CMMC L2

Help
These tools are designed for desktop use and work best on a larger screen.
Self-scoring & preparation aid. CMMC Level 2 certification requires a third-party assessment by an authorized C3PAO; this tool supports preparation and self-scoring only. Based on NIST SP 800-171 Rev 2, the version the CMMC 2.0 Program rule (32 CFR Part 170, effective December 2024) requires for Level 2. SP 800-171 Rev 3 (2024) is published but does not yet apply to CMMC; track it for future planning.
110
SPRS Score
SP 800-171 Rev 2
−2030110 (max)
The 88 tick marks the score DoD generally treats as acceptable risk for contract performance. The goal is a path to 110, with any gaps tracked on a POA&M.

Requirement

Discussion

Implementation Status

Implementation Notes

POA&M Target Date (Partial or Not Met)

Opens the POA&M tool in a new tab and adds this gap as a tracked item (its target date carries over).

Prefill from SSP: a draft starting point

This reads your System Security Plan's SP 800-53 control statuses and maps them to the 110 NIST 800-171 requirements to give you a head start.

This is a draft, not a finished assessment. Don't import and submit. Each 800-171 requirement maps to several 800-53 controls (and is only truly "Met" when all of them are), your SSP may not cover every mapped control, and the mapping is informal (per 800-171 Appendix D). Review and adjust every requirement before relying on the SPRS score.

Only requirements you haven't assessed yet will be filled. Your existing selections are kept.

Reset Assessment?

All saved progress will be permanently cleared. Save a JSON backup first, or reset without saving.

Save as JSON

.json