What it measures
Modern AI reads your read-only configuration data from your connected cloud across the clouds you connect and compares it against the 110-control, 320-objective NIST 800-171 baseline. The result is your CMMC readiness analysis generated from your own data, not a survey, not a static questionnaire, so you see your actual starting point and your specific gaps before your C3PAO walks in, with the runway to close them on your own schedule. A readiness subscription keeps that picture current as your environment changes.
Two evidence sources feed the report:
- Live read-only scans of any cloud you connect, AWS (one-click CloudFormation role), Azure or Microsoft 365 (Service Principal with Reader + Security Reader scope), Okta (read-only API token), CrowdStrike Falcon (read-only OAuth2 client). Each connector is revocable in 30 seconds. Every finding cites a NIST 800-171 control ID, an SPRS deduction weight per the DoD Assessment Methodology, and a SHA-256 hash of the underlying API response.
- Your 7-question intake. Five minutes. Captures CUI scope, contractual posture, and the parts of your environment our connectors can’t reach yet (on-prem, niche SaaS, process-only controls).
Connect zero clouds and you get an intake-based directional gap analysis. Connect one or more clouds and you get measured findings with audit-grade evidence chains. Connect all five and we hand you the most accurate picture available short of a C3PAO walking your facility.
What you get
- Cover page, your self-reported SPRS score next to a directional estimate from your read-only cloud evidence. The delta is the headline. Three patterns we see: small delta (under 10 points) means your self-assessment reflects reality. Moderate (10–30) means your number is high and remediation gets you back in line. Large (over 30) means walk the report with your compliance counsel and surface it to your C3PAO the same week.
- Body, top NIST 800-171 control gaps with control IDs (3.1.1, 3.13.8, etc.), SPRS deduction weights per the DoD Assessment Methodology, and the evidence file that triggered each finding (with SHA-256 hash for chain-of-custody).
- 30-day remediation list, week-by-week actions, ordered by point recovery impact. Each line has expected point recovery if fully closed.
- Methodology + inputs, every number reproducible. Cite the report directly to your C3PAO or your prime if asked.
How it works
- Pay. Stripe checkout. One-time $799. Self-service, start to finish.
- Open your onboarding email (in your inbox within 60 seconds). Click the one link inside.
- Submit the 7-question intake (~5 minutes) and connect any of AWS / Azure / M365 / Okta / CrowdStrike for live evidence. Skip the connectors if you prefer intake-only.
- Receive your PDF. Inbox in minutes after intake. Reply to that email with any question, same-business-day answer, in writing, from a human in the loop.
What it is, and isn’t
The Readiness Snapshot is a measurement instrument. It tells you where you stand. It does not edit your environment, install software, or perform control remediation. It is also not a C3PAO pre-assessment, consulting engagement, or legal opinion. To actually close the gaps, the monthly readiness tiers (Standard, Fortress, Sovereign) measure your environment each cycle against the 110-control baseline, draft your POA&M, and build out your SSP and evidence binder as your data accrues. Your $799 credits 100% to month one if you continue within 30 days.
Privacy, before you connect anything
Every connector is scoped to configuration metadata only, never the data itself. AWS uses the AWS-managed SecurityAudit + ReadOnlyAccess policies (no decryption, no object reads). Azure / M365 use Reader + Security Reader at subscription scope. Okta and CrowdStrike use vendor-defined read-only token scopes. No CUI is harvested. Every connector is revocable in 30 seconds by deleting the role / app / token. Credentials are encrypted at rest with AES-GCM; decrypted in-process only at scan time. The report is private to your inbox, we don’t publish, share, or aggregate it.
Your $799 is protected two ways
It credits back to you. The full $799 applies to month one of any readiness subscription, Standard, Fortress, or Sovereign, if you continue within 30 days. For most buyers the Snapshot is a down payment on the work, not a separate cost.
Every finding is backed by evidence. Each gap in your report cites the exact evidence file behind it, with a SHA-256 hash and a timestamp. If any finding can’t be traced to its evidence, tell us and we’ll correct the report at no charge, that is our accuracy guarantee, in writing.
The Snapshot is a one-time digital deliverable that renders within minutes of your intake. Because it’s delivered to you instantly, the fee isn’t refundable once the PDF is sent, the credit and the accuracy guarantee above are how we carry the risk with you. Full terms on the refund policy.
Run my CMMC Readiness Snapshot, $799 →
No account to create · PDF in your inbox in minutes · $799 credits 100% to month one if you subscribe within 30 days