Free · Takes 5 Minutes · No Commitment

How Ready Are You for CMMC Compliance?

CMMC Level 2 is not a form you file. It means bringing your environment up to 110 security controls and proving it through a formal assessment. Most contractors are only partway there, so the real work ahead is remediation. This five-minute check shows where you stand, and where Dynamic Quest's certified enclave lets you inherit the controls instead of building them. Free, and no technical jargon.

Dynamic Quest is CMMC Level 2 certified, 110 of 110, verifiable in SPRS.

Free · 20 Questions · 5–10 Minutes

Let's Find Out Where You Stand

If you hold a DoD contract or you're pursuing one, reaching CMMC Level 2 usually means closing real gaps across the 110 controls and demonstrating compliance through a formal assessment. The median contractor sits at 60 of 110 today, (2025 State of the DIB Report), so most have roughly fifty controls left to remediate. This tool is the first step, a quick and honest read on where you stand. The expensive part is the remediation and the build, and that is exactly where Dynamic Quest's certified enclave lets you inherit the controls instead of building them, which saves both time and cost.

You'll move through 20 questions covering your contracts, IT environment, security controls, and team readiness. At the end, you'll get an instant score and a breakdown of your biggest gaps, mapped to the CMMC control domains. This tool focuses on the highest-impact controls. To achieve full coverage across all 110 NIST 800-171 practices, you'll need to complete a formal gap assessment.

A few details about your organization first. These help us tailor your results so the findings are specific to your situation, not generic.

About You Contract Status IT Environment Security Posture Your Team
Section 1 of 4

Contracts & CUI Exposure

These questions determine which CMMC level applies to you, and how urgent your timeline is.

What is CUI? Controlled Unclassified Information (CUI) is any government-created or government-related information that requires protection but isn't classified. In defense contracting, this includes technical drawings, specifications, test results, engineering data, contract details, and email correspondence tied to a DoD program. A common question we hear: "If a drawing has measurements on it, is it CUI? If I remove the measurements, is it no longer CUI?" Our answer: when in doubt, treat it as CUI. Erring on the side of conservatism is the only safe approach. The cost of getting it wrong is losing your contract.
1. Do you currently hold a DoD contract or are you a subcontractor to a prime DoD contractor?
This includes any agreement where you deliver goods or services that support a Department of Defense program, directly or through a prime.
1b. What portion of your business involves DoD contracts or defense work?
Why this matters: If your defense work is a subset of a larger business, you may be able to create a CMMC enclave, a protected segment covering only CUI-handling systems, rather than applying CMMC requirements organization-wide. This can significantly reduce cost and complexity.
2. Does your organization handle Controlled Unclassified Information (CUI)?
Examples: DoD technical drawings, engineering specifications, contract terms, test reports, or any data your prime has marked as sensitive or distribution-limited.
3. Has your prime contractor asked you for CMMC documentation or compliance evidence?
4. Has your organization submitted a current SPRS (Supplier Performance Risk System) self-assessment score?
SPRS is the DoD system where contractors self-report their cybersecurity score. Without a submitted score, you may already be ineligible for some new solicitations.

Why this matters: If your organization holds a DoD contract, you likely already attested to NIST 800-171 compliance when you signed it. CMMC is the enforcement of that existing requirement, not a new one. Some organizations deliberately avoid submitting an SPRS score because submitting one with known gaps creates a documented legal obligation to remediate. Submitting an accurate SPRS score is still the right path, but it requires having a remediation plan in place, and it should be filed specifically as a Level 2 Self-Assessment (Level 1 does not satisfy CUI-handling contract clauses).
5. Does your organization use offshore or foreign-operated IT support services (e.g., a managed helpdesk or NOC based outside the US)?
This includes outsourced IT support, cloud service providers, or helpdesk vendors where technicians may be located outside the United States.
About You Contract Status IT Environment Security Posture Your Team
Section 2 of 4

Your IT Environment

The way your systems are set up directly determines how much work is needed to achieve compliance, and how to minimize your assessment scope.

Scope is everything, and scope creep is the #1 cost driver. Some organizations have everything in scope by design (pure-play defense work, no commercial side), and that's a legitimate posture. For most, though, scope can be narrowed by mapping exactly who touches CUI, where it's stored, and how it flows, then isolating those systems into a defined boundary (a "CUI enclave") and certifying only that. We've seen organizations cut their CMMC cost by more than half simply by correctly defining scope before remediation begins. These questions help us assess where you currently stand.
6. What email and productivity platform does your organization primarily use?
7. Where is your CUI (or potentially CUI-related data) currently stored?
Select all that apply.
8. Have you defined and documented a CUI boundary?
This is the set of systems that store, process, or transmit CUI. It defines your System Security Plan (SSP) scope, the foundation of your C3PAO assessment.
9. Does your organization have employees who work remotely or at multiple locations?
Each location where CUI is processed, stored, or transmitted falls within your CMMC assessment scope, including remote workers connecting from home networks and any secondary office sites.
10. Do you use any cloud services, SaaS tools, or third-party vendors that have access to your systems or data?
Examples: managed IT provider, payroll system, CRM, ERP, or any cloud app used in operations.
About You Contract Status IT Environment Security Posture Your Team
Section 3 of 4

Security Controls & Posture

CMMC Level 2 requires 110 controls across 14 domains. These questions assess which foundational controls are already in place.

11. Is Multi-Factor Authentication (MFA) enforced across your organization?
MFA means users must verify their identity with a second factor in addition to their password, for ALL systems, not just email. NIST SP 800-63B is moving away from SMS-based MFA toward FIPS-validated methods (authenticator apps, hardware security keys, smart cards). Plan toward those for CUI-handling systems.
12. Does your organization have a documented and tested Incident Response Plan?
CMMC requires a tested, documented process for detecting, reporting, and recovering from a cybersecurity incident, including a 72-hour CUI breach notification requirement to the DoD.
13. Do you have continuous security monitoring (SIEM / SOC) for your environment?
CMMC Level 2 requires continuous monitoring and log management with a documented response process. 24/7 SOC coverage is highly recommended and is required at Level 3, but is not specifically mandated by NIST 800-171 at Level 2, though some contracts (e.g., DFARS 7012 conditions on CUI handling) may impose stricter requirements. Standard antivirus or basic endpoint protection alone is not sufficient.
14. How would you describe your current vulnerability management process?
Vulnerability management includes the discovery, reporting, and remediation of vulnerabilities within the system.
15. Does your organization provide cybersecurity awareness training to all employees at least annually?
This includes phishing simulation, acceptable use training, and CUI handling procedures, and must be documented for CMMC audit purposes.
About You Contract Status IT Environment Security Posture Your Team
Section 4 of 4

Your Team & Internal Readiness

CMMC compliance is not just an IT project. It requires leadership buy-in, dedicated ownership, and cross-functional coordination.

CMMC is a culture, not an IT project. The most prepared organizations we work with are ones where IT leadership has helped the whole company understand this. As one defense manufacturer put it: "This is not just an IT thing. It is a culture that deals with everything from HR to building and grounds to security." That framing is exactly right. And it starts with leadership understanding what they're being asked to attest to, personally, under federal law.
16. Who currently owns cybersecurity and IT compliance at your organization?
17. Does your leadership team understand what CMMC requires and their personal liability in signing the attestation?
18. Has your organization completed a formal CMMC or NIST 800-171 gap assessment?
19. What is your target timeline to achieve CMMC Level 2 certification?
20. What would be most helpful to you right now?
Select all that apply. This shapes your results and recommendations.
📋
Get Your Full CMMC Readiness Report
Your full report maps every gap to the CMMC control domains, shows your priority remediation steps, and includes a timeline estimate, personalized to your organization's answers.
By submitting, you agree to our Privacy Policy and consent to be contacted by a Dynamic Quest CMMC specialist to review your results.

1%

of defense contractors say they are fully ready for CMMC, down from 4% a year earlier

12–24 mo

to reach CMMC Level 2 on your own

fewer than

0.05%

of MSPs are certified to run a compliant CMMC enclave.

Sources: contractor readiness, 2025 State of the DIB Report (CyberSheath / Merrill Research), 1% in 2025, down from 4% in 2024 and 8% in 2023. Level 2 timeline, 2026 industry estimates. MSP certification rate, Dynamic Quest analysis of certified providers nationally.

What you'll get

A personalized CMMC readiness report, on screen the moment you finish. Five minutes, free, no jargon.

Engage with us

Your CMMC readiness starts with
a conversation

A focused 30 minutes with a CMMC specialist on our team. We'll discuss your contract environment, where you are in the readiness cycle, and what engaging Dynamic Quest would look like in practice, including whether engaging us is the right move at all.