For DoD, DHS & CBP subcontractors

Keep Your Federal Contracts. Get CMMC Ready.

CMMC requirements are now appearing in DoD contracts, and primes are pushing them down to every subcontractor. CyberPolicify walks you through Level 1's 17 practices — or the full Level 2 self-assessment, all 110 NIST SP 800-171 requirements with an estimated SPRS score — and generates the written policies assessors ask for.

Built for machine shops, manufacturers, engineering and IT services firms with 5-50 people — not for primes with a compliance department.

3-minute check, no signup All 17 Level 1 practices Full Level 2 + SPRS score From $49/mo

Why this matters now

  • • The CMMC rule is final — clauses are being added to new DoD solicitations, and primes must flow the requirement down to subcontractors.
  • Level 1 applies to any contractor that handles Federal Contract Information (FCI) — that includes most subs, even without CUI.
  • • Level 1 is an annual self-assessment with an executive affirmation in SPRS — you don't need an expensive third-party assessor, but you do need evidence.
  • • DHS and CBP contractors face the same FAR 52.204-21 basic-safeguarding baseline — the identical 15 requirements behind CMMC Level 1.
  • Handle CUI? Level 2 applies — DFARS 252.204-7019/7020 already require a NIST 800-171 self-assessment score in SPRS, and primes check it before they award.

Which level is your contract?

It comes down to one question: do you only handle Federal Contract Information (FCI), or does Controlled Unclassified Information (CUI) touch your systems?

FCI ONLY

CMMC Level 1

  • 17 basic safeguarding practices (FAR 52.204-21)
  • Annual self-assessment + executive affirmation in SPRS
  • Guided control-by-control assessment with evidence notes
  • The written policies behind every practice, generated for you

Typical: janitorial, landscaping, parts suppliers, services firms with no CUI in scope.

FCI + CUI

CMMC Level 2 (NIST SP 800-171)

  • All 110 NIST SP 800-171 requirements, assessed one by one
  • Live estimated SPRS score on the official DoD scale (−203 to 110) with 5/3/1-point weights
  • POA&M and SPRS submission package for the gaps you can't close yet
  • Know your number before you register on PIEE — or before your prime asks for it

Typical: machine shops with drawings, engineering firms, IT services touching DoD data.

From "are we compliant?" to a defensible self-assessment

Three steps, no consultants, no jargon.

STEP 1

See where you stand — free

Take the 3-minute Audit Ready Check. Get a readiness score across the CMMC Level 1 basics and a plain-English list of your gaps.

STEP 2

Run the full guided assessment

Work through your level control-by-control — all 17 Level 1 practices, or the full 110-requirement Level 2 with a live estimated SPRS score — with evidence notes, an AI gap summary, and a remediation tracker. Documented, not guessed.

STEP 3

Generate the policies primes ask for

Access control, physical security, media disposal, malware protection, and more — AI-generated for your business, exported to Word, ready for a prime's supplier questionnaire.

The math for a small contractor

The $100k+ C3PAO audit? Not currently required.

With CMMC Phase 2 suspended, third-party certification assessments are on hold — the requirement of record today is your NIST 800-171 self-assessment score in SPRS (DFARS 252.204-7019/7020 never paused). That means the compliance bill drops from a six-figure audit to disciplined cyber hygiene — which CyberPolicify runs for $49–$99/month. What the pause means

CMMC consultant engagement

$5,000 – $15,000
  • • One-time readiness engagement
  • • Weeks of scheduling and interviews
  • • Policies handed over as static Word files
  • • Repeat spend at every annual self-assessment

CyberPolicify

$49/mo
  • Guided 17-practice self-assessment, repeatable every year
  • AI-generated policies customized to your business
  • Gap analysis, risk register, and remediation tracking
  • 14-day free trial, no credit card

Handling CUI under a Level 2 contract? CyberPolicify runs the full Level 2 self-assessment — all 110 NIST SP 800-171 requirements with an estimated SPRS score on the official DoD scale (−203 to 110), using the official 5/3/1-point weights — so you know your number before you register on PIEE. Start your Level 2 assessment.

This is what you hand your prime

A real Plan of Action & Milestones generated by CyberPolicify — cover block with your CAGE code and SPRS score, one row per open requirement with its DoD point weight, owners, due dates, milestones, and an Affirming Official signature block. Editable Word and upload-ready PDF. (Sample shown for a fictional contractor.)

Sample CMMC Level 2 POA&M generated by CyberPolicify: SPRS score 98 of 110, 12 open requirements with mitigations, owners, due dates, and milestones

View the full 2-page sample PDF — POA&M generation, SPRS submission package, and SSP tools are part of the Professional plan ($99/mo). The Level 2 assessment itself is on every plan.

Find out where you stand — before your prime asks

Free 3-minute readiness check. No signup, no credit card, no sales call.