Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free CMMC 2.0 Risk Check:
Which Level Applies to You, and What’s Your Estimated SPRS Score?

CMMC 2.0 / NIST SP 800-171 Risk Check

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive CMMC 2.0 risk check below to find out what your DoD contract or subcontract actually requires of you.

    Answer 9 quick questions, starting with which CMMC level your contract requires, then your readiness against the NIST SP 800-171 controls, and get your gap read in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.

    No sign-up to see your result.

    What CMMC 2.0 Actually Covers (the short version)

    CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense’s program for verifying that contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) the way their contract requires.

    It has three levels:

    • Level 1 (Foundational)

      Covers 15 basic safeguarding practices for FCI

    • Level 2 (Advanced)

      Most manufacturers and transportation/logistics subcontractors land here; it aligns to all 110 requirements in NIST SP 800-171 Rev. 2 and applies when your work involves CUI.

    • Level 3 (Expert)

      Adds 24 enhanced requirements from NIST SP 800-172 on top of Level 2, for the most sensitive programs, and is assessed by a government-led team (DIBCAC) rather than a commercial assessor.

    Your contract, RFP, or your prime’s flow-down clause tells you which level applies, not a guess, and question 1 in the tool above is built around exactly that.

    The checklist below is organized around those safeguards.

    The Full CMMC 2.0 / NIST 800-171 Gap Checklist

    Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a prime, contracting officer, or assessor can’t either.

    • 1. Knowing your Required Level:

      ✓ Your contract, RFP, or prime’s flow-down clause states, in writing, whether you’re held to Level 1 (FCI only), Level 2 (CUI, the most common), or Level 3 (highest sensitivity).

      ✓ You haven’t assumed your level based on what a prime mentioned verbally or what a similar contract required last time.

      ✓ You’ve confirmed which programs specifically require Level 2 versus Level 1, since a single company can hold contracts at more than one level at once.

    • 2. Documentation: your SSP and POA&M:

      ✓ A written System Security Plan (SSP) naming every applicable NIST 800-171 control and where CUI actually lives across your systems.

      ✓ A Plan of Action & Milestones (POA&M) tracking any control that isn’t fully implemented yet, with a real remediation date.

      ✓ A named owner responsible for keeping both current as systems, contracts, or vendors change.

    • 3. Your SPRS Score:

      ✓ A current SPRS (Supplier Performance Risk System) score, calculated using the DoD’s assessment methodology, which starts at 110 and deducts 1, 3, or 5 points for every control not fully implemented, with no partial credit.

      ✓ That score reflects your systems as they stand today, not an assessment from a prior year or a best-guess estimate.

      ✓ You understand that submitting an inaccurate score isn’t a paperwork risk, it’s the exact conduct the DOJ’s Civil Cyber-Fraud Initiative has pursued as a False Claims Act violation in past settlements.

    • 4. Access Control:

      ✓ A unique login for every user and system that touches CUI, no shared accounts, no default passwords left in place.

      ✓ Access granted on a need-to-know, least-privilege basis tied to job function.

      ✓ Access removed the same day someone changes roles or leaves.

    • 5. Multi-Factor Authentication (MFA):

      ✓ MFA enforced on every system and remote-access path that touches CUI.

      ✓ MFA required specifically for administrator and privileged accounts, not just standard user logins.

    • 6. Encryption:

      ✓ CUI encrypted at rest: servers, workstations, laptops, and backups alike.

      ✓ CUI encrypted in transit, including email and file transfers, not just when it’s sent through a designated portal.

    • 7. Audit Logging and Monitoring:

      ✓ Access logging enabled on every system that stores or processes CUI.

      ✓ Someone assigned to actually review those logs on a regular schedule, not just collect them.

    • 8. Incident Response:

      ✓ A written incident-response plan specific to CUI, naming who is responsible for DoD notification.

      ✓ Your team knows DFARS 252.204-7012 requires reporting a discovered cyber incident affecting CUI within 72 hours, a clock that starts at discovery, not after your investigation wraps up.

    • 9. Media Protection:

      ✓ Devices and media (laptops, external drives, backups) that hold CUI are securely wiped or destroyed before disposal or reuse.

      ✓ Physical access to that media is controlled in the meantime.

    • 10. Supply Chain and Flow-Down:

      ✓ A current inventory of every subcontractor and vendor, including your IT provider, who can access CUI.

      ✓ Written confirmation each one has the same NIST 800-171 / CMMC requirements flowed down to them that your prime flowed down to you.

      ✓ Awareness that a vendor’s compliance gap becomes your finding if a prime or the DoD ever reviews the chain.

    How to read your gaps?

    • 0 – 2 Gaps

      Strong shape, and your SPRS score is likely close to the 110-point maximum.

    • 3 – 6 Gaps

      Real, findable gaps that would cost you SPRS points or draw a finding in a review.

    • 7+ Gaps

      You’d likely fail that review today, and depending on what’s flagged, relying on your current self-attestation as-is carries real False Claims Act exposure, not just a compliance to-do.

    Most of the technical items above, MFA, encryption, access control, media handling, live in your IT setup, not a policy binder, which is the half of CMMC and NIST 800-171 a managed IT and cybersecurity partner operates for you.

    For more on the operational risks manufacturers specifically carry, and for a deeper walk through CMMC’s levels, requirements, and costs, see our CMMC compliance guide for small businesses.

    CMMC 2.0 Risk Check FAQ

    What is CMMC 2.0 and Who Has to Comply?

    CMMC is the Department of Defense’s program for verifying that contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) at the level their specific contract requires. It applies across the defense industrial base, which includes manufacturers producing parts or materials for defense end use and transportation/logistics providers moving defense-related freight, not just companies that think of themselves as “defense contractors.”

    How do I know which CMMC level applies to me?

    Your contract, RFP, or your prime’s flow-down clause states it. Level 1 applies if you only handle FCI (15 basic safeguarding practices). Level 2, the level most manufacturing and logistics subcontractors land on, applies if you handle CUI and aligns to all 110 NIST SP 800-171 requirements. Level 3 adds 24 enhanced NIST SP 800-172 requirements for the most sensitive programs. If nothing in writing states your level, that’s itself a gap, and it’s question 1 in the tool above.

    What is an SPRS score and why does it matter?

    SPRS (Supplier Performance Risk System) is where DoD contractors submit their NIST 800-171 self-assessment score. The scoring starts at 110 points and subtracts 1, 3, or 5 points for every control not fully implemented, with no partial credit, down to a possible low of -203. Your score is what a contracting officer or prime sees when evaluating whether to award or renew a contract with you.

    Is the CMMC third-party (C3PAO) assessment still required right now?

    As of this writing, no, not on the original timeline. The Department of Defense suspended the Phase 2 requirement, which would have mandated a C3PAO assessment for Level 2 contracts involving CUI starting November 10, 2026, in a July 13, 2026 announcement, citing compliance cost, a shortage of certified assessors, and defense-industrial-base growth concerns. A 60-day CMMC Reform Task Force review is underway, with an industry RFI due August 14, 2026. What hasn’t changed: Phase 1’s Level 1 and Level 2 self-assessment requirements, and SPRS score submission, remain in effect.

    What is False Claims Act exposure and how does it connect to CMMC?

    The False Claims Act lets the government, or a whistleblower on the government’s behalf, pursue a company that knowingly submits false information to obtain a federal contract or payment. Since 2021, the DOJ’s Civil Cyber-Fraud Initiative has specifically targeted contractors who misrepresent their cybersecurity compliance, including inaccurate NIST 800-171 self-assessments and SPRS scores, and it has produced real settlements, including an $9 million settlement with Aerojet Rocketdyne (2022), an $8.4 million settlement involving Raytheon and its successor Nightwing (2025), and a $507,144 settlement with defense contractor LOGZONE (June 2026). An honest “Not sure” or “No” on a self-assessment is a compliance gap to close. A confident but inaccurate “Yes” is the specific conduct that’s drawn these settlements.

    What if a prime contractor is pressuring us to prove compliance before they’ll renew?

    This is increasingly common and it’s a legitimate ask, since a prime carries its own flow-down risk if one of its subcontractors can’t substantiate its compliance. The fastest way to respond is with your SSP, POA&M, and current SPRS score in hand, rather than a verbal assurance. Question 10 in the checklist above (supply chain and flow-down) is where this shows up in your result.

    How much does a CMMC Level 2 assessment cost, and is there really an assessor shortage?

    Yes, cost and assessor availability are real constraints, which is part of why the Phase 2 requirement was paused. Reported C3PAO assessment fees for Level 2 have ranged roughly from the tens of thousands of dollars up into six figures depending on organization size and scope, and preparation work typically costs several times the assessment fee itself. Separately, industry reporting has described a large gap between the number of companies expected to need Level 2 assessments and the number of authorized C3PAOs available to perform them.

    Ready to close your gaps?

    If your result flagged gaps in your SSP, SPRS accuracy, MFA, or vendor flow-down, most of that is documentation and technical work an IT and compliance partner handles day to day.

    LeadingIT helps Chicagoland manufacturers and transportation/logistics providers build the access controls, encryption, and documentation NIST SP 800-171 and CMMC require, and keep your SPRS score and SSP current between contract renewals. We deliver this FOR clients; there’s no CMMC or NIST 800-171 “certification” an IT company can hold, and we don’t claim one.

    Email yourself the full result from the tool above, book a free 30-minute gap review, or see how we support manufacturers and transportation and logistics operations as a managed service.