CMMC readiness involves several parties: the contractor preparing, the assessor reviewing, a program office or DIBCAC with oversight, a prime tracking its subcontractors, and the MSP, MSSP or ESP that supports the contractor’s IT or security. Enclave AI™ measures once and renders that single result to each seat the contractor grants. Once you allow it, the estimated score your team sees is the same one your assessor sees. Below are sample views of each, built with fictional data so you can see the shape of the thing before you buy.
How it fits together
Read-only connectors measure the requirements our extractors cover, your attestations record the rest of the 110, and the evidence is sealed with SHA-256.
Your workspace. Full detail, for your designated people.
Assessor view of the clients they are preparing. Your assessor adds you; your data appears only after you allow it.
Portfolio view for a program office or DIBCAC holding an oversight seat. Appears only after you consent.
Roster view for a prime that names you on an award. Appears only after you accept.
The entities you grant to your provider, and nothing else. Appears only on your grant.
Seat 1. Your workspace
What your designated team sees. Your estimated posture and what moved since the last cycle, how much of the attestation catalog you have answered, your program dates, and a remediation task feed you work down by status.
| Task | Control | Status |
|---|---|---|
| Implement 3.5.10: Store and transmit only cryptographically-protected passwords | 3.5.10 | Open |
| Implement 3.1.10: Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity | 3.1.10 | In progress |
| Implement 3.8.3: System media containing CUI is sanitized or destroyed before disposal or reuse. | 3.8.3 | Open |
| Retire the legacy mail relay before the next cycle | None | In progress |
| Implement 3.6.1: An operational incident-handling capability exists (preparation, detection, analysis, containment, recovery, user response). | 3.6.1 | Done |
| Implement 3.7.5: Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete | 3.7.5 | Waived |
Tasks are generated from the control attestations you record as not implemented, plus any you add yourself, and you move each one through Open, In progress, Done, or Waived. The workspace does not assign an owner or a per-task SPRS point value, so neither is shown.
Seat 2. Your C3PAO
This view gives an assessor its pipeline of OSAs at a glance: what stage each OSA has reached on the platform, how far through the 15 item readiness checklist they are, and the one next step that moves them forward. Your assessor adds you and you are emailed your own link; until you allow sharing there, your assessor sees only your company name and that they added it.
| OSA | Stage | Progress | Measured posture | Next step | Last activity |
|---|---|---|---|---|---|
| Halyard Precision Machining ops@halyard.example | Readiness subscription active | 14 / 15 | Estimated SPRS score 104 (+3 vs prior cycle) measured 11d ago · self-reported at intake: 107 | Their readiness subscription is running. Review cycle deliverables with them. | 8/3/2026 09:12 AM |
| Meridian Defense Works, LLC ops@meridian.example | Measured readiness package delivered | 11 / 15 70d to assessment | Estimated SPRS score 78 (+14 vs prior cycle) measured 6d ago · self-reported at intake: 96 | Their measured package is delivered. It states how it was measured and lists each open gap with a remediation action. | 7/30/2026 04:41 PM |
| Tallgrass Avionics it@tallgrass.example | Intake submitted, package not yet delivered | 7 / 15 | Estimated SPRS score 96 (+9 vs prior cycle) measured 4d ago · self-reported at intake: 101 | They completed intake and their readiness package is not delivered yet. It is measured only for the sources they connect and verify; with none connected it is built from their intake answers. | 8/4/2026 11:58 AM |
| Redline Fasteners Co. it@redline.example |
Level 2 Readiness Snapshot purchased, awaiting intake | 3 / 15 | Not measured self-reported at intake: n/a | They purchased but have not completed the intake. Nudge them to finish it. | 7/22/2026 02:07 PM |
| Juniper Coatings LLC admin@juniper.example | Engaged, left their email on ai4cmmc.ai | 1 / 15 | Not measured self-reported at intake: n/a | They left their email on ai4cmmc.ai (a free gap check or a guide download). The CMMC Level 2 Readiness Snapshot measures the sources they connect and verify. | 6/29/2026 08:33 AM |
The posture column shows the same estimated SPRS score and drift the OSA’s own workspace shows, with the self-reported figure from intake beneath it; an OSA with no measurement on file reads “Not measured”, never zero. This dashboard reports platform activity and does not predict or guarantee an assessment outcome; the certification decision rests solely with the assessing C3PAO.
Seat 3. Your program office or DIBCAC, on your consent
An oversight seat, for a program office tracking a vendor base or for DIBCAC, shows the portfolio of the contractors that consented: how many were measured in the last 30 days, where the exposure sits, and what moved. It is the same measurement, aggregated.
| Contractor | SPRS est. | Δ prev | Met | Not met | Fresh (days) |
|---|---|---|---|---|---|
| Halyard Precision Machining | 104 | +3 | 101 | 4 | 11 |
| Tallgrass Avionics | 96 | +9 | 97 | 7 | 4 |
| Meridian Defense Works, LLC | 78 | +14 | 88 | 14 | 6 |
| Cobalt Systems Group | 67 | 0 | 81 | 21 | 21 |
| Ironwood Composites Inc. | 41 | -6 | 64 | 38 | 38 |
An agency, program office or DIBCAC sets up its seat from a .gov or .mil address; each contractor decides from its own workspace. For Agency / PEO →
Seat 4. Your prime, on a named award
A prime is a commercial counterparty, not a regulator, so it never appears to you as a switch. It names you and the award identifier, the platform emails you a link to your own page, and you decide there. What the prime then sees is its roster with honest denominators (“12 of 60 named subcontractors have consented; 48 have not”) and, for the subcontractors that consented, the estimated SPRS score, how it moved since the previous measurement and how many days ago it was measured, taken from the same canonical posture object your own workspace renders. A subcontractor that has not consented appears by name and award with no posture at all: never a zero, never a placeholder. Withdrawing closes that prime’s view on its next load. Contractor, your MSP, MSSP or ESP, assessor, prime and program office are looking at one canonical compliance state with different permissions, which is the translation chain, from contractor to consultant to assessor to prime to government, collapsed into one record.
A prime sets up its seat on the For Prime page; each subcontractor decides from its own page. For Prime →
Seat 5. Your MSP, MSSP or ESP, on your grant
The provider that supports your IT or security sees the entities you grant, and nothing else: requirement counts and when each was last measured; at Level 2, the open gaps and the responsibility-matrix rows you allocated to it; at Level 1, the open evidence requests. The provider seat does not show your estimated SPRS score. Clients that have not granted appear by name only, with honest denominators: never a zero, never a placeholder.
| Client | Requirements | Open gaps | Last measured |
|---|---|---|---|
| Halyard Precision Machining Level 2 · shared | 101 met · 4 not met | 4 | 9/14/2026 |
| Bluewater Fabrication Co. Notified 9/8/2026 | Awaiting the client’s decision | ||
| Kestrel Tooling LLC | Not shared | ||
Nothing is shared with a provider by default. You grant or withdraw per entity, from your own link or your workspace, and a withdrawn grant closes the provider’s view of that entity. What you share may be Security Protection Data under 32 CFR 170.4; at Level 2, a provider that stores or processes it may be an External Service Provider in your assessment scope (32 CFR 170.19(c)(2)). Record it on your ESP list. For MSP / MSSP / ESP →
Sharing is yours to switch on
No view is automatic and none is something we sell over your head. Your assessor sees your posture only after you allow it from the link you are emailed; an engagement appears on a program office or DIBCAC portfolio only after you enable sharing from your own workspace; a prime sees you only after it names you on an award and you accept; an MSP, MSSP or ESP sees an entity only after you grant it. You can withdraw any of them at any time. Portfolio totals count only the suppliers who have opted in. That is the difference between a contractor choosing to demonstrate readiness and a contractor being surveilled, and we built the switch on your side of it.
Why one shared measurement matters
When the contractor, the assessor, the program office, the prime and the IT provider each keep their own spreadsheet, their numbers can disagree. A single measurement rendered to every seat the contractor grants means each of them reads from the same record. Your evidence carries a SHA-256 seal from the moment it is collected, and each evidence certificate is signed so an assessor or contracting officer can verify it independently, without taking our word for anything.
See a sample deliverable report →
Every company, name, address, date, and figure on this page is fictional and shown to illustrate layout. No customer information appears here. SPRS figures produced by the platform are directional estimates from contractor intake and connected, read-only configuration data. They are not certified C3PAO assessments and not measured DoD-system scores. On the assessor pipeline, the contractor’s self-reported figure from intake is shown separately and labelled as such.