Quiz / CMMC 2.0 readiness
Are you CMMC Level 2 ready?
15 questions across 5 NIST SP 800-171 domains. Maps your answers to a readiness band and identifies your top 3 remediation priorities. Takes about 5 minutes.
Access Control
Q1Multi-factor authentication is enforced on all privileged + remote accounts (including OT engineer VPN).
Q2Role-based access control is documented and reviewed at least quarterly for both IT and OT systems.
Q3Third-party vendor access to plant systems is time-boxed and logged session-by-session.
Risk Assessment
Q1A formal cyber risk assessment against NIST SP 800-171 has been completed in the last 12 months.
Q2A documented POA&M (Plan of Action & Milestones) exists with owners, dates, and residual risk.
Q3OT / ICS systems are included in the risk register (not just corporate IT).
Incident Response
Q1An incident response plan exists, is tested via tabletop at least annually, and covers OT scenarios.
Q2A designated incident commander and 24/7 contact tree is documented for ransomware events.
Q3Immutable, offline backups exist and have been restore-tested in the last 6 months.
Audit & Accountability
Q1Centralized logging captures auth, privilege escalation, and OT protocol anomalies.
Q2Logs are retained for at least 90 days and reviewed at least weekly.
Q3Audit records are protected from unauthorized modification with tamper-evident storage.
Configuration Management
Q1Baseline configurations exist for IT endpoints, servers, and OT devices (PLCs, HMIs, historians).
Q2Patching cadence is documented for IT (monthly) and OT (vendor-approved windows).
Q3Unauthorized software is blocked via allowlisting or equivalent controls.
Mapped to NIST SP 800-171 Rev.3 control objectives underlying CMMC 2.0 Level 2. This is a preliminary self-assessment; a formal CMMC assessment is conducted by a C3PAO. Learn about our CMMC program.
Your readiness score
0 of 15 questions answered
Domain scores
- Access Control0/6 / 0%
- Risk Assessment0/6 / 0%
- Incident Response0/6 / 0%
- Audit & Accountability0/6 / 0%
- Configuration Management0/6 / 0%