CMMC Level 1, Level 2 and Level 3
Stop nation‑state attackers. CMMC compliance follows.
Nation-state attackers go after small defense suppliers to steal controlled drawings, and CMMC exists to stop them. Air D3fense readies you for those attackers. Our certified CMMC assessors guide your preparation, on a platform a junior GRC analyst can run.
- Lead CCA
- Our team holds every CMMC credential, up to Lead Certified CMMC Assessor
- 110
- Level 2 requirements, broken into the 320 checks an assessor uses
- SSP and POA&M
- Plus your SPRS score, built as you work
- US only
- Hosting and AI processing
How it works
A plan with a date, and a clear next step.
We set the target date with you at kickoff and keep you on schedule. Every step tells you exactly what to do next.
- 01
Plan
Set the scope, the CMMC level and the target date. Level 1 covers federal contract information (FCI). Level 2 covers controlled unclassified information (CUI), such as controlled drawings.
- 02
Prepare
Answer the questionnaire, supply evidence, map assets and data flows, and close gaps.
- 03
Prove
Walk into your assessment with your System Security Plan (SSP), Plan of Action and Milestones (POA&M) and SPRS score finished.
- 04
Sustain
Keep your certification current with recurring checks.
Assessment
You answer in plain language. A certified assessor confirms each result.
-
01 · YOU
Answer a questionnaire
Plain-language questions built from the checks in NIST SP 800-171A, grouped by topic. Invite your IT provider to answer the technical ones.
answers -
02 · AI
Suggests an answer
Suggests met or not met for each check, and flags answers that conflict or are missing detail. The AI runs in the United States and is never trained on your answers.
suggestions and flags -
03 · ASSESSOR
Confirms
A certified CMMC assessor reviews each suggestion beside your answer and records the result.
recorded results
Our team holds all three CMMC credentials. Certified CMMC Professional (CCP) is the foundation. Certified CMMC Assessor (CCA) is required to conduct official Level 2 assessments. Lead CCA leads assessment teams. Each requires a Tier 3 background investigation. Work with our team, or bring your own consultant. Either way, you walk into your certification assessment ready.
Deliverables
The documents you owe, built as you go.
System Security Plan
One section per requirement, edited in the platform and exported to Word or HTML.
Plan of Action and Milestones
Each open item has an owner, milestones and a closeout date.
Network and data flow
A network diagram, and a diagram of where controlled unclassified information (CUI) travels.
Evidence
Documents, interviews and observations, requested by name and tracked until supplied.
SPRS score with its worksheet
Your Supplier Performance Risk System (SPRS) score, calculated with the DoD Assessment Methodology weights. Until every requirement is answered, it shows a range.
| Requirement | Points |
|---|---|
| 3.5.3 Multifactor authentication | −3 |
| 3.13.11 FIPS-validated cryptography | −5 |
| 3.4.1 Baseline configurations | −5 |
| 3.11.2 Vulnerability scanning | −5 |
| + 11 more deductions | −11 |
| 110 − 29 | 81 |
For MSPs and MSSPs
Delivering CMMC for clients?
Run every client in its own isolated workspace and see them all on one screen. Licensed per client organization.
Trust
A record an assessor can trust.
Results are signed
Every result records who made it and when, so any answer can be traced.
Nothing scored until reviewed
A requirement nobody has reviewed shows as unanswered and is never scored as zero.
US hosted
Hosting, data and AI processing all stay in the United States.
Permanent record
Scores, results, sign-offs and approvals can be added but never edited.
Request a briefing
Tell us your deadline.
We show you the platform and map a plan to your deadline. One license covers your whole company.
or write to contact@aird3fense.com