Find out where you actually stand against all 14 CMMC Level 2 domains — in about half an hour, without booking a consultant. An AI assessor walks you through each domain in plain language, scores your readiness, and hands you a prioritized POA&M you can act on Monday morning.
One-time fee, shown at checkout. No subscription. Private beta
On July 13, 2026 the DoD CIO issued Memorandum 26-P-1023, suspending the transition to CMMC Phase 2 — previously set for November 10, 2026 — and placing the later phases in abeyance while a CMMC Reform Task Force conducts a 60-day review.
Read it closely and it is a pause, not a repeal. The CMMC program rule still stands, the DFARS was not amended, and Phase 1 obligations remain in force: Level 1 and Level 2 self-assessments still appear in new contracts, DFARS 252.204-7012 still applies, and your SPRS score is still a formal attestation that you sign.
Roughly 220,000 companies in the Defense Industrial Base remain in scope, most of them small shops with no dedicated security staff, held to the same NIST SP 800-171 bar as a prime contractor.
Free SPRS calculators give you a number. This gives you a judgment, the reasoning behind it, and an ordered list of what to do next.
Every CMMC Level 2 domain assessed as Met, Partial, Not Met or N/A — with the key gap named in plain language, not control-speak.
ScorecardYour gaps ordered by what matters most, each with a suggested remediation and sequence — the starting structure for a real Plan of Action and Milestones.
RoadmapOne to three questions per domain, adapted to your environment and your technical depth. No 320-row spreadsheet to interpret alone.
~30 minAn executive-readable readiness report with an overall percentage, domain table and top priorities. Downloadable as PDF, saved to your account.
DeliverableThe assessor opens with your environment — cloud or on-prem, identity provider, size, whether you handle CUI — then works through the 14 domains in order. Answer honestly; nobody is grading you yet.
Each domain is recorded as it's judged, so you can see the picture forming. Stop whenever you like and pick it up later — your progress follows your account, not your browser.
When all 14 domains are covered, you get the readiness report: overall percentage, domain scorecard, top priorities, POA&M skeleton and a recommended next step.
It is a rapid, directional readiness pass: an informed view of where you stand across the 14 domains, what your biggest gaps are, and the order to tackle them in.
It is not an official CMMC assessment, an SPRS submission, or C3PAO certification. Only an authorized C3PAO can certify you at Level 2, and your SPRS affirmation is a formal attestation that carries real legal weight — which is precisely why software alone should never make that call for you.
Most contractors move through three stages. This assessment is stage one — deliberately cheap, fast and honest, so stage two is scoped correctly.
Where you stand today, in about 30 minutes. Directional scorecard and POA&M skeleton. You are here.
A GrayVolk vCISO validates the findings, builds your SSP and a real POA&M, and runs the remediation roadmap with you.
The formal Level 2 assessment by an authorized third party. We prepare you for it; we don't perform it — no one credible does both.
No — not on that date. DoD CIO Memorandum 26-P-1023, dated July 13, 2026, suspended the Phase 2 transition and placed later phases in abeyance pending a 60-day Reform Task Force review. It is a policy pause, not a repeal: Phase 1 self-assessment obligations remain in force. Full explainer →
Level 2 aligns with NIST SP 800-171 and applies to contractors handling CUI. It covers 110 security requirements, which assessors evaluate as 320 individual assessment objectives across 14 domains.
Access Control · Awareness & Training · Audit & Accountability · Configuration Management · Identification & Authentication · Incident Response · Maintenance · Media Protection · Personnel Security · Physical Protection · Risk Assessment · Security Assessment · System & Communications Protection · System & Information Integrity.
No. It's a directional self-assessment aid — not an official assessment, not an SPRS submission, not C3PAO certification. Its job is to show you where you stand before any of those.
Most people finish in 20–40 minutes. You can stop and resume, and your report stays in your account so you can re-read or download it later.
Sometimes. Level 2 allows a limited POA&M pathway with closure required inside 180 days — but not every assessment objective is POA&M-eligible, so certain gaps must be closed before certification.
Eventually, for most CUI contracts — though the timing is now uncertain with Phase 2 suspended. Note that a C3PAO can't both consult for and certify the same client, which is why readiness and remediation happen separately, beforehand.
GrayVolk, a vCISO practice working across CMMC, HIPAA and CLIA compliance and OT/ICS security. We also build and operate Klaviton, our own OT sensor platform — we run the architectures we recommend.
All 14 domains, a prioritized POA&M, and a report you can put in front of your leadership — in about half an hour.