Scrutineer · By framework
CMMC compliance software for NIST 800-171 and CMMC Level 2 self-assessment
CMMC compliance software has one job for a defense contractor: prove all 110 requirements in NIST SP 800-171 Rev 2 are implemented, and hold the evidence that says so. Scrutineer maps what you already run to each requirement and shows the gaps behind your SPRS score before an assessor or a prime contractor finds them.
The DoD suspended CMMC Phase 2 on July 13, 2026, pausing third-party C3PAO assessments. It did not pause the requirement: Phase 1 self-assessments, DFARS 252.204-7012 and NIST SP 800-171 Rev 2 all remain in force. Scrutineer is readiness and decision support, not a C3PAO, and it does not certify anyone.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with CMMC
All 110 requirements, mapped to what you already run
Level 2 is NIST SP 800-171 Rev 2 in full: 110 requirements across 14 families, from access control to system integrity. Scrutineer maps your existing controls to each one, so the work is finding the genuine gaps rather than rebuilding a program you mostly have.
Evidence pulled, not screenshotted
A self-assessment is only as good as what backs it. Read-only connections to your cloud, identity and ticketing stack collect the artifacts behind each requirement continuously, so the evidence attached to a control is current when a prime contractor or an assessor asks for it.
An SPRS score you can defend
The DoD scoring methodology subtracts weighted points for every unimplemented requirement, so a single missing multifactor control can cost you five points. Scrutineer shows which gaps are costing what, tracks each one on a POA&M with a named owner, and re-scores as they close.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps existing controls to all 110 NIST SP 800-171 Rev 2 requirements
- Collects CMMC evidence automatically and read-only
- Tracks gaps on a POA&M with owners and target dates
- Shows what each open gap costs against your SPRS score
- Crosswalks CMMC work to SOC 2, ISO 27001 and FedRAMP controls
- Scores the subcontractors and vendors inside your CUI boundary
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Good questions
Questions about CMMC
Keep reading
Guides that go deeper on CMMC and federal compliance
CMMC Phase 2 suspended: what still applies
What the July 13, 2026 pause changed, what stayed in force, and what defense contractors should do in the gap.
Read the guideRunning a cybersecurity risk assessment
The NIST SP 800-30 method in eight steps: scope, assets, threats, likelihood and impact scoring, then treatment.
Read the guideAll 93 ISO 27001 Annex A controls
Every control by number and name, and the evidence auditors ask for against each one.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification