SentinelSSP
CMMC Level 2 Readiness Platform

Most companies prepare for CMMC backwards. Here's the right way.

SentinelSSP helps defense contractors start with scope, work through controls, map evidence, track gaps, and generate readiness outputs in one connected workflow.

No credit card required. Upgrade when you're ready for the full Level 2 workflow.

110 CMMC Controls

Full Level 1 and Level 2 coverage

Accurate SPRS Score

Control-by-control, DoD Assessment Methodology

The Problem

CMMC compliance is overwhelming. It doesn't have to be.

The consultant quote

You call a CMMC consultant or RPO and get a quote for $25,000 to $50,000. That price covers their time, not your compliance.

The blank SSP

Every template online is a generic starting point that assumes you already know what you're doing. You're still on your own.

The deadline pressure

Your contract requires CMMC certification and the timeline is real. Every week without a plan is a week closer to losing the work.

The Solution

A guided workspace that takes you from overwhelmed to organized.

SentinelSSP replaces the blank page with a structured, step-by-step process built around exactly how CMMC assessments work.

sentinelssp.com/dashboard

SPRS Score Estimate

73/ 110

66% of maximum

Controls

Implemented62
In Progress28
Not Started20

Domain Progress

Access Control78%
Configuration Mgmt91%
Incident Response45%
Risk Assessment60%

How It Works

From blank page to a complete CMMC documentation package - step by step.

1

Define Your Scope

Map your CUI environment and identify exactly which systems, people, and locations are in scope. Skip everything that isn't.

2

Get Your SPRS Score

Work through the controls with guided, plain-language explanations to get an accurate SPRS score calculated with the DoD methodology. Know exactly where you stand.

3

Build Your Documentation

Generate your System Security Plan and your full CMMC policy document set, pre-populated with your actual environment details.

4

Track Your Gaps

See exactly which controls you still need to address, prioritized by severity, so you know what to fix before your assessment.

Not a document dump.

One connected CMMC workflow - scoping, scoring, policies, evidence, and your SSP all feed into each other. Change something upstream and the downstream is already there.

Features

Everything you need. Nothing you don't.

Scoping Advisor

Know exactly what's in scope before you start.

Most contractors waste months working on the wrong systems. Our Scoping Advisor walks you through your environment step by step so you only document what actually matters to CMMC assessors.

Scoping Advisor

Which systems process, store, or transmit CUI?

Engineering workstationsIn Scope
File server (\\\\fs01)In Scope
Email system (M365)In Scope
Payroll system
Guest WiFi network

SPRS Assessment

An accurate SPRS score, control by control.

Assess each of the 110 Level 2 controls with guided, plain-language explanations - no NIST expertise required - and get an SPRS score calculated with the DoD Assessment Methodology. Assessor-grade accuracy, not a quick guess or an AI estimate.

SPRS Score

88/ 110
DoD Methodology
AC.L2-3.1.1EvidenceImplemented
AC.L2-3.1.5EvidenceImplemented
IA.L2-3.5.3In Progress
SC.L2-3.13.11Not Started

Control Tracker

Work through all 110 controls with clear guidance.

Every CMMC Level 1 and Level 2 control explained in plain English, with implementation guidance written for IT professionals and business owners across the DIB. Mark controls as implemented, in progress, or not applicable with a full audit trail.

Access Control

22 controls
AC.L2-3.1.1Authorized Access ControlDone
AC.L2-3.1.2Transaction & Function ControlDone
AC.L2-3.1.9Provide privacy and security noticesIn Progress
AC.L2-3.1.21Limit use of portable storage devicesOpen
AC.L2-3.1.4Separate duties to reduce insider riskN/A

Evidence Mapping

Know exactly what evidence each control needs.

For every control, see the evidence an assessor actually examines - grounded in the CMMC Assessment Guide and NIST 800-171A - then track what you have against each requirement. Map your existing artifacts to the controls they satisfy and go into your assessment knowing exactly where your coverage stands.

AC.L2-3.1.8Unsuccessful logon attempts
Evidence linked
Account Lockout PolicyPolicy
GPO lockout threshold (screenshot)

Recommended evidence

Access control policyConfiguration settingsSystem audit logsSystem security plan

From the CMMC Assessment Guide

Evidence Traceability and Gap Analysis

Generate a complete evidence traceability package.

Map every control to its evidence and generate a professional traceability matrix - in PDF or Excel. See exactly which controls are covered and which still need evidence, so you walk into assessment prep organized, with a clear view of coverage and gaps.

Your evidence stays yours - we document where it lives without storing your files, so you keep your artifacts in your own environment.

Evidence Traceability Matrix

CMMC Level 2 - Acme Defense Systems LLC

XLSXPDF

89

Covered

21

Gaps

47

Artifacts

AC.L2-3.1.1Access Control PolicyCovered
AC.L2-3.1.8Account Lockout GPO screenshotCovered
AU.L2-3.3.1No evidence mappedGap

Policy Builder

Generate your entire documentation package.

Your complete set of CMMC security policies, auto-populated with your organization's actual details and environment. Download everything as a complete documentation package.

Policy Builder

14 Policies

Incident Response Policy

Acme Defense Systems LLC

This Incident Response Policy establishes procedures for detecting, reporting, and responding to cybersecurity incidents affecting controlled unclassified information...

Access Control Policy

Config Mgmt Policy

Risk Assessment Policy

Gap Tracker

A clear list of exactly what you still need to fix.

Every unmet control, scored by severity, with remediation guidance. Know your risk posture at a glance and track progress as you close each gap before your assessment date.

Open Gaps

14 open
AC.L2-3.1.15Authorize remote execution of privileged commands
IA.L2-3.5.3Use multifactor authentication for local access
SC.L2-3.13.10Employ FIPS-validated cryptography for CUI
AU.L2-3.3.1Create and retain system audit logs
CM.L2-3.4.1Establish and maintain baseline configurations

Sentinel AI

Ask anything. Get a straight answer.

Sentinel is trained on CMMC assessment guides, NIST 800-171, and DoD methodology. Ask any compliance question and get an answer grounded in the actual standards, not generic advice.

Sentinel AI

Does AC.L2-3.1.1 apply if we only work on government contracts part of the year?

Yes. AC.L2-3.1.1 applies whenever your systems could process, store, or transmit CUI, regardless of the time of year. Per 32 CFR Part 170, CMMC requirements attach to the contract. If you handle CUI at any point, the controls must be implemented and maintained continuously.

What counts as authorized access in practice?

Security-first. Built for the defense industrial base.

Encrypted and isolated

All data is encrypted in transit with TLS and at rest. Every organization's data is isolated at the database level with row-level security, so your workspace stays separate from every other account's.

Built by practitioners

We built the tool we wished existed when CMMC first landed on our desk. Every feature exists because a real defense contractor needed it.

Standards-grounded

Every control, question, and piece of guidance is grounded in CMMC 2.0, NIST SP 800-171, and the DoD assessment methodology. No paraphrasing, no generic advice.

Simple, transparent pricing.

No hidden fees. No surprise charges. No enterprise contracts.

Free CMMC Readiness

$0/month

Start your CMMC readiness for free with guided scoping, Level 1 assessment, evidence mapping, policies, and SSP export.

  • Full Scoping Advisor - classify your assets and define your assessment boundary
  • Complete Level 1 self-assessment for FCI contractors (all FAR 52.204-21 requirements)
  • Level 1 compliance policies, tailored to your environment
  • Level 1 evidence mapping and structured SSP export
  • A taste of Ask Sentinel AI (10 messages a month)
Get Started Free

Pro

$199/month

Cancel any time. No contract, no setup fees.

Unlock the full Level 2 workflow, including all 110 controls, SPRS scoring, POA&M tracking, policy generation, evidence traceability, SSP export, and unlimited Sentinel AI.

  • Everything in Free, plus all of Level 2
  • Control-by-control Level 2 assessment with an accurate SPRS score
  • All 110 CMMC controls with AI guidance
  • Your full CMMC policy document set, tailored to your environment
  • Evidence mapping with CAG-grounded recommended evidence per control
  • Evidence traceability matrix export (PDF and Excel)
  • POA&M tracker with eligibility rules
  • Structured SSP document export
  • Unlimited, context-aware Ask Sentinel AI
Start with Pro

Compare to $30,000+ for a consultant or RPO engagement - no recurring retainer required.

Your assessor isn't waiting.

Every defense contractor pursuing CMMC faces the same challenge. The ones who pass start early and work through it systematically. SentinelSSP is how you do that.

Get Started Free