Tool
CMMC Level 2 readiness quiz
Twenty questions across the NIST SP 800-171 control families that drive most CMMC Level 2 assessment outcomes. Each answer maps to a 0-to-3 maturity score. At the end you get a total, a gap list (questions you answered 0 or 1), and a recommended next step tied to where you land.
What CMMC Level 2 certification actually requires
CMMC Level 2 is aligned to NIST SP 800-171 (110 controls across 14 families). For most contractors handling Controlled Unclassified Information (CUI), a certified third-party assessment organization (C3PAO) must verify that all 110 controls are implemented. There are some allowances for POA&M (Plan of Action and Milestones) items, but the set of controls that cannot be on a POA&M is growing, and the scoring methodology penalizes each missing control by the weight assigned in the CMMC scoring methodology (1, 3, or 5 points deducted from a maximum of 110).
The contractual trigger is DFARS 252.204-7021 (the CMMC clause), which has been rolling into DoD solicitations on a phased schedule. If your next recompete or new award includes the CMMC clause and you are not certified at the required level by the award date, you will not be eligible. This is a procurement gate, not a best-practice recommendation.
How the readiness score is calculated
Each question maps to a representative control (or in some cases a small cluster of related controls). You pick one of four maturity levels: 0 (not implemented), 1 (partially implemented, no documented evidence), 2 (implemented with some documentation), 3 (fully implemented with evidence continuously generated). Your total is out of 60 points, converted to a percentage, and placed into one of four bands.
The bands are calibrated against the gap between "the control is working" and "an assessor can verify the control is working" (which is typically where programs get caught in pre-assessment). A score above 85 percent means your controls are not only in place but evidenced well enough to survive an assessment. A score in the 60 to 85 range means controls are real but evidence is incomplete. Below 60 and you are in remediation program territory (6 to 12 months of focused work).
What the quiz does not cover
This is a 20-question self-assessment against a 110-control standard. It samples the families that drive most readiness gaps (access control, audit and accountability, configuration management, identification and authentication, incident response, risk assessment, system and communications protection, system and information integrity). It does not evaluate your System Security Plan, your POA&M discipline, your scoping decisions around CUI boundaries, or the specific implementation of any individual control. It is not a substitute for a gap assessment and it is not a pre-assessment readiness review.
It also does not tell you what CUI you actually have or where it flows. CUI scoping is the single most expensive mistake in a CMMC program (either overscoping and making every system in-bounds, or underscoping and missing systems that process CUI through indirect channels like shared file stores, email distribution lists, or developer build pipelines). If you are not certain about your CUI inventory and data flows, start there before worrying about control implementation.
Next steps based on your score
Below 30 percent the program needs structural work first (CUI inventory, scoping, System Security Plan, and baseline configurations) before individual control hardening will move the needle. Between 30 and 60 percent, a targeted remediation program focused on the lowest-scoring families typically closes the gap in 3 to 6 months. Between 60 and 85 percent you are close enough that a formal gap assessment against all 110 controls is the right next step. Above 85 percent you are ready to engage a C3PAO on a pre-assessment basis and schedule the certified assessment.
Regardless of score, do not wait until the CMMC clause appears in a solicitation to begin the program. Lead time from "start remediation" to "certified" runs 9 to 18 months for most mid-sized contractors. If the solicitation window is tighter than that, you are not winning that award.
From quiz to certification
Full 110-control scorecard
Deeper assessment than the quiz โ per-control evidence expectations.
OpenvCISO for CMMC ownership
Named operator runs the SSP, POA&M, C3PAO relationship.
OpenManufacturing CMMC case study
From 60s SPRS to Level 2 certified in 9 months.
OpenZero Trust for 3.13.3
Architectural answer to NIST 800-171 separation requirements.
OpenEFROS for manufacturing
Full defense-industrial-base service stack.
OpenCMMC roadmap call
Book a 20-minute call to plan certification path from your quiz score.
Open