Schedule a call

Free tool · about fifteen minutes

Which CMMC families are worth an hour?

Fourteen questions, one for each requirement family in NIST SP 800-171. Each one describes something you can either do or cannot — no checklists to look up, no jargon to decode. Your answers stay in this browser and are never sent anywhere.

Requirements
110
Assessment objectives
320
Families
14
Questions here
14

1 Access Control

Could you produce a list of everyone who can reach CUI today, without building it first?

Access control is the largest family. If the list has to be assembled, it is not being reviewed, and leavers tend to still be on it.

2 Awareness and Training

Has everyone who handles CUI completed security training in the last twelve months, with a record you could show?

A provider can supply the material; it cannot make your people sit through it. The record is the part usually missing, not the training.

3 Audit and Accountability

If someone opened a CUI file last Tuesday, could you find out who?

Logging that exists but is not retained or searchable answers this question with a shrug, which is the same as no.

4 Configuration Management

Is there a written baseline for how a laptop is built, and would you notice if one drifted from it?

Most firms have a build. Fewer have it written down, and fewer again would spot a machine that stopped matching.

5 Identification and Authentication

Is multi-factor authentication enforced for every person who can reach CUI, and do you know how the accounts that cannot use it are protected instead?

The gap is almost never ordinary staff. It is the shared mailbox, the old service account, and the admin who is an exception. Asked about accounts rather than people, this question flagged firms whose non-interactive service accounts are covered by other means, which the requirement does not ask them to change.

6 Incident Response

If ransomware hit tonight, is there a written plan naming who does what, and has anyone rehearsed it?

A plan nobody has walked through is a document, not a capability.

7 Maintenance

When a machine goes out for repair, is there a record of what was on it and who handled it?

Maintenance is where CUI leaves the building legitimately and without anyone recording that it did.

8 Media Protection

Do you know where every copy of CUI lives, including backups, USB drives and anything a person has on a home machine?

Media protection fails on the copies nobody counted rather than the ones they did.

9 Personnel Security

Is screening done before someone gets CUI access, and is access removed the day they leave?

The leaving half is where this fails. Accounts outlive employment far more often than screening is skipped.

10 Physical Protection

Can you say who physically entered any area holding CUI systems last month?

If your systems are hosted, much of this is inherited from the platform — but the premises where people work are still yours, and a badge system nobody reads produces no evidence either way.

11 Risk Assessment

Has anything been formally assessed for risk in the last year, with a written result?

Vulnerability scanning is not a risk assessment, though it is often offered as one.

12 Security Assessment

Is there a current system security plan, and does it describe the environment you actually run?

An SSP written for the environment of two years ago is a common and expensive finding.

13 System and Communications Protection

When CUI leaves your network — email, file transfer, a laptop taken home — do you know what protects it, and whether that protection is FIPS-validated?

Validated is the operative word, and it is where commercial tooling quietly does not qualify. Knowing which mechanism applies is the point; this family also covers boundary protection and segmentation.

14 System and Information Integrity

Are security patches applied on a defined schedule, and could you show what is currently outstanding?

Patching usually happens. Being able to evidence it on demand usually does not.