How It Works

From purchase to assessment-ready in five straightforward steps

1

Get Access

Demos are coming soon. Once we launch, you’ll purchase online and deploy in your own environment — no sales calls.

2

Deploy On-Premises

Deploy the OVA VM appliance in your own VMware or VirtualBox environment. Your data never leaves your network.

3

Answer Controls

Work through your controls with AI-assisted guidance and contextual help at every step — whether you're on NIST 800-171, NIST 800-53, or CMMC.

4

Upload Artifacts

Attach required evidence and documentation for each control using our checklist.

5

Prepare for Assessment

Track progress, generate reports, and get ready for your C3PAO or self-assessment.

Key Features

Everything you need to prepare for your CMMC assessment

Multiple Compliance Frameworks

Full NIST 800-171 (Level 1 & Level 2) with all 800-171a assessment objectives, plus NIST 800-53 Low, Moderate, and High baselines for federal systems.

Virtual ISSO AI Assistant

AI-powered assistant that helps write and review implementation statements for your controls. Supports Anthropic Claude, OpenAI, and self-hosted models via LM Studio — bring your own API key.

Artifact Management

Checklist of required evidence with upload capability for each control. Know exactly what documentation assessors expect.

Contextual Help

Guidance and help statements for each control explaining what assessors are looking for, in plain language.

Progress Dashboard

Track completion status across all control families. See your tentative and reviewed scores at a glance.

Assessment Prep Workflows

Guided preparation for both Level 1 self-assessment and Level 2 C3PAO assessment. Review and approval workflows included.

Access Audit Tool

Compare User records against Active Directory or System Outputs to identify orphaned accounts, unauthorized access, and access control gaps with tamper-evident audit logging.

Device Inventory Tracker

Track network devices and compare port baselines against nmap scans. Identify unauthorized devices and unexpected open ports automatically.

Pre-Assessment Readiness Scoring

Automated readiness scoring reviews your implementation status, evidence linking, and documentation completeness to tell you if you're ready for assessment.

POA&M Tracking

Plan of Action & Milestones management with milestone tracking, evidence attachments, and change history for audit readiness.

Why On-Premises?

Our deployment model is a key differentiator that saves you money and complexity

No FedRAMP Required

Cloud-hosted GRC tools handling CUI require FedRAMP Moderate authorization. By running on-premises, we avoid this mandate entirely—saving $500k-$1M in compliance costs that would otherwise be passed to you.

Your Data Stays Yours

Sensitive compliance documentation and CUI never leaves your controlled environment. Full data sovereignty with no third-party access.

VM Appliance Simplicity

Import the ~4GB OVA VM appliance into VMware or VirtualBox and boot. No container runtime, no complex infrastructure—just attach and start.

Technical Requirements

Minimal infrastructure needed to run Arcana-GRC

  • Deployment: OVA VM appliance for VMware or VirtualBox.
  • System: 4 CPU cores minimum, 8GB RAM recommended
  • Storage: 40GB for the VM. The appliance is ~4GB on disk — the remainder is headroom for uploaded artifacts, database growth, and backups.
  • Network: Internet connection required for license validation
  • Browser: Modern browser (Chrome, Firefox, Edge, Safari)

Frequently Asked Questions

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is a cybersecurity framework based on NIST 800-171 controls. It's required for companies in the Defense Industrial Base (DIB) that do business with the Department of Defense. CMMC Level 1 is for companies handling Federal Contract Information (FCI), while Level 2 is for those handling Controlled Unclassified Information (CUI). Organizations outside the DIB also use NIST 800-171 to protect sensitive information and demonstrate strong cybersecurity practices.

Why is Arcana-GRC on-premises instead of cloud-based?

Cloud-hosted GRC tools that handle CUI are required to have FedRAMP Moderate authorization—a process that costs $500,000 to $1 million and $150,000+ annually to maintain. These costs get passed to customers. By running on-premises, we avoid FedRAMP entirely, allowing us to offer our tool starting at just $30/month instead of $2,000+. Plus, your sensitive data never leaves your network.

How does licensing work?

Once Arcana-GRC is released for general availability, you will receive a license key and a download link via email after purchase. You import the OVA VM appliance into VMware or VirtualBox and enter your license key on first run. The application validates your license online initially, then periodically re-validates with a grace period for offline operation.

What support is included?

The software includes documentation and contextual help within the tool. For additional support, you can purchase RP consulting hours or contact us via email. We're also happy to answer questions before purchase.

What are the downsides of self-hosting?

With on-premises deployment, you are responsible for securing the environment where the software runs. This includes keeping your host system updated, securing network access to the tool, and maintaining backups of your data. For most organizations already handling CUI, this is consistent with your existing security responsibilities.

Can I try before I buy?

We’re releasing guided demos of Arcana-GRC soon. Learn more → or contact us to be notified when they go live.

How do I know which plan I need?

If your contracts only involve Federal Contract Information (FCI), choose CMMC Level 1 (also includes NIST 800-53 Low). If you handle Controlled Unclassified Information (CUI) or need the full NIST 800-171 control set, choose CMMC Level 2 / Commercial (also includes NIST 800-53 Low, Moderate, and High). When in doubt, contact us for guidance.

Ready to Get Started?

See our transparent pricing and purchase the right level for your organization.

View Pricing