Answer 7 questions. Get your likely CMMC path, readiness band, SPRS estimate, top contract risks, and the next deliverable to buy.
No account needed. We compute the result locally in your browser.
The wizard above gives you your likely CMMC path. This inventory turns that into a defensible boundary: five asset categories from the CMMC Level 2 Scoping Guide, what each one means for an assessment, and your reasoning for why an asset sits inside or outside the boundary. Nothing is uploaded and no CUI is collected.
Scope decides everything downstream: what gets assessed, how many objectives you must evidence, and how large your SSP is. Categorize every asset once, in general terms. Do not upload documents or enter CUI here — describe asset groups, not systems.
Fictional contractor "Northgate Precision LLC". No real system names, hostnames, IPs, or findings — deliberately generic so it is safe to share.
Northgate Precision records 24 CUI assets (engineering laptops and one file share), 4 security protection assets (identity provider, endpoint manager, log collector, VPN), 30 contractor risk managed assets (front-office laptops with the same baseline but no CUI routing), 3 specialized assets (two CNC controllers and one government-furnished test rig), and 60 out-of-scope assets on a separate VLAN with deny-all rules. Their boundary reasoning for out-of-scope: "distinct VLAN, no shared credentials, no route to the CUI file share, verified in the firewall rule export."
Athena works at the assessment-objective level, keeps a provenance trail for every artifact, and scores how defensible your evidence is. We do not guarantee a certification outcome — no tool or consultant can.
Educational readiness aid. This is not legal advice, not an official assessment, not a certification, and not a submitted SPRS score. Your assessment results and any affirmation remain your organization's responsibility.