Organization
Define company scope, system boundary, and assessment context.
CMMC Level 2 readiness
Khestra is a compliance workspace built for the Defense Industrial Base — structured around your assessment workflow, SPRS scoring, and SSP/POA&M exports.
Built for defense contractors pursuing CMMC certification
How it works
Khestra mirrors how assessors and compliance teams actually work — organization profile, control review, readiness checks, then audit-ready exports.
Define company scope, system boundary, and assessment context.
Review all 110 controls with status, SSP text, evidence, and POA&M fields.
Track documentation, evidence coverage, and pre-audit checklist items.
Generate SSP, POA&M, and full audit package zip when review is complete.
Product tour
Real screens from the Khestra workspace — controls, SSP authoring, exports, and integrations.
Review each control with status, SSP narrative, evidence attachments, and POA&M fields. Priority queue surfaces 5-point gaps first.
Write control descriptions with org-aware starters, evidence-backed suggestions, and an SSP preview that shows how text will read in the exported document.
Connect Microsoft Entra ID, AWS, GitHub, and Intune to run automated checks and attach evidence snapshots to mapped CMMC controls.
When assessment and documentation are complete, generate SSP documents, POA&M spreadsheets, and a full audit package zip.
Platform capabilities
Purpose-built for assessors, compliance leads, and executives tracking certification progress.
Track your score against the 110-point model with gap visibility and family breakdowns.
MET / NOT MET / PARTIALLY MET workflow with SSP narratives, evidence, and POA&M fields.
Scheduled evidence collectors with drift detection and freshness alerts.
Org-aware narrative starters and optional AI polish from attached evidence.
SSP, POA&M, and bundled audit packages when your assessment is export-ready.
Microsoft Entra ID sign-in with assessor, contributor, and executive roles.
Integrations
Collectors map checks to CMMC control families — MFA and Conditional Access from Entra, CloudTrail and S3 posture from AWS, branch protection from GitHub, and device compliance from Intune.
Join our pilot program. We’ll walk you through the platform with your scope and help you evaluate fit for your certification timeline.