AI-operated assurance infrastructure for the defense supply chain

Cyber assurance for the Defense Industrial Base has to scale, cost less, and depend less on labor-intensive, point-in-time verification.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC readiness and compliance operations. AI agents perform the recurring measurement, evidence, documentation and readiness workload; accountable humans retain approval, affirmation and professional judgment. Not SaaS. Not consulting. Not a C3PAO.

Only handle FCI? Take the free Level 1 Gap Check →
Generated from your connected cloud’s read-only configuration data, not a survey or a static questionnaire, when you connect a cloud; intake-based if you connect none. Your first PDF is in your inbox minutes after intake, built from your intake answers and sent only to the email on your purchase; connect a supported source and it is re-issued from that source’s configuration data. $999 credits to your first Level 2 subscription invoice if you subscribe with the same billing email within 30 days of receiving the PDF; any amount above that invoice carries to the next one. See a sample report →

The assurance question for the Department. How can DoW establish trustworthy, scalable assurance that a contractor’s asserted implementation state is accurate, today under NIST SP 800-171 Rev. 2, and under Rev. 3 if DoW incorporates it through rulemaking, as its CMMC FAQ (Rev. 2.3, July 2026, B-A3) says it will?

Enclave AI™ by ai4cmmc.ai performs the machine-executable work of establishing and maintaining an evidence-backed NIST SP 800-171 compliance state: measured where a connected source can observe it, substantiated by recorded, hashed evidence where it cannot, and re-measured on a stated schedule. The contractor, its Affirming Official, its assessor, its prime and an authorized government customer, each on the contractor’s grant, read that same recorded state instead of reconstructing it by hand at assessment time. Assessment judgments stay with the contractor and, where one is required, its C3PAO or DIBCAC.

The contractor’s question. It used to be “How do I prepare for and pass my CMMC assessment?”, a question answered with checklist software, document repositories, consultants, SSP generators, POA&M managers and evidence folders. The question now is “How do I continuously know that the compliance state I am affirming is accurate, and how can I prove it?”

Your Affirming Official affirms continuing compliance in SPRS after each assessment and annually thereafter (32 CFR 170.22). Enclave AI records what was measured, when, from which source, and what your team substantiated, each entry hashed with SHA-256 and carried in a tamper-evident audit chain. On Level 1, the chain’s current head is printed on every document you receive, so a later change is detectable against your own copy; Level 2 evidence certificates are Ed25519-signed and checkable at /verify. The record documents the basis and timing of what was affirmed, with the approver’s recorded identity. The decision stays with your Affirming Official. That record is refreshed on a stated schedule: connected sources are re-scanned about every seven days, a full Level 1 cycle runs every 30 days, and Level 2 runs on your tier’s cycle.

What your Affirming Official reviews before deciding comes from that same record: the recorded state of each requirement, the evidence behind it, what changed since the last measurement, and the open gaps and exceptions. Then your Affirming Official decides whether to affirm.

If an accountable official must affirm compliance, Enclave AI™ gives that official technical evidence, refreshed on a recurring schedule, supporting the state being affirmed.

What already applies

The Department of War suspended Phase 2 to reduce bureaucratic burden. It did not suspend your obligation to know and prove your cybersecurity state.

DFARS 252.204-7019 and 7020 already require a current NIST SP 800-171 self-assessment score in SPRS, DFARS 252.204-7021 carries the annual affirmation, and CMMC Phase 1 is in force. Enclave AI™ automates the work behind that obligation: it measures your controls and prepares the SSP, POA&M and evidence your senior official reviews before deciding what to affirm. It re-measures on a stated schedule: connected clouds are re-scanned about every seven days, and your full readiness package is refreshed on your tier’s cycle, every 14 days on Fortress and Sovereign up to every 90 days on Standing. A one-time consultant engagement produces that package once. What follows Phase 2 depends on the DoW CIO’s 60-day review of the program; see the Phase 2 timeline.

The assessment mechanism can change. The need to know whether the controls are actually operating does not.

Level 1
15
FAR 52.204-21 REQUIREMENTS
annual self-assessment
Built On
110
NIST 800-171 CONTROLS
320 assessment objectives
Scored On
−203 to
+110
LEVEL 2 SPRS RANGE
DoD aligned scoring
Filed With
PAT.
PEND.
PATENT PENDING
U.S. Patent & Trademark Office
ElasticD3M, LLC · Patent Pending
See it work

Enclave AI starts from machine measurement of configuration state and technical assurance, not questionnaires. The question is not whether someone completed a questionnaire. It is whether the control is operating, and whether that can be shown as of the last measurement, with the date of that measurement on the record.

Sample view · fictional data · illustrative layout
Meridian Defense Works, LLCSeat 1 · Contractor workspace
Estimated SPRS score
78
Since last cycle
+14
Baseline score
64
Snapshots on file
4
Attestations recorded
93% · 76 / 82
Open tasks
9 of 24
TaskControlStatus
Implement 3.5.10: store and transmit only cryptographically-protected passwords3.5.10Open
Implement 3.1.10: use session lock with pattern-hiding displays after a period of inactivity3.1.10In progress
Implement 3.6.1: stand up an operational incident-handling capability3.6.1Done
46 assets recorded, 12 of them handling CUI · Annual affirmation (32 CFR 170.22): Pending, due 2026-11-30 · Controls that regressed since last cycle: none
Open the full sample dashboards →
Sample view · fictional data · illustrative layout
Section 1 of 4 · Cover & executive summary
CMMC Level 2 Readiness Snapshot™ Report

Intake-based gap analysis for Acme Defense Industries, LLC

Report date: 2026-09-14 · Rendered against: NIST SP 800-171 Rev. 2 (required) · one AWS account connected
Self-Reported SPRS
88
Self-reported readiness score on file, from your intake
Estimated deduction · Enclave AI™
25
From the 7 non-compliant controls the scan measured · not an official measured SPRS score
Coverage is limited to the source you connected; the rest relies on your intake answers
Open the full sample report →

Measure. Agents read configuration metadata from your connected sources, re-scanned about every seven days.

Record. Measured findings and your team’s evidence records are hashed with SHA-256 and carried in a tamper-evident audit chain; Level 2 evidence certificates are Ed25519-signed and checkable at /verify.

Detect drift. Every cycle names the controls that regressed since the last one.

Maintain. Your documents are rebuilt every cycle from the latest measurement.

What the assurance system delivers before anyone asks

The full artifact set, ready for whoever verifies.

Seven deliverables, generated programmatically from your connected sources’ read-only configuration data and your intake: your SPRS readiness report, System Security Plan, POA&M, CUI scoping package, Customer Responsibility Matrix, evidence index, and (for multi-entity contracts) a portfolio roll-up. Refreshed every cycle, with each delivered file’s SHA-256 recorded so a later change to it is detectable. Every document is an output of the same recorded compliance state; your team reviews and approves.

01

Your System Security Plan

All 110 NIST 800-171 controls drafted from your connected cloud’s read-only configuration data and intake answers, under your organization’s name. Your team reviews and approves; Enclave AI does the writing. Rebuilt from current data every cycle, so there is no version-control archaeology in assessment week.

02

Your Evidence Library Index

All 320 NIST 800-171A assessment objectives indexed. The ones your measured scans and your recorded artifacts answer are mapped to that evidence, with the SHA-256 hash recorded for it where one was recorded. The ones nothing has evidenced yet are counted and named on the same index, so you close them before an assessor finds them. Verification-ready is the aim: whoever verifies (your own Affirming Official, a C3PAO, or a government assessor) starts from an indexed, dated record instead of reconstructing one. Rebuilt on your tier’s cycle (every 14 to 90 days); connected sources are re-scanned about every seven days in between.

03

Your POA&M

Every open gap with a proposed owner, target completion date, estimated effort and its place in dependency order; a blocked item names what must finish first. Your readiness review works from the current POA&M, not a spreadsheet. Rebuilt on your tier’s cycle (every 14 to 90 days); connected sources are re-scanned about every seven days in between.

Scalable asset generation

DoD prices Level 2 assessment support in hundreds of person-hours. The artifact set is generated as a compute task.

DoD’s own Regulatory Impact Analysis prices a small entity’s Level 2 certification assessment and affirmations at $104,670 over a three-year cycle, with the C3PAO engagement alone staffed at three people for 120 hours (32 CFR part 170 final rule, 89 FR 83092, at 83185 to 83186). Enclave AI generates the artifact set that work consumes, programmatically: the core deliverable set renders in under a minute, checked by an automated benchmark on every CI build, and your first readiness package is generated after intake, without waiting on a consultant’s calendar. The AI does the assembly; your team spends its hours on judgment calls, not formatting. Enclave AI™ has been in development since April 2026, built against the November 2026 Phase 2 transition and this arithmetic. When the DoW CIO suspended that transition on July 13, 2026, the memo cited prohibitive compliance costs and shortages in third-party assessment capacity, and stated that all other contractual cybersecurity clauses remain intact, DFARS 252.204-7012 included.

The architecture

Built so your FCI and CUI do not need to enter the readiness plane.

Sensitive customer information remains within the customer’s controlled environment; the readiness plane receives only the authorized configuration telemetry necessary to establish compliance state. The architecture is designed so FCI/CUI does not need to enter the central readiness plane.

What the readiness plane keeps includes configuration metadata, the compliance state computed from it, and SHA-256 hashes of evidence that stays with you. What the readiness plane keeps, in full

Enclave AI™ is an assurance system, not another CMMC compliance platform. It establishes, maintains and evidences cyber-compliance state; CMMC is the framework that state is evaluated against today. It converts machine-observed state into controlled, verifiable compliance evidence that each permissioned party can use on the contractor’s grant, without any of them reconstructing the same state, with SHA-256 hashed evidence and Ed25519-signed evidence certificates that make later changes detectable. It relies on the required professional judgment of accountable officials and on the expertise of C3PAOs and the other existing ecosystem stakeholders. The agents take on the repetitive compliance labor; they do not replace accountable officials, assessors or required professional judgment.

The assurance chain, link by link:

  1. Control requirement
  2. Technical implementation
  3. Measurement
  4. Evidence
  5. Validation
  6. Current control state
  7. Drift and change detection
  8. Compliance determination
  9. Accountable human affirmation
  10. Independent verification, when required

Validation in this chain is the agents’ check that each evidence record is complete and in form; files your team supplies stay with you. The affirmation stays with your Affirming Official, and independent verification stays with your C3PAO or DIBCAC.

Metadata-only measurement plane

Don’t send FCI/CUI into another compliance repository. Keep sensitive data in your controlled environment. Six read-only connectors (commercial AWS, Azure and Microsoft 365, plus Google Workspace, Okta and CrowdStrike) under read-only scopes read configuration metadata only: no file, object or message contents are read or stored, and no CUI is ingested. Sensitive customer information remains within the customer’s controlled environment; the readiness plane receives only the authorized configuration telemetry necessary to establish compliance state. The architecture is designed so FCI/CUI does not need to enter the central readiness plane. Evidence integrity is established cryptographically, and every authorized seat sees one current picture of compliance. The boundary, stated precisely →

Integrity you can verify yourself

The platform hashes the scan responses it collects with SHA-256; for files that stay with you, it records the SHA-256 value your team supplies. The recorded artifact manifest, attestations, scope and affirmation are bound into an Ed25519-signed evidence certificate, which names any artifact recorded without a hash. The audit trail is append-only, enforced by the database, not by promise. A C3PAO or contracting officer can verify a certificate offline against our published public key.

A view for every seat

A token-gated workspace for the OSA, a partner dashboard for the C3PAO, a view for your MSP, MSSP or ESP of the entities you grant, on your grant, and an operator console behind it. The posture, POA&M, scope, CRM and evidence artifacts are also served as token-gated Markdown exports, readable by your assessor’s tooling or your own agents, not just as PDF.

One canonical compliance state

Contractor, your MSP, MSSP or ESP, assessor, prime and program office look at the same state.

Enclave AI™ establishes and evidences, on a recurring schedule, the cyber-compliance state that an accountable official, independent assessor, prime contractor or government organization needs to verify.

Today information is translated repeatedly, from contractor to consultant to assessor to prime to government, and every translation adds cost, delay, ambiguity, stale numbers and inconsistent evidence. Enclave AI™ renders one measurement to five seats with different permissions: your workspace, your MSP, MSSP or ESP’s view, your C3PAO’s pipeline, your prime’s roster on a named award, and a program office’s portfolio. Nothing is disclosed to any seat without your grant naming it, and every aggregate counts only what was consented. What each seat sees →

Your MSP, MSSP or ESP: the entities you grant, and nothing else.

Each seat brings its own question to that one state:

  • The contractor (OSA): “Can I safely make this affirmation, and can I defend it tomorrow?”
  • Your MSP, MSSP or ESP: “Can I demonstrate that the services and controls I’m responsible for are actually operating across my client base?” For MSP / MSSP / ESP →
  • Your C3PAO: “Can I verify current state and concentrate assessor effort on exceptions, changes and controls needing human judgment instead of reconstructing the environment every time?” For C3PAO →
  • Your prime: “How do I know the suppliers I rely on remain compliant after they gave me their certification or SPRS information?” For Prime →
  • DoW, an agency or a program office: “How do we obtain trustworthy assurance across an enormous supplier population without paying for, or forcing industry to pay for, continuous manual reassessment?” This is the scale side of the Department’s assurance question at the top of this page. For Agency / PEO →
Human accountability architecture

Who approved this? You will have the answer written down.

AI performs. AI records. AI explains. AI provides evidence. Authorized humans approve the decisions that legally or operationally require human accountability.

Agents perform the recurring work: they measure, assemble, score and deliver on schedule. People keep accountability, authorization and professional judgment, and rule on what the agents produce. Every consequential decision the platform can take, who is accountable for it, and the code that binds it is enumerated and rendered, not typed: who is responsible when the AI is wrong →

Every deliverable Enclave AI™ produces carries a decision record: what the AI produced, what evidence backed it, which quality gate cleared it, and what happened after. Records are sealed in a SHA-256 chain, so any rewrite of recorded history is detectable (tamper-evident), and they map directly to the NIST 800-171 Audit and Accountability family your assessor tests against.

01

Humans decide, AI documents

Documents are delivered once they pass an automated format check; adopting one waits for a named human. The AI produces; your designated executive adopts or rejects, from a signed-in seat, against the SHA-256 of the exact document delivered. When a reviewer disapproves, the reason is captured in the record, not lost in an inbox.

02

Tamper-evident by construction

Each record cites its evidence and carries its approval trail with timestamps, sealed in a SHA-256 hash chain. The database itself refuses edits to recorded history. Your audit trail is a control, not a promise.

03

Assessment-ready exports

An audit package built from the same records your team worked from, mapped to the NIST 800-171 AU family, carrying the hash chain’s verification result. Board-level governance summaries come from the same ledger.

Enclave AI™ by ai4cmmc.ai is an architecture in which AI agents perform measurement, evidence collection and validation, drift detection and artifact maintenance while humans retain judgment, authorization and accountability. Computers do the computing; humans do the executive analysis, review, judgment and data-driven decision-making.

Validation here means the agents check that each evidence record is complete and in form; files your team supplies stay with you, and what they show is your team’s statement.

Reform resilience

Level 1 or Level 2, Rev. 2 or Rev. 3: one architecture, not a new consulting project.

Level 1 and Level 2, Rev. 2 and Rev. 3, and Specialized Assets such as operational technology are capabilities of one AaaS architecture. Level 1 covers the 15 FAR 52.204-21 requirements for Federal Contract Information. Level 2 covers NIST SP 800-171 Rev. 2 for CUI. Rev. 3 is rendered through NIST’s own change analysis, with no Rev. 3 score asserted. At Level 2, operational technology is recorded and documented as Specialized Assets; at Level 1 it is outside the assessment scope (32 CFR 170.19(b)(2)(ii)).

That same recorded state supports self-assessment, C3PAO assessment, delta assessment, prime oversight and government verification without recreating the compliance record for every audience.

Your framework target: Rev 2 today, Rev 3 when you choose

NIST SP 800-171 Rev. 2 is what 32 CFR 170 and DFARS 252.204-7012 bind to today and the only revision with a DoD assessment methodology, so it is the scored baseline: SPRS estimate, POA&M eligibility, Conditional or Final. Rev. 3 (97 requirements, 17 families, 422 objectives) is the emerging target. You choose it at intake or from your workspace, and your workspace documents are also rendered against the Rev. 3 set, mapped through NIST’s own Rev 2 to Rev 3 change analysis, with your Rev. 2 figures alongside. No Rev. 3 score is asserted, because none exists yet.

NIST SP 800-171 defines the security requirements. NIST SP 800-171A defines the assessment procedures. NIST SP 1352, published September 2026, is a NIST primer that gives small businesses a high-level overview of SP 800-171A Rev. 3 assessments; it is reading material. None of them performs the work. Enclave AI™ performs recurring measurement and documentation work against the requirements CMMC uses today: FAR 52.204-21 for Level 1 and NIST SP 800-171 Rev. 2 with SP 800-171A (June 2018) for Level 2 (32 CFR 170.14(c)(3)). DoW has stated it will incorporate Rev. 3 through future rulemaking. NIST does not endorse products and has no role in DoW’s CMMC implementation.

One capability, layered

Knowing your scope is the first half. Acting on it is the second.

Enclave AI™ establishes what you must protect: which systems are in scope, which handle CUI, which can never be touched automatically, and where your control posture stands. That same scope is what an automated response layer needs before it can act safely.

01

Enclave AI™ knows

Asset scope, CUI boundary and control posture. It authorizes nothing and executes nothing. This product, available today.

02

AIR AI™ decides

Correlates separate signals into one incident and proposes containment, inside a scope a commander signed in advance. It holds no credential on any of your systems, so it cannot act on its own conclusion. In development, provisioned per engagement.

03

REL AI™ executes

Holds the credentials and the rollback. Verifies the authorization covers this action against this target right now, executes, confirms it held, and reverses it if it did not. Available per engagement.

No single component both decides and acts, and the separation is enforced by credentials rather than by policy. Enclave AI™ is complete on its own: you can run your CMMC program with it and add nothing else. The response layers attach to it when you want them, and each is provisioned separately.

Level 1

CMMC Level 1 (FCI): 15 FAR 52.204-21 requirements, annual self-assessment, annual affirmation

Level 1 protects Federal Contract Information. It is the 15 basic safeguarding requirements of FAR 52.204-21, self-assessed by your organization every year, with results entered in SPRS and an annual affirmation by your Affirming Official (32 CFR 170.15, 170.22). Level 1 does not permit a POA&M (32 CFR 170.21(a)(1)). Priced separately from Level 2.

Free Level 1 Gap Check
$0

Fifteen questions, one per FAR 52.204-21 requirement. Each answer is recorded as you gave it: in place, not in place, does not apply, or needs evidence. Level 1 has no point score, so none is shown.

Take the free Level 1 Gap Check →
CMMC Level 1 Readiness Snapshot
$299 one-time

Your FCI Scope Record, from a short intake, and one complete Level 1 measurement cycle: what your in-scope connected sources can observe is measured; everything else gets a short evidence request.

Credited in full if you start Level 1 Starter with the same billing email within 30 days of receiving the Snapshot PDF: against your first invoice, with any amount above that invoice applied to the invoices after it.

Enclave AI Level 1 Starter AaaS
$199 per month or $2,388 per year, per OSA entity

A complete Level 1 cycle every 30 days on Starter, with connected sources re-scanned about every seven days.

Your Affirming Official makes the annual affirmation decision and enters it in SPRS; the agents prepare the package.

What the Level 1 agents do →

Level 1 checkout is not open yet. The free Level 1 Gap Check is available now.

CMMC Level 2 (CUI): 110 NIST SP 800-171 Rev. 2 requirements, self / C3PAO / government verification as applicable, annual affirmation

As of September 23, 2026: on July 13, 2026 the DoW CIO suspended the CMMC Phase 2 transition and began a 60-day review of the program, and the USW(A&S) implementing memorandum provides that, during the suspension, solicitations may designate CMMC Level 1 (Self) or Level 2 (Self) only. What still applies.

Two ways to put AI to work for your CMMC Level 2 program

One-time readiness analysis, or documentation kept current every cycle. Both measure from read-only configuration data once you connect a source.

The $999 CMMC Level 2 Readiness Snapshot is a one-time readiness analysis: the first PDF arrives minutes after intake, built from your intake answers, and is re-issued from your connected cloud’s read-only configuration data once you connect a source. A readiness subscription runs Enclave AI™ against your connected cloud and identity configuration, delivering a full CMMC readiness package each cycle: control-gap analysis against the 110-control NIST 800-171 baseline, your SPRS posture, and a prioritized remediation plan, with your SSP and Evidence Library Index building out as your data accrues. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. Billed annually, with a month-to-month option on every tier.

CMMC Level 2 Readiness Snapshot™

Your $999 Level 2 Readiness Snapshot is generated from your connected cloud’s read-only configuration data, not a dated survey or a static questionnaire, when you connect a cloud; intake-based if you connect none. It starts from a 5-minute intake, and the first PDF is in your inbox minutes later, built from your intake answers. Connect any of AWS, Azure, Microsoft 365, Google Workspace, Okta or CrowdStrike (commercial clouds only; read-only, revocable at any time by deleting the role, app or token) and it is re-issued from that source’s configuration data. Enclave AI reads that configuration metadata and turns it into your CMMC readiness analysis, the specific control gaps, and a 30-day remediation list. Async, self-service throughout.

  • Your self-reported SPRS score set beside the estimated deduction from the gaps found
  • Top NIST 800-171 gaps with control IDs and SPRS deduction weights
  • 30-day remediation list, ordered by point recovery impact
  • Your $999 is credited in full if you start a Level 2 subscription with the same billing email within 30 days of receiving the PDF: against your first invoice, with any amount above that invoice applied to the invoices after it, so the Snapshot is a down payment, not a separate cost
Run my Level 2 Readiness Snapshot, $999 →
$999
one-time
PDF within minutes of intake
CMMC L2 Readiness Subscription

Pick the tier that fits your environment. Billed annually, with a month-to-month option.

Standing
$8,340/yr
Small contractors. Every 90 days. 1 entity. Or $695/mo.
Details →
Sentinel
$11,940/yr
Affirmation maintenance. Every 30 days. 1 entity. Or $995/mo.
Details →
Garrison
$17,940/yr
Full package every 60 days. 1 entity. Or $1,495/mo.
Details →
Standard · 30-day cycle
$29,940/yr
Full package every 30 days. 1 entity. Or $2,495/mo.
Details →
Fortress
$59,940/yr
Full package every 14 days. 1 entity. Or $4,995/mo.
Details →
Sovereign
$149,940/yr
Up to 10 entities, each every 14 days. Consolidated parent roll-up. Or $12,495/mo.
Details →

Above 10 entities or a custom contract structure: not offered self-serve at this time · Fair-use terms

What exactly do I get for the $999 Level 2 Readiness Snapshot?

A PDF in four sections, in your inbox minutes after intake. The cover sets your self-reported SPRS score beside the estimated SPRS deduction from the gaps found. The next section lists the top NIST 800-171 control gaps (up to seven) with control IDs, SPRS deduction weights per the DoD Assessment Methodology, and the evidence required to close each one. Then a four-week remediation plan, ordered by point recovery impact, and a methodology note. The first PDF is built from your intake answers; connect any of commercial AWS / Azure / Microsoft 365, Google Workspace, Okta or CrowdStrike for read-only evidence collection and it is re-issued from the measured findings, or skip the connectors and keep the intake-based gap analysis. This is a readiness analysis, not a C3PAO pre-assessment, not consulting, not a legal opinion.

Is CUI leaving my environment?

No. Every connector is read-only, and the scanners read configuration metadata only, never the data itself. AWS uses a one-click CloudFormation role with an inline, configuration-metadata-only policy and no s3:GetObject. Azure uses a Service Principal with Reader + Security Reader at subscription scope. Microsoft 365 uses an app registration with read-only Microsoft Graph application permissions. Google Workspace uses a service account with domain-wide delegation and a read-only Admin SDK Directory scope. Okta uses an API token, and setup asks for one created under a Read-Only Administrator role. CrowdStrike uses an OAuth2 API client, and setup asks for read scopes only (Hosts and Prevention Policies). No CUI is harvested. Every connector is revocable at any time by deleting the role / app / token. Full details in the privacy policy and the DPA attached to every subscription.

Does Enclave AI™ conduct CMMC assessments?

No. Level 2 certification assessments are conducted by C3PAOs authorized by the Cyber AB or by DCMA DIBCAC, and self-assessments are the contractor’s own. What we deliver is the readiness work the agents perform before the C3PAO arrives, and we sit on the readiness side of the 32 CFR part 170 firewall by design. Our policy position explains why.

Will this guarantee I pass my C3PAO assessment?

No agent, consultant or tool can guarantee an assessment outcome, the C3PAO decides. What we do: index all 110 controls and all 320 objectives, separating what your connected clouds measured, what you recorded, and what still has no evidence at all. Assessors score each requirement on whether it is implemented and evidenced; the agents keep that evidence organized and dated. The aim is that your assessor validates evidence instead of waiting for it to be assembled.

How does billing work?

The $999 Level 2 Readiness Snapshot is a one-time charge, nothing to cancel. Subscriptions are billed annually in advance by default; every tier also offers a month-to-month option. Stopping is self-serve in your Stripe billing portal, and takes effect at the end of the paid period you are in. Access continues through that period. Full details on the cancellation page.

Read the full FAQ →

Get your CMMC readiness analysis in minutes

CMMC Level 2 Readiness Snapshot™, $999, PDF in your inbox in minutes.

A directional SPRS estimate from your environment’s read-only cloud configuration data, next to the score you report. The first PDF is built from your intake; connect a supported source (read-only, revocable at any time) and it is re-issued from measured configuration data. Enclave AI™ does the work.

Run my Level 2 Readiness Snapshot →