Skip to content
CMMC Level 2 — C3PAO Readiness

Are you ready for a C3PAO assessment?

Self-rate the 14 NIST SP 800-171 control families and get a deterministic 0-100 readiness estimate with your estimated SPRS score. Takes about 5 minutes.

0 / 17

For each family, how many controls have you implemented?

3.1Access Control

22 controls

3.2Awareness & Training

3 controls

3.3Audit & Accountability

9 controls

3.4Configuration Management

9 controls

3.5Identification & Authentication

11 controls

3.6Incident Response

3 controls

3.7Maintenance

6 controls

3.8Media Protection

9 controls

3.9Personnel Security

2 controls

3.10Physical Protection

6 controls

3.11Risk Assessment

3 controls

3.12Security Assessment

4 controls

3.13System & Communications Protection

16 controls

3.14System & Information Integrity

7 controls

Evidence, SSP, and POA&M

For the controls you have implemented, how much is backed by current evidence?

An assessor cannot accept a "met" claim without a current artifact (evidence older than 90 days counts as stale).

Do you have a System Security Plan (SSP)?

NIST 800-171 control 3.12.4 requires one — the assessor reads it first.

Do you have a documented POA&M tracking your open gaps?

A Plan of Action & Milestones must close eligible gaps inside the 180-day window.