Phase 2 was suspended. The 110 requirements were not. DFARS 252.204-7012, the annual SPRS self-assessment and the affirmation that follows it all still apply — and a false affirmation carries the same exposure with or without a certification deadline.

This assessment scores all 110 CMMC Level 2 practices from NIST SP 800-171 Rev 2, plus the scoping, POA&M eligibility and affirmation questions that decide whether your SPRS score means anything. It is free, it saves as you go, and you can stop and come back to it.

What this is

A readiness assessment against all 110 Level 2 practices, plus the scoping, POA&M and affirmation questions that decide whether your score is usable. We have the background elsewhere — the programme explained, what the 2026 suspension changed, the five asset categories, how SPRS scoring works, what counts as CUI and CMMC against 800-171. Come here when you want a score.

What it covers

DomainPractices
Scope and programme — CUI, asset categories, SSP, ESPs, flow-down6
AC — Access Control22
AT — Awareness and Training3
AU — Audit and Accountability9
CM — Configuration Management9
IA — Identification and Authentication11
IR — Incident Response3
MA — Maintenance6
MP — Media Protection9
PS — Personnel Security2
PE — Physical Protection6
RA — Risk Assessment3
CA — Security Assessment4
SC — System and Communications Protection16
SI — System and Information Integrity7
Assessment readiness and SPRS7

Scoring here, and scoring in SPRS

These are two different scores and it is worth keeping them apart. SPRS is subtractive: you start at 110 and lose 5, 3 or 1 point per unmet requirement, so a score can fall to -203. It is pass or fail per requirement, with no credit for partial work.

This assessment is not that. It scores on a five-step scale, because a readiness view needs to distinguish “we do this but cannot prove it” from “we have not started” — a distinction SPRS deliberately refuses to make. Use this to find and sequence the work, then calculate the SPRS score from the finished result. The readiness section at the end asks you for that figure, so the two sit side by side.

What a POA&M cannot save

Conditional status needs at least 88 of 110, and six practices can never sit on a POA&M at all: external connections, publicly accessible content, the system security plan, visitor escorting, physical access logs and access devices. Any one of those unmet blocks conditional status no matter how good the rest of the score is, which is why they are worth checking before anything else.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicableA justified exclusion, removed from the score

Where the programme stands

Phase 2 of the CMMC rollout was due on 10 November 2026 and was suspended on 13 July 2026. That removed the near-term requirement for third-party certification, but it changed nothing underneath: DFARS 252.204-7012 still applies, all 110 NIST SP 800-171 Revision 2 requirements still apply, and the annual SPRS self-assessment and affirmation still apply. Revision 3 is anticipated and not yet enacted, so Revision 2 remains the assessed baseline.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every practice with your status and notes, the score broken down by domain, a prioritised gap list, and the documents from the CMMC Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 50 minutes. It is the longest assessment here because 800-171 is granular, and Access Control alone is 22 questions.

What to do with your score

Below 40% — stop and settle scope. Categorising assets wrongly is a finding in its own right, and remediating out-of-scope systems is the most expensive mistake in this programme.

40–70% — work the six practices that cannot go on a POA&M first, then the 5-point requirements, since those move the SPRS number fastest.

Above 70% — move to evidence. The gap between “implemented” and “implemented and evidenced” is where assessments are lost, and a C3PAO samples records rather than asking you to describe the control.

Frequently asked questions

Is this assessment really free?

Yes. All 123 questions, the domain breakdown and your overall score cost nothing. The $39 report is optional.

Does this give me an SPRS score?

No. It gives you a readiness score and the gap list behind it. SPRS uses its own subtractive weighting and has to be calculated and submitted by you.

Level 1 or Level 3?

This covers Level 2, the 110 practices from 800-171 Rev 2. Level 1 is 15 FAR requirements; Level 3 adds 24 requirements from 800-172 on top of a completed Level 2.

Does the Phase 2 suspension mean I can stop?

No. The contract clause, the 110 requirements, the self-assessment and the annual affirmation are unaffected. A false affirmation carries False Claims Act exposure whether or not a C3PAO is involved.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.