Everything you need to navigate
CMMC compliance

Explore AskCMMC.ai's powerful features, from intelligent Q&A and document analysis to AI-powered gap assessments, SSP generation, and cross-framework mapping.

Get Started Explore Agents
10
AI Agents
127+
CMMC Controls
15+
Source Documents
0
Data Collected

Getting Started

Up and running in under two minutes

Sign in with SSO

Visit askcmmc.ai and sign in with your Google, Microsoft, or GitHub account. No separate registration needed. SSO gets you in instantly.
  • No passwords to create or remember
  • Enterprise-grade OAuth 2.0 authentication
  • Credential security is handled entirely by your identity provider
  • One-click access from any device with a browser

Pick your CMMC level

Use the level toggle in the header to choose your target maturity level. Every response, citation, and recommendation adjusts automatically.
  • Level 1: 17 practices from FAR 52.204-21 for safeguarding Federal Contract Information (FCI)
  • Level 2: 110 requirements from NIST SP 800-171 Rev 2 for handling Controlled Unclassified Information (CUI)
  • Switch levels at any time. Your chat history is preserved
  • Source documents and citation scope update to match your selection

Ask your first question

Type a compliance question and press Enter. Answers stream in real time with numbered citations you can verify against official documents.
  • Try "Summarize Level 1 practices" for a high-level overview
  • Try "What are the access control requirements at Level 2?" for specific controls
  • Try "What's the difference between FCI and CUI?" for foundational concepts
  • Click any numbered citation to see the exact source text
  • Follow-up questions maintain full conversation context

Explore the rest of the platform

Once you are comfortable with the basics, explore these advanced capabilities:
  • Document Analysis: Upload policies, SSPs, or security documents for AI-powered compliance review
  • Flash & Thinking Modes: Choose between fast answers and deep multi-agent analysis
  • Specialized Agents: 10 purpose-built agents for gap analysis, SSP drafting, cross-framework mapping, and more
  • Chat History: Conversations are saved locally, searchable, and pinnable
  • Keyboard Shortcuts: Power-user shortcuts for navigation, search, and mode switching

Quick tip: The welcome screen includes ready-made prompts you can click right away, like "Summarize Level 1 practices", "List policy gaps", "Create an AUP Policy Draft", or "Give Level 2 checklist".


Chat and Conversations

Organize your compliance research across multiple sessions

Multiple Chat Sessions

Create separate conversations for different compliance topics. Each chat maintains its own context and history, so access control research never bleeds into incident response discussions.

  • Click "+ New Chat" in the sidebar to start a fresh session
  • Switch between chats freely. Context stays intact
  • Titles are generated automatically from your first message

Chat Management

Full control over every conversation through the three-dot menu on each chat entry.

  • Rename: give chats meaningful titles
  • Pin: keep important conversations at the top
  • Delete: remove individual chats you no longer need
  • Clear All: wipe everything from Settings

Context-Aware Follow-Ups

AskCMMC.ai remembers your full conversation history within each chat session. You can ask natural follow-ups like "Tell me more about that", "How does this apply to Level 2?", or "Can you give me an example?" and the AI will understand exactly what you're referring to from earlier messages. No need to repeat yourself or re-explain your question.

Streaming Responses

Answers arrive in real time, token by token, so you can start reading immediately without waiting for the full response to generate. A live progress indicator shows exactly where the AI pipeline stands, from retrieval to reranking to generation, so you always know what's happening behind the scenes.

Keyboard shortcuts: Press Ctrl+Shift+O to create a new chat, / to focus the input, and Ctrl+B to toggle the sidebar.


CMMC Level Support

Tailored guidance for the maturity level that applies to your organization

Level 1: Foundational

Covers 17 CMMC practices derived from FAR 52.204-21, focused on protecting Federal Contract Information (FCI). This is the baseline for every DoD contractor.

  • 6 domains: AC, IA, MP, PE, SC, SI
  • Self-assessment only, no third-party audit required
  • Applies to all contractors handling FCI

Level 2: Advanced

Covers all 110 security requirements from NIST SP 800-171 Rev. 2 for protecting Controlled Unclassified Information (CUI). This is where most defense contractors need to certify.

  • 14 control families with detailed implementation guidance
  • C3PAO third-party assessment required for most contracts
  • Full support for SSP, POA&M, and SPRS scoring

Level 3: Expert (Coming Soon)

Level 3 support is in active development and will cover the enhanced security requirements from NIST SP 800-172, designed for the most sensitive defense programs handling high-value CUI. This level adds controls beyond 800-171 to defend against advanced persistent threats (APTs). Reach out if you would like early access or want to be notified when it launches.

Switching Between Levels

Use the level toggle in the top header to switch between Level 1 and Level 2 at any time. When you switch, the entire knowledge base, FAISS document index, BM25 search index, and response context adjust automatically so every answer is scoped to the correct set of controls, practices, and assessment requirements for your selected level.


Flash and Thinking Modes

Pick speed or depth depending on what you need right now

Feature Flash Mode Thinking Mode
Speed Instant (1 to 3 seconds) Thorough (10 to 30 seconds)
AI Agents Basic retrieval only Full agent pipeline
Query Expansion Not available Multi-query variants
BM25 Keyword Search Not available Hybrid dense + sparse
Cross-Encoder Reranking Not available Precision reranking
Parent Retrieval Not available Full section context
Contextual Compression Not available Noise reduction
Best For Quick lookups, control ID queries, simple definitions Complex analysis, gap assessment, implementation guidance, policy drafting

Use Flash for quick lookups like "What is control 3.5.3?" and switch to Thinking for deeper analysis, such as "Perform a gap analysis of my access control policies against Level 2 requirements."


Response Length Control

Decide how much detail you want in each answer

Auto Mode

Lets the AI decide the best response length based on your question. Simple queries get short answers; complex topics get detailed ones.

Short Mode

Concise responses under 200 words. Ideal for quick lookups, control definitions, or straightforward compliance answers.

Normal Mode

Balanced responses in the 300–600 word range. Covers key points with clear structure without overwhelming detail.

Detailed Mode

Comprehensive answers between 600–1,200 words. Includes implementation guidance, reference tables, and thorough explanations for compliance planning.

Very Detailed Mode

Exhaustive responses in the 1,200–2,500 word range. Step-by-step guidance, checklists, control mappings, and actionable recommendations for deep research.


AI Agents

10 specialized agents that collaborate to answer your compliance questions

In Thinking Mode, your question is automatically routed to the best agent (or combination of agents) by the Orchestrator. You can also select an agent manually using the "+" button next to the chat input.

Query Analyzer

Classifies your question's intent, extracts key entities like control IDs and families, and decides which agent pipeline to activate.

"Access control requirements for Level 2?"

Compliance Agent

Performs deep compliance analysis against CMMC and NIST frameworks. Returns authoritative answers with exact control references you can cite.

"Is MFA required at Level 1?"

Document Analyzer

Reviews uploaded documents (SSPs, policies, procedures) against CMMC requirements. Processes the entire file without chunking so nothing gets missed.

"Review this against Level 2 requirements"

Gap Analysis Agent

Identifies compliance gaps in your security posture and generates POA&M entries with specific remediation steps to close each one.

"Gaps in my access control policies for Level 2"

Web Search Agent

Searches the web for the latest CMMC and NIST updates, policy changes, and security advisories. Uses DuckDuckGo for privacy-respecting real-time results.

"Latest CMMC rulemaking updates?"

Framework Mapping Agent

Maps controls across CMMC, NIST 800-171, ISO 27001, SOC 2, and other frameworks. Essential when your organization carries multiple compliance obligations.

"CMMC to ISO 27001 mapping?"

SSP Builder Agent

Generates System Security Plan drafts with proper structure, control descriptions, and implementation statements. A fast way to jump-start your documentation.

"Draft an SSP section for access control"

Risk Scoring Agent

Calculates CMMC readiness percentages and risk scores so you can prioritize remediation efforts effectively.

"My readiness score for Level 2?"

Policy Update Agent

Monitors changes to DoD, NIST, and CMMC policies and keeps you informed about regulatory shifts that could affect your compliance.

"Changes in the latest CMMC Final Rule?"

Orchestrator Agent

The conductor behind the scenes. Analyzes your query and routes it to the optimal agent or combination of agents. Runs automatically in Thinking Mode, so you never interact with it directly.

Auto-activated in Thinking Mode

Document Upload and Analysis

Upload your compliance documents for AI-powered review

How to Upload

Click the "+" button next to the chat input and choose "Upload File", or drag and drop files directly into the chat area.

  • Maximum file size: 50 MB per attachment
  • Attach multiple files to a single question
  • Each file is used as context for that specific question only

Supported File Types

Handles the document formats compliance teams use every day:

  • PDF for policies, SSPs, and scoping guides (with OCR for scanned documents)
  • DOCX and DOC for Word documents and written procedures
  • XLSX and XLS for spreadsheets and control matrices
  • TXT for plain text files
  • CSV and JSON for structured data

Full-Document Analysis

The Document Analyzer Agent processes your entire file without chunking, giving it the full context needed for a thorough review. You can ask it to:

  • Review your SSP against CMMC requirements
  • Surface gaps in your security policies
  • Summarize key compliance findings
  • Compare your procedures to NIST standards

Document Privacy

Uploaded files are processed entirely in-memory. They are never written to disk, cached, or retained after processing. Once the response is generated, all file data is discarded immediately. No copies are stored anywhere, not in logs, not in temporary storage, and not in the database. Your documents stay yours.

Note: For scanned PDFs (image-based), AskCMMC.ai uses OCR (Optical Character Recognition) to extract text. Results may vary depending on scan quality. Native or digital PDFs will always produce the best results.


Sources and Citations

Every answer is backed by traceable, verifiable references

Numbered Source Citations

Every response includes numbered citations, small inline badges that link directly to the source document used for that part of the answer, similar to how Perplexity works. Click any citation to jump to the source panel and see the exact passage that informed the response. This makes it easy to verify, audit, and share findings with your team.

Source Panel

Below each answer, a source panel displays all referenced documents as clickable cards. Each card shows the source name, relevance score, and a snippet preview on hover. You can expand any card to read the full retrieved passage in context, making it simple to trace exactly where every claim in the response came from.

Authoritative Documents

All answers are grounded in official, authoritative sources. The knowledge base includes:

  • 32 CFR Part 170 (CMMC Final Rule)
  • NIST SP 800-171 Rev. 2
  • FAR 52.204-21 and DFARS clauses
  • CMMC Assessment and Scoping Guides
  • NIST CSF v2.0 and SP 800-50 Rev. 1

Fact-Checked Responses

Built-in guardrails prevent hallucinated control IDs, incorrect framework labels, and common AI errors. The system clearly distinguishes mandatory requirements from recommended best practices and cross-references every claim against the official source documents. If a control ID or framework mapping can't be verified, it won't appear in the response.


Bug and Feature Reports

Help us improve by reporting issues or suggesting features

Report Form

Visit /report to submit a bug report or feature request. The form supports categories, severity levels, screenshots, and detailed descriptions so we can triage quickly.

How It Works

Reports are automatically created as GitHub Issues with the appropriate labels and metadata. Our team reviews every submission and triages by severity and category.


Privacy and Security

Purpose-built for organizations handling sensitive defense information

Zero Data Collection

No personal information, conversation data, or usage patterns are collected, sold, or shared. There is no analytics, no behavioral tracking, and no fingerprinting of any kind.

No AI Training on Your Data

Your questions, documents, and conversations are never used to train or fine-tune any AI model. Data is processed solely to generate your response, then immediately discarded.

In-Memory File Processing

Uploaded documents are processed entirely in-memory, never written to disk, never cached, and never retained beyond response generation.

Secure Authentication

OAuth 2.0 SSO via Google, Microsoft, or GitHub. Session cookies are HttpOnly, SameSite=Lax, and Secure in production, with single active session enforcement.

All Telemetry Disabled

Every third-party library (Hugging Face, PyTorch, Transformers) has been audited. All telemetry, phone-home calls, and usage reporting have been programmatically disabled.

True Deletion

When you delete a conversation, clear history, or remove your account, the data is permanently destroyed. No shadow copies, no hidden backups, no recycle bins.


Account Management

Your profile, usage, and data at a glance

Query Usage

Your current query count is shown in the header. Free trial accounts include a limited number of complimentary queries. Unlimited access is available after a free consultation.

Settings

Open Settings from the avatar dropdown in the top-right corner. From there you can:

  • View FAQs and keyboard shortcuts under Help
  • Contact support at support@askcmmc.ai
  • Use Clear History to delete all chat conversations
  • Use Delete Account to permanently remove all data (requires 3-step confirmation)

Single Session Enforcement

Only one active browser session is allowed per account at a time. If you sign in from a new device or browser, you'll be prompted to either continue there (which automatically signs out the other session) or cancel. This prevents unauthorized concurrent access and ensures your account stays secure across devices.

Sign Out

Click your avatar in the sidebar and then Sign Out to end your session securely. Your full chat history is preserved server-side and will be waiting for you when you return. Signing out invalidates your session token immediately, so no one else can use your browser session after you leave.


Keyboard Shortcuts

Navigate faster without reaching for the mouse

Action Shortcut
New chat Ctrl + Shift + O
Focus chat input /
Send message Enter
New line in message Shift + Enter
Toggle sidebar Ctrl + B
Dismiss / unfocus Esc

Frequently Asked Questions

Answers to the questions we hear most often

What is AskCMMC.ai?
AskCMMC.ai is an AI-powered compliance assistant built to help you understand and navigate CMMC (Cybersecurity Maturity Model Certification) requirements. It uses a multi-stage RAG (Retrieval-Augmented Generation) pipeline to deliver answers grounded in official CMMC documentation, NIST standards, FAR/DFARS clauses, and other authoritative sources. Think of it as having a compliance researcher available around the clock.
How accurate are the responses?
Responses are generated through a multi-stage hybrid RAG pipeline that retrieves information from verified official documents. Built-in guardrails prevent hallucinated control IDs, incorrect framework labels, and other common AI errors. Every response includes numbered source citations so you can verify the information yourself. That said, always validate critical compliance decisions with a qualified C3PAO assessor.
Is my data safe? Will my documents be stored?
Yes. Your uploaded documents are processed entirely in-memory and are never written to disk, cached, or retained after processing. No conversation data is used for model training. All third-party library telemetry has been disabled at the source-code level. You can delete all your data at any time from Settings. More details are in the Privacy and Security section above.
What topics can AskCMMC.ai help with?
AskCMMC.ai specializes in CMMC 2.0 compliance (Levels 1 and 2), NIST SP 800-171 and 800-172 requirements, FAR 52.204-21, the DFARS clauses (252.204-7012, 7019, 7020, 7021), cybersecurity policies and controls, gap analysis, SSP development, assessment preparation, cross-framework mapping (CMMC to ISO 27001, SOC 2, and more), and general defense compliance guidance. Questions outside these areas will be politely declined.
What are query limits?
Free trial accounts include a limited number of complimentary queries so you can explore the platform. Your current usage is displayed in the header. When your trial ends, you can book a free consultation to discuss unlimited access options that fit your organization.
Can I use AskCMMC.ai on mobile devices?
Absolutely. AskCMMC.ai is fully responsive and works seamlessly on phones, tablets, and desktops. The interface adapts automatically. On smaller screens, the sidebar collapses into a mobile-friendly menu, and all features remain accessible via touch.
What is the difference between Flash and Thinking modes?
Flash Mode delivers fast answers in 1 to 3 seconds using basic dense retrieval. It is ideal for quick lookups and straightforward questions. Thinking Mode activates the full AI agent pipeline, including multi-query expansion, hybrid search (BM25 plus dense), cross-encoder reranking, parent-document retrieval, and contextual compression. The result is a deeper, more comprehensive answer in 10 to 30 seconds. The comparison table above has the full breakdown.
Does AskCMMC.ai provide legal or certification advice?
No. AskCMMC.ai is an AI-powered compliance assistant that provides guidance based on official documentation. Its responses do not constitute legal, professional, or certification advice. Always verify critical compliance decisions with a qualified C3PAO assessor, legal counsel, or compliance professional before acting on them.
How do I contact support?
Send us an email at support@askcmmc.ai. We typically respond within 24 hours. You can also submit bug reports or feature requests through the dedicated form at /report.
What browsers are supported?
AskCMMC.ai works on all modern browsers including Chrome, Firefox, Safari, and Edge. We recommend keeping your browser up to date for the best experience and strongest security. The interface uses modern CSS and JavaScript features that are supported in all recent browser releases.
Can my whole team use AskCMMC.ai?
Yes. Each team member signs in with their own SSO account and gets their own private workspace with separate chat history and query limits. Book a free consultation to discuss team and enterprise plans that include shared access for your entire organization.

Best Practices

Get the most out of AskCMMC.ai with these recommendations

Be Specific in Your Questions

The more specific your question, the more precise the answer. Instead of "Tell me about CMMC," try "What are the access control requirements for Level 2 that apply to remote workers?" Specificity helps the retrieval pipeline find the right source passages.

Use Follow-Up Questions

Start broad, then drill deeper. Ask "What is required for media protection at Level 1?" and follow up with "How should I implement that for USB drives?" Conversation context carries forward automatically.

Match the Mode to the Task

Use Flash for quick control lookups and definitions. Switch to Thinking for gap analysis, SSP drafts, cross-framework mapping, or anything that benefits from multi-agent collaboration.

Upload Clean Documents

Native or digital PDFs produce the best results. For scanned documents, ensure the scan quality is high and text is legible. Clear formatting helps the AI extract content more accurately.

Always Verify Source Citations

Every response includes numbered citations for a reason. Before making compliance decisions, review the cited sources to confirm the information matches your interpretation. The AI is a powerful research tool, but human judgment should always be the final authority.

Organize Your Research

Use separate chats for different topics. Pin important conversations, name them descriptively, and treat AskCMMC.ai like a compliance notebook to keep your work organized.