Free Self-Assessment

CMMC Readiness Check

How This Check Helps

CMMC asks defense contractors and subcontractors to prove they protect Federal Contract Information and Controlled Unclassified Information: the 15 Level 1 requirements for FCI, and the 110 NIST SP 800-171 requirements at Level 2 for CUI. This check covers the items that most often decide a contract, including your System Security Plan, multi-factor authentication, encryption and your SPRS score.

The rollout schedule changed during 2026. As of September 2026 the later phases are paused, and contracting officers can currently require Level 1 or Level 2 self-assessments. Confirm the requirement in each solicitation, and use your score to see how ready you are either way.

IT engineer checking a badge-access lock on a secured server room

Answer 25 Questions

Choose Yes, No, Unknown or Not applicable for each question. It takes about 7 minutes, and you see your score as soon as you finish.

Scoping & Data Identification

Have you identified every system that stores, processes, or transmits Controlled Unclassified Information (CUI) or Federal Contract Information (FCI)?

Scoping determines which CMMC level and which of the 110 requirements apply to your company.

Do you have a written System Security Plan (SSP) describing your network, systems, and how CUI is protected?

An SSP is required for Level 2 and can never be waived with a POA&M (CA.L2-3.12.4).

If any cloud service (email, file storage, backup) handles CUI, is it FedRAMP Moderate authorized or an approved equivalent?

DoD requires cloud providers touching CUI to meet the FedRAMP Moderate baseline or a validated equivalent.

Do your prime contract or subcontract terms state whether you only handle FCI, or also handle CUI?

FCI-only companies need Level 1 (the 15 FAR 52.204-21 requirements); any CUI handling triggers Level 2 (110 NIST SP 800-171 requirements).

Access Control & Identity

Do you limit system access to only the employees, contractors, and devices that need it for their job?

Basic access control is required for FCI (FAR 52.204-21(b)(1)(i)) and for CUI (AC.L1-3.1.1).

Do you require multi-factor authentication (password plus a phone app, token, or key) for remote and administrator access?

MFA (requirement 3.5.3) is a 5-point item in the DoD scoring method and cannot be skipped.

Does every employee log in with their own unique username, never a shared or generic login?

Unique identification (IA.L1-3.5.1) lets you trace every action on CUI systems to one person.

Do you control and monitor connections from outside your network, such as remote workers, home computers, or vendor VPNs?

External connections (AC.L2-3.1.20) can never be POA&M'd; it must be fully in place to pass.

System Protection & Monitoring

Do you keep logs of who accessed sensitive systems, and review those logs regularly for unusual activity?

Audit logging (requirement 3.3.1) is how you detect and prove what happened during an incident.

Do you have a process for approving and tracking changes to computer settings, patches, and new software?

Configuration management (requirement 3.4.1) stops unauthorized or risky changes from opening security gaps.

Is CUI encrypted with FIPS-validated encryption whenever it is stored on a device or sent over a network?

FIPS-validated cryptography (3.13.11) is a heavily weighted item, though the one 5-point control that may still be POA&M'd.

Do all computers and servers run anti-malware or antivirus software that updates itself automatically?

Malicious code protection (FAR 52.204-21(b)(1)(xiii)-(xiv)) blocks common ransomware and virus entry points.

Do you track USB drives, backup media, and other removable storage containing CUI, and wipe or destroy it before disposal?

Media protection (3.8.1, 3.8.3) prevents sensitive data from leaving on a lost or discarded device.

Incident Response & Physical Security

Do you have a written plan for detecting, reporting, and recovering from a cybersecurity incident?

An incident response plan (requirement 3.6.1) turns a breach into a managed event instead of chaos.

If CUI were exposed in a breach, could you report it to the Department of Defense within 72 hours?

DFARS 252.204-7012(c) requires rapid reporting to DIBNet; missing the window is itself a compliance failure.

Do you control physical access to your office, server room, or any area where CUI is stored, using locks or badges?

Physical access control (FAR 52.204-21(b)(1)(viii)) is required even at Level 1 and keeps unauthorized people out.

Do you log visitors and escort them while they are in areas containing CUI or sensitive systems?

Visitor escort and physical access logs (3.10.3, 3.10.4) can never be POA&M'd for Level 2 Conditional status.

Do you screen new employees before granting CUI access, and cut off access the same day someone leaves?

Personnel security (3.9.1, 3.9.2) closes the most common insider-risk window: former employees.

Training, Risk & Assessment

Do you train employees at least once a year on phishing, password safety, and handling sensitive information?

Security awareness training (3.2.1) is required, and it is one of the simplest controls to put in place and prove.

Have you assessed the risks and vulnerabilities to the systems that handle your CUI or FCI?

Risk assessment (3.11.1) is the basis for prioritizing which security gaps to fix first.

Have you completed and scored a full self-assessment against every required NIST SP 800-171 practice in the last 3 years?

A current assessment (3.12.1) is required, and a CMMC Level 2 self-assessment must be repeated at least every three years.

For any requirement you have not fully met, do you have a written Plan of Action & Milestones (POA&M) with target dates?

A POA&M is allowed for most Level 2 gaps only above an 80% score and never for 6 named requirements.

Reporting, Documentation & Supply Chain

Have you submitted your current NIST SP 800-171 self-assessment score to the Supplier Performance Risk System (SPRS)?

An SPRS score is a condition of contract award under the CMMC acquisition rule; no score, no award.

Do you submit an annual affirmation in SPRS confirming that you still meet your CMMC requirements?

A senior official must affirm compliance after every assessment and every year after that.

Do your subcontracts require any subcontractor who will see CUI to meet the same CMMC/NIST SP 800-171 requirements?

Flow-down (DFARS 252.204-7012(m)) makes you responsible for your supply chain's cyber posture, not just your own.

This self-assessment is educational. It is not an audit, a certification, legal advice or an insurance underwriting decision. Your answers stay in your browser and are not sent to Triton unless you contact us.

How Your Score Works

Each Yes earns points, weighted by how much the practice matters. No and Unknown earn none, because an assessor treats an undocumented practice as not met. Not applicable removes a question from your total.

A score of 85 percent or higher, with every high-priority item in place, is a strong result. High-priority items include requirements the CMMC rule does not allow on a Plan of Action and Milestones, and heavily weighted items in the DoD scoring method, such as multi-factor authentication and FIPS-validated encryption.

This check is not your official score. The official Level 2 self-assessment is scored with the DoD Assessment Methodology and entered in SPRS.

What Happens After You Finish

A strong score: congratulations. Your CMMC controls are where reviewers expect them to be. If you are happy with your current IT provider, they are doing their job. If you are not, Triton would be a good fit: we can take over without losing what you have built.

Gaps or a failing score: set up a meeting with Triton. We walk through your answers, confirm what is really in place and give you a prioritized plan to close the gaps.

CMMC Readiness Check: Common Questions

No. It is a quick self-check. Your official self-assessment is scored against every NIST SP 800-171 requirement with the DoD Assessment Methodology and submitted in SPRS, and a Level 2 certification assessment is performed by an authorized C3PAO.

If you only handle Federal Contract Information, Level 1 applies. If you handle Controlled Unclassified Information, Level 2 applies. Your contract or solicitation states which level is required.

As of September 2026 the later rollout phases are paused, and contracting officers can currently require Level 1 or Level 2 self-assessments. Check each solicitation, because the requirement is set contract by contract.

No. Your answers stay in your browser, and nothing is sent to Triton unless you choose to contact us.

The owner, the person responsible for contracts or security, or your IT provider. If you are not sure, choose Unknown: an assessor would treat it the same way.

Set up a meeting with Triton. We walk through your answers, confirm what is really in place and help you build your System Security Plan and a prioritized plan to close the gaps.

How Triton Delivers

The Sophos XDR Mandate

We deploy Sophos Firewalls as the non-negotiable perimeter standard. Any firm operating without synchronized endpoint protection is an insurance liability. Sophos Endpoint (EDR/XDR) is the mandatory internal security layer.

AWS Scalability

We deploy on AWS because downtime is not an option. When a critical system goes down, AWS support responds with enterprise urgency, not a ticket queue. Every dollar of downtime is a dollar your IT provider owes you an answer for.

The AI Autonomous Advantage

Axiom, Triton’s proprietary AI monitoring system, gives our engineers real-time visibility that off-the-shelf tools cannot replicate. It is not for sale, it is how we deliver.

Founded in 2001

25 Years of IT Expertise

Serving New England

5 Regional Offices + Dublin & BVI

Under 10 Minute Response

84th Percentile · MSPbots Verified

Sophos Silver · Microsoft Solutions Partner

Security & Cloud Partners

HIPAA · CMMC · SOC 2 · PCI

Multi-Framework Compliance

Let's Discuss Your IT Needs

Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.

Triton Technologies support engineer at workstation