CMMC is in effect, paused in Phase 1: Level 1 self-assessment every year, Level 2 self-assessment every three years, each with an annual affirmation entered in SPRS. Third-party assessments are suspended pending the Department's review.
Start Your Assessment
For defense contractors handling FCI or CUI

What stands behind
your signature.

Every year, a senior official at your company affirms to the Department of Defense that your cybersecurity requirements are met.

DefendR turns your own answers into the documentation behind that affirmation, every line traced to a requirement, with a verification link anyone relying on it can check. Level 1 documentation for FCI. Level 2 readiness for CUI.

Built on FAR 52.204-21 · DFARS 252.204-7012 · NIST SP 800-171

No audit required to start
Independently verifiable
SPRS submission ready
Scroll
Built for the Defense Industrial Base
Independently Verifiable Proof
NIST SP 800-171 Aligned
DoD DIB Supply Chain
0CMMC Level 1 practices covered
$1,999not the $15,000+ a consultant charges
In hoursnot the months a consultant takes
Under an hourto answer the assessment
WHY THIS EXISTS

The obligation is not new. The signature is.

Four facts, each one checkable, and what they mean for a shop that holds or wants DoD work.

SINCE 2016

The 15 safeguards

FAR 52.204-21 has required 15 basic cybersecurity safeguards on any contract involving Federal Contract Information for a decade. Most small shops have been meeting some of them informally all along.

SINCE 10 NOVEMBER 2025

The annual affirmation

CMMC (32 CFR Part 170) adds a self-assessment every year, a score entered in SPRS, and an affirmation signed by a senior company official that the requirements are met. That affirmation is a representation to the federal government, renewed annually.

THE EXPOSURE

A false representation is a False Claims Act case

The Justice Department's Civil Cyber-Fraud Initiative pursues contractors who misstate cybersecurity compliance. Public 2025 settlements include $8.4 million (Raytheon) and $4.6 million (MORSECORP, tied to an inflated SPRS score).

What you are actually buying

Level 1 does not require a System Security Plan, written policies, or a POA&M; those are Level 2 instruments. So this is not paperwork the government demands. It is the documented basis for the affirmation you sign: an assessment record of all 58 objectives attributed to your own answers, the plan that describes how each practice is handled in your shop, the written policies, the worksheet behind your SPRS score, and an honest report of what is not met. Each carries a verification link that proves the document is what it was when generated, from those answers, on that date.

Not a certification, and not a statement that you are compliant. The Gap Report tells you what to fix; the safeguards themselves are yours to implement. Sources: FAR 52.204-21; 32 CFR 170.15 and 170.22; U.S. Department of Justice settlement announcements, 2025.

HOW IT WORKS

From Your Answers to Documentation a Prime Can Check. In Days

Every DoD contract now asks you to put your cybersecurity posture on the record, and that affirmation is a representation to the government. DefendR does the drafting from your own answers, so every line traces to a real requirement and to what you told us. Payment happens after your assessment is complete, not before.

1

Take Your Assessment

Answer a few plain-language questions about how you operate.

Sign up in under 2 minutes
Gap snapshot + SPRS score
2

Your Package Is Prepared

Your documents are drafted from your answers, checked line by line against them, and delivered.

~24-48 hours
Full documentation package delivered
3

Grounded and Verifiable

Every line traces to a requirement and your own answers.

Documentation delivered
A verification link your prime can check

What you receive

FOR FCI · LEVEL 1 DOCUMENTATION · $1,999
  • System Security Plan. Describes your systems and how each of the 17 Level 1 practices is handled in your shop. The first document a prime or assessor asks for.
  • Security Policies. The written rules your company operates by, one per practice area. Practices without written policies are the most common finding in a review.
  • SPRS Affirmation Worksheet. Your score under the DoD methodology and the affirmation record, ready for the Supplier Performance Risk System.
  • Gap Assessment Report, included with every completed assessment. What your answers show as met and not met, requirement by requirement, with plain-language remediation guidance.
  • A verification link on every document. Anyone you share it with can review the recorded issuance date and provenance. The page compares a supplied link fingerprint with the stored record. It does not inspect a recipient's PDF file or certify compliance.
FOR CUI · LEVEL 2 SELF-ASSESSMENT RECORD · FREE TO START · RECORD $3,000
  • Free preliminary picture: eight scope questions and a plain-language interview, then where your answers place you against all 110 NIST SP 800-171 Revision 2 requirements (320 assessment objectives), before you pay anything.
  • The requirement review: every requirement as a row, every objective with the answer that set it, confirmed by you one requirement at a time. Level 1 answers you already gave arrive as proposals.
  • SPRS-methodology score, computed the way the DoD computes it.
  • Gap analysis by requirement, including which gaps may go on a Plan of Action and Milestones and which must be resolved first.
  • A verifiable record with a status card a prime or a broker opens without an account, version history, and the annual affirmation, with the first year of Standing included.
  • What it is not. Not a certification and not a third-party assessment; it is the documented basis for your own Level 2 self-assessment and annual affirmation. Not a Level 2 System Security Plan.
WHO IT'S FOR

Built for Everyone in the Defense Supply Chain

Whether you handle Federal Contract Information, handle CUI, or advise DIB clients as a consultant, DefendR fits how you work.

CMMC Consultants

Generate defensible documentation for each client from their own answers. Your time goes to advisory work and gap analysis, not drafting.

Documentation generated from each client's own answers
Every document independently verifiable by link
A gap snapshot and SPRS score per engagement

Small Defense Manufacturers

You handle Federal Contract Information and need CMMC Level 1 documentation to keep your DoD contracts, without a $15,000-plus consulting engagement. DefendR prepares it in days, not months.

SSP and security policies grounded in your answers
SPRS score calculation and submission guide
A public verification link for each document

Organizations Handling CUI

You handle Controlled Unclassified Information and CMMC Level 2 applies. DefendR measures where you stand against all 110 requirements from your own answers and gives you a verifiable readiness record. Not a certification; the map of what to address before one.

Readiness against all 110 NIST SP 800-171 requirements
SPRS-methodology score and gap analysis by requirement
A verifiable record to share with a prime or broker
Learn more →

Subcontractors & Suppliers

You're part of the defense supply chain and your prime requires CMMC compliance. DefendR makes the documentation straightforward, with no cybersecurity team required.

No cybersecurity expertise needed
Documentation your prime can check
Complete documentation package
COMPLIANCE FRAMEWORK

17 Practices. One Platform.
Zero Guesswork.

DefendR's documentation engine maps directly to the full CMMC Level 1 control set, every family and every practice, in the authoritative language your prime and your SPRS submission expect to see.

FAR 52.204-21
Basic Safeguarding of Covered Contractor Information Systems, the 15 safeguards behind CMMC Level 1.
DFARS 252.204-7012
Safeguarding Covered Defense Information, the clause behind your CMMC obligation.
NIST SP 800-171
The security standard CMMC is built on. Level 1 is a 17-practice subset; Level 2 is all 110 requirements.
SPRS Submission
Score calculation and self-assessment documentation for Supplier Performance Risk System.
FCI / CUI distinction handled automatically
CMMC Level 1 Practices by Domain17 / 17 practices
ACAccess Control
4 practices
IAIdentification & Authentication
2 practices
MPMedia Protection
1 practice
PEPhysical Protection
4 practices
SCSystem & Communications Protection
2 practices
SISystem & Information Integrity
4 practices

Grounded in Real Requirements. Not Invented.

Every document DefendR generates traces to a real CMMC requirement and to your own answers, line by line. Nothing is invented, and each document carries a verification link a prime or a carrier can check independently.

WHO RELIES ON YOUR RECORD

The people who ask “show me” can check for themselves.

Every document carries a verification link. Whoever you share it with can review the recorded issuance date and provenance. The lookup does not inspect or verify the contents of a recipient's PDF file.

Your prime contractor

Your prime contractor can review the document's issuance record through the verification link. That lookup supports its review of your documentation; it does not verify control implementation.

Your insurance broker or carrier

Cyber insurance applications ask for your compliance documentation and treat it as your representation. A verifiable record generated from your own answers is a cleaner representation than a template someone filled in.

A future assessor

Organizations handling CUI hold a Level 2 self-assessment status under Phase 1: a self-assessment against all 110 requirements every three years, affirmed annually in SPRS. A readiness record that already names every gap, and which ones may go on a Plan of Action, is what stands behind that affirmation.

DefendR maintains the document's issuance record and compares a supplied link fingerprint with that record. This lookup does not verify the contents of a recipient's PDF file. It does not verify that your answers are true or that you are compliant; responsibility for the answers remains yours.

From FAR 52.204-21 to a Complete Documentation Package. In Days, Not Months.

Defense manufacturers are automating their compliance documentation with DefendR. Your contracts deserve it.

Get Started Today

Your Documentation,
Grounded and
Verifiable.

For CMMC Level 1 self-assessment. Designed for companies handling Federal Contract Information (FCI). Built on NIST SP 800-171. Every document grounded in your own answers and independently verifiable.

No commitment required. Setup in minutes. Optional standing cancels anytime.