Buyer's Guide

CMMC Level 2 Compliance Software.

What to require, what to ask, and how to choose the right platform for your organization — written for defense contractors, not consultants.

Last updated: February 24, 2026

What it must do Air-gap vs. cloud 110 requirements SSP generation C3PAO readiness Checklist Questions to ask FAQ

If you handle Controlled Unclassified Information (CUI) on a DoD contract, CMMC Level 2 certification is not optional — it's a contract requirement. The question isn't whether you need to comply, but how you get there without spending 18 months and a small fortune on consultants.

CMMC compliance software exists to compress that timeline. But not all tools are equal, and the wrong choice can leave you worse off than starting from scratch. This guide covers what to require, what to avoid, and how to evaluate platforms before you commit.

What CMMC Level 2 software must actually do

A lot of tools market themselves as "CMMC compliance software" while delivering little more than a checklist or a document template. Real compliance software needs to do heavy lifting across six distinct areas:

01 — Requirements Coverage

All 110 NIST SP 800-171 requirements across all 14 domains — not a subset. Each requirement needs dedicated assessment objectives, implementation documentation fields, and evidence linkage.

02 — SSP Generation

Automated System Security Plan generation from your actual environment data — not a fill-in-the-blank template. The SSP must meet the documentation requirements C3PAO assessors actually evaluate.

03 — Policy Automation

All 14 required domain policies and procedures auto-generated from your configuration data. Manually writing 14 policies is weeks of work — software should do this from your answers.

04 — SPRS Scoring

Real-time SPRS score calculation as you document requirements, with point-weight visibility so you can prioritize remediation by DoD score impact rather than guessing.

05 — POA&M Management

A credible Plan of Action & Milestones with realistic timelines demonstrates maturity to assessors. Gaps documented without a remediation plan are worse than gaps with one.

06 — Ongoing Compliance

Certification is valid for 3 years — but maintaining posture requires recurring tasks, training renewals, and policy reviews. Software that only helps you pass once isn't enough.

Air-gapped vs. cloud CMMC platforms

This is the most consequential architectural decision you'll make. It affects your CMMC scoping, your CUI handling obligations, and your shared responsibility model.

Cloud-Based Tools
  • Lower upfront cost, SaaS pricing model
  • Your compliance data stored on vendor infrastructure
  • CUI handling may extend your CMMC boundary to the vendor
  • Vendor's own compliance posture becomes your problem
  • Internet dependency for access
Air-Gapped Appliance
  • All data stays inside your network boundary
  • CUI never transmitted to the cloud
  • No vendor infrastructure in your CMMC scope
  • You own and control the entire compliance record
  • No internet dependency after deployment
The key question to ask
If the vendor stores your SSP, policies, and evidence — is that data CUI? If yes, using a cloud-based tool may expand your CMMC boundary in ways that complicate your assessment. An air-gapped deployment eliminates that question entirely.

Covering all 110 requirements across 14 domains

CMMC Level 2 is built entirely on NIST SP 800-171 Rev 2 — 110 security requirements organized across 14 domains. Every single requirement must be addressed for certification. Beyond just listing requirements, the software should embed the CMMC Assessment Guide guidance for each requirement — the same guidance C3PAO assessors follow.

14
Security domains
110
Requirements — all must be addressed
−203
Worst possible SPRS score

Knowing what assessors look for lets you document controls in the language they expect. Good software doesn't just ask "is this met?" — it shows you the assessor's question so your documentation directly answers it.

See all 14 domains with full requirement lists: CMMC Domain Overview →

SSP and policy generation: templates vs. actual documentation

There's a meaningful difference between a tool that gives you a template to fill in and one that generates your SSP from your environment data. Assessors can tell the difference immediately.

What assessors look for in an SSP

A C3PAO-ready SSP must contain specific sections: Executive Summary, System Identification, Roles & Responsibilities, Tools & Technologies in scope, Control Implementation statements for all 110 requirements, Training records, POA&M, and an Evidence Index. Each control implementation statement should describe your specific environment — not generic language that could describe any organization.

Red flag
Generic language is a red flag. If your SSP reads like it was written for a fictional company, assessors will probe harder during interviews to find out what's actually implemented. A statement like "we use industry best practices for access control" satisfies no one.

What "automated" should actually mean

Real SSP automation synthesizes multiple data sources: your interview responses, asset inventory, personnel and roles, tool configurations, and training records. The output should read like a document written about your organization — because it was.

Ask vendors: "Can I see an example SSP generated by your tool?" Then look for specificity. Does it reference real control mechanisms? Does it describe actual implementation, or generic best practices?

C3PAO assessment readiness: what software should prepare you for

The goal of CMMC compliance software isn't just documentation — it's passing an assessment conducted by a human assessor who is specifically trained to find gaps.

Embedded assessor questions

The CMMC Assessment Guide contains the specific questions C3PAO assessors ask for each of the 110 requirements. Your software should surface these questions before your assessment — not after. Seeing "Can you demonstrate how privileged user activities are logged and reviewed?" while documenting AC controls is far more useful than encountering it for the first time during an interview.

Evidence organization

Assessors want to see evidence — screenshots, configuration exports, policy acknowledgments, training records. Software should let you upload and link artifacts directly to the requirements they satisfy, so on assessment day you can produce evidence for any control instantly.

POA&M credibility

Not every requirement will be fully implemented before your assessment. A well-structured POA&M with realistic timelines, named owners, and documented interim mitigations demonstrates maturity. Assessors are trained to evaluate whether POA&M items are credible — software should help you build plans that hold up to scrutiny.

Evaluation checklist

Use this checklist when evaluating any CMMC Level 2 compliance platform:

Requirements Coverage

  • Covers all 110 NIST SP 800-171 requirements
  • All 14 security domains included — no partial coverage
  • CMMC Assessment Guide guidance embedded per requirement
  • C3PAO assessor questions visible for each control
  • Evidence upload and linkage per control

Documentation

  • Automated SSP generation from environment data — not just a template
  • All 14 domain policies auto-generated
  • Export formats C3PAOs accept (Word, HTML)
  • POA&M creation and tracking
  • Structured evidence index in SSP output

Scoring & Tracking

  • Real-time SPRS score calculation
  • Domain-level score breakdowns
  • Point-weight visibility per requirement
  • Compliance trend tracking over time

Architecture & Data

  • CUI never leaves your network (air-gapped deployment)
  • Single-tenant — no shared infrastructure
  • No cloud dependency after deployment
  • Vendor's scope clearly outside your CMMC boundary

Training & Ongoing

  • Built-in security awareness training satisfying AT.L2
  • Training completion tracking and verifiable records
  • Recurring compliance task scheduling
  • Annual affirmation tracking

Questions to ask any CMMC compliance software vendor

Question 1
Can you show me an actual SSP generated by your tool — not a sample, but one created from real environment data?

Why it matters: Template-based tools can't answer this. Real automation produces specific, environment-based documentation you can verify.
Question 2
Where does my compliance data live, and is it in scope for my CMMC assessment?

Why it matters: If your SSP, policies, and evidence are stored on the vendor's cloud, their infrastructure may be in your CMMC scope — adding complexity and risk to your assessment.
Question 3
Which of the 110 requirements does your software help document versus which require external tools or manual work?

Why it matters: Some tools cover 50–70 requirements well and leave the rest vague. You need complete coverage — gaps in documentation are gaps in your assessment.
Question 4
Do you embed CMMC Assessment Guide guidance — the actual questions assessors ask — within the platform?

Why it matters: Knowing what C3PAO assessors look for for each requirement lets you document controls in the language and format that passes scrutiny.
Question 5
What happens after I pass my assessment — how does your tool support ongoing compliance over the 3-year certification cycle?

Why it matters: Certification is not a one-time event. Annual affirmations, recurring tasks, training renewals, and policy reviews are required to maintain posture.

Frequently asked questions

What should CMMC Level 2 compliance software include?

Complete coverage of all 110 NIST SP 800-171 requirements, automated SSP and policy generation, SPRS score tracking, POA&M management, built-in C3PAO assessor guidance, evidence linkage, security awareness training, and ongoing compliance task tracking.

Air-gapped vs. cloud: which is better for CMMC?

For contractors with strict CUI obligations, air-gapped is generally preferable — your data never leaves your network and the vendor's infrastructure is outside your CMMC scope. Cloud tools have lower upfront cost but introduce shared responsibility concerns that can complicate your assessment boundary.

Can CMMC software guarantee certification?

No. Certification depends on your actual security control implementation, which software cannot do for you. What good software provides is accurate documentation, preparation for assessor questions, and ongoing tracking — all of which significantly improve your odds of passing.

What is SPRS scoring?

The Supplier Performance Risk System score reflects your NIST SP 800-171 implementation, ranging from −203 to 110. It's visible to DoD contracting officers and is calculated from which of the 110 requirements you have fully implemented. Good compliance software calculates this in real time as you document controls.

How long does CMMC Level 2 certification last?

CMMC Level 2 certification is valid for 3 years with annual affirmations required. You must maintain your security posture throughout the certification period — not just at the time of assessment.

Built for the DIB.

1TEN tracks your control posture across all 110 NIST SP 800-171 requirements and generates C3PAO-ready documentation automatically.

Request a Demo