Sample · CMMC Level 2 Readiness Snapshot™

See exactly what the $999 deliverable contains.

Specimen report · Fictional company and data · Sample layout with illustrative data

The PDF you receive follows this structure. When you connect a cloud, the gap rows are read-only scan findings from that environment, covering the controls our extractors measure, which is a focused subset of the 110 NIST SP 800-171 requirements; with nothing connected, the report is an intake-based directional analysis and says so. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. For the Snapshot, the choice is made at intake; the workspace comes with a readiness subscription. Cover and executive summary, up to seven control gaps ranked by deduction weight, a four-week remediation plan, and a methodology note. Below is that structure with fictional data for a fictional DIB manufacturer with one AWS account connected.

Run my Level 2 Readiness Snapshot, $999 → Read product details
Section 1 of 4 · Cover & executive summary
CMMC Level 2 Readiness Snapshot™

Intake-based gap analysis for Acme Defense Industries, LLC

Disclaimer: This document is an AI-generated, intake-based readiness analysis. It is not a C3PAO assessment, not a measured SPRS score, and is not to be filed as an official DoD document. Use for internal preparation only.

Report date: 2026-09-14 · CAGE code: 8XXXX · Last self-assessment: 2026-01-15 · Self-reported readiness score on file: 88 · Rendered against: NIST SP 800-171 Rev. 2 (required)

Executive summary

Scan completed against your connected environment(s). 12 compliant finding(s), 7 non-compliant control(s), 1 item(s) flagged for review. Estimated SPRS deduction from non-compliant controls: 25 point(s). The highest-impact items follow on the next page, ordered by SPRS-recovery value.

Self-reported score commentary

The report sets your self-reported score beside the deduction attributable to the gaps the scan measured, and states that coverage is limited to the cloud(s) you connected: on-premises systems, unconnected services and process-only controls rely on your intake answers.

Section 2 of 4 · Control areas requiring evidence verification

Top control gaps, ranked by DoD Assessment Methodology weight

Each row names the NIST SP 800-171 Rev. 2 control, the DoD Assessment Methodology v1.2.1 weight if unimplemented, the evidence behind the finding, and a 30-day action. Specimen findings:

Findings table scrolls horizontally →

Control ID Finding and 30-day action Weight Evidence
3.5.3 3 IAM user(s) with administrator-level policy attached do not have MFA configured. Action: enforce MFA on all IAM users with administrator policies, or remove the admin policy from accounts that do not need it. −5 AWS evidence: iam.user. API response retained with SHA-256 hash.
3.3.1 No multi-region CloudTrail trail with logging enabled was found. Action: create a multi-region CloudTrail trail with logging enabled and a retention policy that meets your contractual minimum. −5 AWS evidence: cloudtrail.trail. API response retained with SHA-256 hash.
3.13.1 4 security-group rule(s) expose management ports to 0.0.0.0/0. Action: restrict management-port ingress to known CIDRs or a bastion or VPN, and remove the 0.0.0.0/0 rules. −5 AWS evidence: ec2.security_groups. API response retained with SHA-256 hash.
3.14.6 GuardDuty is not enabled in any scanned region. Action: enable GuardDuty in your primary region and in every region that runs workloads. −5 AWS evidence: guardduty.detector. API response retained with SHA-256 hash.
3.13.8 3 of 12 S3 bucket(s) do not enforce TLS in transit. Action: add a bucket policy that denies requests where aws:SecureTransport is false on every bucket that may hold CUI. −3 AWS evidence: s3.buckets. API response retained with SHA-256 hash.
3.1.20 2 of 12 S3 bucket(s) do not have full Public Access Block enabled. Action: enable all four Block Public Access settings on every CUI-relevant bucket. −1 AWS evidence: s3.bucket. API response retained with SHA-256 hash.
3.3.8 None of 1 CloudTrail trail(s) have log-file validation enabled. Action: enable log-file validation and restrict the log bucket and KMS key so audit records cannot be changed undetected. −1 AWS evidence: cloudtrail.trail. API response retained with SHA-256 hash.

The PDF shows up to seven gap rows, one per control, non-compliant findings first, each with an effort label (low, medium or high by weight).

Section 3 of 4 · 30-day remediation plan

30-day remediation plan, ordered by readiness-recovery impact

One step per week from the highest-weight gaps above. Effort and dependencies vary by environment; the plan is a prioritization, not a precise calendar.

Week 1
Enforce MFA on all IAM users with administrator policies. Related control: 3.5.3.
+5 SPRS pts if fully closed
Week 2
Create a multi-region CloudTrail trail with logging enabled. Related control: 3.3.1.
+5 SPRS pts if fully closed
Week 3
Restrict management-port ingress and remove 0.0.0.0/0 rules. Related control: 3.13.1.
+5 SPRS pts if fully closed
Week 4
Enable GuardDuty in every region that runs workloads. Related control: 3.14.6.
+5 SPRS pts if fully closed
Section 4 of 4 · Methodology & closing note

Methodology

Findings come from read-only scans of the environment(s) you connected (AWS via a cross-account IAM role with an inline, configuration-metadata-only policy and no s3:GetObject). Each finding cites a NIST SP 800-171 Rev. 2 control with its DoD Assessment Methodology v1.2.1 weight, and each measured finding stores an excerpt of the API response behind it with its SHA-256 hash. The scan covers a focused set of controls per cloud; intake answers supply context such as CUI scope and prior assessment history. The report is AI-generated and is not a C3PAO assessment, not a measured DoD-system score, and not to be filed as an official DoD document.

The Snapshot is one PDF, delivered once. Re-scans of connected clouds about every 7 days and refreshed documents on a tier cycle come with a readiness subscription.

Your report, built from your connected environment and your intake, in your inbox within minutes of intake.

$999 one-time. Connect a cloud (read-only, revocable at any time), answer the intake, and your PDF arrives within minutes of intake. Async, self-service throughout.

Run my Level 2 Readiness Snapshot, $999 →