The question a Level 2 contractor asks
“Can I safely make this affirmation, and can I defend it tomorrow?”
ai4cmmc.ai measures and evidences the cybersecurity controls underlying CMMC, on a recurring schedule, so contractors can know whether the compliance state they are affirming is actually true. At Level 2 that schedule is stated in days: your connected sources are re-scanned about every seven days, and the full Level 2 package is rebuilt on your tier’s cycle, every 14 to 90 days depending on the tier. Between cycles, a control that a re-scan finds regressed shows in your workspace and in the next cycle’s package.
The record documents what was measured, when, and what your team recorded. Your Affirming Official still decides whether to affirm.
If an accountable official must affirm compliance, Enclave AI™ gives that official technical evidence, refreshed on a recurring schedule, supporting the state being affirmed.
What Level 2 is
- Level 2 protects Controlled Unclassified Information (CUI). Its security requirements are the 110 requirements of NIST SP 800-171 Rev. 2. (32 CFR 170.14(c)(3))
- Each requirement is assessed against the 320 assessment objectives of NIST SP 800-171A (June 2018), and the result is scored under the CMMC Scoring Methodology, with a maximum score of 110. (32 CFR 170.16(c)(1), 170.24)
- There are two Level 2 assessment types: Level 2 (Self), a self-assessment your organization conducts (32 CFR 170.16), and Level 2 (C3PAO), a certification assessment conducted by an authorized C3PAO (32 CFR 170.17). Which one applies is set by the solicitation or contract. Your organization enters self-assessment results in SPRS; a C3PAO submits certification results into the CMMC instance of eMASS, which transmits them to SPRS. A Level 2 assessment recurs at least every three years. (32 CFR 170.16(a)(1), 170.17(a)(1))
- A POA&M is permitted at Level 2 only under the conditions of 32 CFR 170.21(a)(2), which include a minimum assessment score of 80% of the maximum, and the POA&M must be closed out, confirmed by a POA&M closeout assessment, within 180 days of the Conditional CMMC Status Date (32 CFR 170.21(b)).
- Your Affirming Official affirms at completion of the assessment, annually thereafter, and after a POA&M closeout, in SPRS. (32 CFR 170.22)
- Level 2 scope is the assets that process, store or transmit CUI and the assets that provide security protection for them, with the other asset categories the rule defines. (32 CFR 170.19(c))
As of September 23, 2026: on July 13, 2026 the DoW CIO suspended the CMMC Phase 2 transition and began a 60-day review of the program, and the USW(A&S) implementing memorandum provides that, during the suspension, solicitations may designate CMMC Level 1 (Self) or Level 2 (Self) only. While that guidance stands, new solicitations do not designate Level 2 (C3PAO). Source: Under Secretary of War (Acquisition and Sustainment), memorandum “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements,” July 13, 2026, with Attachment 1 (cleared for open publication, 26-P-1023); summary: Crowell & Moring client alert on the July 13, 2026 memorandum. What still applies.
Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace.
What the agents deliver at Level 2
Every Level 2 subscription tier receives the same six-document base set each cycle:
- CMMC Level 2 Readiness Snapshot report: your SPRS readiness analysis with the top control gaps found and, where a connected source was measured, a directional SPRS estimate from the measured findings using the DoD Assessment Methodology weights; measured coverage is limited to the controls the connected-source scans exercise. It is not an official SPRS score; your team enters the score in SPRS.
- System Security Plan: all 110 requirements and 320 objectives, written from what was measured and what your team recorded.
- Plan of Action and Milestones: sequenced remediation, with each open requirement’s 32 CFR 170.21 eligibility called out, so your team can see where a POA&M is permitted and where it is not.
- CUI Scoping Package: your enclave boundary, asset categories and CUI data flows, including operational technology you record.
- Customer Responsibility Matrix: the per-requirement split between you, your ESPs and shared obligations.
- Evidence Library Index: your evidence index, with your recorded artifacts mapped to the 320 assessment objectives and the objectives that have no evidence yet named.
Fortress adds two documents, for eight: the Monitoring Runbook and the Audit-Defense Exhibit List. Sovereign adds four more per subscription, for twelve: the Board Readiness Narrative, the Multi-Entity Portfolio Roll-Up, the C3PAO Handoff Packet and the Subcontractor Flow-Down Matrix.
What is measured: requirements are measured where a connected source can observe them, from the identity, cloud and endpoint connectors you connect, which read configuration metadata only (read-only, revocable). Where no connected source can observe a requirement, it is answered from your recorded artifacts and intake, and the documents say which is which.
What your team keeps
- The scoping decisions: which assets hold CUI and which asset category each one belongs in.
- Implementing the remediation, and deciding whether an open item goes on a POA&M where 32 CFR 170.21 permits one.
- Entering self-assessment results and the score in SPRS. ElasticD3M submits nothing to the government.
- The affirmation: your Affirming Official decides whether to affirm, and affirms in SPRS (32 CFR 170.22). Your workspace shows when the annual affirmation is due and records it once your official has made it.
- Choosing and engaging a C3PAO when your contract requires Level 2 (C3PAO). We do not conduct assessments: self-assessments are your organization’s own, and certification assessments are conducted by independent Cyber AB-authorized C3PAOs or DCMA DIBCAC.
- Professional judgment on every exception, every N/A and every responsibility you allocate to an external service provider.
Cadence
Connected sources are re-scanned about every seven days. The full Level 2 package is rebuilt every 90 days on Standing, every 60 days on Garrison, every 30 days on Sentinel and Standard, every 14 days on Fortress, and every 14 days per entity on Sovereign. The first package ships after intake; the cycle spaces the ones after it.
Start with the Level 2 Readiness Snapshot
CMMC Level 2 Readiness Snapshot™
- Generated from a 5-minute intake plus the configuration metadata of any cloud and identity source you connect (read-only, revocable); intake-based if you connect none
- Your self-reported SPRS score set beside the findings; where a source is connected, a directional SPRS estimate from the measured findings using the DoD Assessment Methodology weights
- Top NIST SP 800-171 gaps with control IDs and SPRS deduction weights, and a 30-day remediation list ordered by point recovery
- Each measured finding names the resource it was read from, and the underlying API response is kept with a SHA-256 hash; the PDF lands in your inbox within minutes of intake
- The $999 credits to your first Level 2 subscription invoice if you subscribe with the same billing email within 30 days of receiving the Level 2 Readiness Snapshot PDF; any amount above your first payment carries to the invoices after it (Refund Policy)
Which environments can be measured: AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike can be connected in their commercial clouds. Microsoft 365 GCC High, Azure Government, AWS GovCloud, Google Cloud and on-premises systems cannot be connected. If your CUI is held there, requirements for that environment that no connected source can observe are answered from your intake answers and any artifacts your team records, not measured.
Run my Level 2 Readiness Snapshot, $999 →The six Level 2 subscription tiers
Six tiers of the same assurance system, priced by the compliance work the agents perform, never by seat. Pace and scope are what change. Annual equals twelve times monthly on every plan; no discounts. Each card has a month-to-month option.
- The six-document base set
- Standing rebuilds the full package every 90 days
- Connected sources re-scanned about every seven days
- The $999 Level 2 Readiness Snapshot is credited toward a Level 2 subscription if you subscribe with the same billing email within 30 days of receiving its PDF; any amount above your first payment carries to the invoices after it
- The six-document base set
- Sentinel rebuilds the full package every 30 days
- Connected sources re-scanned about every seven days
- The six-document base set
- Garrison rebuilds the full package every 60 days
- Connected sources re-scanned about every seven days
- The $999 Level 2 Readiness Snapshot is credited toward a Level 2 subscription if you subscribe with the same billing email within 30 days of receiving its PDF; any amount above your first payment carries to the invoices after it
- The six-document base set
- Standard rebuilds the full package every 30 days
- Connected sources re-scanned about every seven days
- Links, order status, downloads, billing and sign-in from the help page
- Eight documents: the base set plus the Monitoring Runbook and the Audit-Defense Exhibit List
- Fortress rebuilds the full package every 14 days
- Every deliverable passes an automated format quality gate before release
- Twelve documents: everything in Fortress plus the Board Readiness Narrative, the Multi-Entity Portfolio Roll-Up, the C3PAO Handoff Packet and the Subcontractor Flow-Down Matrix
- Sovereign rebuilds each entity’s package every 14 days
- A consolidated roll-up for the parent organization
Above 10 entities, or a custom contract structure: not offered self-serve at this time. Fair-use terms · Refund Policy