Pricing
Priced by the compliance work the agents perform, never by seat.
Price against the function, not the seat.
If the instance performs the recurring compliance function, the comparison is not another GRC seat licence. It is what you spend today on people, consultants, auditors, tooling and remediation management to accomplish that function. DoD’s own Regulatory Impact Analysis (32 CFR part 170 final rule, 89 FR 83092, October 15, 2024) prices a small entity’s Level 2 self-assessment cycle at $37,196 and a C3PAO certification cycle at $104,670 over three years, and those figures are assessment cost only: planning for, conducting and reporting the assessment, plus the annual affirmations. DoD assumed the requirements were already implemented, so implementation and remediation are not in them. Your workspace keeps a work ledger: scan runs completed, findings measured, evidence items hashed, artifacts delivered, posture snapshots captured, each a row count from a named table, never an estimate. Operational leverage, not headcount elimination: the instance does the recurring work; your compliance lead and your executives keep the decisions.
ai4cmmc.ai measures and evidences the cybersecurity controls underlying CMMC, on a recurring schedule, so contractors can know whether the compliance state they are affirming is actually true. You are paying for the recurring work of an assurance system, not for another compliance application to operate.
Two Snapshots, two levels. For FCI only: the Level 1 Readiness Snapshot (FCI, 15 FAR 52.204-21 requirements, $299 one-time; checkout not open yet). For CUI: the Level 2 Readiness Snapshot (CUI, 110 NIST SP 800-171 Rev. 2 requirements, 320 assessment objectives, $999 one-time).
Annual equals twelve times monthly on every plan, Level 1 and Level 2; no discounts.
CMMC Level 1 (FCI): 15 FAR 52.204-21 requirements, annual self-assessment, annual affirmation
Level 1 protects Federal Contract Information. It is the 15 basic safeguarding requirements of FAR 52.204-21, self-assessed by your organization every year, with results entered in SPRS and an annual affirmation by your Affirming Official (32 CFR 170.15, 170.22). Level 1 does not permit a POA&M (32 CFR 170.21(a)(1)). Priced separately from Level 2.
Free Level 1 Gap Check
$0
free
- Fifteen questions, one per FAR 52.204-21 requirement. Each answer is recorded as you gave it: in place, not in place, does not apply, or needs evidence. Level 1 has no point score, so none is shown.
Take the free Level 1 Gap Check →
CMMC Level 1 Readiness Snapshot
$299
one-time
- Your FCI Scope Record, from a short intake
- One complete Level 1 measurement cycle: what your in-scope connected sources can observe is measured; everything else gets a short evidence request
- Your 15-Requirement Compliance Record, Gap and Exception Report and Remediation Action Report (not a POA&M)
- Credited in full if you start Level 1 Starter with the same billing email within 30 days of receiving the Snapshot PDF: against your first invoice, with any amount above that invoice applied to the invoices after it
Level 1 checkout not open yet
Enclave AI Level 1 Starter AaaS
$199
per month or $2,388 per year, per OSA entity
Eleven deliverables
- FCI Scope Record
- 15-Requirement Compliance Record
- Evidence Register
- Automated Measurement Record
- Gap and Exception Report
- Remediation Action Report
- Annual Self-Assessment Package
- SPRS Submission Worksheet
- Annual Affirmation Package
- Drift Monitoring, every 30 days, connected sources about every seven days
- Historical Assurance Record
- Every requirement shows one of three states: SATISFIED, NOT SATISFIED or UNOBSERVED. UNOBSERVED means not yet shown by a connected source that covers your in-scope systems, or by evidence your team recorded. The agent asks for exactly the evidence it needs, checks that the record is complete (every objective answered, an accepted evidence type, dated within the year, a named submitter), records the SHA-256 hash your browser computed, and closes the request. Your files stay with you; what they show is your team’s statement.
- A complete Level 1 cycle every 30 days on Starter, with connected sources re-scanned about every seven days
- No POA&M: Level 1 does not permit one (32 CFR 170.21(a)(1)). The Remediation Action Report is not a POA&M.
- Your Affirming Official makes the annual affirmation decision and enters it in SPRS; the agents prepare the package.
Monthly, $199
Level 1 checkout not open yet
Annual, $2,388
Level 1 checkout not open yet
Level 1 checkout is not open yet. The free Level 1 Gap Check is available now.
The Level 1 page →
CMMC Level 2 (CUI): 110 NIST SP 800-171 Rev. 2 requirements, self / C3PAO / government verification as applicable, annual affirmation
As of September 23, 2026: on July 13, 2026 the DoW CIO suspended the CMMC Phase 2 transition and began a 60-day review of the program, and the USW(A&S) implementing memorandum provides that, during the suspension, solicitations may designate CMMC Level 1 (Self) or Level 2 (Self) only. What still applies.
The free 10-question gap check gives an instant, directional result. The $999 Level 2 Readiness Snapshot then reads the read-only configuration data of the cloud and identity sources you connect; scope you do not connect is intake-based. A readiness subscription runs Enclave AI™, the CMMC assurance system, against your connected cloud and identity configuration, delivering a full CMMC readiness package each cycle: control-gap analysis against the 110-control NIST 800-171 baseline, your SPRS posture, and a prioritized remediation plan, with your SSP and Evidence Library Index building out as your data accrues. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Billed annually, with a month-to-month option on every tier.
Your framework target is yours to choose. Every tier measures and scores against NIST SP 800-171 Rev. 2, the required baseline. Choose Rev. 3 at intake or in your workspace and your workspace documents are also rendered against the 97-requirement Rev. 3 set through NIST’s own change analysis, with no Rev. 3 score invented.
CMMC Level 2 Readiness Snapshot™
Your $999 Level 2 Readiness Snapshot is generated from your connected cloud’s read-only configuration data: not a survey or a static questionnaire when you connect a cloud; intake-based if you connect none. Connect any of AWS, Azure, Microsoft 365, Google Workspace, Okta or CrowdStrike (read-only, revocable from your side at any time) plus a 5-minute intake. Enclave AI reads that configuration metadata and turns it into your CMMC readiness analysis, the specific control gaps, and a 30-day remediation list. PDF in your inbox in minutes. Async, self-service throughout.
Which environments can be measured: AWS, Azure, Microsoft 365, Google Workspace, Okta and CrowdStrike can be connected in their commercial clouds. Microsoft 365 GCC High, Azure Government, AWS GovCloud, Google Cloud and on-premises systems cannot be connected. If your CUI is held there, requirements for that environment that no connected source can observe are answered from your intake answers and any artifacts your team records, not measured.
- Your self-reported SPRS score and, from any source you connect, the estimated SPRS deduction from its measured gaps
- Top NIST 800-171 gaps with control IDs + SPRS deduction weights
- 30-day remediation list ordered by point recovery impact
- Your $999 is credited in full if you start a Level 2 subscription with the same billing email within 30 days of receiving the PDF: against your first invoice, with any amount above that invoice applied to the invoices after it
- Each measured finding names the cloud resource it came from; an excerpt of the API response behind it is kept on file with its SHA-256 hash
Run my Level 2 Readiness Snapshot, $999 →
$999
one-time · PDF within minutes of intake
CMMC L2 Readiness Subscription
Six tiers of the same assurance system, along one decision: how soon do you need to be assessment-ready, and how many entities are you covering. Same product mechanics in each tier; pace, scope and the document set are what change.
Standing
Small contractors, 10 to 100 people. Your compliance state evidenced on a 90-day cycle, without a consultant on retainer.
$8,340
per year · or $695 per month · 1 CUI entity
- Read-only evidence collection across every connected cloud, AWS / Azure / M365 / Google Workspace / Okta / CrowdStrike
- All 110 NIST 800-171 requirements covered and mapped to the 320 800-171A objectives, measured where a connected cloud can measure them and answered from your recorded artifacts and intake where it cannot
- Your System Security Plan, POA&M, evidence set, CUI scoping package (including operational technology you record) and responsibility matrix, refreshed every 90 days
- SPRS estimate recomputed each cycle against the DoD Assessment Methodology weights; the affirmation decision stays with your Affirming Official
- The $999 Level 2 Readiness Snapshot is credited in full toward a Level 2 subscription if you subscribe with the same billing email within 30 days of receiving its PDF: against your first invoice, with any amount above that invoice applied to the invoices after it
Subscribe, $8,340/year →
or pay $695/month →
Sentinel
You already affirmed or passed Level 2. Affirmation maintenance: the compliance state you affirmed stays evidenced until the next affirmation or reassessment.
$11,940
per year · or $995 per month
- Read-only re-scans of every connected cloud about every seven days, AWS / Azure / M365 / Google Workspace / Okta / CrowdStrike
- Connected-cloud evidence refreshed every cycle, mapped to NIST 800-171A objectives
- A Level 2 readiness report PDF every 30 days for your board / your prime
- The six-artifact readiness package every cycle: SPRS report, SSP, POA&M, scope, CRM and evidence index
Subscribe, $11,940/year →
Prefer monthly? $995/month →
Garrison
A prime is asking questions and Standing’s 90-day cycle is not fast enough. Garrison refreshes the full package every 60 days.
$17,940
per year · or $1,495 per month · 1 CUI entity
- The complete six-artifact deliverable set, SPRS report, SSP, POA&M, scope, CRM and evidence index, refreshed every 60 days
- All 110 NIST 800-171 requirements covered and mapped to the 320 800-171A objectives, measured where a connected cloud can measure them and answered from your recorded artifacts and intake where it cannot
- SPRS estimate recomputed each cycle against the DoD Assessment Methodology weights
- The $999 Level 2 Readiness Snapshot is credited in full toward a Level 2 subscription if you subscribe with the same billing email within 30 days of receiving its PDF: against your first invoice, with any amount above that invoice applied to the invoices after it
Subscribe, $17,940/year →
Prefer monthly? $1,495/month →
Standard 30-day cycle
You have ~90 days to put measured evidence behind the score you affirm, before a C3PAO, a DIBCAC review, or a prime asks for it.
$29,940
per year · or $2,495 per month · 1 CUI entity
- Control-gap analysis against the 110-control baseline, refreshed every cycle; your SSP builds out from it as your evidence accrues
- Connected-cloud evidence mapped to NIST 800-171A objectives, each evidence record SHA-256 hashed
- Prioritized remediation plan: every open gap with its control ID, recommended action, and expected point-recovery impact
- SPRS estimate and report each cycle for your own SPRS entry
Subscribe, $29,940/year →
Prefer monthly? $2,495/month →
Fortress
A certification, a DIBCAC review, or a prime’s deadline is locked. You have ~60 days. You need the compliance state behind your score evidenced every 14 days, not an SSP written from scratch.
$59,940
per year · or $4,995 per month · 1 CUI entity
- Everything in Standard, with the package refreshed every 14 days
- Every deliverable passes an automated format quality gate before release; anything that fails is blocked, audited and alerted to the operator rather than sent
- Audit-defense exhibit list every cycle: an assessor-facing index tying each assessment objective to the evidence that answers it, flagging the objectives that have none
Subscribe, $59,940/year →
Prefer monthly? $4,995/month →
Sovereign
Multiple subsidiaries, each with its own CUI environment, each affirming or assessing within the same window.
$149,940
per year · or $12,495 per month · up to 10 entities
- Everything in Fortress’s artifact set, applied per entity across up to 10 CUI environments under one engagement, every 14 days per entity
- Per-entity readiness package, consolidated rollup for the parent organization (per-entity SSP and binder build out as data accrues)
- Adds a board readiness narrative, a C3PAO handoff packet and a subcontractor flow-down matrix, plus a multi-entity portfolio roll-up produced once every entity has delivered its cycle
Subscribe, $149,940/year →
Prefer monthly? $12,495/month →
Above 10 entities or a custom contract structure
Not offered self-serve at this time. Self-serve checkout covers up to 10 entities.
Every tier is billed annually, with a month-to-month option on each card. Each tier carries fair-use thresholds: telemetry events per day, AI agent actions per month, and covered entities. Sustained overage billed at-cost plus 30% margin. Fair-use terms · Refund policy · Terms of Service
ElasticD3M, LLC · 7700 Broadway St, Ste 104 PMB1083 · San Antonio, TX 78209 · United States · CAGE Code: 23E31 · SAM.gov UEI: LXSZZXDYPN16 · hello@ai4cmmc.ai