Before we start
What kind of government information does your company handle?
This decides which CMMC level you're likely to need.
Federal Contract Information (FCI) only Contract information that isn't public, such as statements of work, pricing and schedules.
Controlled Unclassified Information (CUI) Information marked CUI, including technical data, drawings and export-controlled information.
Not sure We'll score you against Level 2, which most DoW contractors handling technical data need.
Access Control
Levels 1 & 2
Question 1 of 18: Is access to your systems limited to authorized people and devices, with each person able to do only what their job requires?
Yes
Partly
No
Not sure
Access Control
Levels 1 & 2
Question 2 of 18: Do you control connections to outside systems, such as personal devices and cloud services, and check that nothing non-public is posted on public websites?
Yes
Partly
No
Not sure
Identification & Authentication
Levels 1 & 2
Question 3 of 18: Does every person have their own account (no shared logins), and must they sign in before using company systems?
Yes
Partly
No
Not sure
Identification & Authentication
Level 2
Question 4 of 18: Is multifactor authentication required for administrator accounts and for all network and remote access?
Yes
Partly
No
Not sure
Media Protection
Levels 1 & 2
Question 5 of 18: Do you wipe or destroy drives, laptops and paper holding contract information before they’re thrown away or reused?
Yes
Partly
No
Not sure
Physical Protection
Levels 1 & 2
Question 6 of 18: Are offices and equipment protected from unauthorized physical access, with visitors escorted and logged?
Yes
Partly
No
Not sure
System & Communications Protection
Levels 1 & 2
Question 7 of 18: Is your network protected at its edge by a firewall, with public-facing systems kept separate from your internal network?
Yes
Partly
No
Not sure
System & Information Integrity
Levels 1 & 2
Question 8 of 18: Do you install security updates promptly, and run up-to-date anti-malware that scans files and downloads?
Yes
Partly
No
Not sure
Awareness & Training
Level 2
Question 9 of 18: Do all staff complete security awareness training, including spotting insider threats, with extra training for administrators?
Yes
Partly
No
Not sure
Audit & Accountability
Level 2
Question 10 of 18: Do you keep audit logs that trace actions to individual users, protect them from tampering, and review them regularly?
Yes
Partly
No
Not sure
Configuration Management
Level 2
Question 11 of 18: Do you keep an inventory of your hardware and software, with standard secure configurations and a process for approving changes?
Yes
Partly
No
Not sure
Incident Response
Level 2
Question 12 of 18: Do you have a tested incident response plan, and could you report a cyber incident to the DoW within 72 hours?
Yes
Partly
No
Not sure
Maintenance
Level 2
Question 13 of 18: Is system maintenance controlled and recorded, with multifactor authentication for remote maintenance sessions?
Yes
Partly
No
Not sure
Personnel Security
Level 2
Question 14 of 18: Are people screened before they can access CUI, and is their access removed promptly when they leave or change roles?
Yes
Partly
No
Not sure
Risk Assessment
Level 2
Question 15 of 18: Do you assess risk and scan for vulnerabilities on a regular schedule, and fix what you find?
Yes
Partly
No
Not sure
Security Assessment
Level 2
Question 16 of 18: Do you have a current System Security Plan (SSP) and a plan of action for closing any gaps?
Yes
Partly
No
Not sure
System & Communications Protection
Level 2
Question 17 of 18: Is CUI encrypted with FIPS-validated cryptography when it’s sent over networks and when it’s stored on laptops and mobile devices?
Yes
Partly
No
Not sure
Security Assessment
Level 2
Question 18 of 18: Have you identified where FCI and CUI are stored and processed, and posted a current NIST SP 800-171 score in SPRS?
Yes
Partly
No
Not sure
%
Leave your details to see your full report: the gaps behind your score and what to do about each one.
Where should we send your report?
Your report opens straight away, with a PDF to download. A CDT compliance lead may follow up to talk through your results.
We use your details only to send your results and follow up. See our privacy policy .