CMMC Level 2 · NIST SP 800-171

Pass your CMMC assessment. Skip the detour.

Answer a guided interview. Walk away with a readiness score, a list of gaps, and a defensible System Security Plan. Built for small defense contractors.

All 110 controls covered
~60 minute interview
30-day money back
Your CMMC Readiness Report
Updated 2 min ago
Your SPRS score
98/110
3 gaps to close before assessment
Access Control
21/22
Audit & Accountability
9/9
Configuration Mgmt
7/9
Identification & Auth
11/11
System Integrity
6/7
Top priority gaps
CM.L2-3.4.9High
User-installed software not technically restricted on macOS
SI.L2-3.14.7Medium
No formal user behavior baseline established
CA.L2-3.12.4Medium
Continuous monitoring strategy not yet documented

The compliance program every DoD contractor now has to face.

CMMC is the Department of Defense's framework for protecting Controlled Unclassified Information across the defense supply chain. If you handle CUI, you'll need certification to keep your contracts.

1

Who needs it

Any contractor or subcontractor that handles Controlled Unclassified Information for the DoD. That's about 80,000 companies.

2

What "Level 2" means

Most contractors need CMMC Level 2 — implementation of all 110 controls in NIST SP 800-171, verified by a third-party assessor.

3

What you submit

A System Security Plan (SSP), a Plan of Action and Milestones (POA&M), and a SPRS self-assessment score.

4

What's at stake

Without certification, you can't bid on or renew DoD contracts. Primes are already requiring it from their subs.

CMMC rollout timeline
In progress
November 2025
Phase 1: Self-assessment requirements appear in DoD solicitations
November 2026 — You are here
Phase 2: Mandatory third-party C3PAO assessments begin
November 2027
Phase 3: Level 2 + Level 3 required on all new contracts
November 2028
Phase 4: Full implementation across all applicable DoD contracts

Four paths. Three are painful.

Here's what contractors are stuck choosing between today.

Hire a consultant
$15,000 – $40,000

A Registered Practitioner drafts your SSP. Quality varies. You wait three to six months.

Cost
$$$$
Time
3–6 months
DIY the template
Free

Download the NIST template. Stare at 110 blank narratives. Hope you got it right.

Cost
$0
Time
80–200 hrs
GRC platform
$15k – $30k/year

Enterprise software built for primes with security teams. Overbuilt for the small end.

Cost
$$$
Time
Ongoing

From unknown to assessment-ready.

A structured interview, a clear diagnosis, and the documents your assessor expects.

1

Tell us about your environment

A guided interview — your tools, your team, your processes. Plain English, no jargon.

~60 min total
2

See where you stand

A readiness score against all 110 controls and a ranked list of gaps with concrete fixes.

Generated in minutes
3

Walk away with your path forward

SSP, POA&M, SPRS worksheet, evidence checklist. Every narrative traceable to your answers.

Ready to submit
Your tech stack 14 of 30
Section 03 · Your tech stack
What do you use to sign in to your business systems?
Your identity provider — the system that authenticates users across your tools.
Okta Workforce Identity
Microsoft Entra ID / Azure AD
Active Directory (on-premises)

A clear read. Every document your assessor wants.

📊

CMMC Readiness Report

Your score against all 110 controls, with a ranked list of gaps by assessor risk. The first thing you want — the last thing most tools give you.

📄

Full SSP

110 control narratives drafted to your environment. Every claim traceable.

🎯

Prioritized POA&M

Pre-populated gap-tracking with remediation steps and timelines.

🗺️

Boundary Diagram

Your CUI environment scope, the #1 source of assessment failure.

SPRS Score & Evidence Checklist

Ready for upload, plus the artifacts assessors will request.

What your finished SSP looks like.

Every narrative is written in the language assessors look for — referencing your specific environment and tagged back to the interview answers that produced it.

  • NIST SP 800-171 Rev 3 structure throughout
  • System description, boundary, roles, and 110 control narratives
  • Confidence flags on every section
  • Ready to export as Word or PDF
See a sample
DRAFT
Meridian Defense Systems
System Security Plan
3.1 AUTHORIZATION BOUNDARY
AC.L2-3.1.1 — LIMIT ACCESS
AC.L2-3.1.2 — TRANSACTION CONTROL
AC.L2-3.1.5 — LEAST PRIVILEGE

Start with the diagnostic.
Add the documents when you're ready.

Diagnostic
Find out where you stand against all 110 controls.
$695
One-time
  • Full guided readiness interview
  • CMMC Readiness Report (110 controls)
  • Prioritized list of gaps
  • Remediation guidance
  • SPRS score worksheet
  • PDF export & email support
Start the diagnostic
Already started with the Diagnostic? Upgrade any time — your fee credits toward the SSP tier. 30-day money back guarantee on both.

The honest answers.

No tool can guarantee assessment outcomes — your assessor is judging your actual environment, not just your document. What we do is tell you, before you ever meet an assessor, where you're strong and where you're exposed. The readiness report scores all 110 controls and flags assessment risk; the SSP narratives are tagged with confidence flags so you know which sections need human review.

Those platforms are priced for mid-market and enterprise — typically $15–30k/year. We're built for the small end. Diagnostic, SSP, and remediation roadmap from a single guided interview, not a platform you configure for months before it produces output.

You'd get generic narratives that don't match assessor expectations. The work isn't "write me an SSP" — it's the structured interview, the diagnostic scoring, the mapping to all 110 controls, and the orchestration that keeps your output internally consistent and traceable. The IRS publishes every tax form for free; TurboTax charges $100 because someone figured out the right questions to ask.

No — intentionally. The interview captures descriptions of how you handle CUI, never CUI itself. You can use Baseline without bringing us into your CMMC assessment boundary.

Version one is tuned for small contractors (10–50 people, cloud-only, M365 GCC High, software or services). If your environment is substantially different — heavy on-prem, manufacturing floors, classified networks — the draft will need more revision. We tell you up front in the intake whether Baseline is a good fit.

Know where you stand. Know what to fix.

One hour of questions. A readiness report in minutes. A defensible SSP the same day.