CMMC compliance check: free Level 1 and Level 2 self-assessment
Answer the 110 NIST SP 800-171 Rev 2 requirements for CMMC Level 2, or the 15 FAR 52.204-21 requirements for Level 1. You get your score out of 110, the gaps by family, which gaps may go on a POA&M, and a PDF report. Free, with no sign-up.
Nothing leaves your browser. The scoring runs on this page, which is blocked from sending data anywhere. This is a self-assessment aid, not an official CMMC assessment, a certification or legal advice.
Status checked on 1 October 2026: Phase 1 of the CMMC rollout is in effect (Level 1 and Level 2 self-assessments, SPRS entry and annual affirmations where a contract requires them). On 13 July 2026 the Department suspended Phase 2, the planned start of required third-party (C3PAO) Level 2 certifications on 10 November 2026, pending a review. No new Phase 2 date has been published. Status and sources.
Self-assessment
Mark each requirement Met only if every NIST SP 800-171A assessment objective for it is satisfied with final evidence. Not applicable counts as met (32 CFR 170.24(b)). Progress: 0 of 110 answered.
AC Access Control 0 of 22 answered
AT Awareness and Training 0 of 3 answered
AU Audit and Accountability 0 of 9 answered
CM Configuration Management 0 of 9 answered
IA Identification and Authentication 0 of 11 answered
IR Incident Response 0 of 3 answered
MA Maintenance 0 of 6 answered
MP Media Protection 0 of 9 answered
PS Personnel Security 0 of 2 answered
PE Physical Protection 0 of 6 answered
RA Risk Assessment 0 of 3 answered
CA Security Assessment 0 of 4 answered
SC System and Communications Protection 0 of 16 answered
SI System and Information Integrity 0 of 7 answered
Each requirement must be fully met; Level 1 allows no POA&M (32 CFR 170.21(a)(1)). Progress: 0 of 15 answered.
How the check works
- Level 2 uses the 110 requirements of NIST SP 800-171 Rev 2 in 14 families, with the point values of 32 CFR 170.24, CMMC Scoring Methodology: 44 requirements are worth 5 points, 14 are worth 3, 51 are worth 1, and the System Security Plan (3.12.4) has no value but is required.
- POA&M eligibility follows 32 CFR 170.21, POA&M requirements: a Conditional status needs a score of at least 88, and only 1-point requirements (plus 3.13.11 when encryption isn't FIPS-validated) can be on the plan, never 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5 or 3.12.4.
- Level 1 uses the 15 requirements of FAR 52.204-21, Basic Safeguarding, assessed with the NIST SP 800-171A objectives of 17 mapped requirements (32 CFR 170.15, Level 1 self-assessment).
New to CMMC? Start with CMMC 2.0 explained, compare Level 1 and Level 2, work through the CMMC compliance checklist, read the 110 NIST SP 800-171 requirements, the POA&M rules and the DoD's cost estimates.
Questions
Is this an official CMMC assessment?
No. It is a free self-assessment aid. It scores the answers you give with the method in 32 CFR 170.24, but only your own assessment against the NIST SP 800-171A objectives (or a C3PAO's) and your affirmation in SPRS set your CMMC status.
How is the Level 2 score calculated?
Start at 110 and subtract the value of every requirement not met: 5, 3 or 1 points, as listed in 32 CFR 170.24. MFA (3.5.3) and FIPS-validated encryption (3.13.11) lose 3 points when partly done and 5 when not done. Not applicable counts as met. The lowest possible score is -203.
What score do I need?
Final Level 2 (Self) needs every requirement met or not applicable, a score of 110. A Conditional status with a POA&M needs at least 88 (80%), and every open item must be a requirement that is allowed on a POA&M. Level 1 has no score: all 15 requirements must be met and no POA&M is allowed.
Are my answers sent anywhere?
No. The form and the scoring run on this page, the PDF and CSV are built on your computer, and the site's security policy blocks the page from sending data anywhere. Answers are kept only in this browser tab until you close it.
Is CMMC Phase 2 still starting on 10 November 2026?
No. On 13 July 2026 the Department suspended Phase 2 pending a review, and no new date had been published when we last checked. Phase 1 self-assessment requirements still apply. See the CMMC status page for the dated sources.