Your result is computed in your browser from your own answers.
Your score is above. Want to see which controls are costing you the points?
Enter your work email to see your control-by-control breakdown, ranked by point impact. Your results and a 30-day starter plan for the gaps it found can go to your inbox. No sales sequence follows.
Your address is used for your results email. Every email carries a one-click unsubscribe link. We never sell it.
This is what you reported. The question is whether your environment backs it up.
This check uses your answers, the same way the number you submit to SPRS uses your judgment. A self-reported score reflects judgment. A measured scan shows what your configuration actually supports, and the two can differ.
The $999 CMMC Level 2 Readiness Snapshot measures the cloud and identity configuration you connect (AWS, Azure, Microsoft 365, Google Workspace, Okta or CrowdStrike; intake-based if you connect none) against the 110-control NIST 800-171 baseline, lists your top control gaps by NIST control ID with the evidence each one requires, and hands you a 30-day remediation plan ordered by readiness-recovery impact, as a PDF emailed after your intake and scan complete. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.
If you start a Level 2 subscription with the same billing email within 30 days of receiving your Level 2 Readiness Snapshot PDF, the $999 is credited in full: against your first invoice, with any amount above that invoice applied to the invoices after it (Refund Policy).
Methodology & honest limits
This check samples 10 controls from NIST SP 800-171 (seven 5-point controls, two 3-point controls, and the SSP requirement, which carries no point value) and scores them on the DoD Assessment Methodology point scale (5 / 3 / 1 points). An “In progress” answer is counted at half weight here; that is this check’s own directional convention, not an assessment finding. Under the CMMC Scoring Methodology (32 CFR 170.24), each requirement is found MET, NOT MET or not applicable, and a reduced deduction for partial implementation exists only on 3.5.3 and 3.13.11. It is a directional self-assessment built from what you reported, not an official SPRS score, not a C3PAO pre-assessment, and not a measurement of your actual systems.
A full assessment covers all 110 controls and 320 assessment objectives, and the 100 controls this check does not sample can only add deductions to the figure above, never remove them. "Not sure" is scored as a gap on purpose: in an assessment, a control you can’t evidence is a control you can’t claim.