIST SP 800-171, or any contractual obligation remains your responsibility and your assessor's.