ScopeHunter · Product
CMMC compliance software for small defense contractors
Built by a service-disabled-veteran-owned shop that had to pass CMMC itself and refused to pay enterprise-GRC prices for a spreadsheet with a login page.
The problem with your current options
Small contractors get two offers today: a spreadsheet of 110 rows you update by hand until it drifts from reality, or an enterprise GRC platform priced for the primes that still expects you to type every status in yourself. Both produce the same artifact — a self-assessment that says what someone hoped, submitted to SPRS under the False Claims Act.
What ScopeHunter does differently
| Instead of… | You get |
|---|---|
| Typing control statuses | Evidence that writes them. A Salt-based hardening formula configures your Linux and Windows hosts against 800-171 and reports what it verified — 137 distinct checks on our own systems. Cloud integration reads disk encryption, firewall exposure, and secret-manager posture straight from GCP. Statuses derive from checks; the transition log records every change and what caused it. |
| Guessing what a control means | Plain-language guidance on every control — what the terms mean (mobile code is not phones), what an assessor checks, when N/A is legitimate and when it silently costs you SPRS points. |
| A score you assembled by hand | The DoD Assessment Methodology computed for you — Annex A weights, the five conditional N/As, the honest treatment of never-assessed requirements. Ours is 43 and we publish it. |
| A POA&M you forgot to update | A register that notices. Generated from your actual deductions, grouped by points recoverable, and flagged item-by-item when live evidence proves a control met — closing stays your click, noticing stops being your job. |
| An SSP written the weekend before | A document assembled from the same data — boundary, inheritance, per-control statements with provenance — that refuses a clean face when hosts drift from what it declares, and freezes only when you attest it. |
| Vulnerability feeds | Findings. 143,000+ vendor advisories mirrored and correlated against the packages your hosts actually run: "2 to patch, 1 reboot pending," with a remediation ledger recording what was exposed, for how long, and how it closed. |
What it will not pretend
ScopeHunter is not a C3PAO and does not certify anyone. It is not an ASV. It cannot make a policy true or a gap disappear — several controls are organizational and stay yours to implement. Features are labeled by maturity on the status page, prototypes included. The product''s job is to make your honest state visible and your evidence durable; the compliance is still yours.
Also speaks SOC 2, ISO 27001, and PCI DSS
The same evidence scores across frameworks: a CMMC control proven by a host check carries its weight into SOC 2 and ISO 27001 through a maintained crosswalk, and PCI DSS SAQ A ships with the same per-requirement guidance. One set of facts, four honest scorecards.
Start where we started
Create an account, connect a system, and get a number you can defend. It will likely be lower than your current spreadsheet says. So was ours.