---
title: "Self-Serve CMMC Level 2 Assessment"
description: "A free ten-question CMMC Level 2 readiness self-assessment against NIST SP 800-171: aggregate score, per-family breakdown, and the full report by email."
url: https://policycortex.com/cmmc-assessment
sealed: 2026-09-02
amended: 2026-09-05
register: cmmc-assessment
records: 5
digest: sha3:e75aa5842a4e8b80b384c54d1874f273f9561ba2e81948db3ab103a52a3a16a6
---

# Ten questions, before the assessor asks them.

CMMC LEVEL 2 / SELF-SERVE ASSESSMENT

This assessment asks ten questions across ten control areas and returns an aggregate CMMC Level 2 readiness score with a per-family breakdown. Five minutes, no cost. Answers stay in your browser; only your email and score are sent if you request the report. It is not an assessment of record; the C3PAO remains the authority.

[Start the assessment](#assessment) · [The 110-control checklist](https://policycortex.com/cmmc-checklist)

## Ten questions, scored zero to three

Each question has four answers, scored 3 to 0. The aggregate is out of 30. Move through the questions in order; you can go back. The result appears once all ten are answered.

1. **Do you enforce multi-factor authentication (MFA) for all users accessing CUI systems?** (AC Access Control): Yes, for all users and all access methods (3) / Yes, but only for remote access (2) / Partially: some systems require MFA (1) / No MFA enforcement (0)
2. **Is CUI encrypted both at rest and in transit across your cloud environment?** (SC System and Communications Protection): Yes, using FIPS 140-2 validated encryption everywhere (3) / Encrypted in transit, but not consistently at rest (2) / Some encryption, but no formal standard enforced (1) / Unsure or no encryption policy (0)
3. **Do you collect, retain, and review audit logs for all CUI-relevant systems?** (AU Audit and Accountability): Yes, centralized logging with automated alerting and regular review (3) / Logs collected centrally but reviewed only during incidents (2) / Some logging in place, but not centralized (1) / Minimal or no audit logging (0)
4. **Do you maintain and enforce baseline configurations for all cloud resources?** (CM Configuration Management): Yes, with automated drift detection and remediation (3) / Baselines documented but checked manually or periodically (2) / Some standards exist but inconsistently applied (1) / No formal baseline configurations (0)
5. **Do you have a documented and tested incident response plan for CUI breaches?** (IR Incident Response): Yes, documented, tested annually, and includes DFARS 7012 72-hour reporting (3) / Documented but not tested within the past year (2) / Informal process exists but not documented (1) / No incident response plan (0)
6. **How often do you perform risk assessments on systems that process CUI?** (RA Risk Assessment): Continuously or quarterly with documented methodology (3) / Annually (2) / Only when required by a contract or audit (1) / Never performed a formal risk assessment (0)
7. **Do you conduct regular security assessments and maintain a POA&M (Plan of Action and Milestones)?** (CA Security Assessment): Yes, ongoing assessments with active POA&M tracking (3) / Annual assessment with POA&M, but not actively tracked (2) / One-time assessment done, no active POA&M (1) / No security assessments or POA&M (0)
8. **Do all personnel with access to CUI complete security awareness training?** (PS Personnel Security): Yes, role-based training with annual refreshers and completion tracking (3) / Annual general security training for all employees (2) / Training available but not mandatory or tracked (1) / No security awareness training program (0)
9. **Do you have a System Security Plan (SSP) that maps to all 110 NIST 800-171 controls?** (PL System Security Plan): Yes, current SSP covering all 110 controls with evidence (3) / SSP exists but does not cover all controls or is outdated (2) / Partial documentation exists but no formal SSP (1) / No SSP (0)
10. **Are your cloud environments hosted in FedRAMP-authorized or GovCloud regions?** (PE Physical and Environmental Protection): Yes, all CUI workloads in FedRAMP High or GovCloud (3) / Some workloads in GovCloud, others in commercial regions (2) / Planning to migrate but currently in commercial cloud (1) / All in commercial cloud with no migration plan (0)

## What the score means

The aggregate score falls into one of three bands. The band and its reading are printed here, before you answer, so the scale cannot move after the fact. Control areas covered: AC, SC, AU, CM, IR, RA, CA, PS, PL, PE.

- **score.operational**: OPERATIONAL: 80 percent and above. Your organization shows strong CMMC readiness. A few targeted improvements could get you assessment-ready.
- **score.partial**: PARTIAL: 50 to 79 percent. You have foundational practices in place but significant gaps remain. A structured remediation plan is critical before engaging a C3PAO.
- **score.at-risk**: AT RISK: Below 50 percent. Your organization has substantial gaps in its NIST 800-171 baseline. Phase II is paused, but Phase I self-assessments, DFARS safeguards, and selected government reviews remain active.

## What this score is not

**Stated limit.** PolicyCortex is not a C3PAO and does not certify anything. This score is a self-assessment across ten questions; CMMC Level 2 certification assessments are performed by a C3PAO against all 110 requirements of NIST SP 800-171. The record makes verification cheaper; it does not guarantee any outcome.

## From a score to a record

To go from a score to a record: work the 110-control checklist requirement by requirement, then read how the evidence package is handed to the assessor. For product access in your own tenant, submit a separate request so we can review your environment and agree on scope and onboarding. Completing this public questionnaire does not create an account or grant product access. [Request Access](https://app.policycortex.com/auth?mode=request-access).

- **cmmc.checklist**: [The 110-control checklist: every requirement, by control family.](https://policycortex.com/cmmc-checklist)
- **cmmc.handoff**: [eMASS and C3PAO handoff package: what the assessor receives.](https://policycortex.com/cmmc/emass-c3pao-handoff)
- **cmmc.glossary**: [The glossary: terms as assessors use them.](https://policycortex.com/cmmc/glossary)
- **federal**: [The federal register: ATO, FedRAMP 20x, 800-53, 800-171, CMMC.](https://policycortex.com/federal)

## Questions about the assessment

**Q: Is the CMMC readiness assessment free?**
A: Yes. Ten questions, five minutes, no cost and no account. The full report is emailed only if you ask for it.

**Q: Does the score certify CMMC Level 2 readiness?**
A: No. It is a self-assessment across ten control areas. CMMC Level 2 certification assessments are performed by a C3PAO against all 110 requirements; PolicyCortex is not a C3PAO and does not certify anything.

**Q: What happens to my answers?**
A: They stay in your browser. If you request the report, your email address and the aggregate score are sent to PolicyCortex; the individual answers are not.

**Q: What should I do after the assessment?**
A: Work the 110-control checklist requirement by requirement, then read how the evidence package is handed to the assessor. For product access in your own tenant, submit a separate request so we can review your environment and agree on scope and onboarding. Completing this public questionnaire does not create an account or grant product access.

The score is a start. The evidence is the point. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | THE ASSESSMENT | 8fe60399d98f | 8059c733d3db |
| REC 0001 | WHAT THE SCORE MEANS | 7d2514dd2658 | 8fe60399d98f |
| REC 0002 | STATED LIMIT | 2dd587e9772c | 7d2514dd2658 |
| REC 0003 | NEXT RECORDS | 85be597ebc56 | 2dd587e9772c |
| REC 0004 | FAQ | e75aa5842a4e | 85be597ebc56 |

Head sha3:e75aa5842a4e8b80b384c54d1874f273f9561ba2e81948db3ab103a52a3a16a6. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
