Skip to main content

Free tool // CMMC self-assessment

CMMC Level 2readiness score.

Fifteen questions across the five highest-impact CMMC practice families. You get a Level 2 readiness score and every gap mapped to the NIST SP 800-171 practice it comes from, so you know what a C3PAO would open first.

3 minutes · No signup · No email

What this audit covers
01

Access Control & Authentication

NIST SP 800-171 family AC (Access Control) + IA (Identification and Authentication). Limit system access to authorized users, enforce least privilege, require multi-factor authentication for privileged and remote access. AC.L2-3.1.1 through 3.1.22.

02

Configuration Management & Maintenance

NIST SP 800-171 family CM (Configuration Management) + MA (Maintenance). Baseline configurations, change control, software whitelisting, controlled maintenance.

03

Incident Response & Audit Accountability

NIST SP 800-171 family IR (Incident Response) + AU (Audit and Accountability). Detect, report, contain, and recover from cyber incidents. Audit logs must be reviewed and retained.

04

Media Protection & Physical Security

NIST SP 800-171 family MP (Media Protection) + PE (Physical Protection). Protect digital and physical media containing CUI; control physical access to facilities housing CUI systems.

05

System & Information Integrity + Risk Assessment

NIST SP 800-171 family SI (System and Information Integrity) + RA (Risk Assessment). Identify and report system flaws; protect against malicious code; periodic risk assessments.

Free · No signup · Mapped to NIST SP 800-171 Rev. 3 control families