CMMC 2.0 · DFARS 252.204-7012 · NIST 800-171

Get to 110.

The fastest path to CMMC Level 1, 2, and 3 readiness — built for defense contractors who can't afford to fail an assessment, and can't afford a six-figure consultant either.

Take the 5-min Quick Check No signup. Just a score.
110
Level 2 controls
NIST 800-171 Rev 2
320
Assessment objectives
scored by C3PAO
Nov '26
Phase 2 deadline
L2 cert required
80K+
DIB contractors
affected

Eligibility, not just compliance.

CMMC is the gate to every new DoD contract by 2028. Failing the assessment doesn't mean a penalty. It means you can't bid.

→ DEADLINE
Nov 10, 2026
Phase 2 begins. Level 2 C3PAO certification becomes mandatory in new contracts. The 36-month full rollout starts.
→ CONSULTING COST
$50K–$150K
Typical fee for a CMMC L2 readiness engagement with a boutique consultancy. Annual. Doesn't include remediation labor.
→ TIMELINE
6–18 months
Average time from "we should look at CMMC" to assessment-ready. The earlier you start, the cheaper it stays.
→ LIABILITY
FCA exposure
CEO annual affirmations create False Claims Act risk. DOJ has active cases over inaccurate 800-171 attestations. This is not optional.

Built by an assessor. For the assessed.

Score110 is not another GRC checkbox tool. It's the workflow a senior assessor uses, packaged as software — so you can prepare without paying one by the hour.

▸ FEATURE.01

AI-Evaluated Evidence

Upload your access control policy. Score110 reads it and tells you which of the six AC-3.1.1 assessment objectives are actually addressed — and which are not. No more guessing what a C3PAO will see.

▸ FEATURE.02

Mock C3PAO Interview

AI roleplays an assessor asking the actual interview questions for each control. You practice. We score you. Walk into your real assessment having already done it three times.

▸ FEATURE.03

Living SSP

Watch your System Security Plan write itself as you complete each control. No more "we'll document it at the end." The artifact assessors require, generated as you go.

▸ FEATURE.04

SPRS Score, Real-Time

Watch your DoD Assessment Methodology score update with every answer. Out of 110. Negative-203 floor. Submit-ready.

▸ FEATURE.05

CSP Inheritance

Tell us you use M365 GCC High, AWS GovCloud, or Azure Government — and Score110 pre-fills the shared responsibility matrix for every control. Stop reinventing it.

▸ FEATURE.06

POA&M That Knows the Rules

CMMC restricts which controls are POA&M-eligible. Score110 enforces the 180-day closure rule, blocks ineligible items, and keeps your remediation plan submission-ready.

Where do you actually stand?

13 questions. 5 minutes. A real assessment-style score out of 110 — no email required to see it.

▸ READINESS ASSESSMENT

Get your Score

This isn't a marketing quiz. The questions map to NIST 800-171 controls and the DoD Assessment Methodology. Your score reflects where a C3PAO assessor would likely land.

5 minutes 13 questions Anonymous
QUESTION 01 / 13

0

05585105110
SECTION SCORES
PRIORITY GAPS
▸ EARLY ACCESS

Be among the first 100 to access Score110

Founding members get the Advanced tier at 50% off for life — plus a free 30-min readiness consultation with the founder before launch. Limited to first 100 signups.

Reserve my spot

Three tiers. One assessment posture.

Annual pricing. No per-user nickel-and-diming. Everything you need to walk into your assessment confident.

Starter

FCI only · Level 1

$999/yr
  • All 17 Level 1 controls (FAR 52.204-21)
  • AI evidence evaluation
  • SSP auto-generation
  • Annual self-affirmation tracking
  • Gap report exports
  • Single user

Expert

CUI Enhanced · Level 3

$7,999/yr
  • Everything in Professional
  • 24 enhanced 800-172 controls (L3)
  • Subcontractor flow-down tracking
  • Audit log + compliance history
  • White-label gap report exports
  • Priority support
  • Unlimited users
Rex Wilburn, Founder
CERTIFICATIONCISM
EDUCATIONM.S. Info Assurance
ATOs ACHIEVED23+ Systems
SPECIALTYRMF · eMASS · 800-171

Rex Wilburn

FOUNDER · SECURITY CONTROLS ASSESSOR

Score110 is built by a working assessor — not a SaaS company that hired one. I've taken 23+ federal systems through the Risk Management Framework to full Authority to Operate, written and reviewed System Security Plans across DoD and federal civilian environments, and worked the eMASS workflow that makes or breaks an ATO.

I built this tool because I watched too many small and mid-sized defense contractors get crushed by consulting fees they couldn't afford for work that could be largely systematized. CMMC is a serious compliance regime. It is not, however, magic — and you shouldn't need to mortgage your business to get through it.

Every question in the Quick Check, every control template, every evidence prompt comes from work I've actually done. This is the tool I wish my clients had a year before they called me.

Common questions, direct answers.

Rev 2. C3PAO assessments are currently conducted against Rev 2 under a DoD class deviation, with 110 controls and 320 assessment objectives. Building Score110 to Rev 3 would mean failing your assessment. When DoD authorizes Rev 3 for CMMC assessments, we'll add it as an option — but Rev 2 remains the assessment standard for the foreseeable future.
We're building toward a launch ahead of the November 2026 CMMC Phase 2 deadline. Founding members on the waitlist get early access, locked-in pricing, and a free 30-minute readiness consultation with the founder.
No, and that's by design. C3PAOs are independent third parties required for Level 2 certification. Score110 makes sure that when you sit down with them, you're prepared, your evidence is sufficient, and your SSP is real. We're the preparation. They're the assessment.
Score110 is a CUI-aware product built by a security professional. Your data never leaves a FedRAMP-aligned environment, is encrypted at rest and in transit, and is never used to train AI models. Full security documentation will be available before the platform launches.
The Quick Check above is designed to help with this. If you're still not sure after taking it, the founding member consultation is exactly the kind of question we'll help you answer.
It approximates it. The 110-point scale matches the DoD Assessment Methodology max, and the question weighting reflects how DoD scores critical controls. The Quick Check is a directional read in 5 minutes; the full platform produces a defensible, evidence-backed score you can submit.