Scrutineer.ai

Scrutineer · By framework

CMMC compliance software for NIST 800-171 and CMMC Level 2 self-assessment

CMMC compliance software has one job for a defense contractor: prove all 110 requirements in NIST SP 800-171 Rev 2 are implemented, and hold the evidence that says so. Scrutineer maps what you already run to each requirement and shows the gaps behind your SPRS score before an assessor or a prime contractor finds them.

The DoD suspended CMMC Phase 2 on July 13, 2026, pausing third-party C3PAO assessments. It did not pause the requirement: Phase 1 self-assessments, DFARS 252.204-7012 and NIST SP 800-171 Rev 2 all remain in force. Scrutineer is readiness and decision support, not a C3PAO, and it does not certify anyone.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with CMMC

All 110 requirements, mapped to what you already run

Level 2 is NIST SP 800-171 Rev 2 in full: 110 requirements across 14 families, from access control to system integrity. Scrutineer maps your existing controls to each one, so the work is finding the genuine gaps rather than rebuilding a program you mostly have.

Evidence pulled, not screenshotted

A self-assessment is only as good as what backs it. Read-only connections to your cloud, identity and ticketing stack collect the artifacts behind each requirement continuously, so the evidence attached to a control is current when a prime contractor or an assessor asks for it.

An SPRS score you can defend

The DoD scoring methodology subtracts weighted points for every unimplemented requirement, so a single missing multifactor control can cost you five points. Scrutineer shows which gaps are costing what, tracks each one on a POA&M with a named owner, and re-scores as they close.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps existing controls to all 110 NIST SP 800-171 Rev 2 requirements
  • Collects CMMC evidence automatically and read-only
  • Tracks gaps on a POA&M with owners and target dates
  • Shows what each open gap costs against your SPRS score
  • Crosswalks CMMC work to SOC 2, ISO 27001 and FedRAMP controls
  • Scores the subcontractors and vendors inside your CUI boundary
CMMC readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Mapped to controls · evidence-linked 3 GAPS

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Good questions

Questions about CMMC

CMMC compliance means meeting the Cybersecurity Maturity Model Certification requirements the Defense Department attaches to contracts that involve federal contract information or controlled unclassified information. In practice it means implementing a defined set of security requirements, documenting them in a System Security Plan, assessing yourself against them, posting a score in SPRS and affirming annually that you still comply.
Yes. On July 13, 2026 the Defense Department suspended the Phase 2 transition that was due to start November 10, 2026, pausing mandatory third-party C3PAO assessments while a CMMC Reform Task Force runs a 60-day review. Nothing else stopped. Phase 1 Level 1 and Level 2 self-assessments, NIST SP 800-171 Rev 2 and DFARS 252.204-7012 all remain in force, and no replacement date has been announced.
There are three. Level 1 covers federal contract information and requires the 15 basic safeguards in FAR 52.204-21, self-assessed annually. Level 2 covers controlled unclassified information and requires all 110 requirements in NIST SP 800-171 Rev 2. Level 3 adds 24 selected enhanced requirements from NIST SP 800-172, for a total of 134, and is assessed by the government DIBCAC rather than a commercial assessor.
NIST SP 800-171 is the standard: the actual list of 110 security requirements for protecting controlled unclassified information in nonfederal systems. CMMC is the verification program the Defense Department wraps around it, defining who has to assess, at what level, how often, and how the result gets posted and affirmed. You implement 800-171; CMMC is how you prove you did.
The Phase 1 deadline already passed. The 48 CFR acquisition rule took effect November 10, 2025, so contracting officers have been putting CMMC self-assessment requirements into applicable new contracts and option years since then. The Phase 2 date of November 10, 2026 was suspended on July 13, 2026 with no replacement announced, so treat Phase 1 obligations as live and Phase 2 timing as unknown.
It varies enormously with scope and starting posture. The Defense Department CIO cited more than $7 billion a year in aggregate cost to small and medium businesses as part of the reasoning for pausing Phase 2. For an individual contractor the money goes into remediation, documentation and, when third-party assessment resumes, the assessment itself. Enclaving CUI into a narrow boundary is the single biggest lever on that number.
No, and be wary of any vendor implying otherwise. Software maps your controls, gathers evidence, tracks your POA&M and helps you score yourself accurately. A CMMC certification is issued only through the official assessment process, by an authorized C3PAO at Level 2 or by the government DIBCAC at Level 3. Scrutineer prepares you for that process rather than substituting for it.
A good deal of it, yes. Access control, multifactor authentication, logging, configuration management, incident response and media protection all appear in some form across SOC 2, ISO 27001 and NIST SP 800-171. What does not carry over is the CUI-specific scoping: identifying exactly where controlled unclassified information lives and drawing an assessment boundary around it. That part is CMMC-specific work no crosswalk removes.

Keep reading

Guides that go deeper on CMMC and federal compliance

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification