- Every requirement starts as Not implemented, so your starting score is −203. Mark each one honestly — a requirement only counts if it is fully implemented and documented in your System Security Plan (SSP).
- Each requirement is weighted 1, 3, or 5 points based on its security impact. Unimplemented requirements subtract their weight from 110.
- Two requirements (3.5.3 MFA and 3.13.11 FIPS encryption) allow partial credit. Five remote-access/wireless/mobile requirements can be N/A if the capability doesn't exist in your environment.
- Your score and top gaps update live. Scroll to the bottom for your summary.
💾 Your progress saves automatically on this device as you answer. To finish later or on another device, scroll to Save your progress below and we'll email you a private link.
Your results
Highest-value gaps to fix first
Save your results
Create a free account to keep your SPRS score, your prioritized gap list, and your whole CMMC packet in one place — and pick up on any device. Just your email, no cost.
🔓 The calculator stays free and ungated — your score is already on this page. 🔒 We store your answers only so you can resume — never shared or sold. (Don't enter actual CUI — this is a self-assessment aid.)
Create free account →Prefer not to sign up? We'll email your SPRS score report — your number, your prioritized gaps to fix first, and a private link back to your packet. No account needed.
Ready to act on these gaps? Turn them into an assessor-ready SSP and a Plan of Action & Milestones — both free, both built from this assessment.
Generate my SSP sections → Build my POA&M →Want these documents generated from your own answers — branded, editable, regeneration included — plus the 14 policies no tool drafts for you? Get the $99 CMMC Level 2 Starter Kit →