Skip to content
Cyber Defense Technologies

Free tool · About 5 minutes

How ready are you for CMMC?

Answer 18 plain-language questions based on NIST SP 800-171 and the FAR basic safeguarding requirements. You'll get an estimated readiness score, your likely gaps and practical next steps.

Before we start

What kind of government information does your company handle?

This decides which CMMC level you're likely to need.

Access Control Levels 1 & 2

Question 1 of 18: Is access to your systems limited to authorized people and devices, with each person able to do only what their job requires?

Access Control Levels 1 & 2

Question 2 of 18: Do you control connections to outside systems, such as personal devices and cloud services, and check that nothing non-public is posted on public websites?

Identification & Authentication Levels 1 & 2

Question 3 of 18: Does every person have their own account (no shared logins), and must they sign in before using company systems?

Identification & Authentication Level 2

Question 4 of 18: Is multifactor authentication required for administrator accounts and for all network and remote access?

Media Protection Levels 1 & 2

Question 5 of 18: Do you wipe or destroy drives, laptops and paper holding contract information before they’re thrown away or reused?

Physical Protection Levels 1 & 2

Question 6 of 18: Are offices and equipment protected from unauthorized physical access, with visitors escorted and logged?

System & Communications Protection Levels 1 & 2

Question 7 of 18: Is your network protected at its edge by a firewall, with public-facing systems kept separate from your internal network?

System & Information Integrity Levels 1 & 2

Question 8 of 18: Do you install security updates promptly, and run up-to-date anti-malware that scans files and downloads?

Awareness & Training Level 2

Question 9 of 18: Do all staff complete security awareness training, including spotting insider threats, with extra training for administrators?

Audit & Accountability Level 2

Question 10 of 18: Do you keep audit logs that trace actions to individual users, protect them from tampering, and review them regularly?

Configuration Management Level 2

Question 11 of 18: Do you keep an inventory of your hardware and software, with standard secure configurations and a process for approving changes?

Incident Response Level 2

Question 12 of 18: Do you have a tested incident response plan, and could you report a cyber incident to the DoW within 72 hours?

Maintenance Level 2

Question 13 of 18: Is system maintenance controlled and recorded, with multifactor authentication for remote maintenance sessions?

Personnel Security Level 2

Question 14 of 18: Are people screened before they can access CUI, and is their access removed promptly when they leave or change roles?

Risk Assessment Level 2

Question 15 of 18: Do you assess risk and scan for vulnerabilities on a regular schedule, and fix what you find?

Security Assessment Level 2

Question 16 of 18: Do you have a current System Security Plan (SSP) and a plan of action for closing any gaps?

System & Communications Protection Level 2

Question 17 of 18: Is CUI encrypted with FIPS-validated cryptography when it’s sent over networks and when it’s stored on laptops and mobile devices?

Security Assessment Level 2

Question 18 of 18: Have you identified where FCI and CUI are stored and processed, and posted a current NIST SP 800-171 score in SPRS?

%

Leave your details to see your full report: the gaps behind your score and what to do about each one.

Where should we send your report?

Your report opens straight away, with a PDF to download. A CDT compliance lead may follow up to talk through your results.

We use your details only to send your results and follow up. See our privacy policy.