Check all 17 FAR 52.204-21 controls in about 5 minutes. See your gap report instantly — no account, no CSV, no upload. Email required to unlock gaps beyond the first 3.
Progress — 0/17 answered
0/17 answered
0
/ 17 met
Authorized Access Control
Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
Transaction & Function Control
Limit system access to the types of transactions and functions that authorized users are permitted to execute.
External Connections
Verify and control/limit connections to external information systems.
Control CUI on Public Systems
Control information posted or processed on publicly accessible information systems.
Security Awareness Training
Ensure managers, system administrators, and users are made aware of security risks and applicable policies.
Identify Users & Devices
Identify information system users, processes acting on behalf of users, or devices.
Authenticate Users & Devices
Authenticate (or verify) the identities of users, processes, or devices before allowing access.
Media Sanitization
Sanitize or destroy information system media before disposal or reuse.
Limit Physical Access
Limit physical access to organizational systems, equipment, and operating environments to authorized individuals.
Escort Visitors
Escort visitors and monitor visitor activity; maintain audit logs of physical access.
Boundary Protection
Monitor, control, and protect organizational communications at external boundaries and key internal boundaries.
Security Engineering
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security.
Public Access DMZ
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
Flaw Remediation
Identify, report, and correct information system flaws in a timely manner.
Malware Protection
Provide protection from malicious code at appropriate locations within organizational systems.
Update Malware Definitions
Update malicious code protection mechanisms when new releases are available.
Periodic System Scans
Perform periodic scans of the information system and real-time scans of files from external sources.
This tool is for estimation and educational purposes only. It does not constitute a formal CMMC self-assessment or a valid SPRS submission. For an official Level 2 certification, a C3PAO assessment is required. Nothing in this tool constitutes legal advice.
Any contractor who handles Federal Contract Information (FCI) — information provided by or generated for the government under a contract — but does NOT handle CUI must meet Level 1 requirements.
Level 1 is a self-assessment. No C3PAO required. The contractor's senior official must annually affirm compliance and submit the SPRS score to SPRS.mil. A false affirmation is a False Claims Act violation.
If your contract involves Controlled Unclassified Information, Level 2 applies — all 110 NIST SP 800-171 Rev 2 controls and a third-party C3PAO assessment. Use our Level 2 SPRS calculator for that.
Access Control (4), Awareness & Training (1), Identification & Authentication (2), Media Protection (1), Physical Protection (2), System & Communications Protection (3), System & Information Integrity (4).
Need Level 2? If your DoD contract includes DFARS 252.204-7021 or handles CUI, Level 2 applies — 110 controls and a C3PAO assessment. Use the full SPRS calculator or start your Level 2 program in Aegis Firma.
Aegis Firma tracks your SPRS over time, manages POA&M deadlines, generates your SSP, and prepares you for the C3PAO assessment.
Start free assessment