IronHelm by TopaTek Private beta

CMMC compliance for defense contractors, without the consultant bill.

IronHelm walks a small contractor from "what is CUI" to a certification-ready package: scoping, assessment with a live SPRS score, step-by-step fixes for your tools, generated policies and a System Security Plan, evidence that checks itself, training, and the readiness checks an assessor runs. Built by TopaTek from the tools we use in our own CMMC engagements.

Beta testers use the full Professional plan free during the beta and get a launch discount afterward.

The IronHelm dashboard: SPRS score, requirements met, open POA&M items, evidence, training, and the five-step path to certification

Five steps. The app knows which one you are on.

Every page tells you what to do next, why it matters, and what an assessor will ask to see.

1Scope

Six questions decide Level 1 or 2 and write your system boundary.

Scope step
2Assess

110 requirements, 320 objectives, plain-language guidance, live SPRS score.

Assess step
3Fix

Every gap becomes a POA&M item with a step-by-step playbook for your tools.

Fix step
4Prove

66 documents, an AI-drafted System Security Plan, and an evidence checklist.

Prove step
5Certify

Readiness gates a C3PAO checks, then an evidence room for the assessor.

Certify step

What is inside

An assessment that tells you where you stand, in points

Work through the objectives the assessor will actually test. The SPRS score updates as you go, and the what-if panel shows the fewest fixes to reach 110.

  • All 110 requirements and 320 assessment objectives
  • Plain-language explanation and steps on every objective
  • Assign owners, track evidence, and see who changed what
An assessment objective page

Playbooks that replace the consultant's to-do list

Fifty-two playbooks for the requirements small contractors miss most. Each one names the exact settings in Microsoft 365 or Google Workspace, the evidence to capture, and the question the assessor will ask.

  • Your open gaps first, sorted by the points they cost you
  • Microsoft 365, Google Workspace, and on-premises tracks
  • Common mistakes that cost people points at assessment
The playbooks list

Documents and a System Security Plan you do not write from scratch

Answer the profile once. Sixty-six policies, procedures, plans, and forms fill themselves in, and the AI drafts an implementation statement for every objective for you to approve.

  • Policies, procedures, plans, and forms generated from your answers
  • One-click SSP drafting with accept or discard per statement
  • Formal approvals and acknowledgment campaigns with records
The documents page

Evidence that checks itself

Connect Microsoft 365 read-only and the platform verifies MFA, admin roles, guest accounts, device compliance, and logging, then records the dated results as evidence. Ask the AI whether an artifact would satisfy an assessor before the assessor sees it.

  • Weekly automated checks with drift alerts
  • AI review of screenshots, exports, and policies
  • An evidence checklist per requirement with pointers and expiry
The connectors page

Ready for the assessor, and for the assessor's questions

Readiness gates mirror what a C3PAO looks for. When they are green, give the assessor a read-only evidence room and rehearse the interviews with an AI that plays the assessor for each role.

  • Assessment package, SSP, and POA&M exports in one click
  • Assessor evidence room with requests that become tasks
  • Mock interviews for leadership, IT, HR, facilities, and staff
The certification page

Compliance that stays compliant

A calendar of the reviews, tests, and training an assessor expects to see repeated, with owners, reminders, and a Monday digest that says what needs attention this week.

  • Recurring compliance calendar with 18 activities
  • Security awareness training with quizzes and records
  • Incident log with the 72-hour DFARS reporting countdown
The compliance calendar

Built for

Defense contractors

10 to 200 people, handling FCI or CUI, who need Level 1 or Level 2 and do not have a security team. Everything above, self-serve, with expert help from TopaTek available when you want it.

Consultants and MSPs

Run every client in its own workspace with the same tools, deliverables in Word and Excel, a review queue, and white-label ready exports. Three workspaces included.

Prime contractors

See where each supplier stands with a readiness statement they share by invite code. Aggregates only, never their workspace.

Pricing at launch

Beta testers pay nothing during the beta. A typical Level 2 consulting engagement costs $20,000 to $60,000; a year of Professional is $5,990.

Starter

$199 per month, annual $1,990

For contractors that handle FCI only and need CMMC Level 1.

  • Level 1 self-assessment (17 practices)
  • POA&M, tasks, reminders, compliance calendar
  • Evidence repository (2 GB) and checklist
  • Policy and procedure generation
  • Remediation playbooks (general steps)
  • Training courses with records
  • Sign in with Microsoft, 3 seats

Consultant

$1,199 per month, annual $11,990

For consultants and MSPs running CMMC programs for several clients.

  • Everything in Professional for every client
  • Continuous monitoring included for every workspace
  • 3 client workspaces included, $149 per additional
  • Deliverables: Excel, Word report, SSP, POA&M, statements
  • Expert review queue and services
  • White-label ready exports, 25 seats, 50 GB

Employee seats for training-only staff ($6), extra storage ($29), continuous monitoring ($149), and expert services (spot-checks, full reviews, mock audits, done-for-you documents) are added inside the app. Prices in USD.

Questions we get

Do I still need a consultant?

Most companies will not. IronHelm covers scoping, assessment, remediation instructions, documents, evidence, training, and assessor preparation. If you want a human to review your work or run a mock audit, those are one-time services inside the app, priced per engagement rather than by the hour.

Where does my data live, and can I upload CUI?

Data is stored in the United States. The platform is designed to hold evidence that a control exists, never CUI itself, so it stays outside your CUI boundary and needs no FedRAMP authorization. The trust page and the shared responsibility statement inside the app explain exactly what we do and what stays yours.

What does the beta include?

The full Professional plan free for the length of the beta, a launch discount afterward, and a direct line to the people building it. Beta testers shape what we build next.

Level 1 or Level 2?

If your contracts include DFARS 252.204-7012 or mention CUI, ITAR, or export-controlled data, you need Level 2. FCI only means Level 1. The scoping wizard asks the questions that decide it.

How long does it take?

Assessment takes most companies two to four weeks of part-time work. Remediation depends on the gaps; the playbooks estimate hours and typical cost for each one, and the dashboard tracks the total remaining.

Does it use AI on my data?

Only when you ask it to, and names and identifiers are replaced with placeholders before any text leaves our servers. You can bring your own API key so usage bills to your account, and nothing is ever used to train models.

Get early access

Beta testing opens soon. Beta testers use the full Professional plan free during the beta, get a launch discount, and shape what we build next. Consultants and MSPs are welcome; there is a multi-client workspace for you.

One email when the beta opens, one when we launch. Nothing else.

By signing up you agree to receive two emails from TopaTek about IronHelm. No CUI is required to use the platform; do not send CUI by email.