Compliance Disclaimer
Last updated: June 13, 2026
Please read this disclaimer carefully before using CMCGuardian or relying on any documents it generates.
CMCGuardian is a preparation tool, not a certification
CMCGuardian, operated by SharpAudit LLC, helps organizations prepare self-assessment documentation aligned to NIST SP 800-171 Rev. 2 and CMMC Level 2. It generates draft System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and gap reports, and it calculates a Supplier Performance Risk System (SPRS) score based solely on the information you provide.
CMCGuardian does not:
- Certify, validate, or attest to your compliance with any standard or regulation;
- Act as a Certified Third-Party Assessment Organization (C3PAO), registered practitioner, or assessor;
- Guarantee that you will pass any assessment or achieve any certification;
- Replace the judgment of a qualified compliance professional or assessor.
You are responsible for the accuracy of your documentation
The documents and scores CMCGuardian produces are drafts generated from your inputs. You are solely responsible for reviewing, verifying, correcting, and validating all output before relying on it or submitting it to the Department of Defense, SPRS, a prime contractor, an assessor, or any other party.
Submitting inaccurate or unsupported information to the federal government — including an inaccurate SPRS score or SSP — can carry serious legal consequences, including potential liability under the False Claims Act. CMCGuardian does not verify the truth of your answers. Before submitting any self-assessment, you should ensure your documentation accurately reflects your actual security practices, and you should consider independent review by a qualified professional.
No legal advice
Nothing provided by CMCGuardian or SharpAudit LLC constitutes legal advice. For questions about your specific legal or contractual obligations, consult a qualified attorney or compliance professional.
No CUI
CMCGuardian runs on commercial cloud infrastructure and is not authorized for the storage, processing, or transmission of Controlled Unclassified Information (CUI), Federal Contract Information (FCI), classified, or export-controlled information. Describe your security practices — not the protected data itself.
Questions
Contact SharpAudit LLC at support@cmcguardianapp.com.