Frequently Asked Questions

Straight CMMC answers.

Don’t see your question? The help page covers links, status, billing, refunds and sign-in.

Before you buy

Is CUI leaving my environment when I connect a cloud?

Not by design. Every connector reads configuration metadata, not the data itself. AWS uses a CloudFormation role with an inline, configuration-metadata-only policy and no s3:GetObject (no decryption, no object reads). Azure uses a Service Principal with Reader + Security Reader at subscription scope; Microsoft 365 uses read-only Microsoft Graph application permissions; one of them, SharePointTenantSettings.Read.All, is broad enough under Microsoft’s permission model to read SharePoint content, and the scanner makes no content-reading call. Google Workspace uses the read-only Admin SDK Directory scope. Okta and CrowdStrike use read-only API tokens and scopes. The agents read who has MFA enabled, whether CloudTrail is logging, whether a bucket’s public access is blocked, not what’s in the bucket.

Stored connector credentials (Azure, Microsoft 365, Google Workspace, Okta, CrowdStrike) are encrypted at rest with AES-GCM; AWS works through a role your account lets us assume, so no AWS key is stored. Scan evidence is the configuration API response, stored with its SHA-256 hash. Every connector is revocable from your side by deleting the CloudFormation stack, Service Principal, service account, API token, or OAuth2 client, with no support ticket. Once revoked, the next scan cannot read anything.

Details in the privacy policy and the DPA, which the Terms incorporate for every purchase.

Will Enclave AI guarantee I pass my C3PAO assessment?

No platform can guarantee that, the C3PAO decides. Assessors score each requirement on whether it is implemented and evidenced; the agents keep that evidence organized and dated.

What the platform does: all 110 controls and all 320 assessment objectives are indexed, with the objectives your evidence answers separated from the ones that have none. We do not claim every objective is evidenced; the index counts and names the ones that are not, so they are yours to close rather than your assessor's to discover. Every recorded artifact is listed in the Evidence Library Index with its NIST control ID and its SHA-256 hash. Your team enters its own score in SPRS, now with measured evidence behind the requirements your connected clouds can observe.

Your C3PAO retains its independence and its judgment. We don’t talk to your assessor on your behalf; the package comes to you, and what you share with your assessor is your decision.

Is Enclave AI in production, and who is using it?

Enclave AI is built and running in production, and its agents run end to end on synthetic test subscriptions, from purchase through intake and measurement to delivered documents. It has been hardened week over week since April 2026: code changes in 22 of the 26 weeks from April through September 2026, and more than 16,000 automated tests that run on every change and, since June 2026, on a weekly schedule.

The next milestones are deployment in real Defense Industrial Base customer environments and measured results from them: how the system performs, what it costs to operate, and how useful its evidence is there. The architecture itself is not what remains to be proven.

How is this different from a compliance dashboard?

Enclave AI is Agent-as-a-Service, not a dashboard your team fills in. It is built for CMMC only: the agents, control mappings, evidence collection and SSP generation are tuned to NIST SP 800-171 Rev. 2 and NIST SP 800-171A.

The work product lands in your inbox each cycle, written by the agents, for your team to review and, if you choose, share with your C3PAO: the System Security Plan PDF, the POA&M, the Evidence Library Index, and the SPRS posture report. The agents work whether you log in or not. The deliverables ship whether you read them or not.

Practical implication: if you don’t want to spend your week inside another compliance dashboard, you don’t have to. If your team is one person wearing the compliance hat alongside three other hats, the tier subscriptions are designed for that situation.

What does the $999 CMMC Level 2 Readiness Snapshot actually buy me?

A PDF in your inbox within minutes of intake submission. Three things on it:

  • Your self-reported SPRS score and the estimated SPRS deduction from the read-only scan of any source you connect (AWS via CloudFormation role, Azure / M365 via Service Principal, Google Workspace via service account, Okta via API token, CrowdStrike via OAuth2 client, connect any combination, including zero; with none connected, the analysis is built from your intake answers).
  • The top NIST 800-171 control gaps driving the difference, each with a control ID (3.1.1, 3.13.8, etc.), the SPRS deduction weight per the DoD Assessment Methodology, and the evidence an assessor would request; for a connector-measured finding, an excerpt of the API response behind it is kept on file with its SHA-256 hash.
  • A 30-day remediation list ordered by point recovery impact, with expected point recovery per item.

What it is not: a C3PAO pre-assessment, a certification, a legal opinion, or consulting. It is a measurement, nothing more.

The $999 credits toward your first Level 2 subscription invoice if you start a Level 2 subscription within 30 days of receiving the Snapshot PDF, with the same billing email (terms in the refund policy). Net cost of a Level 2 Readiness Snapshot that converts: $0. Net cost of a Level 2 Readiness Snapshot that confirms you’re not ready and you walk away: $999 well spent.

How does billing work?

The full subscription. From the day you subscribe you get the welcome email, the intake, the read-only connectors, the first scan of what you connect, and the first deliverable bundle (SSP, POA&M, CUI scoping package, customer responsibility matrix, evidence library index, and SPRS posture report with its remediation list). Every tier’s core PDFs pass an automated format quality gate that blocks any PDF that fails it. On Fortress, you also get a deliverable cycle every 14 days, the monitoring runbook and the audit-defense exhibit list. On Sovereign, per-entity bundles, the parent-level roll-up, and parent-level account handling.

Billing is annual in advance by default, with a month-to-month option. The card you provide at checkout is charged the tier price on the day you subscribe, the year on the annual link or the month on the monthly link, and again on the same day of each following period until you cancel. Cancellation is self-serve in your Stripe billing portal. The link to it is in your subscription welcome email and on the onboarding page that email opens. If the portal cannot be opened, the page that link opens offers Cancel at the end of the current period, which works without the portal, and written notice to legal@elasticd3m.com from the address on the account is honoured identically. Access continues through the end of the paid period after cancellation.

The first deliverable bundle ships after your intake, so you can judge the work product before your next renewal. You can cancel in the Stripe billing portal before the next renewal.

Do I have to get on a call?

No. Stripe checkout, intake, scan, PDF in inbox, the entire buy-and-deliver path is self-service. Links, order status, downloads, billing and refund requests start from the help page.

Above 10 entities, or a custom contract structure, is not offered self-serve at this time.

How much does each tier cost and how do I pick?

Six Level 2 subscription tiers, billed annually with a month-to-month option, all managed in the Stripe billing portal:

  • Standing, $8,340/yr or $695/mo. Single entity. Read-only re-scans of your connected clouds about every seven days, with your SSP, POA&M, evidence set, scoping package and SPRS estimate refreshed every 90 days. The lowest-priced Level 2 tier.
  • Sentinel, $11,940/yr or $995/mo. Single entity. Affirmation maintenance: read-only re-scans about every seven days and the full deliverable set every 30 days, to keep the record of an already-affirmed or already-certified environment current until the next affirmation or reassessment.
  • Garrison, $17,940/yr or $1,495/mo. Single entity. The full deliverable set refreshed every 60 days, for the contractor whose prime or assessment window makes Standing’s 90-day cycle too slow.
  • Standard, $29,940/yr or $2,495/mo. Single entity. One full readiness package every 30 days: SSP, POA&M, Evidence Library Index, SPRS posture report. For OSAs more than 60 days from a C3PAO date, or with no specific date yet but a contract that’ll require it soon.
  • Fortress, $59,940/yr or $4,995/mo. Single entity. A deliverable cycle every 14 days + the monitoring runbook + an audit-defense exhibit list every cycle. For OSAs inside 60 days of a confirmed assessment date.
  • Sovereign, $149,940/yr or $12,495/mo. Up to 10 entities under one contract. Per-entity deliverables, parent-level roll-up posture report, one engine and one framework target across every entity, parent-level account handling. For parent organizations with multiple subsidiaries holding separate CUI.

Annual pricing per tier: Standing $8,340, Sentinel $11,940, Garrison $17,940, Standard $29,940, Fortress $59,940, Sovereign $149,940. Annual equals twelve times monthly on every tier; there are no discounts. Every tier also has a month-to-month option billed monthly in advance. Fair-use thresholds in Terms of Service.

Product, what actually ships

What is CMMC Level 1, and what does Enclave AI do for it?

Level 1 protects Federal Contract Information. It is the 15 basic safeguarding requirements of FAR 52.204-21, self-assessed by your organization every year, with results entered in SPRS and an annual affirmation by your Affirming Official (32 CFR 170.15, 170.22). Level 1 does not permit a POA&M (32 CFR 170.21(a)(1)). Level 1 is priced separately from Level 2, and Level 1 checkout is not open yet.

See the Level 1 page.

What does Agent-as-a-Service actually mean for me?

SaaS sells you a subscription plus homework: the software holds the forms, and your people spend the labor hours filling them in, every cycle, for every entity. That does not scale. In AaaS the agents do the work. They measure, collect and record evidence, draft and maintain the documents, and deliver a report for a named person to approve or deny. People keep accountability, authorization and professional judgment.

If a dashboard is what you want, this isn’t the right product. If outcome-shaped work product is what you want, it is.

How does the multi-cloud scan work?

Each connector is read-only, scoped, and revocable:

  • AWS. One-click CloudFormation role with an inline, configuration-metadata-only policy and no s3:GetObject. Reads IAM users, their MFA devices and the account password policy; CloudTrail, GuardDuty, Amazon Inspector, Security Hub and AWS Config status; S3 bucket names and each bucket’s Public Access Block, default encryption and bucket policy; SSM patch state; EBS encryption by default, security groups, subnets and route tables; AWS Backup plans and vaults; KMS key metadata. Maps findings to 3.1.20, 3.3.1, 3.3.5, 3.3.8, 3.4.1, 3.5.3, 3.5.7, 3.5.8, 3.8.9, 3.11.2, 3.13.1, 3.13.5, 3.13.6, 3.13.8, 3.13.10, 3.13.16, 3.14.1 and 3.14.6. A stack created from template version 1.1.0 reaches only 3.1.20, 3.3.1, 3.3.8, 3.5.3 and 3.14.6 until it is updated with the current template.
  • Azure. Service Principal with Reader + Security Reader. Scans Conditional Access policies and security defaults, privileged role assignments, Azure Policy baseline assignments, Key Vaults, Backup vaults, Storage account encryption, network security groups exposing management ports, and whether the Activity Log is routed to a Log Analytics workspace. Maps to 3.1.5, 3.3.1, 3.4.1, 3.5.3, 3.8.9, 3.13.1, 3.13.8 and 3.13.10. The Microsoft Defender for Cloud check (3.14.6) has not yet been run against a live Azure subscription; if Azure refuses the read, it is reported as needs review. It does not read Microsoft Sentinel.
  • Microsoft 365 / Entra ID. App registration with read-only Microsoft Graph application permissions. Scans per-user MFA registration (on Microsoft Entra ID P1 or P2) and replay-resistant authentication methods, stale and never-signed-in accounts, privileged role sprawl, Conditional Access for remote access, user traceability, SharePoint external sharing, and Intune enrollment and security configuration. Per-user MFA registration and Intune enrollment have not yet been run against a live Microsoft 365 tenant. Unified audit log retention does not produce a measurement today and is reported as needs review. Maps to 3.1.x, 3.3.x, 3.4.2, 3.5.x.
  • Google Workspace. Service account with domain-wide delegation, read-only Admin SDK Directory scope. Scans 2-Step Verification on admin accounts, dormant and never-logged-in active accounts, and super-admin sprawl. Maps to 3.1.1, 3.1.5, 3.5.3.
  • Okta. Read-only API token. Scans password policy strength and reuse, sign-on session lifetime, and whether the System Log is streamed to a SIEM. Maps to 3.1.11, 3.3.1, 3.5.7 and 3.5.8. The admin MFA enrolment check (3.5.3) has not yet been run against a live Okta org; when Okta refuses the read, it is reported as needs review.
  • CrowdStrike Falcon. An OAuth2 API client you create with read scopes. Reports the number of hosts reporting to Falcon for you to reconcile against your in-scope endpoint inventory; sensor coverage (3.14.2) is not measured. The prevention-policy check (3.14.5) has not yet been run against a live Falcon tenant; any policy it cannot read is reported as needs review.

Each measured finding stores an excerpt of the API response behind it with its SHA-256 hash. Deliverable cadence by tier: every 90 days on Standing, every 60 days on Garrison, every 30 days on Sentinel and Standard, every 14 days on Fortress, and every 14 days per entity on Sovereign. Separately, every connected cloud is re-scanned about every seven days, and a control that regressed is flagged in your workspace.

What if my environment isn’t fully in cloud?

You still get a readiness package. The intake captures the parts the cloud connectors can’t reach, on-prem infrastructure, niche SaaS, process-only controls, contractual posture. In your System Security Plan, each requirement with evidence states whether it was measured from a connected source or attested by your team, so anyone you share it with, including your C3PAO, sees the distinction. Connected sources today are AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike; other environments are covered from your recorded evidence.

How does drift get detected?

On the weekly re-scan. About every seven days the platform re-reads each connected source and compares the result with the previous snapshot. A requirement that moved from met to not met is flagged in your workspace with the change in the SPRS estimate, and the next deliverable cycle is built from the current state. On Sovereign, the board narrative adds a “Movement since the previous cycle” section. We do not promise “drift detected in minutes”. We promise the deliverable bundle reflects the measured posture each cycle.

What deliverable file formats do I get?

Every document delivered to your inbox is a PDF. On every tier: System Security Plan, POA&M, CUI Scoping Package, Customer Responsibility Matrix, Evidence Library Index, and SPRS posture report. Fortress adds the monitoring runbook and the Audit-Defense Exhibit List; Sovereign adds the board narrative, the portfolio roll-up, the C3PAO handoff pack and the flow-down matrix. The Exports and verification section of your workspace links the same work as files you can load into your own tooling: posture, POA&M, scope, CRM and the evidence index as Markdown; your readiness result as JSON or CSV, plus an eMASS-aligned JSON or CSV for import; and your System Security Plan, POA&M and readiness self-assessment results as OSCAL JSON (the System Security Plan in OSCAL 1.1.2, the other two in OSCAL 1.2.3). Our automated tests check each OSCAL file against NIST’s published OSCAL JSON schema for the version it declares. We do not produce Word or Excel files. The Evidence Library Index maps each recorded artifact to its NIST control ID and the assessment objectives it answers, with the SHA-256 hash you recorded for it. The same section links your evidence integrity certificate, a JSON document sealed with SHA-256 over the roots of your evidence manifest, control attestations, recorded CUI scope and annual affirmation and, when a signing key is provisioned, signed with Ed25519, so an assessor can verify the record offline. It is issued once at least one evidence artifact or control attestation is recorded. The section also links a point-in-time posture statement and the verify page, which checks either one without an account. The signature covers that certificate, not the PDFs.

Who is responsible when the AI is wrong?

AI performs. AI records. AI explains. AI provides evidence. Authorized humans approve the decisions that legally or operationally require human accountability. Agents perform the recurring work; people keep accountability, authorization and professional judgment. Every consequential decision the platform can take, who is accountable for it (the operator, your designated executive, or your authorized user, never an agent), and the code that binds it is enumerated in a decision registry and rendered to /accountability, not typed. Your executives adopt or reject each delivered document from a signed-in seat against the SHA-256 of the exact bytes delivered.

Which NIST SP 800-171 revision do you measure against, Rev 2 or Rev 3?

Both, and you choose. Rev. 2 is what 32 CFR 170 binds CMMC Level 2 to today (32 CFR 170.14(c)(3)), what the DFARS 252.204-7012 class deviation keeps as the assessment standard (CMMC FAQ Rev. 2.3, B-A3), and what the CMMC scoring methodology in 32 CFR 170.24 measures, so it is the scored baseline: SPRS estimate, POA&M eligibility, Conditional or Final. Rev. 3 (published May 2024; 97 requirements, 17 families, 422 assessment objectives) is the emerging target. Choose it at intake or from your workspace and your workspace documents (readiness export, OSCAL SSP, workspace view) are also rendered against the Rev. 3 set, mapped through NIST’s own Rev 2 to Rev 3 change analysis, with your Rev. 2 figures alongside. No Rev. 3 score is asserted, because DoD has published none. The one-time Snapshot is scored under Rev. 2.

Do NIST SP 800-171A Rev. 3 or NIST SP 1352 change what CMMC assesses today?

NIST SP 800-171 defines the security requirements. NIST SP 800-171A defines the assessment procedures. NIST SP 1352, published September 2026, is a NIST primer that gives small businesses a high-level overview of SP 800-171A Rev. 3 assessments; it is reading material. None of them performs the work. Enclave AI™ performs recurring measurement and documentation work against the requirements CMMC uses today: FAR 52.204-21 for Level 1 and NIST SP 800-171 Rev. 2 with SP 800-171A (June 2018) for Level 2 (32 CFR 170.14(c)(3)). DoW has stated it will incorporate Rev. 3 through future rulemaking (CMMC FAQ Rev. 2.3, B-A3). NIST does not endorse products and has no role in DoW’s CMMC implementation (NIST SP 1352).

Does the platform replace my compliance staff?

No, and the framing matters. Operational leverage, not headcount elimination. The platform handles scheduled measurement, evidence collection, and document production. Your compliance lead keeps making executive decisions, what residual risk to accept, what to escalate, what to flag in board reporting. Accountability, authorization and professional judgment stay with your people by design. The platform is built to take the recurring measurement and document work off your compliance lead.

Assurance, for the Department and for primes

The assurance question for the Department

How can DoW establish trustworthy, scalable assurance that a contractor’s asserted implementation state is accurate, today under NIST SP 800-171 Rev. 2, and under Rev. 3 if DoW incorporates it through rulemaking, as its CMMC FAQ (Rev. 2.3, July 2026, B-A3) says it will?

Enclave AI™ by ai4cmmc.ai performs the machine-executable work of establishing and maintaining an evidence-backed NIST SP 800-171 compliance state: measured where a connected source can observe it, substantiated by recorded, hashed evidence where it cannot, and re-measured on a stated schedule. The contractor, its Affirming Official, its assessor, its prime and an authorized government customer, each on the contractor’s grant, read that same recorded state instead of reconstructing it by hand at assessment time. Assessment judgments stay with the contractor and, where one is required, its C3PAO or DIBCAC.

The contractor’s question

It used to be “How do I prepare for and pass my CMMC assessment?”, a question answered with checklist software, document repositories, consultants, SSP generators, POA&M managers and evidence folders. The question now is “How do I continuously know that the compliance state I am affirming is accurate, and how can I prove it?”

Your Affirming Official affirms continuing compliance in SPRS after each assessment and annually thereafter (32 CFR 170.22). Enclave AI records what was measured, when, from which source, and what your team substantiated, each entry hashed with SHA-256 and carried in a tamper-evident audit chain. On Level 1, the chain’s current head is printed on every document you receive, so a later change is detectable against your own copy; Level 2 evidence certificates are Ed25519-signed and checkable at /verify. The record documents the basis and timing of what was affirmed, with the approver’s recorded identity. The decision stays with your Affirming Official. That record is refreshed on a stated schedule: connected sources are re-scanned about every seven days, a full Level 1 cycle runs every 30 days, and Level 2 runs on your tier’s cycle.

What your Affirming Official reviews before deciding comes from that same record: the recorded state of each requirement, the evidence behind it, what changed since the last measurement, and the open gaps and exceptions. Then your Affirming Official decides whether to affirm.

Compliance, statutory boundaries

Does Enclave AI conduct CMMC assessments?

No. Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness. AI agents perform the recurring measurement, evidence, documentation and readiness workload; accountable humans retain approval, affirmation and professional judgment. Self-assessments are the OSA’s own, and certification assessments are conducted by independent Certified Third Party Assessment Organizations (C3PAOs) authorized by the Cyber AB, or by DCMA DIBCAC. We are an AaaS provider in the CMMC ecosystem, built to make life easier for the OSAs preparing for assessment, the C3PAOs assessing them, the RPOs guiding them, and the MSPs, MSSPs and ESPs supporting them.

Read more in our Policy Position on the structural integrity of the CMMC ecosystem.

Is Enclave AI a Registered Practitioner Organization (RPO)?

No. ElasticD3M, LLC is not a Registered Practitioner Organization (RPO) and does not provide CMMC consulting services. It is an Agent-as-a-Service (AaaS) provider: its AI agents perform the recurring measurement, evidence and documentation work, and the customer’s accountable officials make every decision and attest. An RPO may use the platform in its own work if it chooses.

Will running the $999 Level 2 Readiness Snapshot disqualify a C3PAO from assessing me?

No. The Code of Professional Conduct required by 32 CFR 170.8(b)(17)(ii)(G) bars a CMMC ecosystem member that served as a consultant preparing an organization for a CMMC assessment within the past 3 years from taking part in that organization’s Level 2 certification assessment. The CMMC Level 2 Readiness Snapshot is a measurement product, not a consulting engagement: no advisor, no SOW, no recommendation beyond the factual gap list and its remediation actions. ElasticD3M is not a C3PAO, and your C3PAO plays no part in producing the Snapshot.

Does the platform cover CMMC Level 3?

No. Level 3 is not offered on this platform. We will not sell you a Level 2 subscription and tell you it covers Level 3.

Does CMMC Level 2 assess our operational technology?

Under 32 CFR 170.19 today, OT that can process, store or transmit CUI but is unable to be fully secured is a Specialized Asset. At Level 2 you document it in your inventory, SSP and network diagram and show it is managed under your risk-based policies; the assessor’s instruction is “Review the SSP. Do not assess against other CMMC security requirements.” At Level 1 Specialized Assets are not part of the assessment scope. Level 3 is not offered on this platform.

Does OT change our SPRS score?

The platform computes no SPRS points for Specialized Assets. At Level 2 the assessor reviews the SSP for these assets (32 CFR 170.19(c)(1)) and does not assess them against other CMMC security requirements. Your inventory, SSP and network diagram still have to account for them.

Do you monitor our OT network?

No. Enclave AI™ documents OT you record. SCADA and OT security readiness is a separate product: ai4scada.ai.

What 32 CFR 170.19 says about operational technology, and what the platform records: Operational technology in your CMMC scope →

Can I use this if I’m not in the Defense Industrial Base?

No. The Level 2 Readiness Snapshot and the subscription tiers are CMMC / NIST 800-171-specific. If your compliance need is SOC 2, ISO 27001, HIPAA, PCI, or anything other than CMMC / NIST 800-171, this is not the right product for you. Buying it anyway would waste your money.

Operational, billing, contracts, support

How do payments work?

Stripe Checkout, billed immediately with no free trial. The help page covers billing.

How do I cancel?

Inside the Stripe billing portal, yourself, without contacting us. Cancelling there stops the renewal. The link is in your subscription welcome email and on the onboarding page that email opens. If the portal cannot be opened, the page that link opens offers Cancel at the end of the current period, which works without the portal, and written notice to legal@elasticd3m.com is honoured identically. Subscriptions are billed annually by default, with a month-to-month option; auto-renewal stops at the end of the then-current paid period. The $999 Level 2 Readiness Snapshot is a one-time purchase. Full cancellation policy.

Do I need an MSA or NDA before signing up?

No. On every tier, the Terms you accept at Stripe checkout (section 8, Customer Data and Confidentiality) and the DPA bind both parties to mutual confidentiality from checkout, before any data flows. If your legal team requires a standalone mutual NDA before subsidiary data flows, send it to legal@elasticd3m.com before you connect.

A custom MSA is not offered self-serve at this time; the Terms accepted at checkout are the agreement.

What’s the liability structure?

Enclave AI’s work product is readiness documentation, not a legal opinion, not a certification, not a substitute for a C3PAO assessment, not a guarantee of pass. Every material compliance decision stays with your executives. Full liability terms in the Terms of Service.

Is there a C3PAO partner discount?

No. Pricing is the same for every buyer and there are no discount codes. The C3PAO Partner Program pays nothing to partners either, by design: no fee of any kind attaches to an OSA your firm refers or assesses, so nothing we pay can create a financial interest in an assessment you perform. What the program offers is a consent-gated pipeline dashboard showing the readiness of the OSAs that choose to share it with your firm. Details on the For C3PAO page.

Still have questions?

The help page covers links, status, billing, refunds and sign-in.

Start with the $999 CMMC Level 2 Readiness Snapshot →

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC readiness and compliance operations. AI agents perform the recurring measurement, evidence, documentation and readiness workload; accountable humans retain approval, affirmation and professional judgment. Not SaaS. Not consulting. Not a C3PAO. It serves the OSAs preparing for assessment, the C3PAOs assessing them, the RPOs guiding them, and the MSPs, MSSPs and ESPs supporting them. We do not conduct assessments: self-assessments are the OSA’s own, and certification assessments are conducted by independent Cyber AB-authorized C3PAOs or DCMA DIBCAC. ElasticD3M, LLC is a Texas limited liability company.