How it works Pricing FAQ Log in Get started

Get ready for your CMMC assessment. Without the detour.

Answer a guided interview. Walk away with a readiness score, a prioritized list of gaps, and a draft System Security Plan. Built for small defense contractors.

All 110 controls covered
~60 minute interview
30-day money back

How contractors handle CMMC today.

Most options cost too much or do too little. Here's how Baseline compares.

Hire a consultant
$15,000 – $40,000

A consultant drafts your SSP. Quality varies. You wait three to six months.

Cost
$$$$
Time
3–6 months
DIY the template
Free

Download the NIST template. Stare at 110 blank narratives. Hope you got it right.

Cost
$0
Time
80–200 hrs
GRC platform
$15k – $30k/year

Enterprise software built for primes with security teams. Overbuilt for the small end.

Cost
$$$
Time
Ongoing

From blank page to your compliance baseline.

A structured interview, a clear diagnostic, and the documentation your team needs to move forward.

1

Tell us about your environment

A guided interview walks you through your tools, team, and processes. Hover over any term you don't know for an instant definition.

~60 min total
2

See where you stand

The moment you finish, your answers are scored against the framework. You see exactly which controls you meet, where you fall short, and what to focus on first.

Generated in minutes
3

Walk away with the documents you need

The drafts your assessor will ask for are generated from your answers and traceable back to them. Ready for your team to review, refine, and submit.

Same-day output
Inside the interview

The product, up close.

What the interview actually looks like. Three real moments, in plain English.

1
Structured questions

Multiple-choice questions handle the structured parts of your environment. Hover over any underlined term for an instant definition, or expand "Why are we asking?" to see how your answer flows into the framework.

About your company 5 of 30
Section 01 · About your company
Hover over any underlined term
What types of Controlled Unclassified InformationCUIGovernment information that requires safeguarding but isn't classified. If you handle sensitive material for a federal agency that doesn't carry a "Secret" or "Top Secret" marking, it's likely CUI. do you handle?
Check all that apply. Not sure? Pick the closest match — we'll help you confirm later.
CTIControlled Technical InformationEngineering drawings, technical specs, source code, and other technical data with military or space application. Common for defense contractors. — Controlled Technical Information
Export Controlled (ITARInternational Traffic in Arms RegulationsU.S. rules controlling the export of defense-related articles and services. If your work involves military technology, ITAR likely applies. / EARExport Administration RegulationsU.S. rules controlling exports of dual-use items — products with both commercial and military application.)
Privacy / PII
Knowing what categories of CUI you handle determines which marking, handling, and protection requirements apply to your environment. The answer flows into multiple SSP control narratives.
MP.L2-3.8.1Media ProtectionProtect physical and digital media containing CUI wherever it lives. MP.L2-3.8.4Media MarkingMark media with appropriate CUI labels so handlers know what protections apply. AC.L2-3.1.9Privacy NoticesDisplay CUI privacy and security notices before granting access to sensitive systems.
2
Open-ended detail

Open-ended questions capture the things only you know — your processes, your roles, your edge cases. Example answers shown to guide you.

How people work 22 of 30
Section 04 · How people work
What happens when someone leaves the company?
Tell us how fast access is removed and who's responsible.
HR notifies IT within 4 hours of termination. IT disables the Okta account immediately, which cascades to M365, GitHub, and Splunk. Devices are collected the same day
3
Final review

A summary screen lets you review and edit before generation. Nothing is locked — change anything that doesn't reflect your environment, then continue.

Interview complete 30 of 30
All sections answered
Review your answers
Edit any section before we generate your report.
About your company 5/5
Your people 4/4
Tech stack 8/8
How people work 5/5
Operations 5/5

The interview takes about an hour. Your answers are auto-saved as you go, so you can pause and resume anytime.

Try the interview

A readiness check, plus the drafts you'll need.

📊

CMMC Readiness Report

A score against all 110 controls based on your answers, with a ranked list of gaps to address. The first thing you want before you talk to an assessor.

See sample report
📄

SSP Draft

110 control narratives drafted from your answers. Designed for your team's review before submission.

🎯

POA&M Starter Template

A POA&M scaffold populated with your identified gaps. You add the remediation owners, timelines, and resources that fit your team.

SPRS Score & Evidence Checklist

A worksheet for your SPRS submission, plus a checklist of artifacts assessors typically request.

What your SSP draft looks like.

Every narrative is structured around NIST 800-171 expectations and tagged back to the interview answers that produced it — so you know what to verify before submission.

  • NIST SP 800-171 Rev 3 structure throughout
  • System description, boundary, roles, and 110 control narratives
  • Confidence flags on every section
  • Word and PDF export for review and editing
See a sample
DRAFT
Meridian Defense Systems
System Security Plan
3.1 AUTHORIZATION BOUNDARY
AC.L2-3.1.1 — LIMIT ACCESS
AC.L2-3.1.2 — TRANSACTION CONTROL
AC.L2-3.1.5 — LEAST PRIVILEGE

Start with the diagnostic.
Add the documents when you're ready.

Diagnostic
Find out where you stand against all 110 controls.
$695
One-time
  • Full guided readiness interview
  • CMMC Readiness Report (110 controls)
  • Prioritized list of gaps
  • Remediation guidance
  • SPRS score worksheet
  • PDF export & email support
  • 12-month dashboard access
Start the diagnostic
Dashboard access lets you re-view your report, track gap closure, and re-run the interview as your environment changes — for 12 months. After that, refresh access renews at $495/year. 30-day money back guarantee on both tiers.

Common questions, answered.

There's no tool — and no consultant — that can guarantee an assessment outcome. Your assessor is evaluating your actual environment, not just your document. What Baseline does is tell you, before you ever meet an assessor, where you're strong and where you're exposed. The readiness report scores all 110 controls and flags assessment risk; the SSP narratives are tagged with confidence flags so you know which sections need human review.

Those platforms are priced for mid-market and enterprise — typically $15–30k/year. We're built for the small end. Diagnostic, SSP, and remediation roadmap from a single guided interview, not a platform you configure for months before it produces output.

You'd get generic narratives that don't match assessor expectations. The work isn't "write me an SSP" — it's the structured interview, the diagnostic scoring, the mapping to all 110 controls, and the orchestration that keeps your output internally consistent and traceable. The IRS publishes every tax form for free; TurboTax charges $100 because someone figured out the right questions to ask.

No — intentionally. The interview captures descriptions of how you handle CUI, never CUI itself. You can use Baseline without bringing us into your CMMC assessment boundary.

Baseline is currently optimized for small defense contractors with relatively standard cloud-based environments — typically 10 to 50 employees, primarily working in Microsoft 365 GCC High, providing software or professional services to DoD customers. If your environment fits that profile, the generated documentation will closely match how your business actually operates.

If your environment is substantially different — heavy on-premises infrastructure, manufacturing or industrial control systems, classified networks, or specialized regulated workloads — the generated draft will need more revision to reflect your reality. The interview will still produce useful starting documentation, but you'll likely want hands-on help refining sections that fall outside the standard archetype — either from your internal compliance team or from a CMMC consultant familiar with your environment type. We're working to expand support for more environment types over time.

Know where you stand. Know what to fix.

One hour of questions. A readiness report in minutes. An SSP draft the same day, ready for your review.