Killinchu / UDS — full injection
UDS Core compatible ZARF-packaged DOCTRINE v11 LOCKED · 749 · 14 · 163 · SLSA L1 honest (L2 in progress) · Λ Conjecture (not a theorem)
/uds › /uds/cmmc

CMMC Level 1 — 17 practices (FAR 52.204-21)

CMMC Level 1 protects Federal Contract Information (FCI) via the 17 basic safeguarding practices of FAR 52.204-21, self-attested annually in SPRS at no cost. Below is an honest self-assessment of the killinchu demo posture — no C3PAO assessment, no "17/17 MET" overclaim.

5 COMPLIANT
met in demo posture
7 PARTIAL
met on cluster deploy
5 N/A
facility/founder action
17 total
FAR 52.204-21 practices

The 17 practices — honest tally (6 domains: AC · IA · MP · PE · SC · SI)

DomainPracticeRequirementStateNote
ACAC.L1-3.1.1Limit system access to authorized usersPARTIALKeycloak/OIDC in UDS Core; demo Space is single-operator.
ACAC.L1-3.1.2Limit access to permitted transactions/functionsPARTIAL2-person Yuyay gate + Pepr admission; full RBAC on cluster deploy.
ACAC.L1-3.1.20Verify/control connections to external systemsPARTIALAir-gap default; egress audited (harden-runner egress-policy).
ACAC.L1-3.1.22Control info posted on publicly accessible systemsCOMPLIANTPublic surfaces carry only non-CUI demo data; honest labels.
IAIA.L1-3.5.1Identify users/processes/devicesPARTIALOIDC identities on cluster; demo Space anonymous read.
IAIA.L1-3.5.2Authenticate identities before accessPARTIALKeycloak auth on UDS Core deploy; demo read is public by design.
MPMP.L1-3.8.3Sanitize/destroy media before disposalN/ANo physical CUI media in HF demo; founder action on contract.
PEPE.L1-3.10.1Limit physical access to systemsN/ACloud-hosted demo; air-gap tower is founder-controlled premises.
PEPE.L1-3.10.3Escort/monitor visitorsN/AFacility control = founder action; not in scope for demo.
PEPE.L1-3.10.4Maintain physical-access audit logsN/AFacility control = founder action.
PEPE.L1-3.10.5Control/manage physical access devicesN/AFacility control = founder action.
SCSC.L1-3.13.1Monitor/control comms at boundariesPARTIALIstio mTLS + NetworkPolicy in bundle; default-deny manifests.
SCSC.L1-3.13.5Public-access subnets physically/logically separatedPARTIALNamespace isolation + AuthorizationPolicy; full segmentation on deploy.
SISI.L1-3.14.1Identify/report/correct flaws timelyCOMPLIANTTrivy + Dependabot + gitleaks CI; SBOM diff pipeline.
SISI.L1-3.14.2Provide malicious-code protectionCOMPLIANTSigned images only; cosign verify-blob gate; NeuVector in UDS Core.
SISI.L1-3.14.4Update malicious-code protection mechanismsCOMPLIANTAutomated CI scanners pinned + Dependabot updates.
SISI.L1-3.14.5Perform periodic + real-time scansCOMPLIANTTrivy on every push; NeuVector runtime scan on cluster.

CMMC Level 1 is a self-attestation — an authorized company official affirms compliance in SPRS. It is not a third-party (C3PAO) certification; that is Level 2+. CUI-driven Level 2/3 controls are deferred until a contract imposes CUI.

Deeper delta (live, public)

The Space serves a live CMMC Level 2 / NIST SP 800-171 (110-control) delta as a real data endpoint — useful for the moment a contract escalates scope: /api/killinchu/uds/v1/cmmc/delta (HTTP 200). It reports honest SATISFIED / PARTIAL / ROADMAP / N/A tallies per control family — explicitly "not a C3PAO assessment".

Verifiable evidence

ADDITIVE · self-contained · Doctrine v11 LOCKED 749/14/163 · Λ Conjecture 1 · every cited link curl-verified HTTP 200 · sign: Yachay <yachay@szlholdings.dev> · Co-Authored-By: Perplexity Computer Agent