How the CMMC Readiness Assessment Is Scored
The full method behind the score: what the 12 questions map to, the exact arithmetic that turns your answers into a number, and — the part most readiness tools leave out — how that number differs from the official DoD score your contracting officer can see.
Last verified July 27, 2026
The 20-second version
- • 12 questions, one per NIST SP 800-171 control family (of the 14 families; Physical Protection and Security Assessment are not covered).
- • Four answer levels — Not Started, In Progress, Implemented, Verified — scored 0 / 33 / 67 / 100 percent.
- • Overall score = the plain unweighted average of those 12 percentages. Every family counts exactly the same.
- • This is not an SPRS score. The official DoD methodology weights individual requirements 5, 3, and 1 points and runs from +110 down to −203 — for that number, use the SPRS Score Calculator.
What the assessment measures
The assessment asks one question per control family and records a single maturity level for that whole family. It is deliberately coarse: the goal is a five-minute directional readout that tells you where to look first, not a requirement-by-requirement audit of all 110 controls. Here is every question it asks and what sits behind it.
| Family | What the question covers |
|---|---|
| 3.1 Access Control | Role-based access, least privilege, remote access controls, session management. |
| 3.2 Awareness & Training | User security training, specialized training for privileged roles, insider threat awareness. |
| 3.3 Audit & Accountability | System event logging, log review and analysis, log protection, cross-system correlation. |
| 3.4 Configuration Management | Baseline configurations, change control, least functionality, software restrictions. |
| 3.5 Identification & Authentication | Multi-factor authentication, password policy, authenticator management, identity verification. |
| 3.6 Incident Response | Incident handling procedures, reporting, response testing, lessons learned. |
| 3.7 Maintenance | Controlled maintenance, maintenance tools, nonlocal maintenance, maintenance personnel. |
| 3.8 Media Protection | Media access, marking, storage, transport, sanitization, destruction. |
| 3.9 Personnel Security | Personnel screening, access agreements, termination and transfer procedures. |
| 3.11 Risk Assessment | Risk assessment procedures, vulnerability scanning, risk response planning. |
| 3.13 System & Communications Protection | Boundary protection, architecture, encryption in transit, network segmentation. |
| 3.14 System & Information Integrity | Flaw remediation, malicious code protection, security alerts, system monitoring. |
What it does not cover — and why
Two of the fourteen NIST SP 800-171 families are absent. Both omissions change how you should read your result, so they are worth stating plainly rather than burying:
3.10 Physical Protection
Facility-dependent and poorly served by a single self-reported question — it needs a walkthrough of your actual space, not a dropdown.
3.12 Security Assessment
This family contains 3.12.4, the System Security Plan requirement. An SSP is a document to be reviewed, not a maturity level to self-rate — and it is the gate for a real assessment (see below).
Practically: your score here says nothing about your physical security posture, and it does not know whether you have a System Security Plan. If you do not have an SSP, that is the first thing to fix regardless of what this assessment reports.
How the score is built
Every answer maps to a raw value from 0 to 3, which is then expressed as a percentage of the maximum. There is no hidden weighting, no industry adjustment, and no calibration against other respondents.
| Answer | Raw | Family score | What it means |
|---|---|---|---|
| Not Started | 0 | 0% | No formal process in place. |
| In Progress | 1 | 33% | Currently being developed or partially implemented. |
| Implemented | 2 | 67% | Fully implemented but not independently verified. |
| Verified | 3 | 100% | Implemented and verified by a third party or internal audit. |
The formula
Family score = raw value ÷ 3 × 100, rounded to the nearest whole number — so a family can only ever score 0, 33, 67, or 100.
Overall score = the sum of all 12 family scores ÷ 12, rounded. Each family contributes exactly one twelfth. An unanswered question counts as Not Started.
Gaps = every family scoring below 67%, sorted lowest first. In practice that means each family you marked Not Started or In Progress.
A worked example
Suppose you answer Verified for 4 families, Implemented for 4, In Progress for 3, and Not Started for 1:
(4 × 100) + (4 × 67) + (3 × 33) + (1 × 0) = 400 + 268 + 99 + 0 = 767
767 ÷ 12 = 63.9 → 64 overall — the “Progressing” band.
Four families fall below 67%, so the results screen lists 4 gaps, starting with the Not Started family.
How the bands are labelled
80 – 100
Strong Foundation
50 – 79
Progressing
25 – 49
Early Stage
0 – 24
Getting Started
Note the consequence of the arithmetic: a company that has genuinely implemented every single family — but had none of it independently verified — scores exactly 67 and lands in “Progressing”, not “Strong Foundation”. Verification is what separates the top band, which mirrors how assessors actually treat unevidenced claims.
How this differs from the official DoD score
This is the most important section on the page. The assessment above is a maturity average. The score the government actually sees — the one you self-report into SPRS — is computed a completely different way, under the NIST SP 800-171 DoD Assessment Methodology v1.2.1, Annex A / §5.
That methodology starts you at 110 — one point per requirement, all met — and deducts the weight of every requirement you have not implemented. The weights are not equal:
| Weight | How many | Why it matters |
|---|---|---|
| 5 points | 44 requirements | Deducted in full if not met. These carry 220 of the 313 deductible points — most scores are decided here. |
| 3 points | 14 requirements | Significant but not existential. 42 points total. |
| 1 point | 51 requirements | Necessary for a clean 110, but rarely the reason a score collapses. 51 points total. |
| No score | 3.12.4 (SSP) | Carries no point value because without a System Security Plan the assessment cannot be conducted at all. |
Those weights total 313 deductible points, which is why the official scale runs from +110 down to −203. A negative score is not a rounding artefact — it is the normal starting position for an organisation that has not done the work.
Two requirements carry partial credit
Annex A values these at “3 to 5” rather than a flat 5:
- • 3.5.3 (multi-factor authentication) — deducts 3 instead of 5 if MFA covers remote and privileged users but not all users; the full 5 only if none is in place.
- • 3.13.11 (FIPS-validated cryptography) — deducts 3 instead of 5 if encryption is employed but not FIPS-validated; the full 5 if encryption is absent.
The practical warning
Because our 12-family average weights everything equally and the DoD methodology does not, the two numbers can disagree sharply. An organisation that answers Implemented across the board scores 67 here — a respectable-looking result — while still sitting well below zero in SPRS if a dozen of the 5-point requirements are unmet. Treat a good score on this page as permission to proceed to a real scored assessment, never as a substitute for one.
Want the SPRS number itself? We built that too.
Everything described in this section — the 5/3/1 weights, both partial-credit paths, and the 3.12.4 gate — is implemented requirement by requirement in our SPRS Score Calculator. Use the readiness assessment for a five-minute directional readout of where to look; use the SPRS calculator when you need the number a contracting officer can see and a gap list ordered by points recovered. Two different measurements, published side by side on purpose.
The priority map lists all 110 requirements in assessor priority order, colour-coded by the same point values described above.
Does any of this still apply after the Phase 2 suspension?
Yes. On July 13, 2026 the Department of War suspended CMMC Phase 2 and opened a 60-day program review. That removed a certification gate — the requirement for third-party C3PAO certification as a condition of award — and nothing else. The obligations that generate the scores described on this page are untouched:
- • Phase 1 self-assessments — still required in new DoD solicitations.
- • SPRS scores — still submitted, still expected to be current, and still computed with the 5/3/1 weights above. Overstating one carries False Claims Act exposure.
- • DFARS 252.204-7012 — CUI safeguarding, incident reporting, and the NIST SP 800-171 controls themselves, all unchanged.
The deadline moved. The controls did not. Our living CMMC program status brief tracks what changed and what replaces Phase 2 as the review reports.
What this assessment is not
- • Not a formal CMMC assessment or certification. Only an authorized C3PAO can perform an official CMMC assessment. Results here are for planning purposes.
- • Not an SPRS submission. Nothing you enter is reported to any government system, and no score computed here is valid for SPRS.
- • Not evidence-based. Every answer is self-reported. The tool cannot see your systems and does not check any claim against artefacts.
- • Not requirement-level. Twelve questions cannot resolve 110 requirements. Two organisations with identical scores here can differ by hundreds of SPRS points.
Frequently asked questions
How is the CMMC readiness assessment scored?
Each of the 12 questions maps to one NIST SP 800-171 control family and is answered on a four-level scale: Not Started (0), In Progress (1), Implemented (2), Verified (3). Each answer is converted to a percentage of the maximum — 0%, 33%, 67%, or 100% — and the overall score is the unweighted average of the 12 family percentages, rounded to the nearest whole number. Any family scoring below 67% (that is, Not Started or In Progress) is flagged as a gap and listed worst-first.
Is this the same as my SPRS score?
No, and the difference matters. This tool averages 12 control families with equal weight. The official DoD Assessment Methodology scores all 110 individual requirements with unequal weights — 44 are worth 5 points, 14 are worth 3, and 51 are worth 1 — starting at 110 and deducting for each requirement not met, which is why the official range runs from +110 down to −203. A strong result here does not imply a strong SPRS score, because a handful of unmet 5-point requirements can drive an official score deeply negative while the family averages still look healthy. If you want the SPRS number itself rather than a maturity average, use our SPRS Score Calculator at cabrilloclub.com/insights/tools/sprs-score-calculator — it implements the DoD weights requirement by requirement, including both partial-credit paths and the System Security Plan gate.
Which NIST 800-171 control families does the assessment cover?
Twelve of the fourteen: Access Control (3.1), Awareness & Training (3.2), Audit & Accountability (3.3), Configuration Management (3.4), Identification & Authentication (3.5), Incident Response (3.6), Maintenance (3.7), Media Protection (3.8), Personnel Security (3.9), Risk Assessment (3.11), System & Communications Protection (3.13), and System & Information Integrity (3.14). Physical Protection (3.10) and Security Assessment (3.12) are not covered — the first needs a facility walkthrough rather than a self-rating, and the second turns on whether a System Security Plan exists at all.
What counts as a gap in the results?
Any control family scoring below 67% — meaning you answered Not Started or In Progress. Families answered Implemented or Verified are not flagged. Gaps are sorted lowest score first, so the top of the list is where the assessment thinks your next hour is best spent.
Which NIST 800-171 requirements are worth the most points?
Forty-four requirements are worth 5 points each under the DoD Assessment Methodology, including multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11). Those two carry built-in partial credit: 3.5.3 deducts 3 instead of 5 if MFA covers remote and privileged users but not all users, and 3.13.11 deducts 3 instead of 5 if encryption is employed but is not FIPS-validated.
Does a good score here mean we are CMMC certified?
No. This is a preliminary self-evaluation for planning purposes. It is not a formal CMMC assessment, certification, or compliance determination, and it produces no SPRS submission. Only an authorized C3PAO can perform an official CMMC assessment.
Does the CMMC Phase 2 suspension mean this no longer matters?
No. The Department of War suspended CMMC Phase 2 on July 13, 2026 pending a 60-day review, which removed a certification gate — not the underlying obligations. Phase 1 self-assessments, SPRS score submissions, and DFARS 252.204-7012 (CUI safeguarding and the NIST SP 800-171 controls themselves) all remain in force, and all of them are scored with the same weights described on this page.
Know the method? Go get your number.
The assessment takes about five minutes and gives you a ranked gap list. If the gaps look expensive, the 25-minute session is where we work out what your actual SPRS position is and what it costs to move it.
Source for all point values on this page: NIST SP 800-171 DoD Assessment Methodology v1.2.1 (June 24, 2020), Annex A and Section 5 — the same weights used in SPRS scoring.