CMMC Level 2 / NIST 800-171 automation

Know your CMMC gaps
before your assessor does.

Evidence-based control scoring pulled straight from your cloud, not a self-attestation checklist you hope holds up under audit.

Read-only access · No agents · 110 controls scored

Compliance postureCMMC Level 2
64%Overall posture+4% this month
ACAccess Control82%
AUAudit & Accountability58%
SCSystem & Comms Protection41%
IAIdentification & Auth74%

Evidence connected

AWS · GitHub · M365

The part nobody tells you

Your gap list isn't proof you did compliance wrong.

CMMC Level 2 is new, the assessment ecosystem is still standing itself up, and the requirements have shifted more than once since your prime sent that flow-down letter. Every subcontractor your size got the same letter this year.

The gap isn't that you were careless. It's that nobody handed a 20-person shop the resources a prime's own compliance department has — and most of what's marketed to you is sized for companies ten times your headcount.

You don't need a compliance department. You need your actual gaps, mapped to what a C3PAO will actually ask for, without paying enterprise-GRC prices to get them.

Prime requirement cascaded to many subcontractorsPrime Contractor

One requirement, cascaded to many

Before anyone reviews your evidence

Three places your compliance posture gets judged before a human ever opens your file.

01

The flow-down checklist

Your prime's contracts team checks a box on whether you can self-attest, and increasingly, whether you've started a real assessment. No checklist, no subcontract.

02

The pre-assessment scan

C3PAOs are starting to run automated evidence checks before the formal assessment even begins. What your AWS, GitHub, and M365 environments actually show matters before a person looks at anything.

03

What a security researcher finds

Public-facing gaps — exposed repos, stale IAM policies, unpatched systems — get found whether or not you were ready to be looked at.

The only one of these you fully control is what your evidence actually shows. That's what a gap scan gives you before anyone else looks.

The system

What we actually do, in the order we do it.

01

Baseline

We pull your evidence from AWS, GitHub, and M365 and run it against the NIST 800-171 control set — the same public framework a C3PAO assessor uses, not a proprietary scoring system. You get your actual gap list, not a sales call.

02

Map to OSA

Every gap gets mapped to the Open Security Architecture Security Capability Model, so you can see which capability domain it falls under, not just a bare control number.

03

Score and prioritize

One consistent, data-driven scoring pass across every control — not selective spot-checks — so nothing gets missed and nothing gets inflated.

04

Generate your POA&M

Every unmet control becomes a real Plan of Action & Milestones entry, ready for your prime or your assessor, not a generic template you fill in yourself.

The good news

You don't need a GRC platform sized for a Fortune 500 compliance team.

Vanta, Drata, and OneTrust are built for compliance teams — plural. A 20–200 person DoD subcontractor doesn't have one of those; it has an IT admin doing this alongside their actual job.

Being audit-ready isn't about buying a seat you'll use once a quarter. It's about having your evidence mapped to the controls that actually apply to you, and current when the assessor asks.

Built for DoD subcontractors preparing for CMMC Level 2 assessment

110NIST 800-171 controls scored
3Evidence sources connected
0Agents to install

Customer logos appear here once reference agreements are signed.

The mechanism

Raw cloud config in. Defensible assessment package out.

Every stage turns scattered account settings into a control-by-control record you can hand an assessor without flinching.

01 · Ingest

Evidence connectors

Link AWS, GitHub, and Microsoft 365 once. Configuration and activity are pulled read-only on a schedule — nothing installed on your endpoints.

AWSIAM · CloudTrail · Config
GitHubBranch rules · secrets
M365MFA · DLP · audit log
02 · Normalize

One evidence schema

Every source is flattened into the same evidence shape, so an MFA setting in M365 and an IAM policy in AWS answer the same control question.

03 · Score

All 110 controls, rated

Each control resolves to met, partial, or failed, with the evidence that produced the verdict attached.

64%+4% MoM

Coverage by family

AC
AU
SC
IA
CM
IR
04 · Map

CMMC ↔ NIST 800-171

One piece of evidence satisfies its CMMC practice and the NIST 800-171 requirement behind it — mapped once, never re-gathered.

CMMC AC.L2-3.1.5800-171 3.1.5
CMMC AU.L2-3.3.5800-171 3.3.5
05 · Attest

Immutable audit trail

Every score change is append-only and timestamped with the evidence hash behind it, so you can prove when a control was met — not just that it is.

2026-01-14 09:12 · AC.L2-3.1.5 → Metsha256:4f1c…a09e
06 · Export

POA&M export

Open gaps become Plan of Action & Milestones entries with owners, remediation steps, and target dates — formatted the way assessors expect.

POAM_2026Q1.xlsx
SSP_appendix.docx
evidence_bundle.zip
Pricing

Priced below one day of consultant time

No per-control fees, no per-seat surprises. Cancel whenever your assessment is behind you.

Assess

For a single entity getting its first honest score.

$490/ month
  • All 110 NIST 800-171 controls scored
  • 1 connector (AWS, GitHub, or M365)
  • Monthly evidence refresh
  • Gap list with plain-English reasons
Start assessing
Most common

Operate

For contractors actively closing gaps before an assessment.

$1,290/ month
  • Everything in Assess
  • All three connectors, continuous sync
  • POA&M generation and export
  • Evidence bundle for your assessor
  • Posture history and trend tracking
Get Started

Enclave

For primes and MSPs managing multiple subcontractor environments.

Custom
  • Everything in Operate
  • Multi-org rollup dashboard
  • SSO and role-based access
  • Custom control mappings
  • Named compliance advisor
Talk to us
FAQ

Questions we get before every assessment

Still unsure whether this fits your contract requirements? Reach out and we'll tell you plainly if it does not.

See your actual NIST 800-171 gap list, mapped and scored.

Connect your AWS, GitHub, or M365 environment and get a real baseline — the same control set a C3PAO will use, not a sales pitch.