Free tool · about fifteen minutes
Which CMMC families are worth an hour?
Fourteen questions, one for each requirement family in NIST SP 800-171. Each one describes something you can either do or cannot — no checklists to look up, no jargon to decode. Your answers stay in this browser and are never sent anywhere.
- Requirements
- 110
- Assessment objectives
- 320
- Families
- 14
- Questions here
- 14
1 Access Control
Could you produce a list of everyone who can reach CUI today, without building it first?
Access control is the largest family. If the list has to be assembled, it is not being reviewed, and leavers tend to still be on it.
2 Awareness and Training
Has everyone who handles CUI completed security training in the last twelve months, with a record you could show?
A provider can supply the material; it cannot make your people sit through it. The record is the part usually missing, not the training.
3 Audit and Accountability
If someone opened a CUI file last Tuesday, could you find out who?
Logging that exists but is not retained or searchable answers this question with a shrug, which is the same as no.
4 Configuration Management
Is there a written baseline for how a laptop is built, and would you notice if one drifted from it?
Most firms have a build. Fewer have it written down, and fewer again would spot a machine that stopped matching.
5 Identification and Authentication
Is multi-factor authentication enforced for every person who can reach CUI, and do you know how the accounts that cannot use it are protected instead?
The gap is almost never ordinary staff. It is the shared mailbox, the old service account, and the admin who is an exception. Asked about accounts rather than people, this question flagged firms whose non-interactive service accounts are covered by other means, which the requirement does not ask them to change.
6 Incident Response
If ransomware hit tonight, is there a written plan naming who does what, and has anyone rehearsed it?
A plan nobody has walked through is a document, not a capability.
7 Maintenance
When a machine goes out for repair, is there a record of what was on it and who handled it?
Maintenance is where CUI leaves the building legitimately and without anyone recording that it did.
8 Media Protection
Do you know where every copy of CUI lives, including backups, USB drives and anything a person has on a home machine?
Media protection fails on the copies nobody counted rather than the ones they did.
9 Personnel Security
Is screening done before someone gets CUI access, and is access removed the day they leave?
The leaving half is where this fails. Accounts outlive employment far more often than screening is skipped.
10 Physical Protection
Can you say who physically entered any area holding CUI systems last month?
If your systems are hosted, much of this is inherited from the platform — but the premises where people work are still yours, and a badge system nobody reads produces no evidence either way.
11 Risk Assessment
Has anything been formally assessed for risk in the last year, with a written result?
Vulnerability scanning is not a risk assessment, though it is often offered as one.
12 Security Assessment
Is there a current system security plan, and does it describe the environment you actually run?
An SSP written for the environment of two years ago is a common and expensive finding.
13 System and Communications Protection
When CUI leaves your network — email, file transfer, a laptop taken home — do you know what protects it, and whether that protection is FIPS-validated?
Validated is the operative word, and it is where commercial tooling quietly does not qualify. Knowing which mechanism applies is the point; this family also covers boundary protection and segmentation.
14 System and Information Integrity
Are security patches applied on a defined schedule, and could you show what is currently outstanding?
Patching usually happens. Being able to evidence it on demand usually does not.
What this suggests
We have not given you a readiness score or an SPRS figure. Fourteen questions cannot produce one honestly, and a number that looks official and turns out to be wrong is worse than no number — the first real assessment would contradict it.
This is an indicator, not an assessment. It is based on fourteen questions, one per requirement family. CMMC Level 2 is assessed against 320 objectives across 110 requirements, and nothing here has examined any of them. Cloud Kings is not a C3PAO and does not perform certification assessments.
If you want the real thing
A scoped gap analysis walks all 110 requirements and 320 objectives, and produces the System Security Plan and POA&M an assessor actually reads. We will also tell you plainly if your contract does not require the stricter path.
Book a scoping call