Skip to main content
Lightbridge Cloud A Lightbridge.ai company

Free Readiness Assessment

NIST 800-171 / CMMC Level 2 Readiness Assessment

Lightbridge Cloud built the NIST 800-171 / CMMC Level 2 Readiness Assessment as a free, scored self-assessment across the 14 NIST SP 800-171 control families that CMMC Level 2 verifies. Answer 14 questions in about 10 minutes, see your overall readiness tier immediately, and unlock a full domain-by-domain breakdown by sharing your contact details.

14 questions. About 10 minutes. Free.

Step 1 of 5Access and Identity

Access and Identity

Access Control

How consistently does your organization limit system access to authorized users, processes, and devices, and enforce least privilege?

Not in placeFully implemented and documented

Identification and Authentication

How consistently do you verify the identity of users, processes, and devices before granting access, including multifactor authentication?

Not in placeFully implemented and documented

What We Measure

14 control families. One question each. One readiness tier.

NIST SP 800-171 organizes 110 controls into 14 families, and CMMC Level 2 verifies that same baseline. This assessment asks one readiness question per family so you can see where your program stands today, family by family.

01

Access Control

Who can reach a system holding CUI, and under what constraints. Covers account management, least privilege, and remote access.

What we ask

How consistently does your organization limit system access to authorized users, processes, and devices, and enforce least privilege?

02

Awareness and Training

Whether staff and administrators understand the security risks tied to their roles, including recognizing and reporting a potential incident.

What we ask

How well are your employees and administrators trained on security risks and their responsibilities for protecting Controlled Unclassified Information (CUI)?

03

Audit and Accountability

Whether activity on systems handling CUI is logged, protected from tampering, and actually reviewed, not just collected.

What we ask

How mature are your audit logging practices: are logs created, protected, retained, and reviewed to trace user activity and detect misuse?

04

Configuration Management

Whether systems run from a known, hardened baseline, with change control and limits on what software is allowed to run.

What we ask

Do you maintain baseline system configurations, control changes to them, and restrict unauthorized or unnecessary software?

05

Identification and Authentication

How identity is verified before access is granted, including whether multifactor authentication is in place for privileged and remote access.

What we ask

How consistently do you verify the identity of users, processes, and devices before granting access, including multifactor authentication?

06

Incident Response

Whether a documented plan exists for detecting, reporting, and recovering from a security incident, and whether anyone has tested it.

What we ask

Do you have a documented incident response plan, and have you tested your ability to detect, report, and recover from a security incident?

07

Maintenance

How system maintenance, including remote sessions, is authorized, monitored, and tied to a specific person and purpose.

What we ask

How well do you control and monitor system maintenance, including remote maintenance sessions and the tools and personnel used to perform it?

08

Media Protection

How digital and physical media carrying CUI is marked, protected, and sanitized before reuse, transport, or disposal.

What we ask

How consistently do you protect, mark, and sanitize digital and physical media containing CUI before reuse, transport, or disposal?

09

Personnel Security

Whether people are screened before they get access to CUI, and whether that access is revoked promptly when a role or employment changes.

What we ask

Do you screen individuals before granting them access to systems containing CUI, and revoke that access promptly when personnel depart or change roles?

10

Physical Protection

How physical access to the facilities and equipment that process or store CUI is controlled and monitored.

What we ask

How well do you control and monitor physical access to the facilities, equipment, and media where CUI is processed or stored?

11

Risk Assessment

How often the organization looks for risk, including vulnerability scanning, and whether findings turn into action.

What we ask

How regularly do you assess risk to your operations, assets, and systems, including scanning for vulnerabilities and acting on the results?

12

Security Assessment

Whether security controls are periodically tested for effectiveness, with a documented plan of action for anything that falls short.

What we ask

Do you periodically assess the effectiveness of your security controls and maintain a documented plan of action for any gap you find?

13

System and Communications Protection

How information is protected at system boundaries, including whether CUI is encrypted in transit.

What we ask

How well do you monitor, control, and protect information at the boundaries of your systems, including encrypting CUI in transit?

14

System and Information Integrity

How quickly flaws are found and fixed, and whether active protection against malicious code is in place.

What we ask

How quickly do you identify, report, and correct system flaws, and do you maintain active protection against malicious code?

This tool gauges readiness. It does not certify anything.

Lightbridge Cloud built this assessment to help a contractor prioritize where to focus, not to stand in for a required submission or an official finding. The result is a self-reported tier, not a Supplier Performance Risk System score, a C3PAO assessment, or a CMMC certification. Lightbridge Cloud is an independent, vendor-neutral readiness advisor: it prepares organizations for those outcomes, it does not issue them.

For the regulatory background behind these 14 families, read our guide to DFARS and NIST 800-171. For the structured engagement that follows a low or mixed readiness tier, see CMMC compliance and readiness advisory.

Part of a broader GovCon compliance picture.

CMMC is one piece of what a government contractor's cloud environment has to satisfy. The Cloud Services for Government Contractors hub maps the rest, from FedRAMP to GovCloud and Impact Levels to export control, and points to the right starting place for your situation.

NIST 800-171 / CMMC Level 2 Readiness Assessment: frequently asked questions

What does this NIST 800-171 / CMMC Level 2 Readiness Assessment measure?
It measures your self-reported readiness across the 14 NIST SP 800-171 control families that CMMC Level 2 is built on: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. One question per family produces an overall readiness tier and, once unlocked, a score for each family.
Is this the same as an official CMMC assessment or an SPRS score?
No. The Supplier Performance Risk System (SPRS) score comes from a DoD-defined methodology that weights and scores each of the 110 individual NIST SP 800-171 controls, not an average of 14 family-level questions. This tool gives a general readiness gauge to help you prioritize where to focus before a formal self-assessment or a C3PAO engagement, not a substitute for either. See our DFARS and NIST 800-171 guide for how SPRS scoring actually works.
Is Lightbridge Cloud a C3PAO, or does completing this tool certify my organization?
No to both. Lightbridge Cloud is an independent readiness advisory firm, not a CMMC Third-Party Assessment Organization, and this tool does not produce a certification decision. Only an accredited C3PAO, or DIBCAC for Level 3, can conduct the assessment that leads to CMMC certification. Lightbridge Cloud helps organizations prepare for that assessment; it does not perform it.
How long does the assessment take?
About 10 minutes. There are 14 questions, one per control family, grouped into 5 short steps so the pace stays manageable. Your overall readiness tier appears the moment you finish the last question.
Why do I have to share my contact details to see the full breakdown?
Your overall tier appears for free the moment you finish the 14 questions. The domain-by-domain breakdown, which names your strongest control family and your biggest gap, unlocks after you share your name, work email, and company, so a Lightbridge Cloud readiness advisor can follow up with real context rather than a generic reply.
Who should take this assessment?
IT leads, security officers, and compliance owners at organizations in the Defense Industrial Base that handle, or expect to handle, Controlled Unclassified Information. It is a useful starting point whether you are years into a CMMC program or have not yet scoped one.
What happens after I complete the assessment?
You see your full domain breakdown on screen immediately after you submit your details. A Lightbridge Cloud readiness advisor will also follow up within one business day to walk through your results and discuss whether a formal gap assessment makes sense for your environment.
Does completing this assessment satisfy any DoD or contract requirement?
No. This is an internal, preparatory exercise. It does not record a score in SPRS, does not substitute for a required NIST SP 800-171 self-assessment your contract may call for, and does not replace a C3PAO assessment where one is required. Treat it as a starting point for prioritizing your own program, not as a compliance deliverable.

From a self-reported tier to a defensible plan.

When your results point to real gaps, Lightbridge Cloud runs a full NIST 800-171 gap assessment and builds the System Security Plan and remediation roadmap a C3PAO assessment will hold you to.