CMMC Level 2 · Controlled Unclassified Information

Your CMMC Level 2 compliance state, established, maintained and evidenced: agents read configuration metadata from the sources you connect, re-scanned about every seven days, and rebuild the documents for 110 requirements and 320 objectives from that state on your tier’s cycle. The SPRS entry and the affirmation decision stay with your team.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC readiness and compliance operations. AI agents perform the recurring measurement, evidence, documentation and readiness workload; accountable humans retain approval, affirmation and professional judgment. Not SaaS. Not consulting. Not a C3PAO.

The question a Level 2 contractor asks

“Can I safely make this affirmation, and can I defend it tomorrow?”

ai4cmmc.ai measures and evidences the cybersecurity controls underlying CMMC, on a recurring schedule, so contractors can know whether the compliance state they are affirming is actually true. At Level 2 that schedule is stated in days: your connected sources are re-scanned about every seven days, and the full Level 2 package is rebuilt on your tier’s cycle, every 14 to 90 days depending on the tier. Between cycles, a control that a re-scan finds regressed shows in your workspace and in the next cycle’s package.

The record documents what was measured, when, and what your team recorded. Your Affirming Official still decides whether to affirm.

If an accountable official must affirm compliance, Enclave AI™ gives that official technical evidence, refreshed on a recurring schedule, supporting the state being affirmed.

What Level 2 is

As of September 23, 2026: on July 13, 2026 the DoW CIO suspended the CMMC Phase 2 transition and began a 60-day review of the program, and the USW(A&S) implementing memorandum provides that, during the suspension, solicitations may designate CMMC Level 1 (Self) or Level 2 (Self) only. While that guidance stands, new solicitations do not designate Level 2 (C3PAO). Source: Under Secretary of War (Acquisition and Sustainment), memorandum “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements,” July 13, 2026, with Attachment 1 (cleared for open publication, 26-P-1023); summary: Crowell & Moring client alert on the July 13, 2026 memorandum. What still applies.

Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace.

What the agents deliver at Level 2

Every Level 2 subscription tier receives the same six-document base set each cycle:

  1. CMMC Level 2 Readiness Snapshot report: your SPRS readiness analysis with the top control gaps found and, where a connected source was measured, a directional SPRS estimate from the measured findings using the DoD Assessment Methodology weights; measured coverage is limited to the controls the connected-source scans exercise. It is not an official SPRS score; your team enters the score in SPRS.
  2. System Security Plan: all 110 requirements and 320 objectives, written from what was measured and what your team recorded.
  3. Plan of Action and Milestones: sequenced remediation, with each open requirement’s 32 CFR 170.21 eligibility called out, so your team can see where a POA&M is permitted and where it is not.
  4. CUI Scoping Package: your enclave boundary, asset categories and CUI data flows, including operational technology you record.
  5. Customer Responsibility Matrix: the per-requirement split between you, your ESPs and shared obligations.
  6. Evidence Library Index: your evidence index, with your recorded artifacts mapped to the 320 assessment objectives and the objectives that have no evidence yet named.

Fortress adds two documents, for eight: the Monitoring Runbook and the Audit-Defense Exhibit List. Sovereign adds four more per subscription, for twelve: the Board Readiness Narrative, the Multi-Entity Portfolio Roll-Up, the C3PAO Handoff Packet and the Subcontractor Flow-Down Matrix.

What is measured: requirements are measured where a connected source can observe them, from the identity, cloud and endpoint connectors you connect, which read configuration metadata only (read-only, revocable). Where no connected source can observe a requirement, it is answered from your recorded artifacts and intake, and the documents say which is which.

What your team keeps

Cadence

Connected sources are re-scanned about every seven days. The full Level 2 package is rebuilt every 90 days on Standing, every 60 days on Garrison, every 30 days on Sentinel and Standard, every 14 days on Fortress, and every 14 days per entity on Sovereign. The first package ships after intake; the cycle spaces the ones after it.

Start with the Level 2 Readiness Snapshot

CMMC Level 2 Readiness Snapshot™

  • Generated from a 5-minute intake plus the configuration metadata of any cloud and identity source you connect (read-only, revocable); intake-based if you connect none
  • Your self-reported SPRS score set beside the findings; where a source is connected, a directional SPRS estimate from the measured findings using the DoD Assessment Methodology weights
  • Top NIST SP 800-171 gaps with control IDs and SPRS deduction weights, and a 30-day remediation list ordered by point recovery
  • Each measured finding names the resource it was read from, and the underlying API response is kept with a SHA-256 hash; the PDF lands in your inbox within minutes of intake
  • The $999 credits to your first Level 2 subscription invoice if you subscribe with the same billing email within 30 days of receiving the Level 2 Readiness Snapshot PDF; any amount above your first payment carries to the invoices after it (Refund Policy)

Which environments can be measured: AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike can be connected in their commercial clouds. Microsoft 365 GCC High, Azure Government, AWS GovCloud, Google Cloud and on-premises systems cannot be connected. If your CUI is held there, requirements for that environment that no connected source can observe are answered from your intake answers and any artifacts your team records, not measured.

Run my Level 2 Readiness Snapshot, $999 →

Take the free gap check first · See a sample report →

$999
one-time · PDF within minutes of intake

The six Level 2 subscription tiers

Six tiers of the same assurance system, priced by the compliance work the agents perform, never by seat. Pace and scope are what change. Annual equals twelve times monthly on every plan; no discounts. Each card has a month-to-month option.

Standing
Small contractors keeping posture and paperwork current between assessments.
$8,340
per year · or $695 per month · 1 CUI entity
  • The six-document base set
  • Standing rebuilds the full package every 90 days
  • Connected sources re-scanned about every seven days
  • The $999 Level 2 Readiness Snapshot is credited toward a Level 2 subscription if you subscribe with the same billing email within 30 days of receiving its PDF; any amount above your first payment carries to the invoices after it
Subscribe, $8,340/year → or pay $695/month →
Sentinel
Affirmation maintenance: you already affirmed or passed Level 2 and keep the evidence current until the next affirmation or reassessment.
$11,940
per year · or $995 per month · 1 CUI entity
  • The six-document base set
  • Sentinel rebuilds the full package every 30 days
  • Connected sources re-scanned about every seven days
Subscribe, $11,940/year → Prefer monthly? $995/month →
Garrison
A prime is asking questions and a 90-day rebuild is not fast enough.
$17,940
per year · or $1,495 per month · 1 CUI entity
  • The six-document base set
  • Garrison rebuilds the full package every 60 days
  • Connected sources re-scanned about every seven days
  • The $999 Level 2 Readiness Snapshot is credited toward a Level 2 subscription if you subscribe with the same billing email within 30 days of receiving its PDF; any amount above your first payment carries to the invoices after it
Subscribe, $17,940/year → Prefer monthly? $1,495/month →
Standard
You want measured evidence behind the score you affirm before a C3PAO, a DIBCAC review or a prime asks for it.
$29,940
per year · or $2,495 per month · 1 CUI entity
  • The six-document base set
  • Standard rebuilds the full package every 30 days
  • Connected sources re-scanned about every seven days
  • Links, order status, downloads, billing and sign-in from the help page
Subscribe, $29,940/year → Prefer monthly? $2,495/month →
Fortress
A certification, a DIBCAC review or a prime’s deadline is fixed and the documents cannot start from scratch.
$59,940
per year · or $4,995 per month · 1 CUI entity
  • Eight documents: the base set plus the Monitoring Runbook and the Audit-Defense Exhibit List
  • Fortress rebuilds the full package every 14 days
  • Every deliverable passes an automated format quality gate before release
Subscribe, $59,940/year → Prefer monthly? $4,995/month →
Sovereign
Several subsidiaries, each with its own CUI environment, each affirming or assessing in the same window.
$149,940
per year · or $12,495 per month · up to 10 entities
  • Twelve documents: everything in Fortress plus the Board Readiness Narrative, the Multi-Entity Portfolio Roll-Up, the C3PAO Handoff Packet and the Subcontractor Flow-Down Matrix
  • Sovereign rebuilds each entity’s package every 14 days
  • A consolidated roll-up for the parent organization
Subscribe, $149,940/year → Prefer monthly? $12,495/month →

Above 10 entities, or a custom contract structure: not offered self-serve at this time. Fair-use terms · Refund Policy

Next