🛡️ CMMC 2.0 Assessment Tool
📊 Dashboard
📋 Questionnaire
Certification
Scope
🔍 Assessment
📝 POA&Ms
🖥️ Inventory
📥 Export CSV
📋 Assessment Questionnaire
new org
Pre-Assessment Questionnaire Score:
0
/ 107
Organization Information
Organization Name *
Point of Contact (POC) Name
POC Title
POC Email
POC Phone
CAGE Code
System Description
this is test only
Organization Scope & Size
Physical locations handling CUI or FCI
Total employees and contractors
Authorized to access Government Information
Account Inventory
User Accounts
Local Administrator Accounts
Application Accounts
Service Accounts
Domain Administrator Accounts
Other Accounts
Security Posture Questions
Do you allow employees to access systems from personal devices (BYOD)?
No
Yes
Can employees work remotely? If so, with what equipment?
Select...
No remote work
Yes — Organization-provided equipment only
Yes — Personal equipment allowed
Yes — Both org-provided and personal
Do employees periodically receive security awareness training?
No
Yes
Is staff trained to recognize and properly handle CUI/FCI?
No
Yes
Comprehensive list of sensitive information types?
No
Yes
Comprehensive hardware inventory?
No
Yes
Comprehensive software inventory?
No
Yes
Comprehensive cloud resources inventory?
No
Yes
Do you have a network diagram?
No
Yes
Can you show how/where CUI flows within your organization?
No
Yes
Employee roles defined with information category access?
No
Yes
Do all users have local admin privileges?
Yes
No
Multifactor Authentication (MFA)
Does your organization require MFA for:
Remote Administration
No
Yes
All User Remote Access
No
Yes
All Administrator Logins
No
Yes
All User Logins
No
Yes
Admin Access to Cloud Resources
No
Yes
User Access to Cloud Resources
No
Yes
Infrastructure & Incident Response
Wi-Fi deployment?
No Wi-Fi
Yes — Part of corporate network
Yes — Separate guest network
Do you have an incident response plan?
No
Yes
Are IR roles and responsibilities identified?
No
Yes
Has the IR plan been tested in the past 12 months?
No
Yes
Prior self-assessment against NIST SP 800-171?
No
Yes — Requirements only
Yes — With 171A objectives
Comprehensive IT/cybersecurity policies and procedures?
No
Yes
💾 Save Questionnaire
Cancel