GrayVolk
GrayVolk
CMMC Level 2 · NIST SP 800-171

CMMC Level 2
Readiness Assessment.

Find out where you actually stand against all 14 CMMC Level 2 domains — in about half an hour, without booking a consultant. An AI assessor walks you through each domain in plain language, scores your readiness, and hands you a prioritized POA&M you can act on Monday morning.

Start your assessment  → See what you get  ↓

One-time fee, shown at checkout. No subscription. Private beta

All 14 Domains
Prioritized POA&M
~30 Minutes
Downloadable Report
Where Things Stand

Phase 2 is suspended.
Your obligations are not.

On July 13, 2026 the DoD CIO issued Memorandum 26-P-1023, suspending the transition to CMMC Phase 2 — previously set for November 10, 2026 — and placing the later phases in abeyance while a CMMC Reform Task Force conducts a 60-day review.

Read it closely and it is a pause, not a repeal. The CMMC program rule still stands, the DFARS was not amended, and Phase 1 obligations remain in force: Level 1 and Level 2 self-assessments still appear in new contracts, DFARS 252.204-7012 still applies, and your SPRS score is still a formal attestation that you sign.

Roughly 220,000 companies in the Defense Industrial Base remain in scope, most of them small shops with no dedicated security staff, held to the same NIST SP 800-171 bar as a prime contractor.

What moved is the deadline for third-party certification. What didn't move is that you are still accountable for NIST SP 800-171 — and still have to answer "how far off are we, and what do we fix first?"

Read the full analysis: what the suspension changes  →

What You Get

A readiness picture, not a checklist.

Free SPRS calculators give you a number. This gives you a judgment, the reasoning behind it, and an ordered list of what to do next.

🗂️

All 14 domains scored

Every CMMC Level 2 domain assessed as Met, Partial, Not Met or N/A — with the key gap named in plain language, not control-speak.

Scorecard
🎯

Prioritized POA&M skeleton

Your gaps ordered by what matters most, each with a suggested remediation and sequence — the starting structure for a real Plan of Action and Milestones.

Roadmap
💬

An adaptive interview

One to three questions per domain, adapted to your environment and your technical depth. No 320-row spreadsheet to interpret alone.

~30 min
📄

A report you can circulate

An executive-readable readiness report with an overall percentage, domain table and top priorities. Downloadable as PDF, saved to your account.

Deliverable
How It Works

Three steps, one sitting.

— The Process
01 · Answer the questions

The assessor opens with your environment — cloud or on-prem, identity provider, size, whether you handle CUI — then works through the 14 domains in order. Answer honestly; nobody is grading you yet.

02 · Watch the scorecard fill

Each domain is recorded as it's judged, so you can see the picture forming. Stop whenever you like and pick it up later — your progress follows your account, not your browser.

03 · Generate your report

When all 14 domains are covered, you get the readiness report: overall percentage, domain scorecard, top priorities, POA&M skeleton and a recommended next step.

Be Clear About Scope

What this is — and what it isn't.

It is a rapid, directional readiness pass: an informed view of where you stand across the 14 domains, what your biggest gaps are, and the order to tackle them in.

It is not an official CMMC assessment, an SPRS submission, or C3PAO certification. Only an authorized C3PAO can certify you at Level 2, and your SPRS affirmation is a formal attestation that carries real legal weight — which is precisely why software alone should never make that call for you.

Any vendor implying a scan can make you "CMMC compliant" is selling you risk. A tool can show you the gaps; a qualified human still has to close them and sign. We'd rather tell you that up front.
Where It Fits

The first step, not the whole journey.

Most contractors move through three stages. This assessment is stage one — deliberately cheap, fast and honest, so stage two is scoped correctly.

① AI Readiness Assessment

Where you stand today, in about 30 minutes. Directional scorecard and POA&M skeleton. You are here.

② Human Gap Engagement

A GrayVolk vCISO validates the findings, builds your SSP and a real POA&M, and runs the remediation roadmap with you.

③ C3PAO Certification

The formal Level 2 assessment by an authorized third party. We prepare you for it; we don't perform it — no one credible does both.

Questions

CMMC, answered plainly.

Is CMMC Phase 2 still happening in November 2026?

No — not on that date. DoD CIO Memorandum 26-P-1023, dated July 13, 2026, suspended the Phase 2 transition and placed later phases in abeyance pending a 60-day Reform Task Force review. It is a policy pause, not a repeal: Phase 1 self-assessment obligations remain in force. Full explainer →

What is CMMC Level 2?

Level 2 aligns with NIST SP 800-171 and applies to contractors handling CUI. It covers 110 security requirements, which assessors evaluate as 320 individual assessment objectives across 14 domains.

What are the 14 domains?

Access Control · Awareness & Training · Audit & Accountability · Configuration Management · Identification & Authentication · Incident Response · Maintenance · Media Protection · Personnel Security · Physical Protection · Risk Assessment · Security Assessment · System & Communications Protection · System & Information Integrity.

Is this an official CMMC assessment?

No. It's a directional self-assessment aid — not an official assessment, not an SPRS submission, not C3PAO certification. Its job is to show you where you stand before any of those.

How long does it take?

Most people finish in 20–40 minutes. You can stop and resume, and your report stays in your account so you can re-read or download it later.

Can I win contracts with an open POA&M?

Sometimes. Level 2 allows a limited POA&M pathway with closure required inside 180 days — but not every assessment objective is POA&M-eligible, so certain gaps must be closed before certification.

Do I need a C3PAO?

Eventually, for most CUI contracts — though the timing is now uncertain with Phase 2 suspended. Note that a C3PAO can't both consult for and certify the same client, which is why readiness and remediation happen separately, beforehand.

Who is behind the assessment?

GrayVolk, a vCISO practice working across CMMC, HIPAA and CLIA compliance and OT/ICS security. We also build and operate Klaviton, our own OT sensor platform — we run the architectures we recommend.

Start Here

Know where you stand
while you still have room to fix it.

All 14 domains, a prioritized POA&M, and a report you can put in front of your leadership — in about half an hour.