Skip to content
CMMC Guidance
Readiness check

Ten questions.
About five minutes.

A real assessment takes days, and the evidence gathering behind it takes weeks. This is the short version: ten of the 110 requirements, chosen because they are where findings actually land.

Answer honestly rather than optimistically. Every question names what an assessor asks to see, because the gap that costs money is usually not the control itself — it is being unable to evidence a control you genuinely have.

  1. 1.Do you have a System Security Plan that describes your actual environment, and has it been updated in the last year?

    An assessor asks to see: The document itself, with system boundaries, and a revision date somebody can defend.

    CA.L2-3.12.4 · Security Assessment

  2. 2.Is access to systems holding Controlled Unclassified Information limited to named, authorised users?

    An assessor asks to see: An account list matched to current staff, and the process that removes access when someone leaves.

    AC.L2-3.1.1 · Access Control

  3. 3.Is multifactor authentication enforced for privileged accounts and for all network access?

    An assessor asks to see: Policy configuration showing enforcement, not availability, and the exception list.

    IA.L2-3.5.3 · Identification and Authentication

  4. 4.Are audit logs created and retained across the in-scope systems?

    An assessor asks to see: Retention settings, and logs from a date you did not choose.

    AU.L2-3.3.1 · Audit and Accountability

  5. 5.Does somebody actually review and correlate those logs, on a schedule?

    An assessor asks to see: Review records with names and dates. Collecting logs nobody reads is the most common version of this gap.

    AU.L2-3.3.5 · Audit and Accountability

  6. 6.Are security incidents tracked, documented, and reported to the designated officials?

    An assessor asks to see: A ticket trail for a real incident, and the reporting path written down before it was needed.

    IR.L2-3.6.2 · Incident Response

  7. 7.Where cryptography protects Controlled Unclassified Information, is it FIPS-validated?

    An assessor asks to see: Certificate numbers for the modules in use. Strong encryption and validated encryption are different findings.

    SC.L2-3.13.11 · System and Communications Protection

  8. 8.Do you maintain baseline configurations and a current inventory of in-scope systems?

    An assessor asks to see: The inventory, and evidence it matches what is on the network today.

    CM.L2-3.4.1 · Configuration Management

  9. 9.Are systems scanned for vulnerabilities on a schedule, and when new ones are announced?

    An assessor asks to see: Scan history and what was done about the findings.

    RA.L2-3.11.2 · Risk Assessment

  10. 10.Is media holding Controlled Unclassified Information sanitised or destroyed before disposal or reuse?

    An assessor asks to see: Certificates of destruction, or the documented procedure and who performs it.

    MP.L2-3.8.3 · Media Protection

What this is not

It is not a Supplier Performance Risk System score, and it is not an assessment. Ten questions cannot produce either. What it can do is tell you whether the heaviest common failures are behind you, and give you the requirement identifiers to look up before anyone quotes you for anything.

The full requirement text for all 110 is published in the Knowledge Base, with the scoring methodology and the seven-step roadmap. None of it is behind a form.

Want the real number?

The readiness call assesses your environment rather than your recollection of it. No cost, and an engineer runs it.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.