The Engine Behind Our Speed
PolicyCortex - NIST & CMMC Evidence Automation
PolicyCortex connects live control state, remediation work, and evidence so your NIST SP 800-171 self-assessment is defensible today and reusable for whatever CMMC becomes next.
Regulatory update · July 13, 2026
CMMC Phase II is paused. Phase I is not.
The Department suspended the transition to Phase II and pending or future CMMC implementation milestones while it reviews the program. Phase I self-assessments remain in place. During the interim, NIST SP 800-171 Rev. 2 will be enforced through self-assessments and selected government-led assessments, and DFARS 252.204-7012 still requires contractors and subcontractors to safeguard covered defense information.
What PolicyCortex Is
PolicyCortex is AeoliTech's policy-as-code governance platform, built to automate the control validation, evidence collection, and drift detection that consume the most calendar time in a manual CMMC readiness program.
It is not a product we resell. It is the technology we built and deploy in every AeoliTech CMMC engagement.
PolicyCortex runs as a native integration with Azure, AWS, and GCP, including Azure Government Cloud and M365 GCC/GCC High environments where most DoD contractor CUI environments live.
The Problem It Solves
Manual CMMC readiness takes 12-18 months not because the controls are complicated, but because evidence collection and control validation are time-intensive when done by hand. A compliance analyst manually pulling screenshots of access control configurations, logging every change, and maintaining an up-to-date SSP burns 40-60% of the readiness calendar on documentation tasks that produce no new compliance value.
PolicyCortex automates those tasks. Controls are validated against live system state. Evidence is collected continuously and tagged to CMMC practice areas. When something drifts, a configuration changes, a user is provisioned outside policy, a logging gap appears, PolicyCortex flags it immediately instead of at the next manual review cycle.
How It Connects to CMMC
PolicyCortex is configured during every AeoliTech Acceleration and Evidence Vault engagement to monitor and document against the 110 NIST SP 800-171 Rev. 2 requirements that comprise the current CMMC Level 2 baseline:
Access Control (AC)
Policy enforcement rules validate least-privilege configurations, MFA enforcement, and session controls continuously.
Audit & Accountability (AU)
Log collection, retention, and integrity validation are automated and evidence-packaged.
Configuration Management (CM)
Baseline deviations are detected in near-real time, with evidence of corrective action automatically captured.
Identification & Authentication (IA)
Identity governance rules enforce and document authentication standards.
Incident Response (IR)
Playbook automation supports documentation of IR test and execution events.
System & Comms Protection (SC)
Network segmentation and encryption configurations are continuously validated.
All evidence is maintained in a structured vault, organized by CMMC domain, requirement, and assessment objective, so a self-assessment, selected government review, prime-contractor review, or future C3PAO assessment starts from the same traceable record.
The AeoliTech ↔ PolicyCortex Relationship
AeoliTech is the cleared, founder-led CMMC readiness practice. PolicyCortex is the platform AeoliTech built and uses to deliver engagements faster, with higher evidence quality, than a manual approach can match. They are operated together: AeoliTech provides the cleared engineering expertise and CMMC delivery framework; PolicyCortex provides the automation layer.
PolicyCortex also operates as a standalone platform at policycortex.com for organizations that want to deploy it independently. In every AeoliTech CMMC engagement, it is deployed, configured, and operated by the same cleared engineer leading your readiness program.
Why This Matters
The July 13 pause makes continuous evidence more important, not less. A one-time certification sprint can go stale while the program is under review. PolicyCortex keeps the assessment score, SSP, POA&M, control state, and supporting artifacts aligned so the same work supports today's Phase I obligations and tomorrow's revised assessment model.
Leonard Esere built the controls at MITRE, carried the ATO at LANL, and ran PCI DSS at Frontier Airlines, and then built PolicyCortex to automate the most labor-intensive parts of that same work. The platform is not theoretical. It is the product of 12+ years of hands-on federal compliance delivery.