Garde1 by Complai Solutions: A CMMC Compliance Operating System Built From Scratch
The Challenge
CMMC compliance traditionally costs Defense Industrial Base contractors $50K to $200K in consultants and 6 to 12 months of manual work. Complai Solutions set out to turn that process into software.
The vision required measuring all 110 NIST SP 800-171 controls and 320 assessment objectives against contractors' live systems, continuously. No existing low-code or off-the-shelf tool could carry that load.
Key Challenges Faced
- No Off-the-Shelf Fit
- The problem was too complex and too regulated for configuration tools. It demanded a platform engineered from the ground up.
- Regulatory Complexity at Scale
- 110 controls, 320 assessment objectives, 14 CMMC domains, and native SPRS scoring from -203 to +110, all modeled into a working evaluation engine.
- Live Evidence, Not Screenshots
- Compliance had to be proven from real system configuration, pulled automatically from 20+ security platforms and Windows endpoints, not from manually gathered PDFs.
- Audit-Grade Integrity
- Assessors, the C3PAOs who certify contractors, must trust the output. Every artifact needed versioning, content hashing, full traceability, and signed exports.
The Solution
TekConnected engineered a ground-up platform from scratch. Meeting all four constraints at once ruled out spreadsheets with automations bolted on and any rented workflow tool.
What We Engineered
- Cloud-Native Web Application
- Six integrated product modules in one system of record, hosted on AWS.
- Connector Framework
- 20+ OAuth and API integrations across identity, cloud, endpoint, SIEM, and vulnerability tools.
- Windows Endpoint Agent
- A lightweight service collecting device-level evidence daily across the customer's fleet.
- Multi-Workflow Evaluation Engine
- Scores all 110 controls and 320 objectives against live evidence.
- Tool-Grounded AI Assistant
- The Garde1 Consultant answers cited to the organization's real controls and evidence, with no open-web lookups.
- C3PAO Auditor Portal
- Role-based, signed, tamper-evident audit exports.
Approach and Strategy
- Domain-First Architecture
- TekConnected modeled the full NIST SP 800-171 control set and its 320 objectives before building the interface, so the data model mirrored the regulation.
- Evidence Pipeline Design
- The connector and agent layer maps raw system data to specific controls automatically, eliminating manual screenshot collection.
- Deterministic Evaluation Logic
- Scoring reflects measured reality through native SPRS scoring, not policy text.
- Audit-Grade Data Integrity
- Version control, SHA-256 content hashing, and end-to-end traceability built into every document and evidence record.
- Continuous Monitoring
- Scheduled re-evaluation and drift detection so compliance holds after the assessment, not just before it.
The build case is that some problems outgrow no-code. When the logic runs this deep, across 320 objectives, deterministic scoring, and audit-grade integrity, configuration tools hit a ceiling. A purpose-built platform becomes the product itself: defensible IP rather than a rented workflow.
Technology Stack
Results & Outcomes
- 110 / 110 Controls Modeled
- Full NIST SP 800-171 Rev. 2 coverage.
- 320 Assessment Objectives
- Built into the evaluation engine.
- 14 CMMC Domains
- Scored on a live compliance dashboard.
- 20+ Pre-Built Connectors
- Plus a Windows agent for automated evidence collection.
- 6 Integrated Product Modules
- In a single platform.
- C3PAO Auditor Portal
- Live and functional.
Strategic Impact
- From paperwork to measurement: compliance proven from live systems, not static documents.
- Out of MVP, in production: Garde1 is live and running real assessments at app.garde1.com.
- Built to extend beyond CMMC, with architecture designed to layer additional frameworks (FedRAMP, ISO, SOC 2) over time.
- Software economics: designed to replace $50K to $200K consultant engagements with a continuous SaaS workflow.
- Assessor-trusted output: signed, versioned, fully traceable evidence packages.
Who This Applies To
This build pattern fits an organisation that:
- Faces regulatory logic too deep for configuration tools to model
- Must prove compliance from live system configuration rather than gathered screenshots
- Needs an external auditor to trust versioned, hashed, fully traceable output
- Wants a purpose-built platform as defensible IP instead of a rented workflow






