Fortress runs Enclave AI™ on a 14-day delivery cadence, for OSAs whose C3PAO date is locked. Same read-only cloud-evidence mechanism as Standard, paced tighter, and the same automated format quality gate on every readiness package before it is released. Agents perform the recurring work against your connected clouds’ read-only configuration data each cycle; your people keep accountability, authorization and professional judgment. Your SSP and Evidence Library Index build out across your cycles as your environment data accrues.
What Fortress includes
- A cycle every 14 days, not every 30. Your readiness package and SPRS posture report regenerate every 14 days instead of every 30. The gap between “a control drifted” and “you have a deliverable that reflects the drift” is cut by more than half.
- Monitoring Runbook, every cycle. What is watched in each connected environment, on what cadence, and the response steps when a control drifts, built from the checks that actually ran in your latest scan. A connected environment that produced no findings shows zero checks, not a clean result.
- The same automated format quality gate as every tier. Not a Fortress extra: it runs on every tier, Standard included. Every readiness package and remediation plan is parsed and checked before it is released: that the PDF opens and carries text, that no text runs off the printable page, that no markup leaked into the prose, and that no em-dash (a house-style rule) appears. A document that fails is not sent. The refusal is written to the append-only audit log and the operator is alerted to fix the render. There is no person assigned to your account and no human reads a deliverable before it ships; the gate is software, it runs on every document, and it fails closed.
- Audit-Defense Exhibit List, every cycle. An assessor-facing exhibit index that ties each assessment objective to the evidence that answers it and flags the objectives that have none, regenerated with every cycle so the index you hand your C3PAO matches the binder you hand over with it. It is in every Fortress bundle from the first cycle, so each cycle shows which objectives still have no evidence indexed against them.
- Self-service help. The same as Standard: links, order status, document downloads and copies, billing and team sign-in start from the help page, without waiting on anyone.
- Everything in Standard. The full readiness package built from read-only scans of your connected clouds, an SPRS posture estimate, your highest-impact gaps listed by control ID against the 110-control, 320-objective NIST 800-171 baseline, with your SSP and Evidence Library Index building out as your data accrues. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.
What each cycle hands you
A control-by-control readiness analysis that cleared the format quality gate, a draft POA&M whose owners and dates are proposals for your team to confirm, and measured connected-cloud findings, each mapped to a NIST control ID and, where the scan captured an evidence payload, carrying a SHA-256 hash of it. What your assessor concludes is theirs to decide.
From purchase through Day 56
- Purchase. Stripe processes your subscription. Welcome email + intake link.
- Intake. You answer the intake and connect the sources you want measured. Connectors are read-only, and you can revoke each one from your side at any time.
- Day 0, after intake. First scan. Your first readiness package: control-gap analysis against the 110-control NIST 800-171 baseline, your SPRS posture, and a 30-day remediation plan. The format quality gate runs on the package before it is released to you.
- Day 14. Second bundle. Refreshed readiness package and SPRS posture.
- Day 28. Third bundle. Refreshed readiness package and SPRS posture.
- Day 42. Fourth bundle. The Audit-Defense Exhibit List, in every bundle since the first, names every assessment objective your binder does not yet cover, and the POA&M carries a proposed remediation action for each open gap.
- Day 56. Fifth bundle. Days count from the delivery of your first package: each package is due 14 days after the previous one was delivered, so a later intake moves the whole schedule with it.
“Why not just buy Standard and pay a consultant?”
Fortress agents do the reading and the drafting a consultant would otherwise be engaged for, every 14 days, with the automated format quality gate on every document. The monthly option is month-to-month with no long-term contract. It is not a consultancy: nobody is assigned to your account, and your own team makes every executive decision.
Not on Fortress
- Multi-entity / multi-subsidiary scope. If your CUI environment spans more than one corporate entity under one contract, Sovereign covers up to 10.
- Integration with on-premise GRC, ticketing or SIEM tools. Not on the platform today, on any tier.
- CMMC Level 3. Not on the platform today.
The Big Idea, restated
Your self-reported SPRS score and what your connected environment shows can differ. Fortress measures that difference every 14 days, runs every deliverable through an automated format quality gate that blocks anything that fails it, and gives you a control-by-control readiness analysis, a draft POA&M and measured connected-cloud findings to take into your assessment.
Start your subscription
$59,940 per year, or $4,995 month-to-month. If you received your $999 CMMC Level 2 Readiness Snapshot PDF in the last 30 days and subscribe with the same billing email, the $999 credits to your first Level 2 subscription invoice (Refund Policy).
Subscribe to Fortress, $59,940/year →