Skip to main content

RPO Workspace

Assessment work in ASCERA happens in the RPO Workspace, which you reach from RPO Workspace in the left navigation. It is the central place for evaluating and reporting on your organization’s gap assessment readiness, and it is designed for both assessors and regular users to view control statuses, generate reports, and track historical assessments.

ASCERA continuously monitors automations to gather evidence through Automated Control Evidence (ACE) and to maintain ongoing compliance through Continuous Control Monitoring (CCM) where applicable.

The page is divided into two tabs:

  • Active - the current, in-progress gap assessment
  • History - completed gap assessments with detailed records

Active Tab

Gap Assessment

  • Generate Gap Assessment Report - captures a snapshot of the system’s assessment readiness, based on the assessor’s findings and recommendations.
  • Complete Gap Assessment - generates the final gap assessment report and starts a new assessment. The completed assessment moves to the History tab.

Assessor Controls Matrix

Below the gap assessment actions, the Assessor Controls Matrix shows every control in the framework, grouped by domain, with running totals for Met Controls, Not Met Controls, Not Started Controls, and N/A Controls.

For frameworks that support it, such as CMMC Level 2 and NIST 800-171, an SPRS Score is shown alongside those totals.

Two actions apply across the whole matrix:

  • Sync All Controls - brings the assessor matrix into line with the current control states.
  • Mark All Controls As Ready - communicates readiness state to other stakeholders.

The matrix can be narrowed with a search box, a Weight filter, an Is POA&M-able? filter, and status checkboxes for Met, Not Met, N/A, and Not Started.

History Tab

The History tab provides a log of all previously completed gap assessments in a tabular format. Each entry includes:

  • Gap Assessment - the name of the completed assessment, which includes the system name and completion date
  • Completion Date
  • Hash - a unique hash representing the assessment state

Available actions on each row:

  • Expand row - view detailed results for the completed assessment.
  • Copy - copy the hash to the clipboard.
  • Download - save a copy of the assessment data.
  • Delete - permanently remove the assessment from the history log.

Formal C3PAO Assessments

The RPO Workspace covers gap assessments. Formal CMMC Level 2 assessment work, including an assessor compliance matrix, objective-level assessment with QA review, eMASS report generation, and an OSC SSP manager, lives in the separate C3PAO Assessment Workspace, reached from C3PAO in the left navigation. The C3PAO workspace requires a license that includes it.

Best Practices

  • Generate reports regularly to track changes in readiness over time.
  • Use Mark All Controls As Ready to quickly reflect assessor findings across the system.
  • Archive and back up assessments by downloading from the History tab.
  • Use the hash to verify assessment integrity or reference a specific version in audits.