Standard is built for the OSA with a C3PAO date ahead and limited bandwidth. Enclave AI™ establishes your compliance state from your connected clouds’ read-only configuration metadata, re-scanned about every 7 days, and from your intake where no connected source reaches. The readiness plane receives only the authorized telemetry needed to establish compliance state, never file, mailbox or message contents. Each 30-day cycle delivers a CMMC readiness package built from that state and measured against the 110-control, 320-objective NIST 800-171 baseline: your highest-impact control gaps, your SPRS posture, and a prioritized plan for what to fix next. Your SSP and Evidence Library Index are assembled across your cycles as your environment data accrues. Agents perform the recurring work. Your people keep accountability, authorization and professional judgment: your designated executives approve or disapprove each delivered document, and your Affirming Official decides what to affirm.
What you walk away with each 30-day cycle
- A control-by-control readiness analysis, not a template. Measured against your intake answers and your connected clouds, aligned to NIST SP 800-171 Rev. 2, every one of the 110 controls and 320 assessment objectives addressed by control ID. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Your System Security Plan is assembled from this analysis and built out across your cycles as your evidence accrues.
- A draft POA&M built from your open gaps. Every open gap is listed with the control ID it maps to and its 32 CFR 170.21 POA&M eligibility, plus a proposed owner and date that are marked as proposals for your team to confirm or change.
- An Evidence Library Index building out from your environment and your recorded artifacts. Each cycle pulls fresh configuration metadata from your connected AWS / Azure / M365 / Google Workspace / Okta / CrowdStrike accounts (read-only: AWS through an inline, configuration-metadata-only policy with no s3:GetObject; Azure through Reader + Security Reader; Microsoft 365 through read-only Microsoft Graph application permissions), hashes the API response with SHA-256, files it under the NIST control it measures, and maps it to that control’s assessment objectives.
- An estimate of where your SPRS posture stands. Estimated against your measured evidence using the DoD Assessment Methodology weights. If your estimate moved since the last cycle, your workspace shows the change and any controls that regressed.
- Your framework target, your choice. NIST SP 800-171 Rev. 2 is the scored baseline (it is what 32 CFR 170 binds to, and the only revision with a DoD assessment methodology). Choose Rev. 3 at intake or in your workspace and every workspace document is also rendered against the 97-requirement Rev. 3 set through NIST’s own change analysis, Rev. 2 figures alongside, no Rev. 3 score invented.
- Executive review of every deliverable. Your designated executives review each completed package from their signed-in seat and record approve or disapprove against the exact document delivered; a disapproval requires a reason and the ruling lives in an append-only ledger. Who is responsible when the AI is wrong →
- Self-service help. Links, order status, document downloads and copies, billing and team sign-in start from the help page, without waiting on anyone.
What life looks like 30 days in
When your prime asks for your current SPRS posture, the most recent readiness package is already in your inbox. When a measured control drifts, for example an S3 bucket’s public access block is turned off or the tenant’s Conditional Access policies are removed, the next re-scan of your connected sources (about every 7 days) records it, your workspace shows the regressed control, and the next cycle’s POA&M is rebuilt from the new findings without you opening a ticket.
Not on Standard
- Fortress runs a deliverable cycle every 14 days and adds a Monitoring Runbook and an Audit-Defense Exhibit List to each cycle. The automated format quality gate that blocks a deliverable that fails it is not a Fortress extra: it runs on every tier, Standard included.
- Multi-entity / multi-subsidiary scope under one contract, that’s Sovereign, up to 10 entities.
- Custom integrations to legacy on-premise GRC, ticketing, or SIEM. Not offered on any tier today.
- CMMC Level 3 (selected NIST SP 800-172 requirements, assessed by DCMA DIBCAC under 32 CFR 170.18). Not on the platform today, and we say so on the FAQ.
The first 30 days, step by step
- Minute 0. Stripe processes your subscription. Welcome email lands with two links: your onboarding page (intake and connectors) and your asset register.
- Minutes 5–15. You answer the intake about your environment, your self-reported SPRS score and your DFARS 252.204-7012 flow-down. You connect the clouds you want measured, AWS via CloudFormation role (one click), Azure / M365 via Service Principal, Google Workspace via a read-only service account, Okta via API token, CrowdStrike via OAuth2 client. Each connector is read-only and you can revoke it at any time by deleting the role, app or token.
- Minutes 15–60. First multi-cloud scan runs. Your first CMMC readiness package lands in your inbox: control-gap analysis against the 110-control NIST 800-171 baseline, your SPRS posture against your self-reported score, and a 30-day remediation plan ordered by point-recovery impact.
- Days 1–30. Your connected sources are re-scanned about every 7 days, and your workspace shows any control that regressed. Your SSP and Evidence Library Index build out as data flows in.
- Day 30 cycle. Second full cycle. A refreshed readiness package built from the latest scan results, with your workspace showing the score change since the last cycle.
How Enclave AI™ differs from a compliance dashboard.
A compliance dashboard is Software As A Service (SaaS): you log in and you see your score, and the work that remains is your team’s to schedule.
Our operating model is Agent as a Service (AaaS) rather than conventional SaaS. SaaS sells you a subscription plus homework: the software holds the forms, and your people spend the labor hours filling them in, every cycle, for every entity. That does not scale. In AaaS the agents do the work. They measure, collect and record evidence, draft and maintain the documents, and deliver a report for a named person to approve or deny. People keep accountability, authorization and professional judgment.
The work product lands in your inbox each cycle: your control-gap analysis against the 110-control NIST 800-171 baseline, your SPRS posture report, and a prioritized remediation plan, with your SSP and Evidence Library Index building out as your environment data accrues. Enclave AI™ does the work; your designated executives can review each report and approve or disapprove it, and your Affirming Official makes every affirmation decision. You can ignore the platform for 29 days and the deliverables still ship on day 30.
The Big Idea, restated
A self-reported SPRS score is only as current as the environment behind it. Standard measures your environment against the framework target every 30 days, shows you the gaps and the plan to close them in writing, and leaves the decision on what to affirm with your executives.
Start your subscription
$29,940 per year, or $2,495 month-to-month. The $999 CMMC Level 2 Readiness Snapshot credits in full to your first Level 2 subscription invoice if you subscribe with the same billing email within 30 days of receiving its PDF, under the Refund Policy.
Subscribe to Standard, $29,940/year →