What it measures
Which Snapshot this is. The CMMC Level 2 Readiness Snapshot covers Controlled Unclassified Information (CUI): the 110 NIST SP 800-171 Rev. 2 requirements and their 320 assessment objectives. Handle only Federal Contract Information (FCI)? The CMMC Level 1 Readiness Snapshot covers the 15 FAR 52.204-21 requirements for $299. Level 1 checkout is not open yet.
The agents read the read-only configuration data of the clouds you connect and compare it against the 110-control, 320-objective NIST 800-171 baseline, measuring the controls those sources can show. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. The result is your CMMC readiness analysis generated from your own data, not a survey or a static questionnaire when you connect a cloud; intake-based if you connect none, so you see your actual starting point and your specific gaps before an assessor does, with the runway to close them on your own schedule. A readiness subscription re-scans connected sources about every seven days and rebuilds the package on its tier’s cycle.
Two evidence sources feed the report:
- Read-only scans of any source you connect: AWS (one-click CloudFormation role), Azure (Service Principal with Reader + Security Reader at subscription scope, plus Microsoft Graph Policy.Read.All), Microsoft 365 (Service Principal with read-only Microsoft Graph application permissions), Google Workspace (service account with the read-only Admin SDK directory scope), Okta (API token created by a Read-Only Admin), CrowdStrike Falcon (OAuth2 API client with read scopes). You can revoke each connector on your side at any time. Every measured finding cites a NIST 800-171 control ID, its SPRS deduction weight per the DoD Assessment Methodology, and the resource it was measured on; an excerpt of the API response behind it is kept on file with its SHA-256 hash.
- Your intake form. Captures your primary CUI environment (including on-premise and hybrid, which no connector reaches), your self-reported SPRS score, your security tools, your DFARS 252.204-7012 flow-down and any prior third-party assessment.
Connect zero clouds and you get an intake-based directional gap analysis. Your first PDF, sent within minutes of intake, is intake-based. Connect a source and a re-issued report follows with measured findings for the controls that source can show, built from the first connected source whose scan completes; sources connected after that re-issue are not added to it (a readiness subscription reads them on its next cycle).
What you get
- Cover page: your self-reported SPRS score and, when you connect a cloud, the estimated SPRS deduction from the non-compliant controls the scan found. That deduction is the headline. Three patterns worth checking: no deduction means the controls the scan could reach agree with your self-assessment, while the controls it could not reach are unmeasured, not confirmed. A small deduction points to a short remediation list. A large deduction is worth reviewing with your compliance counsel before your next affirmation.
- Body: your top NIST 800-171 control gaps (up to seven) with control IDs (3.1.1, 3.13.8, etc.), SPRS deduction weights per the DoD Assessment Methodology, and, for measured findings, the resource each finding came from, with the underlying API response kept on file under a SHA-256 hash.
- 30-day remediation list: week-by-week actions ordered by point recovery impact. Each measured gap on it shows the points it recovers if fully closed.
- Methodology note: which sources were measured, which were not, and the scoring basis. The report is for internal preparation: it is not a C3PAO assessment and is not to be filed as an official DoD document.
How it works
- Pay. Stripe checkout. One-time $999. Self-service, start to finish.
- Open your onboarding email (sent as soon as Stripe confirms your payment). Click the onboarding link inside.
- Submit the intake and connect any of AWS, Azure, Microsoft 365, Google Workspace, Okta or CrowdStrike for measured evidence. Skip the connectors if you prefer intake-only.
- Receive your PDF. Inbox within minutes of intake. Links, order status, downloads and refund requests: the help page.
What it is, and isn’t
The Level 2 Readiness Snapshot is a measurement instrument. It tells you where you stand. It does not edit your environment, install software, or perform control remediation. It is also not a C3PAO pre-assessment, consulting engagement, or legal opinion. To track the gaps while your team closes them, the readiness subscriptions re-scan connected sources about every seven days, rebuild your package on the tier’s cycle (every 14 to 90 days, by tier), draft your POA&M, and build out your SSP and Evidence Library Index as your data accrues. Your $999 is credited in full if you start a Level 2 subscription with the same billing email within 30 days of receiving the PDF: against your first invoice, with any amount above that invoice applied to the invoices after it.
Privacy, before you connect anything
Every connector is read-only, and the scanners read configuration metadata only, never the data itself. AWS uses a CloudFormation role with an inline, configuration-metadata-only policy and no s3:GetObject (no decryption, no object reads). Azure uses Reader + Security Reader at subscription scope plus Microsoft Graph Policy.Read.All; Microsoft 365 uses read-only Microsoft Graph application permissions; Google Workspace uses the read-only Admin SDK directory scope. Okta uses an API token created by a Read-Only Admin, and CrowdStrike a read-only OAuth2 API client. No CUI is harvested. You can revoke any connector at any time by deleting the role / app / token / API client on your side. Credentials are encrypted at rest with AES-GCM; decrypted in-process only at scan time. The report goes to your inbox and your onboarding page; we do not publish it.
Your $999 is protected two ways
It credits back to you. The full $999 is credited toward any Level 2 subscription, at any Level 2 tier (not toward Level 1 Starter), if you subscribe with the same billing email within 30 days of receiving the PDF: against your first invoice, with any amount above that invoice applied to the invoices after it. If you continue, the Level 2 Readiness Snapshot is a down payment on the work, not a separate cost.
Every measured finding names its evidence. Each measured gap in your report names the resource it was measured on, and an excerpt of the API response behind it is kept on file with its SHA-256 hash.
The Level 2 Readiness Snapshot is a one-time digital deliverable that renders within minutes of your intake. Because it’s delivered that quickly, the fee isn’t refundable once the PDF is sent, the credit above is how we share the risk with you. Full terms on the refund policy.
Run my CMMC Level 2 Readiness Snapshot, $999 →
No account to create · PDF in your inbox within minutes of intake · $999 credited in full toward a Level 2 subscription started with the same billing email within 30 days of receiving the PDF