Our mission

Small contractors shouldn't need a $50,000 consultant to do business with the DoD.

The problem

CMMC was written to raise the cybersecurity floor across the defense industrial base. In practice, it hit the smallest contractors the hardest. The 10-person construction firms running USACE contracts, the machine shops that supply parts to primes, the electrical subs on base renovation jobs.

These are the companies doing the actual work. Most don't have an IT department, let alone a full-time compliance officer. When a prime asks them for an SPRS score or proof of CMMC Level 2 readiness, they face a choice: hire a consultant who charges between $30,000 and $80,000 to prepare documentation, or lose the contract.

Neither outcome serves the DoD, the contractor, or the mission.

What we built

ClearCUI is a software system that does the work a consultant would do, structured around the authoritative source documents: NIST SP 800-171 Rev 2, 32 CFR Part 170, DFARS 252.204-7012, and the CMMC Assessment Guide Level 2.

You answer structured questions about how your organization handles CUI: who is responsible, which systems are involved, what technical mechanisms are in place, where the evidence lives. The platform generates a System Security Plan, a POA&M that follows the 32 CFR 170.21 prohibited-controls rules, and a full set of family policies. Every output cites the control language verbatim.

The price is $4,200 / year because that is what the software costs to operate. There is no consultant layer, no professional services engagement, no upsell path.

What we believe

Every output has to be defensible.

A System Security Plan that wouldn't survive a C3PAO assessment is worse than no SSP at all. It gives a contractor false confidence. Everything ClearCUI generates is written against the authoritative source documents, with control references, determination objectives, and evidence requirements that stand up to audit.

CUI stays with the contractor.

We don't ask you to upload drawings, specs, or any controlled content. The platform captures compliance metadata: roles, systems, technical controls. Not CUI itself. The free tools run entirely client-side; the paid platform stores structured assessment data in US-based cloud infrastructure with full access controls.

The price reflects the cost of the software.

$4,200 / year is not a volume discount or an introductory rate. It is the cost of running a platform that serves small contractors at the scale they operate. There is no enterprise tier, no hidden professional services, no implementation fee.

Start here

Know your SPRS score before the prime asks.

The calculator runs entirely in your browser. No signup, no sales follow-up.

Open the SPRS calculator