sha3:e75aa5842a4e8b80b384c54d1874f273f9561ba2e81948db3ab103a52a3a16a6IntactCMMC LEVEL 2 / SELF-SERVE ASSESSMENT
Ten questions, before the assessor asks them.
This assessment asks ten questions across ten control areas and returns an aggregate CMMC Level 2 readiness score with a per-family breakdown. Five minutes, no cost. Answers stay in your browser; only your email and score are sent if you request the report. It is not an assessment of record; the C3PAO remains the authority.
8fe60399d98f142232838e78f9fa6579467a34b96b7eecc44aedcb32ca81a9dfprev:8059c733d3dbTen questions, scored zero to three
Each question has four answers, scored 3 to 0. The aggregate is out of 30. Move through the questions in order; you can go back. The result appears once all ten are answered.
ACAccess Control
Do you enforce multi-factor authentication (MFA) for all users accessing CUI systems?
7d2514dd2658b55d87a03d0415b65e33dcb8059d26fa832ee4d619ae7c45d9ebprev:8fe60399d98fWhat the score means
The aggregate score falls into one of three bands. The band and its reading are printed here, before you answer, so the scale cannot move after the fact. Control areas covered: AC, SC, AU, CM, IR, RA, CA, PS, PL, PE.
- score.operational
- OPERATIONAL: 80 percent and above. Your organization shows strong CMMC readiness. A few targeted improvements could get you assessment-ready.
- score.partial
- PARTIAL: 50 to 79 percent. You have foundational practices in place but significant gaps remain. A structured remediation plan is critical before engaging a C3PAO.
- score.at-risk
- AT RISK: Below 50 percent. Your organization has substantial gaps in its NIST 800-171 baseline. Phase II is paused, but Phase I self-assessments, DFARS safeguards, and selected government reviews remain active.
2dd587e9772c5262ce0e88aef18b9f021207cba5d291c13f54f58ee3d656dfd9prev:7d2514dd2658What this score is not
85be597ebc56fccfd7053bef3ec655d73075a3f96dbd5de81bde66fdde1e44e1prev:2dd587e9772cFrom a score to a record
To go from a score to a record: work the 110-control checklist requirement by requirement, then read how the evidence package is handed to the assessor. For product access in your own tenant, submit a separate request so we can review your environment and agree on scope and onboarding. Completing this public questionnaire does not create an account or grant product access. Request Access.
- cmmc.glossary
- The glossary: terms as assessors use them.
e75aa5842a4e8b80b384c54d1874f273f9561ba2e81948db3ab103a52a3a16a6prev:85be597ebc56Questions about the assessment
- Q-01
Is the CMMC readiness assessment free?
Yes. Ten questions, five minutes, no cost and no account. The full report is emailed only if you ask for it.
- Q-02
Does the score certify CMMC Level 2 readiness?
No. It is a self-assessment across ten control areas. CMMC Level 2 certification assessments are performed by a C3PAO against all 110 requirements; PolicyCortex is not a C3PAO and does not certify anything.
- Q-03
What happens to my answers?
They stay in your browser. If you request the report, your email address and the aggregate score are sent to PolicyCortex; the individual answers are not.
- Q-04
What should I do after the assessment?
Work the 110-control checklist requirement by requirement, then read how the evidence package is handed to the assessor. For product access in your own tenant, submit a separate request so we can review your environment and agree on scope and onboarding. Completing this public questionnaire does not create an account or grant product access.
The score is a start. The evidence is the point.