Updated 24 Jul 2026 CMMC Phase 2 was suspended on July 13. Your SPRS self-assessment was not. What this means →
For 5–50 person DoD subcontractors

Your SPRS score is the number that matters now.

CMMC Phase 2 is suspended. Your NIST 800-171 self-assessment isn't. CMMC Map walks all 110 controls in plain English and writes the SSP, POA&M and policies as you go — so the score you post is one you can defend.

Free to assess · No credit card · Documents from $49/mo
Control dashboard
SPRS · live
Current score
41
of 110 · started at −173
Recalculates as you work. Every deduction traced to the control that caused it.
AC.L2-3.1.1
Limit system access to authorized users
Met
AU.L2-3.3.1
Create and retain audit logs
−5
CM.L2-3.4.1
Maintain baseline configurations
Met
IA.L2-3.5.3
Use multifactor authentication
Partial
IR.L2-3.6.1
Establish incident handling
Open
Every control carries a plain-English explanation, an evidence checklist, and the SSP narrative it feeds.
110
controls in NIST SP 800-171 Rev 2
−203 → 110
the SPRS scoring range
3 years
maximum age of a posted score
~40%
pre-filled after the scoping wizard
July 13, 2026

What the CMMC suspension actually changed

The Department of War suspended CMMC Phase 2, including the November 10 milestone that would have put C3PAO assessments into new solicitations. A CMMC Reform Task Force has 60 days to report — roughly September 11. Here is the honest version of what that means for a small sub.

Paused

  • CMMC Phase 2 rollout — including the Nov 10, 2026 C3PAO milestone
  • DFARS 252.204-7021 — still on the books, but cannot be required in new solicitations during the pause
  • New certification milestones — pending the task force review

Unchanged — still required today

  • DFARS 252.204-7012 — safeguarding, 72-hour incident reporting
  • DFARS 252.204-7019 — your NIST 800-171 Basic self-assessment
  • DFARS 252.204-7020 — government right of access to results
  • NIST SP 800-171 Rev 2 — the same 110 controls
  • A current SPRS score — within three years, to be considered for award
Our read: this is not relief. A suspended certification regime means nobody is coming to check your homework — right up until someone does, and then it's a lawyer rather than an assessor. Self-assessment is now the primary enforcement mechanism, which makes an overstated SPRS score a False Claims Act problem instead of an audit finding. The work didn't get smaller. The deadline pressure got replaced by liability pressure, and liability is worse.
Who this is for

You can run a business. Nobody taught you NIST 800-171.

You wear every hat already — owner, salesperson, IT lead, and now compliance officer. This landed on your desk because there's no one else's desk to land on.

Your prime is asking about your SPRS score and you're not certain what a good answer looks like, or how to get one without a $50K consultant.

Three hours into the NIST publication you've decoded four controls out of 110. You're not slow. Those documents were written for federal agencies with compliance teams, not for a machine shop with twelve people and one server closet.

CMMC Map asks plain-English questions about your shop, then does the paperwork. You don't need to become a security expert. You need a defensible number and the documents behind it.

How it works

From a blank spreadsheet to a score you can defend

Four steps. About fifteen minutes to a real starting point.

Step one
Answer the scoping wizard
Fifteen minutes of plain-English questions about your shop — where CUI lives, who touches it, what tools you run. No CMMC background required. Your answers pre-fill roughly 40% of the 110 controls.
Step two
Walk the 110 controls
Every control explained for a small business, with an evidence checklist telling you exactly what to gather and what to write. Ask the built-in assistant anything, on any control.
Step three
Generate your documents
One click produces the SSP, the POA&M and all 14 required policies, auto-filled from your control answers and formatted for assessor review.
Step four
Post a score you can stand behind
A live SPRS score with pass/fail per control and every deduction traced to its cause — so when your prime asks, or a contracting officer pulls your record, the number has documentation underneath it.
Documents

The part everyone leaves until last — done first

Roughly 70% of this work is documentation. Auto-filled from your control answers, editable, and formatted the way an assessor expects to read it.

System Security Plan
Per-control narrative across all 110 controls, generated from your answers and honest about gaps.
SSP
Plan of Action & Milestones
Every open gap with an owner, a milestone and a remediation date.
POA&M
14 required policies
Editable Word documents, mapped to the control families that require them.
Included
Readiness report
Pass / at risk / fail per control with prioritized remediation.
Paid
Audit bundle
One archive: SSP, POA&M, policies, evidence index and training records.
Paid
Security awareness training
Covers AT.L2-3.2.1, 3.2.2 and 3.2.3 in-app, with per-employee records an assessor can verify.
Paid
Pricing

The assessment is free. The paperwork is $49.

Find out where you stand without paying anything. If you want the documents an assessor asks for — the SSP, the POA&M, the 14 policies — that's $49 a month, cancel anytime. A formal assessment runs $50K and up.

Free
$0 forever
  • Scoping wizard — 15 minutes, plain English
  • All 110 NIST 800-171 controls explained
  • Live SPRS score, recalculated as you work
  • Gap list and evidence checklists
  • No credit card, no time limit
Start free
CMMC Map
$49 /month
  • Everything in Free
  • System Security Plan, POA&M and all 14 policies
  • Audit bundle, readiness report and exports
  • AI assistant on every control
  • Security awareness training with records
Unlock documents
Common questions

Straight answers, current as of July 24, 2026

Is CMMC cancelled?
No — suspended, not cancelled. On July 13, 2026 the Department of War suspended CMMC Phase 2, including the November 10, 2026 milestone that would have put C3PAO third-party assessments into new solicitations. A CMMC Reform Task Force has 60 days to deliver recommendations, putting a report around September 11, 2026. DFARS 252.204-7021 remains on the books but cannot be required in new solicitations during the pause, and existing CMMC Level 2 certifications retain their value.
Do I still need an SPRS score?
Yes. Nothing about your self-assessment obligation changed. DFARS 252.204-7012, 7019 and 7020 all remain in force, and a current NIST SP 800-171 Basic self-assessment posted in SPRS — no more than three years old — is still required for you to be considered for award. With certification paused, self-assessment is now the primary enforcement mechanism.
What's the difference between NIST 800-171 and CMMC?
NIST SP 800-171 Revision 2 is the actual security standard — the 110 controls you implement. Your SPRS score is calculated from those same 110 controls using the DoD Assessment Methodology, on a scale from −203 to 110. CMMC was the certification wrapper around that same control set: a process for having a third party verify what you self-attested. The standard is unchanged. Only the verification mechanism is paused.
What SPRS score do I actually need?
110 is a perfect score, meaning all 110 controls are fully implemented. There's no universal minimum written into the regulation, but primes increasingly screen on it, and a low or stale score is the most visible signal a contracting officer has about you. More important than the number is that you can defend it — an overstated score is a False Claims Act exposure, and that risk didn't go away with the suspension.
Does NIST 800-171 Rev 3 change my requirements?
Not yet. SPRS scoring and DFARS compliance are still based on NIST SP 800-171 Revision 2 and its 110 controls. DoD has not adopted Rev 3, which would require new rulemaking. Build to Rev 2 today. CMMC Map tracks rule changes and will update when a formal transition happens.
Do I need to upload CUI to use CMMC Map?
No. CMMC Map is a readiness and documentation tool. You upload compliance documentation — policies, configuration screenshots, training records — not controlled technical data. Every upload is scanned for CUI indicators before it enters the system, and the AI assistant does not process CUI.
How does the AI work, and does it see my data?
CMMC Map uses language models to restate federal requirements in plain English and to draft narrative sections that you then edit. It does not decide whether you are compliant, and it does not submit anything on your behalf. Your assessment data is never sent to a model provider for training.
Will CMMC Map replace a C3PAO?
No, and we're direct about that. CMMC Map is not a C3PAO and does not perform certified assessments. It prepares your documentation and your score. If and when third-party certification resumes, a C3PAO conducts the assessment.
I don't have any IT staff. Can I still use this?
That's exactly who this is built for. Every control is rewritten in plain English with a "what this means for your business" explainer, and the assistant answers questions about your specific setup. Most shops reach a defensible position in eight to twelve weeks of evening work.
Who built this
David McLaughlin
Founder
ProphetMind
Fairfax, Virginia

One person, not a platform.

I built CMMC Map because I watched small subcontractors get handed a 110-row spreadsheet and a deadline with nobody to ask. Most compliance tools sell you a dashboard when your real problem is that your scope is wrong — you don't know which systems are actually in the boundary, so every answer after that is guesswork.

This isn't a venture-backed platform with a support queue. When you email [email protected], I'm the one who answers. When a rule changes — like it did on July 13 — the site gets updated that week, because I'd rather tell you inconvenient news than let you find it from your prime.

Get in touch

Questions first? That's normal.

We reply from a real inbox ([email protected]), usually same day. Your information is never shared or sold.

The CMMC Brief

The rules keep moving — July 13 proved that. Once or twice a month we send the changes that actually affect small subs, in plain English, like everything else we do.

Rule changes and deadline shifts, decoded · One practical tip per issue · No spam, unsubscribe anytime