CMMC Level 2 Readiness

    How ready are you for CMMC Level 2?

    Answer 48 practice-level questions across the 14 NIST SP 800-171 security domains. Enter your email to receive an instant scorecard with domain breakdowns and prioritized gaps.

    NIST 800-171 aligned

    Questions map directly to the 14 CMMC Level 2 security domains and key practices.

    Instant gap analysis

    See domain-level RAG scores and your top five priority remediation areas.

    Results delivered

    Provide your email to receive and share the tailored readiness report.

    Tell us where to send your results

    Enter a business email address so we can deliver your personalized CMMC readiness summary.

    We'll only use this to share your scorecard.

    Access Control (AC)

    Max 11 pts

    Limit system access to authorized users, processes, and devices, and restrict the types of transactions and functions that authorized users are permitted to execute.

    4 pts

    Yes = full points • No = 0 points.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Awareness & Training (AT)

    Max 8 pts

    Ensure that managers and users of organizational systems are aware of the security risks and are trained to carry out their information security responsibilities.

    3 pts

    Yes = full points • No = 0 points.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    Audit & Accountability (AU)

    Max 12 pts

    Create, protect, and retain system audit logs and records to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

    4 pts

    Yes = full points • No = 0 points.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Configuration Management (CM)

    Max 11 pts

    Establish and maintain baseline configurations and inventories of organizational systems throughout their system development life cycles.

    3 pts

    Yes = full points • No = 0 points.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Identification & Authentication (IA)

    Max 9 pts

    Identify and authenticate users, devices, and processes as a prerequisite to allowing access to organizational systems.

    4 pts

    Yes = full points • No = 0 points.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Incident Response (IR)

    Max 10 pts

    Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

    4 pts

    Yes = full points • No = 0 points.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    3 pts

    Yes = full points • No = 0 points.

    Maintenance (MA)

    Max 7 pts

    Perform timely maintenance on organizational systems and provide effective controls on maintenance tools, techniques, mechanisms, and personnel.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    2 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Media Protection (MP)

    Max 10 pts

    Protect system media containing CUI, both paper and digital. Control access to, and disposal of, media containing CUI.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Personnel Security (PS)

    Max 8 pts

    Screen individuals prior to authorizing access to systems containing CUI and ensure CUI is protected during and after personnel actions.

    3 pts

    Yes = full points • No = 0 points.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Physical Protection (PE)

    Max 7 pts

    Limit physical access to organizational systems, equipment, and operating environments to authorized individuals.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    Risk Assessment (RA)

    Max 9 pts

    Periodically assess the risk to organizational operations, organizational assets, and individuals resulting from the operation of organizational systems.

    4 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    2 pts

    Yes = full points • No = 0 points.

    Security Assessment (CA)

    Max 9 pts

    Periodically assess security controls to determine if they are effective in their application and develop and implement plans of action to correct deficiencies.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    3 pts

    Yes = full points • No = 0 points.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    System & Communications Protection (SC)

    Max 13 pts

    Monitor, control, and protect communications at the external and key internal boundaries of organizational systems.

    4 pts

    Yes = full points • No = 0 points.

    4 pts

    Yes = full points • No = 0 points.

    3 pts

    Yes = full points • No = 0 points.

    2 pts

    Yes = full points • No = 0 points.

    System & Information Integrity (SI)

    Max 13 pts

    Identify, report, and correct system flaws in a timely manner. Protect systems from malicious code and monitor system security alerts.

    4 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    4 pts

    Yes = full points • No = 0 points.

    3 pts

    Rate maturity from 1 (ad hoc) to 5 (optimized & automated).

    Points earned = (selected level ÷ 5) × weight.

    2 pts

    Yes = full points • No = 0 points.

    How scoring works

    Each practice is weighted by risk impact aligned to NIST SP 800-171 controls.

    Answer every question with either Yes/No or a 1–5 maturity level. Your score automatically updates once you submit the form.

    • Yes earns the full weight. No earns 0.
    • Maturity items use (selected level ÷ 5) × weight.
    • Domain and overall results include a red / amber / green (RAG) status.

    Domain weight summary

    Access Control (AC)11 pts • 4 questions
    Awareness & Training (AT)8 pts • 3 questions
    Audit & Accountability (AU)12 pts • 4 questions
    Configuration Management (CM)11 pts • 4 questions
    Identification & Authentication (IA)9 pts • 3 questions
    Incident Response (IR)10 pts • 3 questions
    Maintenance (MA)7 pts • 3 questions
    Media Protection (MP)10 pts • 4 questions
    Personnel Security (PS)8 pts • 3 questions
    Physical Protection (PE)7 pts • 3 questions
    Risk Assessment (RA)9 pts • 3 questions
    Security Assessment (CA)9 pts • 3 questions
    System & Communications Protection (SC)13 pts • 4 questions
    System & Information Integrity (SI)13 pts • 4 questions