The Altiri Governed Knowledge Layer (AGKL) turns compliance documentation into a living, versioned, assessor-navigable asset — built on the Open Knowledge Format (OKF) and owned entirely by you.
An estimated 70,000 defense suppliers are expected to need CMMC Level 2; fewer than 2,000 are certified.
CMMC Phase 2 — the rule requiring third-party Level 2 certification on applicable new DoD contracts — has been suspended pending a 60-day review, so the previously anticipated November 10, 2026 effective date is no longer a confirmed timeline. With a 6–9 month typical readiness runway, the organizations that clear their windows calmly will be the ones for whom "where is the evidence, and is it current?" stopped being a research question months earlier.
AGKL reshapes the documentation behind CMMC Level 2 from a set of files into a versioned, linked, queryable knowledge layer — your assessor-facing record, on infrastructure you designate.
Policies, controls, evidence, POA&M items, risks, and decisions — versioned, linked, plainly readable files mapped to NIST SP 800-171 Rev 2, on infrastructure you designate.
Every change to every document is recorded: what, when, by whom. Documentation change control as a property of the format, not a process bolted on.
Every evidence item carries a date and a review cycle; the system flags what's expiring before an assessor finds it.
Assessor-style questions answered from your own record with file citations; validated to say "that's not in the record" rather than invent. Human approval gates every AI-proposed change. Nothing sensitive leaves your environment through any AGKL component.
Two tiers. Foundation is fixed-fee and gets AGKL stood up on infrastructure you designate; Managed Curation is a monthly retainer that keeps the knowledge layer current as your evidence, controls, and SSP evolve.
| Tier | Scope | Deliverable | Fee |
|---|---|---|---|
| Foundation | One-time AGKL deployment on client infrastructure: OKF schema mapping, okf-grc conventions wired up, NIST SP 800-171 Rev 2 control linkage, initial SSP and policy concepts authored in your bundle. | Live instance with SSP, policies, control map, and one full evidence cycle; written deployment handoff. | $45,000 fixed fee |
| Managed Curation | Ongoing retainer: monthly evidence review, control and POA&M updates, stale-item flagging, pre-assessment walk-throughs twice per year. | Assessment-ready knowledge layer maintained continuously; named Altiri curation lead. | $6,500 / month retainer |
Every knowledge bundle, evidence artifact, policy, System Security Plan, control map, and POA&M created or maintained as part of your AGKL engagement is owned by you, the client — not by Altiri. The OKF specification is an open standard published by Google Cloud; Altiri holds no ownership claim on it. The okf-grc conventions are open-source and maintained by Altiri LLC; you receive an irrevocable license to use, fork, and extend them on your own infrastructure, including after the engagement ends.
On retainer termination, you retain a complete, portable copy of your bundle in the OKF schema you designated at deployment. Altiri does not retain a working copy of your evidence, SSP, or control data once the engagement closes; we retain redacted, anonymized engagement notes scoped to the practitioner's own internal QA, not your record. Source-conversion escrow is available — your bundle can be cross-rendered to a JSON or YAML flat-file form on request, so it remains consumable by tools other than AGKL without an active retainer relationship.
Seven questions defense suppliers ask most about AGKL.
AGKL is not a GRC platform, not a managed hosting service, and not a CMMC consulting engagement. It is a knowledge-layer deployment on infrastructure you designate (your laptop, your VPC, your Git host, or an air-gapped instance). Compliance program management — gap assessments, SSP authorship, control implementation, C3PAO coordination — is delivered as a separate CMMC advisory engagement.
GRC platforms centralize the compliance record for a compliance team's day-to-day workflow and keep it inside the vendor's product. AGKL turns the record itself into a versioned, linked, queryable knowledge layer using the Open Knowledge Format — so the questions you'd ask an assessor ("where is the evidence for AC.L2-3.1.5, and is it current?") are answered by the structure of the data, not by a UI built by the GRC vendor. You own the bundle; the format is open; the AI that lives on top cites the file it answered from.
Your evidence, SSP, control map, and POA&M are stored on infrastructure you designate under your own accounts. On retainer termination, you retain a complete, portable copy of your bundle in the OKF schema you chose at deployment. The OKF specification is open and published by Google Cloud — it does not depend on Altiri. The okf-grc conventions are open-source with an irrevocable license; fork, rename, or republish them without our involvement. Source-conversion escrow to a flat JSON or YAML form is available on request, so the bundle remains consumable by tools that are not AGKL.
AI in AGKL is advisory only. Every AI-proposed change to your bundle requires explicit human approval before it is committed. AI answers are scoped to your record: if the answer is not in your bundle, the agent returns "not in the record" rather than inventing. Nothing sensitive leaves your environment through any AGKL component — all model access is configurable to run against local models, your own cloud project, or an air-gapped instance.
AGKL does not act as a system of record for your compliance program — your SSP and POA&M remain authoritative. AGKL does not operate as a CMMC assessor, C3PAO, or Registered Provider Organization. AGKL does not certify you, does not issue findings, and does not replace the role of a C3PAO at assessment. AGKL does not own your data, does not train external models on it, and does not transmit it off your designated infrastructure.
Foundation is a one-time, fixed-fee deployment — your scope on engagement signing determines the deliverable; no hourly overruns creep in mid-engagement. Managed Curation is a flat monthly retainer priced against named deliverables (monthly evidence review, stale-item flagging, twice-yearly pre-assessment walkthrough), not against seat count or evidence volume. Engagement scope and any change in scope are agreed in writing before work begins in either tier.
An assessor navigates by control identifier. Each NIST SP 800-171 Rev 2 control — for example AC.L2-3.1.1 — is a hub linking to the implementation statement, the relevant policies, the evidence artifacts, the named owners, the last review date, and the change history. They can ask AGKL questions and get cited answers from your bundle; or they can browse the control map directly. Nothing in AGKL is shaped to flatter the audit — staleness shows up honestly, missing evidence shows up as missing, and gaps remain visible until you choose to close them.