One requirement, cascaded to many
Know your CMMC gaps
before your assessor does.
Evidence-based control scoring pulled straight from your cloud, not a self-attestation checklist you hope holds up under audit.
Read-only access · No agents · 110 controls scored
Evidence connected
AWS · GitHub · M365
Your gap list isn't proof you did compliance wrong.
CMMC Level 2 is new, the assessment ecosystem is still standing itself up, and the requirements have shifted more than once since your prime sent that flow-down letter. Every subcontractor your size got the same letter this year.
The gap isn't that you were careless. It's that nobody handed a 20-person shop the resources a prime's own compliance department has — and most of what's marketed to you is sized for companies ten times your headcount.
You don't need a compliance department. You need your actual gaps, mapped to what a C3PAO will actually ask for, without paying enterprise-GRC prices to get them.
Three places your compliance posture gets judged before a human ever opens your file.
The flow-down checklist
Your prime's contracts team checks a box on whether you can self-attest, and increasingly, whether you've started a real assessment. No checklist, no subcontract.
The pre-assessment scan
C3PAOs are starting to run automated evidence checks before the formal assessment even begins. What your AWS, GitHub, and M365 environments actually show matters before a person looks at anything.
What a security researcher finds
Public-facing gaps — exposed repos, stale IAM policies, unpatched systems — get found whether or not you were ready to be looked at.
The only one of these you fully control is what your evidence actually shows. That's what a gap scan gives you before anyone else looks.
What we actually do, in the order we do it.
Baseline
We pull your evidence from AWS, GitHub, and M365 and run it against the NIST 800-171 control set — the same public framework a C3PAO assessor uses, not a proprietary scoring system. You get your actual gap list, not a sales call.
Map to OSA
Every gap gets mapped to the Open Security Architecture Security Capability Model, so you can see which capability domain it falls under, not just a bare control number.
Score and prioritize
One consistent, data-driven scoring pass across every control — not selective spot-checks — so nothing gets missed and nothing gets inflated.
Generate your POA&M
Every unmet control becomes a real Plan of Action & Milestones entry, ready for your prime or your assessor, not a generic template you fill in yourself.
You don't need a GRC platform sized for a Fortune 500 compliance team.
Vanta, Drata, and OneTrust are built for compliance teams — plural. A 20–200 person DoD subcontractor doesn't have one of those; it has an IT admin doing this alongside their actual job.
Being audit-ready isn't about buying a seat you'll use once a quarter. It's about having your evidence mapped to the controls that actually apply to you, and current when the assessor asks.
Built for DoD subcontractors preparing for CMMC Level 2 assessment
Customer logos appear here once reference agreements are signed.
Raw cloud config in. Defensible assessment package out.
Every stage turns scattered account settings into a control-by-control record you can hand an assessor without flinching.
Evidence connectors
Link AWS, GitHub, and Microsoft 365 once. Configuration and activity are pulled read-only on a schedule — nothing installed on your endpoints.
One evidence schema
Every source is flattened into the same evidence shape, so an MFA setting in M365 and an IAM policy in AWS answer the same control question.
All 110 controls, rated
Each control resolves to met, partial, or failed, with the evidence that produced the verdict attached.
Coverage by family
CMMC ↔ NIST 800-171
One piece of evidence satisfies its CMMC practice and the NIST 800-171 requirement behind it — mapped once, never re-gathered.
Immutable audit trail
Every score change is append-only and timestamped with the evidence hash behind it, so you can prove when a control was met — not just that it is.
POA&M export
Open gaps become Plan of Action & Milestones entries with owners, remediation steps, and target dates — formatted the way assessors expect.
Priced below one day of consultant time
No per-control fees, no per-seat surprises. Cancel whenever your assessment is behind you.
Assess
For a single entity getting its first honest score.
- All 110 NIST 800-171 controls scored
- 1 connector (AWS, GitHub, or M365)
- Monthly evidence refresh
- Gap list with plain-English reasons
Operate
For contractors actively closing gaps before an assessment.
- Everything in Assess
- All three connectors, continuous sync
- POA&M generation and export
- Evidence bundle for your assessor
- Posture history and trend tracking
Enclave
For primes and MSPs managing multiple subcontractor environments.
- Everything in Operate
- Multi-org rollup dashboard
- SSO and role-based access
- Custom control mappings
- Named compliance advisor
Questions we get before every assessment
Still unsure whether this fits your contract requirements? Reach out and we'll tell you plainly if it does not.
See your actual NIST 800-171 gap list, mapped and scored.
Connect your AWS, GitHub, or M365 environment and get a real baseline — the same control set a C3PAO will use, not a sales pitch.