NIST 800-171 · CMMC Level 1 & 2 Readiness
The CMMC contract clause started landing in DoD solicitations in November 2025. Before you spend on a C3PAO assessment, get an honest read on your SPRS score and your exact gap list — so you fix the right things first, not everything at once.
The Department of Defense's CMMC rule (48 CFR) was published on September 10, 2025, and the contract clause (DFARS 252.204-7021) began appearing in contracts starting November 10, 2025, kicking off a phased rollout through 2026. Most organizations need 9–12 months to fully implement NIST SP 800-171, validate it, and pass a third-party (C3PAO) assessment. If Controlled Unclassified Information touches your business and you haven't measured your SPRS score, you're already inside that window.
Here's the trap most small subcontractors fall into: they either freeze — doing nothing until a contract is at risk — or panic-spend, hiring a big firm to “fix everything.” Both are expensive. The smart first move is cheap and fast: measure, then prioritize.
Answer a short set of questions and get an immediate estimate of your SPRS score the way the DoD computes it, plus which of the 110 controls are likely gaps. No sales call, no credit card.
A documented, evidence-based gap report: where you stand control-by-control, what to fix first (ranked by SPRS point impact), and exactly what a C3PAO will look for. The roadmap you hand your team — or your assessor.
See your estimated SPRS score and top gaps in about five minutes.
We turn that into a prioritized, documented gap report for $299.
Work the ranked list — and keep it current with SupervEyes monitoring.
Honest by design. InitialEyes is not a C3PAO, and this is not a certification. A readiness assessment tells you where you stand and what to fix before your formal assessment — it does not produce a CMMC certification or an attestation. We'll tell you plainly what you still need and who performs it. That honesty is the point: you get an accurate picture, not a sales pitch dressed up as a stamp.
No. CMMC Level 2 certification is issued by an accredited C3PAO after a formal assessment. We prepare you for that — we measure your readiness and hand you the gap list so the formal assessment goes smoothly and you don't pay to discover surprises.
It's the NIST 800-171 self-assessment score (out of 110) the DoD uses to gauge your implementation. A low or unrealistic score is a red flag; our free read gives you an honest estimate.
It depends on the CUI/FCI in your contracts and where you fall in the phased rollout — but the 9–12 month implementation runway means the practical deadline is now, well ahead of the contract that requires it.
A C3PAO assessment is a formal, in-depth certification event that costs far more. Our $299 readiness assessment is the inexpensive first step that tells you whether you're ready for that — and what to fix if you're not.
A service of All-American Tech Services LLC, a Missouri company operating since 2015. Every framework is reconciled control-by-control against its authoritative source; we never reproduce copyrighted control text, and readiness is never sold as certification. A readiness assessment is not a validating assessment and does not produce an Attestation of Compliance.