Skip to main content
CMMC update: Phase 2 transition suspended July 13, 2026

CMMC Preparation, Simplified.

Organize your NIST SP 800-171 self-assessment, remediation evidence, and assessment preparation in one place. 10 AI features help you identify gaps and plan next steps.

NIST SP 800-171 Rev 2 alignedAll 110 requirements included for trackingSupports Level 2 preparationCUI uploads prohibited

No credit card required · Free assessment included · Cancel anytime

110
Level 2 Security Requirements
Annual
CMMC Affirmation Cadence
-203→110
SPRS Score Range
NIST 800-171 Rev 2 Aligned
Designed for CUI-Free Metadata
DFARS Assessment Support
4 steps to stronger preparation

How it works

Build a repeatable assessment and remediation workflow at a pace that matches your organization, system boundary, and contract.

Start here

Assess Your Controls

Review all 110 NIST SP 800-171 requirements. Enter each status and see an estimated SPRS score update from those entries.

Prioritize

Identify & Prioritize Gaps

AI drafts possible next steps from entered statuses. Validate scope, risk, dependencies, effort, and applicability with responsible personnel.

Your timeline

Remediate & Document

Assign remediation tasks, upload evidence, generate policy drafts, and build your SSP draft. Integrations collect selected metadata and suggest mappings for human review.

Prepare

Prepare for the Required Assessment

Use interview prep, readiness indicators, and assessor collaboration tools to organize your evidence for the assessment type specified in your contract.

See it in action

Everything you need, nothing you don't

From self-assessment through remediation and assessment preparation, keep your work mapped, scored, and documented.

cmmccommand.org/dashboard

Estimated SPRS score using DoD assessment weights across all 110 NIST SP 800-171 requirements.

Estimated SPRS Score

47

Score range: -203 to 110

+23 this month

68 / 110 controls implemented

ACAccess Control
14 5 3
64%
AUAudit & Accountability
7 1 1
78%
ATAwareness & Training
2 1 0
67%
CMConfiguration Mgmt
4 3 2
44%
IAIdentification & Auth
8 2 1
73%
IRIncident Response
1 1 1
33%
MAMaintenance
3 2 1
50%
SCSystem & Comms
9 4 3
56%
10 AI features · Professional plan

Your AI preparation assistant

Draft gap narratives, remediation ideas, evidence questions, and interview practice from the data you enter. Outputs require qualified human review and do not predict assessment acceptance.

AI Executive Summary

Draft implementation-status narrative from entered control metadata for human review.

AI Gap Analysis

Owner-review gap drafts with SPRS deduction context; validate risk, scope, dependencies, and applicability.

AI Policy Drafting

Generate editable policy drafts aligned to relevant NIST SP 800-171 requirements.

AI SSP Narratives

Draft per-requirement implementation statements for your System Security Plan.

AI Preparation Advisor

Chat-based Q&A grounded in entered assessment data, with qualified-human review still required.

AI Remediation Plans

Draft remediation steps, dependencies, and evidence considerations for owner review.

AI Evidence Review

Automated feedback to help reviewers identify possible evidence gaps before an assessment.

AI Interview Prep

Practice with illustrative questions informed by assessment objectives; not assessor-approved answers.

AI Control Mapping

Suggest NIST mappings from selected integration metadata for human review.

AI-enhanced POA&M Narratives

Draft owner-review remediation outlines for POA&M exports from canonical gap metadata.

Everything you need

From first requirement to organized review

Built specifically for CMMC Level 2 preparation in the Defense Industrial Base, with human validation required for scope, evidence, and findings.

Free

Guided Self-Assessment

Walk through all 110 NIST SP 800-171 controls across 14 families with plain-English guidance.

Starter+

Evidence Vault

Upload, organize, and link policy documents and audit artifacts directly to controls with expiration tracking.

Free

SPRS Impact Simulator

Toggle entered statuses and see an estimated SPRS score scenario using published DoD deductions.

Free

Implementation Progress

Track preparation indicators by domain and review common assessment focus areas.

Professional+

Metadata Drift Alerts

Scheduled checks can alert on detected changes in selected integration metadata; they do not establish continuous compliance.

Starter+

SSP & POA&M Generation

Generate structured System Security Plan and Plan of Action & Milestones drafts from your assessment data.

Professional+

10 Security Integrations

Collect selected security metadata and suggest NIST mappings for human review.

Professional+

Remediation Task Board

Assign, prioritize, and track remediation tasks with deadline alerts and burn-down analytics.

Live Interactive Demo

Explore the platform with clearly labeled fictional sample data, no sign-up required.

Starter+

Role-Based Workflows

5 roles (Admin, Compliance Manager, Employee, Auditor, External) across workspaces. Invite contractors and assessors to collaborate without mixing your data.

Starter+

Asset Inventory & CUI Boundary

Document systems that process CUI and map the boundary for assessment scoping and review.

Starter+

Incident Response Tracker

Report, investigate, and resolve security incidents. Full NIST IR lifecycle with timeline tracking.

Starter+

Training & Awareness

Assign and track security awareness training. Monitor completion rates and satisfy 3.2.x requirements.

10 integrations

Works with your existing security stack

Sync selected security metadata and suggested NIST mappings for human review. Integrations can reduce, but not eliminate, manual evidence work.

Microsoft Entra ID

MFA, users, conditional access

Microsoft 365 & Defender

Endpoint, patches, encryption

CrowdStrike Falcon

EDR, threats, incident response

Google Workspace

2SV, admin audit, drive policies

AWS

IAM, CloudTrail, Security Hub

SentinelOne

Endpoint protection, threat data

Tenable.io

Vulnerability scans, risk scores

KnowBe4

Training completion, phishing rates

Jamf Pro

Apple MDM, device compliance

Okta

MFA, users, audit logs

Integrations request selected security-tool metadata, not documents. Some metadata may include account or device identifiers. Suggested NIST mappings require human review and do not establish an assessment finding.

Why switch?

Manual compliance vs. CMMC Command

Centralize the work your team would otherwise track across spreadsheets, documents, and separate remediation tools.

Feature
Manual / Consultant
CMMC Command
110-control NIST 800-171 assessment
Spreadsheets & Word docs
Guided walkthrough with SPRS scoringFREE
SPRS score calculation
Manual formula, error-prone
Estimate from entered statuses using published DoD weightsFREE
Gap analysis & prioritization
Manual review or external support
AI-generated with SPRS impact contextPRO+
SSP & POA&M document generation
Draft and maintain manually
Structured drafts from assessment dataSTARTER+
Evidence collection & vault
Screenshots & file shares
Upload vault (Starter) + metadata integrations (Professional)PRO+
Policy documentation
Hire a consultant or write from scratch
5-20 aligned templates + AI draftingSTARTER+
Remediation task management
Spreadsheet tracking
Task board with deadline alerts & analyticsPRO+
Assessment preparation
Organize and practice manually
AI interview practice + internal progress indicatorsPRO+
Metadata drift review
Periodic manual review
Metadata drift checks every 4 hoursPRO+
Asset inventory & CUI boundary
Spreadsheet asset list
CUI boundary inventory fields and asset categoriesSTARTER+
Incident response tracking
Email chains & Word docs
Full IR lifecycle with timeline & metricsSTARTER+
Security awareness training
Track in spreadsheet, hope people complete
Assign, track, monitor completion ratesSTARTER+
Team & organization management
Ad-hoc email, no role controls
Role-based access, org switcher, up to 10 Starter seatsSTARTER+
Platform price
Varies by internal and external support
Free to start, from $249/mo

CMMC Command is a preparation and workflow aid. It does not certify compliance, replace a required C3PAO or government assessment, or guarantee an assessment outcome.

Selected security metadata collected from supported tools

Microsoft Entra ID
Microsoft 365
CrowdStrike
Google Workspace
AWS
SentinelOne
Tenable.io
KnowBe4
Jamf Pro
Okta

110 controls. Zero guesswork.

Full NIST SP 800-171 Rev 2 coverage with DoD assessment weights built in. Track each requirement and review an estimated SPRS score.

Evidence vault, not a spreadsheet.

Centralized evidence with expiration tracking and limited marker screening. Do not upload CUI; review files before sharing or assessment use.

AI that knows CMMC.

Claude-powered gap analysis and SSP narratives scoped to your specific control gaps, not generic compliance boilerplate.

Structured documentation drafts.

Structured System Security Plan and POA&M drafts generated from your assessment data, with SPRS impact context and owner-defined milestones.

110NIST SP 800-171 Requirements
320Assessment Objectives
10Security Tool Integrations
-203→110Full SPRS Score Range
ROI Calculator

Model a Time-Cost Scenario

Use your own expected time savings and loaded labor or consulting rate. Results are planning estimates, not guaranteed savings.

Your numbers

Illustrative starting values; adjust to match your situation

Hours you expect to save monthly0 hrs/mo
0 hrs/mo80 hrs/mo
Loaded labor or consulting rate$150/hr
$50/hr$400/hr
Modeled monthly time value$0
CMMC Command platform$749 / mo
Modeled difference$749 / mo

Modeled monthly difference

Breaks even at 5 hrs/mo

Enter at least 5 expected saved hours at this rate

Modeled annual difference

Mathematical break-even: 5 entered hours per month. Actual savings depend on adoption, scope, labor rates, and work displaced.

Planning estimate only. Excludes C3PAO or government assessment, remediation, technology, legal, and certification costs.

Build a detailed scenario
Simple pricing

Start free, scale as you grow

Every plan includes a free assessment. No surprise fees. Cancel anytime.

Monthly
Annual

Free

Assess your CMMC readiness in minutes.

$0forever

No credit card required

  • 1 user seat
  • 1 workspace
  • All 110 NIST SP 800-171 controls
  • Estimated SPRS score updates
  • Gap analysis dashboard
  • SPRS Impact Simulator
  • Implementation Progress dashboard
Get Started Free

Starter

For small contractors building compliance artifacts.

$249/month

Or

  • Everything in Free
  • 10 user seats + team management
  • 5 workspaces
  • Evidence vault with expiration tracking
  • SSP & POA&M document export
  • 5 policy templates + team acknowledgments
  • SPRS trend history & CSV export
  • Asset inventory + CUI boundary mapping
  • Incident response tracker
  • Training & awareness tracker
  • Audit log
Get Started

Professional

For teams with a dedicated compliance program.

$749/month

Or

  • Everything in Starter
  • 20 user seats
  • 10 workspaces
  • 10 AI features incl. Compliance Advisor
  • All 20 policy templates + AI drafting
  • Remediation task board with deadline alerts
  • 320-objective assessment tracking
  • 10 integrations + drift monitoring
  • Task analytics (burn-down & velocity)
  • Executive PDF report
Get Started
Coming Soon

Enterprise

For large contractors with multiple programs and auditors.

Custom

Tailored to your organization's needs

  • Everything in Professional
  • Unlimited user seats
  • Unlimited workspaces
  • Multi-entity portfolio management
  • C3PAO assessor collaboration portal
  • SSO / SAML authentication
  • REST API with API key management
  • Unlimited integrations
  • Dedicated success manager + SLA

Start free with all 110 NIST controls. No credit card required. Joining a team via invite never counts against workspace limits. Government pricing available. Contact sales@cmmccommand.org

CMMC Command Pricing Plans

PlanMonthly PriceAnnual PriceUsersFeatures
Free$0/month$0/year1 user seat1 user seat, 1 workspace, All 110 NIST SP 800-171 controls, Estimated SPRS score updates, Gap analysis dashboard, SPRS Impact Simulator, Implementation Progress dashboard
Starter$249/month$2,490/yearEverything in FreeEverything in Free, 10 user seats + team management, 5 workspaces, Evidence vault with expiration tracking, SSP & POA&M document export, 5 policy templates + team acknowledgments, SPRS trend history & CSV export, Asset inventory + CUI boundary mapping, Incident response tracker, Training & awareness tracker, Audit log
Professional$749/month$7,490/yearEverything in StarterEverything in Starter, 20 user seats, 10 workspaces, 10 AI features incl. Compliance Advisor, All 20 policy templates + AI drafting, Remediation task board with deadline alerts, 320-objective assessment tracking, 10 integrations + drift monitoring, Task analytics (burn-down & velocity), Executive PDF report
EnterpriseCustom/monthCustom/yearEverything in ProfessionalEverything in Professional, Unlimited user seats, Unlimited workspaces, Multi-entity portfolio management, C3PAO assessor collaboration portal, SSO / SAML authentication, REST API with API key management, Unlimited integrations, Dedicated success manager + SLA
Current CMMC rollout status

Phase 2 transition is suspended

On July 13, 2026, DoD suspended the transition to Phase 2 and future implementation milestones while it reviews the program. Phase 1 remains in effect.

A CMMC requirement applies when the solicitation or contract includes DFARS 252.204-7021 and specifies the required level and assessment type. Separate safeguarding and SPRS obligations may still apply. Confirm your contract's terms with your contracting officer or qualified adviser.

Common questions

Frequently asked questions

Everything you need to know about CMMC Command and getting prepared for your required assessment.

CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Rev 2. During the current DoD suspension, solicitations and contracts may designate Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3. Verify the latest solicitation and any contract modification; separate DFARS safeguarding and SPRS obligations may also apply.

CMMC Command Frequently Asked Questions

What is CMMC Level 2 and who needs it?

CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Rev 2. During the current DoD suspension, solicitations and contracts may designate Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3. Verify the latest solicitation and any contract modification; separate DFARS safeguarding and SPRS obligations may also apply.

What happened to the CMMC Phase 2 deadline?

On July 13, 2026, DoD suspended the transition to Phase 2 and future implementation milestones while it reviews the program. Phase 1 remains in effect, and there is currently no authoritative November 2026 Phase 2 certification deadline. Check each solicitation and contract for DFARS 252.204-7021 and the specified CMMC requirement.

Can I use CMMC Command for my self-assessment?

Yes. The free tier provides a guided review of all 110 NIST SP 800-171 Rev 2 requirements and an estimated SPRS score based on the statuses you enter. Confirm the final score and any submission obligation against your contract, DFARS 252.204-7019, and the DoD Assessment Methodology.

What's included in each plan?

The free plan has no time limit - you get all 110 NIST SP 800-171 requirements, estimated SPRS score calculation, and gap analysis. Starter ($249/mo) adds the evidence vault with expiration tracking, SSP and POA&M document export, 5 policy templates with team acknowledgments, asset inventory, and incident response tracking. Professional ($749/mo) adds all 10 AI features, 20 policy templates, 10 security tool integrations, the remediation task board, and advanced analytics. Enterprise is coming soon with planned multi-entity, REST API, and assessor-collaboration features.

How does the AI preparation assistant work?

Our 10 AI features use entered assessment metadata to generate gap-analysis narratives, remediation-plan and POA&M narrative drafts, SSP implementation-statement drafts, evidence-gap feedback, illustrative interview practice, and integration-mapping suggestions. AI endpoints are designed not to receive uploaded documents. Do not enter CUI or classified information; limited safety checks do not determine information status.

Do you store CUI or sensitive documents?

CMMC Command is not intended or authorized for CUI or classified information. Do not upload it. Evidence files uploaded by users are stored in the platform; automated marker screening is limited, does not inspect every format or image, and is not a CUI determination. Our security practices are documented at cmmccommand.org/security.

How does CMMC Command compare to hiring a consultant?

CMMC Command supports assessment tracking, gap analysis, document drafting, evidence organization, and remediation planning starting free, or $249/mo for evidence management and document export, or $749/mo for AI-generated narratives, integration-metadata review, and remediation workflows. It does not determine compliance, replace a required assessor, or guarantee an assessment result.

What integrations are supported?

We connect with 10 security tools: Microsoft Entra ID, Microsoft 365 & Defender, CrowdStrike Falcon, Google Workspace, AWS, SentinelOne, Tenable.io, KnowBe4, Jamf Pro, and Okta. Integrations collect selected security metadata and map it to relevant NIST requirements for human review, reducing but not eliminating manual evidence work. Available on Professional and Enterprise plans.

Can I cancel anytime?

Monthly plans renew monthly; annual plans are billed for an annual term. You may cancel renewal, and paid access continues through the current billing period. Available CSV exports cover controls, evidence metadata, audit logs, and tasks. See the Terms for billing and refund details.

Free 110-control assessment included

Build a stronger assessment record.
Start today.

Start organizing your NIST SP 800-171 assessment, evidence, and remediation work. Free assessment, no credit card required.

No credit card required · Free tier includes all 110 controls · Cancel anytime