cloudcorps
CMMC Level 2

How ready are you, really?

Twelve yes-or-no questions. Three minutes. No email required, and your answers never leave your browser. CMMC Phase 2 starts hitting DoD contracts on November 10, 2026. If you handle CUI, this is the clock that matters.

progress: 0/12 answered_

001

Do you know which of your contracts carry DFARS 252.204-7012 (CUI handling)?

002

Have you submitted a current NIST 800-171 self-assessment score to SPRS?

003

Is CUI stored only in a defined, access-controlled environment (not general file shares or personal email)?

004

Is multi-factor authentication required on every account, everywhere?

005

Are laptops and servers encrypted at rest, and traffic encrypted in transit?

006

Do you have a written, current System Security Plan (SSP)?

007

Do you keep POA&Ms for known gaps, with owners and dates?

008

Are security logs collected centrally and actually reviewed?

009

Does every employee get documented security-awareness training?

010

Do you have an incident-response plan you've tested in the last year?

011

Are personal and BYOD devices either blocked from company data or centrally managed?

012

Could you hand an assessor evidence (policies, configs, logs) within a week?

This is a directional screen, not an assessment, a certification, or legal advice. CMMC Level 2 assesses 110 controls from NIST SP 800-171; a real gap assessment covers all of them with evidence.