Scrutineer · By framework
CMMC compliance software for NIST 800-171 and CMMC Level 2 self-assessment
CMMC compliance software has one job for a defense contractor: prove all 110 requirements in NIST SP 800-171 Rev 2 are implemented, and hold the evidence that says so. Scrutineer maps what you already run to each requirement and shows the gaps behind your SPRS score before an assessor or a prime contractor finds them.
The DoD suspended CMMC Phase 2 on July 13, 2026, pausing third-party C3PAO assessments. It did not pause the requirement: Phase 1 self-assessments, DFARS 252.204-7012 and NIST SP 800-171 Rev 2 all remain in force. Scrutineer is readiness and decision support, not a C3PAO, and it does not certify anyone.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with CMMC
All 110 requirements, mapped to what you already run
Level 2 is NIST SP 800-171 Rev 2 in full: 110 requirements across 14 families, from access control to system integrity. Scrutineer maps your existing controls to each one, so the work is finding the genuine gaps rather than rebuilding a program you mostly have.
Evidence pulled, not screenshotted
A self-assessment is only as good as what backs it. Read-only connections to your cloud, identity and ticketing stack collect the artifacts behind each requirement continuously, so the evidence attached to a control is current when a prime contractor or an assessor asks for it.
An SPRS score you can defend
The DoD scoring methodology subtracts weighted points for every unimplemented requirement, so a single missing multifactor control can cost you five points. Scrutineer shows which gaps are costing what, tracks each one on a POA&M with a named owner, and re-scores as they close.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps existing controls to all 110 NIST SP 800-171 Rev 2 requirements
- Collects CMMC evidence automatically and read-only
- Tracks gaps on a POA&M with owners and target dates
- Shows what each open gap costs against your SPRS score
- Crosswalks CMMC work to SOC 2, ISO 27001 and FedRAMP controls
- Scores the subcontractors and vendors inside your CUI boundary
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Requirement reference
The 14 NIST SP 800-171 families behind CMMC Level 2
CMMC Level 2 maps to all 110 security requirements in NIST SP 800-171 Rev 2. They are grouped into 14 families, and they are not evenly sized: three families carry nearly half the total, which is where scoping and remediation effort concentrates.
| Family | Requirements | What it covers | Where teams lose time |
|---|---|---|---|
| Access Control (AC) | 22 | Who can reach CUI, from where, with what privilege, including remote access and portable devices. | The largest family by some distance. Access reviews, session controls and remote access restrictions all live here. |
| System and Communications Protection (SC) | 16 | Boundary protection, encryption in transit and at rest, network segmentation, denial of service defenses. | Second largest. FIPS-validated cryptography is a recurring stumbling block, since ordinary encryption is not automatically sufficient. |
| Identification and Authentication (IA) | 11 | Unique identities, multifactor authentication, password and authenticator management. | Multifactor for both local and network access to privileged accounts is stricter than most commercial baselines. |
| Audit and Accountability (AU) | 9 | Creating, protecting, retaining and reviewing audit logs so actions trace to individuals. | Retention and the requirement to actually review logs, rather than only collect them. |
| Configuration Management (CM) | 9 | Baseline configurations, change control, least functionality, allowlisting. | Maintaining an accurate baseline inventory once the boundary includes contractor laptops. |
| Media Protection (MP) | 9 | Protecting, marking, transporting and sanitizing media holding CUI, including backups. | Marking and sanitization procedures that exist on paper and are never evidenced. |
| System and Information Integrity (SI) | 7 | Flaw remediation, malicious code protection, monitoring for attacks and indicators. | Patch timelines and proving the monitoring produced action, not just alerts. |
| Maintenance (MA) | 6 | Controlled system maintenance, including remote and third-party maintenance. | Supervision and sanitization requirements around external maintenance providers. |
| Physical Protection (PE) | 6 | Limiting physical access to systems and CUI, escorting visitors, protecting work sites. | Remote and hybrid work, where the work site is somebody's home office. |
| Security Assessment (CA) | 4 | Assessing controls, producing a system security plan, and running the plan of action and milestones. | The SSP and POA&M are the two documents an assessor reads first, and they are usually written last. |
| Awareness and Training (AT) | 3 | Security awareness for all users and role-based training for those with security duties. | Evidencing that the training actually reached the people the requirement names. |
| Incident Response (IR) | 3 | Incident handling capability, testing it, and reporting incidents. | DFARS 252.204-7012 separately requires reporting cyber incidents to DoD within 72 hours. |
| Risk Assessment (RA) | 3 | Periodic risk assessment, vulnerability scanning and remediating what the scans find. | Remediation timelines, not the scanning itself. |
| Personnel Security (PS) | 2 | Screening people before granting CUI access, and protecting CUI during transfers and terminations. | Smallest family, and rarely the problem. |
| All 110, scored and evidenced | 110 across 14 families | A self-assessment score posted to SPRS, backed by an SSP, a POA&M and evidence per requirement. | This is where Scrutineer sits: mapping what you already run onto the 110, and keeping the evidence current between assessments. |
Counts are for NIST SP 800-171 Revision 2, which is the revision CMMC Level 2 currently requires; Revision 3 is not required. Level 1 is a separate, smaller set of 15 safeguards drawn from FAR 52.204-21, and Level 3 adds 24 requirements from NIST SP 800-172 on top of the 110. Mandatory third-party Level 2 assessments were suspended in July 2026 with no replacement date, but Level 1 and Level 2 self-assessments, SPRS score posting and the annual senior official affirmation remain in force. Scrutineer prepares and maintains this evidence and does not issue a CMMC certification.
Good questions
Questions about CMMC
Keep reading
Guides that go deeper on CMMC and federal compliance
CMMC Phase 2 suspended: what still applies
What the July 13, 2026 pause changed, what stayed in force, and what defense contractors should do in the gap.
Read the guideRunning a cybersecurity risk assessment
The NIST SP 800-30 method in eight steps: scope, assets, threats, likelihood and impact scoring, then treatment.
Read the guideAll 93 ISO 27001 Annex A controls
Every control by number and name, and the evidence auditors ask for against each one.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification