Results carry Low confidence — not a substitute for a C3PAO-certified CMMC assessment. SPRS scores must not be submitted to DoD without a certified assessment.
cmmc-advisor is a guided self-assessment against NIST SP 800-171 Revision 2, the 110 controls behind CMMC Level 2. You describe your environment, the tool evaluates what you report control by control, and you get back a clear picture of where you stand and what to fix first. It assesses the security posture you declare. It does not scan your network or connect to your systems.
Register with your work email, confirm it from the link we send you, and sign in.
Work through plain-language questions organized by the 14 control families, starting with the boundary of the environment that handles Controlled Unclassified Information (CUI). Your answers build the description the engine assesses. Save and return at any time, and attach existing policies to support your answers.
The engine evaluates each of the 110 controls and marks it Met, Partial, Not Met, or Not Applicable, each with a short rationale tied to the assessment objective.
You receive a Supplier Performance Risk System (SPRS) score summarizing where you stand against the 110 controls. The score is a self-assessment, labeled low confidence. It shows your gaps and where to focus first. It is not a certification and does not replace a certified third-party (C3PAO) assessment.
The report prioritizes your gaps and produces draft remediation documents — a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) — so you know exactly where to look and what to do next.
Re-run the assessment as your posture improves to track your score over time.
A DoD framework that requires contractors handling Controlled Unclassified Information (CUI) to achieve and document a defined security posture. Level 2 is the baseline for most defense contracts.
Published by the National Institute of Standards and Technology, this standard defines 110 security requirements across 14 families — from Access Control to System Integrity. CMMC Level 2 maps directly to it.
Any company in the Defense Industrial Base (DIB) that creates, processes, or transmits CUI must achieve CMMC Level 2. This includes prime contractors, subcontractors, and suppliers across the supply chain.
A numeric score from −203 to 110 that reflects your compliance posture. It starts at 110 and deducts points for each unmet or partially met control. Self-reported to the DoD; a score below 88 requires a POA&M.
A remediation roadmap that lists every control gap, the owner responsible for closing it, target completion dates, and interim mitigations. Required when your SPRS score is below 110 and you still want to bid on contracts.
A NIST-required document (control 3.12.4) that describes your CUI enclave boundary, which systems are in scope, and how each of the 110 controls is implemented. CMMC-Advisor generates a draft SSP automatically from your assessment.