Terms of Service
Last updated: August 1, 2026
1. Service Description
CMMC Command provides a software-as-a-service platform for Defense Industrial Base (DIB) contractors to perform NIST SP 800-171 self-assessments, manage evidence, generate gap analysis reports, and produce System Security Plans (SSPs) in support of CMMC Level 2 preparation and assessment activities.
2. Not Legal or Compliance Advice
This tool is a compliance management aid, not a substitute for professional legal, cybersecurity, or compliance advice. We do not guarantee that use of this tool will result in CMMC status or certification. Users should consult qualified advisers and, when a certification assessment is required, an authorized Certified Third-Party Assessment Organization (C3PAO).
3. Account Responsibilities
You are responsible for maintaining the confidentiality of your account credentials and for all activities under your account. Company administrators are responsible for managing team member access and ensuring appropriate role assignments.
4. Subscription & Billing
Paid plans are billed monthly or annually through our PCI DSS compliant payment processor. You may cancel at any time; access continues through the end of the current billing period. Refunds are provided at our discretion for annual plans within the first 14 days.
5. Data Ownership
You retain full ownership of all compliance data, evidence files, and documents uploaded to the platform. We claim no intellectual property rights over your content. Upon account termination, you may export your data before deletion.
6. Limitation of Liability
CMMC Command is provided “as is.” We are not liable for any damages arising from your use of the service, including but not limited to loss of contracts, failed assessments, or data breaches caused by your configuration or third-party integrations.
7. Contact
For questions about these terms, contact legal@cmmccommand.org.