SelfCMMC
A self-run CMMC Level 2 pre-assessment that scans a defense contractor's live software stack, maps every tool against its FedRAMP authorization status, and hands back an SSP gap doc and a CUI-flow graph before the C3PAO assessment.
An 80-person defense contractor has a Department of Defense contract that now requires a CMMC Level 2 certification, and a single coordinator who has no idea whether the company's actual running stack will pass. They can pay a C3PAO assessor $30K-$80K to find out — then wait, fail on the first pass alongside most of their peers, and remediate blind. The thing they need before writing that check is an honest map of where they stand and what's broken, and nothing self-serve gives it to them.
The compliance lead (or the owner wearing the compliance hat) at one of ~80,000 small-to-mid defense-industrial-base contractors facing a Level 2 requirement they cannot self-evaluate. The budget line already exists: the $30K-$80K they are about to hand a C3PAO assessor, plus the far larger cost of failing it and missing the contract.
CMMC 2.0 Phase 2 November 2026 enforcement is a confirmed named regulation with 18-month assessor wait times — a confirmed-strength signal.
Assessor scarcity and a five-figure cost of failure against a mandatory deadline is real productive tension, but it is partially paraphrasable as a known scanner pattern aimed at a new regime.
Two cross-references plus three inbound connections to compliance-scanner kin, but no cluster evidence — a modest, not dense, position in the graph.
The temporal window is the standout: a confirmed federal mandate (CMMC 2.0 Phase 2) with a hard November 2026 enforcement date, a quantified assessor bottleneck (under 600 assessors against 80,000 contractors), and a self-serve price tier that research confirms is absent across every reviewed tool today. The buyer is real and budget-anchored, and the productive tension — a mandatory deadline colliding with assessor scarcity and a five-figure cost of failure — is resolvable by a live-stack scan rather than a questionnaire.
Convergence is thin (a couple of cross-references into compliance-scanner kin, no cluster evidence), and the angle is partially paraphrasable as a 'Vanta-style scanner for CMMC' — Vanta already markets a CMMC product and could descend without prohibitive structural cost. The SSP outputs may also pull users back toward consultant review, softening the self-serve promise. Defensibility has to come from the accumulating CUI asset graph, not the scan itself.
Genesis doesn't invent in isolation — SelfCMMC shares architecture with, or powers, these ideas.
Discussion
No comments yet — be the first to weigh in.
