Get CMMC Level 2 ready
in 30 days.
Armory is the operating system for small defense contractors. Upload what you have, answer the questions a real auditor will ask, and ship a complete readiness package to your C3PAO.
Per DFARS 252.204-7021, your organization must hold an active CMMC Level 2 certification by the contract renewal date. Failure to comply will result in non-renewal of contract FA8650-23-C-1004.
- 01Upload what you havePolicies, an old SSP, or nothing at all.
- 02AI generates your gap analysisKnow exactly what's missing in 5 minutes.
- 03Complete tasks one by oneStep-by-step instructions, no jargon.
- 04Export and pass assessmentC3PAO-ready package in 30 days or less.
Generate gap analysis
Three inputs. Output is a control-by-control readiness report mapped to NIST SP 800-171 Rev. 2.
- CRITICALAC.L2-3.1.1No multi-factor authentication on admin accounts
- CRITICALIR.L2-3.6.1No documented incident response plan
- HIGHMP.L2-3.8.3No media sanitization procedures
- HIGHAU.L2-3.3.1Insufficient audit log retention (90 days required)
- MEDCM.L2-3.4.2Baseline configurations not documented
From letter received to readiness package shipped.
We don't sell AI. We sell "keep your contract" — and we use AI to make it 10× faster and 5× cheaper than a consultant.
- 01DAY 0
Panic, then triage
Upload your SSP — or tell us you don't have one. We map your current posture against all 110 NIST 800-171 controls in under a minute.
OutputGap analysis · Top 3 risks · Cost & timeline estimate - 02DAY 1–7
Discovery & documentation
Async chat interviews, 5 minutes at a time. The AI generates your System Security Plan, 12 required policy documents, and a network diagram template — pre-filled with your CAGE, NAICS, and systems inventory.
OutputSSP · 12 policies · Network diagram · Evidence checklist - 03DAY 8–21
Remediation
Each missing control becomes a step-by-step task. Upload screenshots; vision models verify the evidence and confirm the control is satisfied.
OutputTask tracker · Evidence vault · Daily digest - 04DAY 22–30
Validation & readiness
Pre-assessment scan runs the questions a C3PAO will ask. Export a complete readiness package: SSP, evidence binder, POA&M, and an introduction letter for your assessor.
OutputReadiness package · POA&M · C3PAO handoff
Every NIST 800-171 family.
Mapped, scored, attributable.
Tasks written like a tech manual, not a TED talk.
Every missing control becomes an ordered procedure. Vision models verify uploaded screenshots against expected configuration state. No more "send us a folder of PNGs and pray."
- 01Log into Microsoft 365 Admin Center
- 02Navigate to Security & Compliance → MFA
- 03Enable 'Require MFA for all admin accounts'
- 04Capture screenshot of confirmation screen
Five-minute interviews.
A complete SSP at the end.
- ARMORYWhere does CUI live in your environment? Pick all that apply.Q 07 / 24 · AC.L2-3.1.3
- YOUM365 SharePoint, two engineering laptops, and a NAS in the back office.answered · 14:02 EDT
- ARMORYThe NAS is a flag. Is it on the same VLAN as guest Wi-Fi?follow-up · auto
- YOUHonestly not sure. It's the Synology in the wiring closet.answered · 14:03 EDT
- ARMORYLogged. Generating a network segmentation task and adding 'Synology DS-series' to the systems inventory. SC.L2-3.13.1 will be drafted.action taken · 14:03 EDT
- SSP-001DRAFTEDSystem Security Plan47 pages · auto-filled from intake
- POL-002DRAFTEDAccess Control Policy6 pages · auto-filled from intake
- POL-003DRAFTEDIncident Response Plan11 pages · auto-filled from intake
- DIA-004PENDINGNetwork Diagram (template)1 page · auto-filled from intake
- INV-005DRAFTEDSystems Inventory3 pages · auto-filled from intake
Cryptographically pinned.
Assessor-ready on day 30.
Two infrastructures.
Matched to what your contract actually requires.
FCI rides commercial. CUI rides GovCloud. We will not host CUI on AWS Commercial — and you should not trust anyone who will.
SOC 2 Type II commercial cloud
For suppliers who only touch Federal Contract Information (FCI) — janitorial, food service, office supplies. Self-attestation under FAR 52.204-21 runs on SOC 2 Type II infrastructure with full audit logging.
- Hosting
- AWS commercial · SOC 2 Type II
- Scope
- 17 FAR 52.204-21 practices
- Attestation
- Self-attestation via SPRS
- Pricing
- $99 / month
AWS GovCloud (US) dedicated enclave
CUI cannot legally live on commercial cloud. Level 2 prep runs in a dedicated us-gov-west-1 enclave with FIPS 140-2 validated encryption, US-persons-only operators, and DFARS 252.204-7012 incident reporting under a signed BAA.
- Hosting
- AWS GovCloud · us-gov-west-1
- Encryption
- FIPS 140-2 validated · KMS auditable
- Operators
- US persons only · background-checked
- Reporting
- DFARS 7012 · 72-hour incident SLA
Two tiers. One platform.
Pick the level your contracts require.
17 FAR 52.204-21 practices, 4 policy templates, SPRS-ready self-attestation form. For janitorial, food service, and other FCI-only suppliers.
Full 110-control NIST 800-171 prep on a dedicated AWS GovCloud (US) enclave: AI Copilot, SSP & POA&M, mock C3PAO assessor, evidence vault, C3PAO handoff bundle.
Geopolitical risk monitoring, single-source vulnerability detection, pre-qualified domestic alternatives.
SBIR & DIU solicitation matching, technical approach drafting, compliance checklist for submission.
Already CMMC-ready?
Add supplier monitoring.
Once your audit is behind you, layer on OFAC, BIS Entity List, DLA, and commodity-feed monitoring against your bill of materials. When a Tier-2 vendor goes dark, you have a pre-qualified domestic alternate before the prime asks. Bolt onto any tier for +$99/mo.
MONITORED · LAST SWEEP 14:30Z
- ALT-018ASierra CircuitsSunnyvale, CA · lead 21 days · ITAR-registered+18%
- ALT-018BAdvanced AssemblyAurora, CO · lead 28 days · DFARS-compliant+11%
- ALT-018CSummit InterconnectAnaheim, CA · lead 34 days · AS9100D+24%
- 14:22ZOFACNew entity added — Shenzhen Precision parent (Hongli Group)
- 13:48ZBISEntity List update: 4 PRC drone OEMs
- 11:02ZUSGSTantalum spot up 7.4% on Kazakhstan export delays
- 08:30ZDLADPAS rating issued on contract FA8650-23-C-1004