How ready are you, really?
Twelve yes-or-no questions. Three minutes. No email required, and your answers never leave your browser. CMMC Phase 2 starts hitting DoD contracts on November 10, 2026. If you handle CUI, this is the clock that matters.
progress: 0/12 answered_
Do you know which of your contracts carry DFARS 252.204-7012 (CUI handling)?
Have you submitted a current NIST 800-171 self-assessment score to SPRS?
Is CUI stored only in a defined, access-controlled environment (not general file shares or personal email)?
Is multi-factor authentication required on every account, everywhere?
Are laptops and servers encrypted at rest, and traffic encrypted in transit?
Do you have a written, current System Security Plan (SSP)?
Do you keep POA&Ms for known gaps, with owners and dates?
Are security logs collected centrally and actually reviewed?
Does every employee get documented security-awareness training?
Do you have an incident-response plan you've tested in the last year?
Are personal and BYOD devices either blocked from company data or centrally managed?
Could you hand an assessor evidence (policies, configs, logs) within a week?
This is a directional screen, not an assessment, a certification, or legal advice. CMMC Level 2 assesses 110 controls from NIST SP 800-171; a real gap assessment covers all of them with evidence.