CMMC requirements are now appearing in DoD contracts, and primes are pushing them down to every subcontractor. CyberPolicify walks you through Level 1's 17 practices — or the full Level 2 self-assessment, all 110 NIST SP 800-171 requirements with an estimated SPRS score — and generates the written policies assessors ask for.
Built for machine shops, manufacturers, engineering and IT services firms with 5-50 people — not for primes with a compliance department.
It comes down to one question: do you only handle Federal Contract Information (FCI), or does Controlled Unclassified Information (CUI) touch your systems?
Typical: janitorial, landscaping, parts suppliers, services firms with no CUI in scope.
Typical: machine shops with drawings, engineering firms, IT services touching DoD data.
Three steps, no consultants, no jargon.
Take the 3-minute Audit Ready Check. Get a readiness score across the CMMC Level 1 basics and a plain-English list of your gaps.
Work through your level control-by-control — all 17 Level 1 practices, or the full 110-requirement Level 2 with a live estimated SPRS score — with evidence notes, an AI gap summary, and a remediation tracker. Documented, not guessed.
Access control, physical security, media disposal, malware protection, and more — AI-generated for your business, exported to Word, ready for a prime's supplier questionnaire.
The $100k+ C3PAO audit? Not currently required.
With CMMC Phase 2 suspended, third-party certification assessments are on hold — the requirement of record today is your NIST 800-171 self-assessment score in SPRS (DFARS 252.204-7019/7020 never paused). That means the compliance bill drops from a six-figure audit to disciplined cyber hygiene — which CyberPolicify runs for $49–$99/month. What the pause means
Handling CUI under a Level 2 contract? CyberPolicify runs the full Level 2 self-assessment — all 110 NIST SP 800-171 requirements with an estimated SPRS score on the official DoD scale (−203 to 110), using the official 5/3/1-point weights — so you know your number before you register on PIEE. Start your Level 2 assessment.
A real Plan of Action & Milestones generated by CyberPolicify — cover block with your CAGE code and SPRS score, one row per open requirement with its DoD point weight, owners, due dates, milestones, and an Affirming Official signature block. Editable Word and upload-ready PDF. (Sample shown for a fictional contractor.)

View the full 2-page sample PDF — POA&M generation, SPRS submission package, and SSP tools are part of the Professional plan ($99/mo). The Level 2 assessment itself is on every plan.
Free 3-minute readiness check. No signup, no credit card, no sales call.