- What's the difference between the Policy Wizard and the Management Platform?
- The Policy Wizard generates documentation: it asks structured questions about your environment and composes a complete policy and procedure set from CCA-authored content. The Management Platform handles everything that happens after — acknowledgement campaigns, version control, scheduled review reminders, guided tabletop exercises, and the audit-readiness dashboard. Most customers use both; some bring their own policies and only use the Management Platform (Change Management tier).
- What does NIST SP 800-171 mapping mean?
- Every Poliato-authored policy and procedure is pre-mapped to specific NIST SP 800-171 control identifiers (for example, AC.L2-3.1.1 for access control). When your assessor asks which document addresses a given control, the assessment navigator answers in one click. The reverse-mapping view lets you start from a control ID and see every policy and procedure that addresses it.
- Can I bring my own policies instead of using the Wizard?
- Yes. The Change Management (BYOP) tier is built for this case — upload your existing policy and procedure documents and use Poliato as the management layer. Control mapping is manual on the BYOP tier, automatic on the With Policies tier where Poliato authored the content.
- How do acknowledgement campaigns work?
- Send any policy version to your roster of managed users. Each recipient gets a notification, reads the policy, and acknowledges it. Poliato records timestamps, user identity, and the exact policy version. Automated reminders nudge stragglers. The output is a C3PAO-defensible report that proves who agreed to what, when — exportable as audit evidence.
- What is a guided tabletop exercise?
- A tabletop exercise is an incident-response rehearsal that CMMC effectively requires. Poliato runs structured scenarios drawn from NIST guidance, prompts each participant for their response at each stage, automatically transcribes the conversation, and produces an exercise artifact ready for the audit binder.
- Can subcontractors use Poliato?
- Yes — via the subcontractor portal. Invite external parties to acknowledge specific policies without granting them full platform access. Their acknowledgements roll into your reporting alongside your internal roster. Useful for CMMC flow-down requirements where the prime contractor needs evidence of subcontractor compliance.
- Can I export documentation if I cancel?
- Yes. PDF export is available at any time during the trial, any paid subscription, and remains usable after cancellation. The PDF is a point-in-time record sufficient to demonstrate compliance. Editable Word export is not supported by design — the living version of each document stays in the platform.