Self-assessment guide

    The CMMC Level 2 Self-Assessment Checklist (All 110 Controls)

    CMMC Level 2 is aligned to the 110 security requirements of NIST SP 800-171 Rev. 2, organized into 14 domains. This checklist walks through every domain, what a self-assessment actually involves, and how the SPRS score comes out of it — so you know what you're being measured on before an assessor shows up.

    Self-assessment progress

    Answered
    0 / 110
    Met
    0
    Not met
    0
    Not applicable
    0

    A practice is only Met when every applicable assessment objective beneath it is satisfied. If even one objective fails, the whole practice is Not Met. Answering here produces a readiness view and a gap report — it is not a certification and not an official assessment result.

    Not Applicable is not the same as Met. N/A is only offered for the specific requirements where it is documented as potentially valid, it never counts as a satisfied practice, and it needs a written justification an assessor can test. Practices satisfied (0) counts Met answers only.

    Assess the 110 requirements

    • AC.L2-3.1.1
      6 objectives

      Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

      Status for AC.L2-3.1.1
    • AC.L2-3.1.2
      2 objectives

      Limit system access to the types of transactions and functions that authorized users are permitted to execute.

      Status for AC.L2-3.1.2
    • AC.L2-3.1.3
      5 objectives

      Control the flow of CUI in accordance with approved authorizations.

      Status for AC.L2-3.1.3
    • AC.L2-3.1.4
      3 objectives

      Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

      Status for AC.L2-3.1.4
    • AC.L2-3.1.5
      4 objectives

      Employ the principle of least privilege, including for specific security functions and privileged accounts.

      Status for AC.L2-3.1.5
    • AC.L2-3.1.6
      2 objectives

      Use non-privileged accounts or roles when accessing nonsecurity functions.

      Status for AC.L2-3.1.6
    • AC.L2-3.1.7
      4 objectives

      Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.

      Status for AC.L2-3.1.7
    • AC.L2-3.1.8
      2 objectives

      Limit unsuccessful logon attempts.

      Status for AC.L2-3.1.8
    • AC.L2-3.1.9
      2 objectives

      Provide privacy and security notices consistent with applicable CUI rules.

      Status for AC.L2-3.1.9
    • AC.L2-3.1.10
      3 objectives

      Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.

      Status for AC.L2-3.1.10
    • AC.L2-3.1.11
      2 objectives

      Terminate (automatically) a user session after a defined condition.

      Status for AC.L2-3.1.11
    • AC.L2-3.1.12
      4 objectives

      Monitor and control remote access sessions.

      Not applicable is only valid here: Only if no remote access to in-scope systems is permitted at all.

      Status for AC.L2-3.1.12
    • AC.L2-3.1.13
      2 objectives

      Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

      Not applicable is only valid here: Only if no remote access to in-scope systems is permitted at all.

      Status for AC.L2-3.1.13
    • AC.L2-3.1.14
      2 objectives

      Route remote access via managed access control points.

      Not applicable is only valid here: Only if no remote access to in-scope systems is permitted at all.

      Status for AC.L2-3.1.14
    • AC.L2-3.1.15
      4 objectives

      Authorize remote execution of privileged commands and remote access to security-relevant information.

      Not applicable is only valid here: Only if no remote access to in-scope systems is permitted at all.

      Status for AC.L2-3.1.15
    • AC.L2-3.1.16
      2 objectives

      Authorize wireless access prior to allowing such connections.

      Not applicable is only valid here: Only if no wireless access exists in the assessment scope.

      Status for AC.L2-3.1.16
    • AC.L2-3.1.17
      2 objectives

      Protect wireless access using authentication and encryption.

      Not applicable is only valid here: Only if no wireless access exists in the assessment scope.

      Status for AC.L2-3.1.17
    • AC.L2-3.1.18
      3 objectives

      Control connection of mobile devices.

      Not applicable is only valid here: Only if no mobile devices connect to in-scope systems.

      Status for AC.L2-3.1.18
    • AC.L2-3.1.19
      2 objectives

      Encrypt CUI on mobile devices and mobile computing platforms.

      Not applicable is only valid here: Only if CUI is never stored on mobile devices or platforms.

      Status for AC.L2-3.1.19
    • AC.L2-3.1.20
      6 objectives

      Verify and control/limit connections to and use of external systems.

      Not applicable is only valid here: Only if there are no external systems or connections in scope.

      Status for AC.L2-3.1.20
    • AC.L2-3.1.21
      3 objectives

      Limit use of portable storage devices on external systems.

      Not applicable is only valid here: Only if portable storage on external systems is technically impossible.

      Status for AC.L2-3.1.21
    • AC.L2-3.1.22
      5 objectives

      Control CUI posted or processed on publicly accessible systems.

      Not applicable is only valid here: Only if no publicly accessible system is operated in scope.

      Status for AC.L2-3.1.22
    • AT.L2-3.2.1
      4 objectives

      Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.

      Status for AT.L2-3.2.1
    • AT.L2-3.2.2
      3 objectives

      Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.

      Status for AT.L2-3.2.2
    • AT.L2-3.2.3
      2 objectives

      Provide security awareness training on recognizing and reporting potential indicators of insider threat.

      Status for AT.L2-3.2.3
    • AU.L2-3.3.1
      6 objectives

      Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

      Status for AU.L2-3.3.1
    • AU.L2-3.3.2
      2 objectives

      Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.

      Status for AU.L2-3.3.2
    • AU.L2-3.3.3
      3 objectives

      Review and update logged events.

      Status for AU.L2-3.3.3
    • AU.L2-3.3.4
      3 objectives

      Alert in the event of an audit logging process failure.

      Status for AU.L2-3.3.4
    • AU.L2-3.3.5
      2 objectives

      Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

      Status for AU.L2-3.3.5
    • AU.L2-3.3.6
      2 objectives

      Provide audit record reduction and report generation to support on-demand analysis and reporting.

      Status for AU.L2-3.3.6
    • AU.L2-3.3.7
      3 objectives

      Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

      Status for AU.L2-3.3.7
    • AU.L2-3.3.8
      6 objectives

      Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

      Status for AU.L2-3.3.8
    • AU.L2-3.3.9
      2 objectives

      Limit management of audit logging functionality to a subset of privileged users.

      Status for AU.L2-3.3.9
    • CM.L2-3.4.1
      6 objectives

      Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.

      Status for CM.L2-3.4.1
    • CM.L2-3.4.2
      2 objectives

      Establish and enforce security configuration settings for information technology products employed in organizational systems.

      Status for CM.L2-3.4.2
    • CM.L2-3.4.3
      4 objectives

      Track, review, approve or disapprove, and log changes to organizational systems.

      Status for CM.L2-3.4.3
    • CM.L2-3.4.4
      1 objectives

      Analyze the security impact of changes prior to implementation.

      Status for CM.L2-3.4.4
    • CM.L2-3.4.5
      8 objectives

      Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

      Status for CM.L2-3.4.5
    • CM.L2-3.4.6
      2 objectives

      Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.

      Status for CM.L2-3.4.6
    • CM.L2-3.4.7
      15 objectives

      Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

      Status for CM.L2-3.4.7
    • CM.L2-3.4.8
      3 objectives

      Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.

      Status for CM.L2-3.4.8
    • CM.L2-3.4.9
      3 objectives

      Control and monitor user-installed software.

      Status for CM.L2-3.4.9
    • IA.L2-3.5.1
      3 objectives

      Identify system users, processes acting on behalf of users, and devices.

      Status for IA.L2-3.5.1
    • IA.L2-3.5.2
      3 objectives

      Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.

      Status for IA.L2-3.5.2
    • IA.L2-3.5.3
      4 objectives

      Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

      Status for IA.L2-3.5.3
    • IA.L2-3.5.4
      1 objectives

      Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

      Status for IA.L2-3.5.4
    • IA.L2-3.5.5
      2 objectives

      Prevent reuse of identifiers for a defined period.

      Status for IA.L2-3.5.5
    • IA.L2-3.5.6
      2 objectives

      Disable identifiers after a defined period of inactivity.

      Status for IA.L2-3.5.6
    • IA.L2-3.5.7
      4 objectives

      Enforce a minimum password complexity and change of characters when new passwords are created.

      Status for IA.L2-3.5.7
    • IA.L2-3.5.8
      2 objectives

      Prohibit password reuse for a specified number of generations.

      Status for IA.L2-3.5.8
    • IA.L2-3.5.9
      1 objectives

      Allow temporary password use for system logons with an immediate change to a permanent password.

      Status for IA.L2-3.5.9
    • IA.L2-3.5.10
      2 objectives

      Store and transmit only cryptographically-protected passwords.

      Status for IA.L2-3.5.10
    • IA.L2-3.5.11
      1 objectives

      Obscure feedback of authentication information.

      Status for IA.L2-3.5.11
    • IR.L2-3.6.1
      7 objectives

      Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

      Status for IR.L2-3.6.1
    • IR.L2-3.6.2
      6 objectives

      Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

      Status for IR.L2-3.6.2
    • IR.L2-3.6.3
      1 objectives

      Test the organizational incident response capability.

      Status for IR.L2-3.6.3
    • MA.L2-3.7.1
      1 objectives

      Perform maintenance on organizational systems.

      Status for MA.L2-3.7.1
    • MA.L2-3.7.2
      4 objectives

      Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.

      Status for MA.L2-3.7.2
    • MA.L2-3.7.3
      1 objectives

      Ensure equipment removed for off-site maintenance is sanitized of any CUI.

      Status for MA.L2-3.7.3
    • MA.L2-3.7.4
      1 objectives

      Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.

      Status for MA.L2-3.7.4
    • MA.L2-3.7.5
      2 objectives

      Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.

      Status for MA.L2-3.7.5
    • MA.L2-3.7.6
      1 objectives

      Supervise the maintenance activities of maintenance personnel without required access authorization.

      Status for MA.L2-3.7.6
    • MP.L2-3.8.1
      4 objectives

      Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.

      Status for MP.L2-3.8.1
    • MP.L2-3.8.2
      1 objectives

      Limit access to CUI on system media to authorized users.

      Status for MP.L2-3.8.2
    • MP.L2-3.8.3
      2 objectives

      Sanitize or destroy system media containing CUI before disposal or release for reuse.

      Status for MP.L2-3.8.3
    • MP.L2-3.8.4
      2 objectives

      Mark media with necessary CUI markings and distribution limitations.

      Status for MP.L2-3.8.4
    • MP.L2-3.8.5
      2 objectives

      Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.

      Status for MP.L2-3.8.5
    • MP.L2-3.8.6
      1 objectives

      Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.

      Not applicable is only valid here: Only if CUI is never transported outside controlled areas on digital media.

      Status for MP.L2-3.8.6
    • MP.L2-3.8.7
      1 objectives

      Control the use of removable media on system components.

      Status for MP.L2-3.8.7
    • MP.L2-3.8.8
      1 objectives

      Prohibit the use of portable storage devices when such devices have no identifiable owner.

      Status for MP.L2-3.8.8
    • MP.L2-3.8.9
      1 objectives

      Protect the confidentiality of backup CUI at storage locations.

      Status for MP.L2-3.8.9
    • PS.L2-3.9.1
      1 objectives

      Screen individuals prior to authorizing access to organizational systems containing CUI.

      Status for PS.L2-3.9.1
    • PS.L2-3.9.2
      3 objectives

      Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.

      Status for PS.L2-3.9.2
    • PE.L2-3.10.1
      4 objectives

      Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.

      Status for PE.L2-3.10.1
    • PE.L2-3.10.2
      4 objectives

      Protect and monitor the physical facility and support infrastructure for organizational systems.

      Status for PE.L2-3.10.2
    • PE.L2-3.10.3
      2 objectives

      Escort visitors and monitor visitor activity.

      Status for PE.L2-3.10.3
    • PE.L2-3.10.4
      1 objectives

      Maintain audit logs of physical access.

      Status for PE.L2-3.10.4
    • PE.L2-3.10.5
      3 objectives

      Control and manage physical access devices.

      Status for PE.L2-3.10.5
    • PE.L2-3.10.6
      2 objectives

      Enforce safeguarding measures for CUI at alternate work sites.

      Not applicable is only valid here: Only if no alternate work sites are used for in-scope work.

      Status for PE.L2-3.10.6
    • RA.L2-3.11.1
      2 objectives

      Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.

      Status for RA.L2-3.11.1
    • RA.L2-3.11.2
      5 objectives

      Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

      Status for RA.L2-3.11.2
    • RA.L2-3.11.3
      2 objectives

      Remediate vulnerabilities in accordance with risk assessments.

      Status for RA.L2-3.11.3
    • CA.L2-3.12.1
      2 objectives

      Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

      Status for CA.L2-3.12.1
    • CA.L2-3.12.2
      3 objectives

      Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

      Status for CA.L2-3.12.2
    • CA.L2-3.12.3
      1 objectives

      Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

      Status for CA.L2-3.12.3
    • CA.L2-3.12.4
      8 objectives

      Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

      Status for CA.L2-3.12.4
    • SC.L2-3.13.1
      8 objectives

      Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.

      Status for SC.L2-3.13.1
    • SC.L2-3.13.2
      6 objectives

      Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.

      Status for SC.L2-3.13.2
    • SC.L2-3.13.3
      3 objectives

      Separate user functionality from system management functionality.

      Status for SC.L2-3.13.3
    • SC.L2-3.13.4
      1 objectives

      Prevent unauthorized and unintended information transfer via shared system resources.

      Status for SC.L2-3.13.4
    • SC.L2-3.13.5
      2 objectives

      Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

      Status for SC.L2-3.13.5
    • SC.L2-3.13.6
      2 objectives

      Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

      Status for SC.L2-3.13.6
    • SC.L2-3.13.7
      1 objectives

      Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).

      Not applicable is only valid here: Only if no remote devices establish non-remote connections.

      Status for SC.L2-3.13.7
    • SC.L2-3.13.8
      3 objectives

      Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

      Status for SC.L2-3.13.8
    • SC.L2-3.13.9
      3 objectives

      Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.

      Status for SC.L2-3.13.9
    • SC.L2-3.13.10
      2 objectives

      Establish and manage cryptographic keys for cryptography employed in organizational systems.

      Status for SC.L2-3.13.10
    • SC.L2-3.13.11
      1 objectives

      Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

      Status for SC.L2-3.13.11
    • SC.L2-3.13.12
      3 objectives

      Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.

      Not applicable is only valid here: Only if no collaborative computing devices exist in scope.

      Status for SC.L2-3.13.12
    • SC.L2-3.13.13
      2 objectives

      Control and monitor the use of mobile code.

      Not applicable is only valid here: Only if mobile code is not used in scope.

      Status for SC.L2-3.13.13
    • SC.L2-3.13.14
      2 objectives

      Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

      Not applicable is only valid here: Only if Voice over IP is not used in scope.

      Status for SC.L2-3.13.14
    • SC.L2-3.13.15
      1 objectives

      Protect the authenticity of communications sessions.

      Status for SC.L2-3.13.15
    • SC.L2-3.13.16
      1 objectives

      Protect the confidentiality of CUI at rest.

      Status for SC.L2-3.13.16
    • SI.L2-3.14.1
      6 objectives

      Identify, report, and correct system flaws in a timely manner.

      Status for SI.L2-3.14.1
    • SI.L2-3.14.2
      2 objectives

      Provide protection from malicious code at designated locations within organizational systems.

      Status for SI.L2-3.14.2
    • SI.L2-3.14.3
      3 objectives

      Monitor system security alerts and advisories and take action in response.

      Status for SI.L2-3.14.3
    • SI.L2-3.14.4
      1 objectives

      Update malicious code protection mechanisms when new releases are available.

      Status for SI.L2-3.14.4
    • SI.L2-3.14.5
      3 objectives

      Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

      Status for SI.L2-3.14.5
    • SI.L2-3.14.6
      3 objectives

      Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

      Status for SI.L2-3.14.6
    • SI.L2-3.14.7
      2 objectives

      Identify unauthorized use of organizational systems.

      Status for SI.L2-3.14.7

    Prioritized gap report

    Nothing marked Not Met yet. Gaps appear here ordered by the points each one costs.

    Sanitized example

    Fictional contractor "Northgate Precision LLC". No real system names, hostnames, IPs, or findings — deliberately generic so it is safe to share.

    Northgate Precision marks CM.L2-3.4.1 Not Met because their baseline configuration is documented for servers but not laptops — objective 3.4.1[a] fails, so the whole practice is Not Met. They mark AC.L2-3.1.16 Not Applicable with the justification "no wireless networking exists in the CUI enclave; wireless radios disabled by policy" — an assessor will test that claim, so it must be true.

    One path forward

    Free result → $129 CMMC Survival Report → Athena workspace

    1. Free, right now: keep the result and downloads from this tool. No account, no e-mail required.
    2. $129 CMMC Survival Report: an objective-level readiness snapshot with your weakest practices, prioritized remediation order, and an assessor-facing narrative.
    3. Athena workspace / evidence sprint: continuous objective-level tracking, evidence defensibility scoring, and assessor-ready artifacts.

    Athena works at the assessment-objective level, keeps a provenance trail for every artifact, and scores how defensible your evidence is. We do not guarantee a certification outcome — no tool or consultant can.

    The other free CMMC tools

    Score all 110 requirements with official weighted deductions.
    Every NIST SP 800-171A Rev. 2 objective with evidence planning.
    Categorize assets and define your assessment boundary.
    Build a DoD-oriented POA&M with eligibility warnings.
    Day-one evidence list, mock intake, and readiness verdict.

    Educational readiness aid. This is not legal advice, not an official assessment, not a certification, and not a submitted SPRS score. Your assessment results and any affirmation remain your organization's responsibility.

    How the self-assessment works

    A CMMC L2 self-assessment is only permitted for a limited set of CUI programs — most CUI-carrying contracts require a C3PAO third-party assessment. But every organization should run an internal self-assessment first: it produces your SPRS score, drives your SSP, and tells you whether you're ready to invite a C3PAO.

    The workflow, at a glance:

    1. Scope — identify which assets store, process, or transmit CUI. Wrong scope = wrong score.
    2. Assess every objective in each of the 110 requirements against NIST 800-171A. All-or-nothing per control.
    3. Score — start at 110, subtract 1/3/5 points per unmet control (DoD Assessment Methodology weights).
    4. POA&M the gaps you can close in 180 days (score must be ≥ 88 and control must be POA&M-eligible).
    5. Submit the score, scope, and assessment date to SPRS with an affirming-official attestation.

    Doing this by hand takes days.

    Athena runs the same 110-control assessment in ~60 seconds and shows you exactly where the deductions land. Free — no signup.

    Start the free Quick Score

    The 14 domains — 110 controls total

    CodeDomainControlsWhat it covers
    ACAccess Control22Least privilege, session control, remote access, external systems.
    ATAwareness & Training3Security awareness for users and privileged roles.
    AUAudit & Accountability9Logging, review, protection, and retention of audit records.
    CMConfiguration Management9Baselines, change control, least functionality, USB/software allow-lists.
    IAIdentification & Authentication11Unique IDs, MFA, password complexity, credential management.
    IRIncident Response3IR plan, handling, reporting, and testing.
    MAMaintenance6Controlled maintenance, media sanitization, remote maintenance MFA.
    MPMedia Protection9Marking, storage, transport, and sanitization of media and CUI.
    PSPersonnel Security2Screening and termination/transfer procedures.
    PEPhysical Protection6Facility access, visitor logs, alternate sites, monitoring.
    RARisk Assessment3Risk assessments and vulnerability scanning cadence.
    CASecurity Assessment4SSP, control assessment, POA&M, continuous monitoring.
    SCSystem & Communications Protection16Boundary protection, FIPS crypto, session termination, DNS.
    SISystem & Information Integrity7Flaw remediation, malicious code protection, monitoring, alerts.
    —Total110

    How SPRS scoring works, in one paragraph

    You start at 110. Each of the 110 requirements is worth 1, 3, or 5 points, weighted by risk under the DoD Assessment Methodology. Scoring is all-or-nothing per control — miss one objective (per NIST 800-171A) and you lose the full point value. The lowest possible score is -203. A Final CMMC L2 status requires 110 with all controls met; Conditional is available at 88–109 with a valid POA&M closed within 180 days; below 88 there is no CMMC status.

    Full walkthrough with worked examples: how to calculate your SPRS score.

    Checklist structure — how to run it by domain

    For each of the 14 domains, do the same four passes:

    1. Read every requirement's objectives in NIST 800-171A. This is what an assessor grades against — not the requirement summary.
    2. Ask "who does this, on what asset, and how do I know?" — the answer is the evidence.
    3. Mark met / not met per objective. If any objective is not met, the whole control is not met.
    4. Capture the evidence artifact (policy, config export, log sample, screenshot) with the date and the person who produced it.

    For domain-specific evidence examples, see the Athena CMMC control evidence library, which has per-control pages for the highest-weighted requirements (3.1.1 access control, 3.5.3 MFA, 3.13.11 FIPS encryption, and more).

    Run all 110 automatically.

    Get an evidence-backed SPRS score projection in 60 seconds — free, no signup, no credit card.

    • All 110 controls
    • SPRS score projection
    • No signup required
    Start the free Quick Score

    Frequently asked questions

    How many controls are in CMMC Level 2?

    110 — the same 110 security requirements as NIST SP 800-171 Rev. 2, organized into 14 domains.

    Can I self-assess for CMMC Level 2?

    Only for a limited set of CUI programs designated as self-assessment-eligible. Most CUI-carrying DoD contracts require a C3PAO third-party assessment. Check the specific contract or solicitation.

    What's the passing SPRS score for CMMC Level 2?

    110 with all controls met supports Final status. 88–109 with a valid POA&M supports Conditional status (180 days to close). Below 88 is no CMMC status.

    What's the difference between a requirement and an objective?

    A requirement is the top-level control (e.g. 3.5.3, Use multifactor authentication). Objectives are the specific determinations an assessor makes about that requirement, per NIST 800-171A. Scoring is per-control, but grading is per-objective — miss one objective and the control fails.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.