Free Self-Assessment
CMMC Readiness Check
How This Check Helps
CMMC asks defense contractors and subcontractors to prove they protect Federal Contract Information and Controlled Unclassified Information: the 15 Level 1 requirements for FCI, and the 110 NIST SP 800-171 requirements at Level 2 for CUI. This check covers the items that most often decide a contract, including your System Security Plan, multi-factor authentication, encryption and your SPRS score.
The rollout schedule changed during 2026. As of September 2026 the later phases are paused, and contracting officers can currently require Level 1 or Level 2 self-assessments. Confirm the requirement in each solicitation, and use your score to see how ready you are either way.
Answer 25 Questions
Choose Yes, No, Unknown or Not applicable for each question. It takes about 7 minutes, and you see your score as soon as you finish.
This self-assessment is educational. It is not an audit, a certification, legal advice or an insurance underwriting decision. Your answers stay in your browser and are not sent to Triton unless you contact us.
How Your Score Works
Each Yes earns points, weighted by how much the practice matters. No and Unknown earn none, because an assessor treats an undocumented practice as not met. Not applicable removes a question from your total.
A score of 85 percent or higher, with every high-priority item in place, is a strong result. High-priority items include requirements the CMMC rule does not allow on a Plan of Action and Milestones, and heavily weighted items in the DoD scoring method, such as multi-factor authentication and FIPS-validated encryption.
This check is not your official score. The official Level 2 self-assessment is scored with the DoD Assessment Methodology and entered in SPRS.
What Happens After You Finish
A strong score: congratulations. Your CMMC controls are where reviewers expect them to be. If you are happy with your current IT provider, they are doing their job. If you are not, Triton would be a good fit: we can take over without losing what you have built.
Gaps or a failing score: set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.
CMMC Readiness Check: Common Questions
Is this my official CMMC score?
No. It is a quick self-check. Your official self-assessment is scored against every NIST SP 800-171 requirement with the DoD Assessment Methodology and submitted in SPRS, and a Level 2 certification assessment is performed by an authorized C3PAO.
Do I need Level 1 or Level 2?
If you only handle Federal Contract Information, Level 1 applies. If you handle Controlled Unclassified Information, Level 2 applies. Your contract or solicitation states which level is required.
Is CMMC being enforced right now?
As of September 2026 the later rollout phases are paused, and contracting officers can currently require Level 1 or Level 2 self-assessments. Check each solicitation, because the requirement is set contract by contract.
Do you store my answers?
No. Your answers stay in your browser, and nothing is sent to Triton unless you choose to contact us.
Who should answer the questions?
The owner, the person responsible for contracts or security, or your IT provider. If you are not sure, choose Unknown: an assessor would treat it the same way.
What happens if my score is low?
Set up a meeting with Triton. We walk through your answers, confirm what is really in place and help you build your System Security Plan and a prioritized plan to close the gaps.
How Triton Delivers
The Sophos XDR Mandate
We deploy Sophos Firewalls as the non-negotiable perimeter standard. Any firm operating without synchronized endpoint protection is an insurance liability. Sophos Endpoint (EDR/XDR) is the mandatory internal security layer.
AWS Scalability
We deploy on AWS because downtime is not an option. When a critical system goes down, AWS support responds with enterprise urgency, not a ticket queue. Every dollar of downtime is a dollar your IT provider owes you an answer for.
The AI Autonomous Advantage
Axiom, Triton’s proprietary AI monitoring system, gives our engineers real-time visibility that off-the-shelf tools cannot replicate. It is not for sale, it is how we deliver.
Founded in 2001
25 Years of IT Expertise
Serving New England
5 Regional Offices + Dublin & BVI
Under 10 Minute Response
84th Percentile · MSPbots Verified
Sophos Silver · Microsoft Solutions Partner
Security & Cloud Partners
HIPAA · CMMC · SOC 2 · PCI
Multi-Framework Compliance
Let's Discuss Your IT Needs
Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.