Comprehensive assessment covering 110 practices required to protect Controlled Unclassified Information (CUI) in DoD contracts.
CMMC Level 2 is the advanced tier required for organizations handling Controlled Unclassified Information (CUI). It encompasses all 110 security requirements from NIST SP 800-171 and requires third-party certification for most contracts.
Comprehensive security controls covering all aspects of protecting sensitive government information in contractor systems.
Most CUI contracts require assessment by a CMMC Third-Party Assessment Organization (C3PAO) every three years.
Directly maps to NIST Special Publication 800-171, the federal standard for protecting CUI in non-federal systems.
CMMC Level 2 practices are organized into 14 security domains based on the NIST 800-171 security requirement families.
22 practices
3 practices
9 practices
9 practices
11 practices
3 practices
6 practices
9 practices
6 practices
2 practices
3 practices
4 practices
16 practices
7 practices
Organizations that receive, process, store, or transmit Controlled Unclassified Information.
Prime contractors and subcontractors in the defense supply chain handling sensitive technical data.
Organizations already subject to DFARS cybersecurity requirements transitioning to CMMC.
Organizations preparing for formal third-party CMMC assessment and certification.
Assessment Dashboard Screenshot
Placeholder for assessment interface image
Our assessment automatically calculates your Supplier Performance Risk System (SPRS) score based on the DoD Assessment Methodology. Scores range from -203 to 110.
All practices not implemented
Typical starting point with major gaps
All 110 practices fully implemented
Our assessment tool guides you through all 110 practices with clear explanations, automatically calculating your SPRS score as you progress.
Navigate through the 14 security domains, reviewing practices in each area.
For each practice, assess your current implementation: Met, Partially Met, Mostly Met, or Not Met.
Add implementation notes and create remediation plans for any gaps identified.
Track your calculated SPRS score and generate comprehensive reports for C3PAO preparation.
A complete Level 2 assessment typically takes 4-8 hours depending on organizational complexity and existing documentation.
Practice Assessment Interface Screenshot
Placeholder for rating interface image
Generate comprehensive reports to document your CMMC Level 2 compliance status, support your SPRS submission, and prepare for C3PAO assessment.
Complete assessment results with SPRS score, domain summaries, and detailed practice-by-practice compliance status.
Plan of Action & Milestones report documenting gaps and remediation timelines required for SPRS submission.
A password-protected JSON file containing all your assessment data. Use it to restore your assessment or transfer between devices.
SPRS Score Dashboard Preview
Placeholder for report screenshot
Domain Summary Preview
Placeholder for report screenshot
The right CMMC level depends on the type of information you handle in your DoD contracts.
Try our CMMC Level 2 assessment tool with a free trial. Calculate your SPRS score, identify gaps, and prepare for C3PAO certification.