
Pre-configured assessment templates for vendor risk, security review, compliance review, asset impact analysis and more, are all available in the C1Risk platform. You can also provide your own custom assessments to the C1Risk platform. Here is a quick and easy guide to for creating and uploading your internal and external risk assessments.

Policies, controls, and evidence can be mapped to regulations and standards then easily viewed from your GRC Library in C1Risk


Audit can be managed on-screen with your Auditor in the C1Risk platform. Set your evidence collection period then see your regulatory/standard control library, mapped internal controls, and relevant evidence, based on your selected audit period.

As documentation for audit is collected, compliance managers review and approve/reject documents and track this process in the C1Risk platform.

Set it and forget it! Automate evidence collection on the C1Risk platform.



This video will walk you through the following:
1. How to map internal controls to standards or regulations
2. How to map standards and regulations to internal controls
3. How to bulk upload internal controls with mapping


Use the Control Library as your main workflow for setting up your Internal Controls.

Evidence from an IRL, PBC, or from your own spreadsheets, can be easily bulk uploaded into the C1Risk platform.


Reports and assessment review/response/finding details can be quickly exported to either an .CSV or PDF report for your clients.


Once you have responded and submitted your assessment, upon review, the risk manager will send you a notification with any findings/issues that require further attention or risk mitigation.

Mapping Findings to the Risk Register and Risk Register to the Vendor to provide a Vendor Risk Score.


CMMC requires a NIST Self-Assessment be submitted to the Supplier Performance Risk System (SPRS - "Spurs"). This video demonstrates how managed service providers, or your own internal team, can easily conduct the Self-Assessment, including:
1. Sending the assessment to one or multiple entities
2. Respond with access to 800-171A implementation guidance
3. Auto-score the assessment based on the DoD scoring methodology
4. Auto-create findings
5. Export a ready for submission report

Once an assessment has been completed, you can track and mitigate findings in the C1Risk platform and/or export a summary report of the assessment in Excel or PDF format with the click of one button.

Why wade through spreadsheets scoring assessments, adding findings, and creating reports, when you can easily auto-create and manage findings and reporting in the system or "one-click" export reports into PDFs or Excel. Great for MSP, Consultants and TPRM Teams.

All C1Risk assessment templates can be configured to auto-create findings based upon responses. See how easy it is to score an assessment using the C1Risk platform.

CMMC Certification is easy, affordable, and assured on the C1Risk platform. No need for expensive consultants and spreadsheets when you have all the tools and information you need on our best-in-class integrated risk management platform:
1. Complete your assessment with the 800-171A guidance supplement
2. Auto-score your response and create findings and risk mitigation plans
3. Create export your 'ready for submission report' and for SPRS

All DIBs (Defense Industrial Base Sector) vendors must submit a NIST 800-171 Self-Assessment through SPRS (https://www.sprs.csd.disa.mil/) before December 31. C1Risk provides the Assessment and the report needed to submit to SPRS for quick, complete readiness as you begin your CMMC journey.

Fast, reliable, affordable. Get CMMC Certified with C1Risk on our best in class, integrated risk and compliance management platform.