The PDF you receive follows this structure. When you connect a cloud, the gap rows are read-only scan findings from that environment, covering the controls our extractors measure, which is a focused subset of the 110 NIST SP 800-171 requirements; with nothing connected, the report is an intake-based directional analysis and says so. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. For the Snapshot, the choice is made at intake; the workspace comes with a readiness subscription. Cover and executive summary, up to seven control gaps ranked by deduction weight, a four-week remediation plan, and a methodology note. Below is that structure with fictional data for a fictional DIB manufacturer with one AWS account connected.
Disclaimer: This document is an AI-generated, intake-based readiness analysis. It is not a C3PAO assessment, not a measured SPRS score, and is not to be filed as an official DoD document. Use for internal preparation only.
Report date: 2026-09-14 · CAGE code: 8XXXX · Last self-assessment: 2026-01-15 · Self-reported readiness score on file: 88 · Rendered against: NIST SP 800-171 Rev. 2 (required)
Scan completed against your connected environment(s). 12 compliant finding(s), 7 non-compliant control(s), 1 item(s) flagged for review. Estimated SPRS deduction from non-compliant controls: 25 point(s). The highest-impact items follow on the next page, ordered by SPRS-recovery value.
The report sets your self-reported score beside the deduction attributable to the gaps the scan measured, and states that coverage is limited to the cloud(s) you connected: on-premises systems, unconnected services and process-only controls rely on your intake answers.
Each row names the NIST SP 800-171 Rev. 2 control, the DoD Assessment Methodology v1.2.1 weight if unimplemented, the evidence behind the finding, and a 30-day action. Specimen findings:
Findings table scrolls horizontally →
| Control ID | Finding and 30-day action | Weight | Evidence |
|---|---|---|---|
| 3.5.3 | 3 IAM user(s) with administrator-level policy attached do not have MFA configured. Action: enforce MFA on all IAM users with administrator policies, or remove the admin policy from accounts that do not need it. | −5 | AWS evidence: iam.user. API response retained with SHA-256 hash. |
| 3.3.1 | No multi-region CloudTrail trail with logging enabled was found. Action: create a multi-region CloudTrail trail with logging enabled and a retention policy that meets your contractual minimum. | −5 | AWS evidence: cloudtrail.trail. API response retained with SHA-256 hash. |
| 3.13.1 | 4 security-group rule(s) expose management ports to 0.0.0.0/0. Action: restrict management-port ingress to known CIDRs or a bastion or VPN, and remove the 0.0.0.0/0 rules. | −5 | AWS evidence: ec2.security_groups. API response retained with SHA-256 hash. |
| 3.14.6 | GuardDuty is not enabled in any scanned region. Action: enable GuardDuty in your primary region and in every region that runs workloads. | −5 | AWS evidence: guardduty.detector. API response retained with SHA-256 hash. |
| 3.13.8 | 3 of 12 S3 bucket(s) do not enforce TLS in transit. Action: add a bucket policy that denies requests where aws:SecureTransport is false on every bucket that may hold CUI. | −3 | AWS evidence: s3.buckets. API response retained with SHA-256 hash. |
| 3.1.20 | 2 of 12 S3 bucket(s) do not have full Public Access Block enabled. Action: enable all four Block Public Access settings on every CUI-relevant bucket. | −1 | AWS evidence: s3.bucket. API response retained with SHA-256 hash. |
| 3.3.8 | None of 1 CloudTrail trail(s) have log-file validation enabled. Action: enable log-file validation and restrict the log bucket and KMS key so audit records cannot be changed undetected. | −1 | AWS evidence: cloudtrail.trail. API response retained with SHA-256 hash. |
The PDF shows up to seven gap rows, one per control, non-compliant findings first, each with an effort label (low, medium or high by weight).
One step per week from the highest-weight gaps above. Effort and dependencies vary by environment; the plan is a prioritization, not a precise calendar.
Findings come from read-only scans of the environment(s) you connected (AWS via a cross-account IAM role with an inline, configuration-metadata-only policy and no s3:GetObject). Each finding cites a NIST SP 800-171 Rev. 2 control with its DoD Assessment Methodology v1.2.1 weight, and each measured finding stores an excerpt of the API response behind it with its SHA-256 hash. The scan covers a focused set of controls per cloud; intake answers supply context such as CUI scope and prior assessment history. The report is AI-generated and is not a C3PAO assessment, not a measured DoD-system score, and not to be filed as an official DoD document.
The Snapshot is one PDF, delivered once. Re-scans of connected clouds about every 7 days and refreshed documents on a tier cycle come with a readiness subscription.
$999 one-time. Connect a cloud (read-only, revocable at any time), answer the intake, and your PDF arrives within minutes of intake. Async, self-service throughout.
Run my Level 2 Readiness Snapshot, $999 →