The Twenty Questions
Twenty questions across all fourteen NIST SP 800-171 control families. You get a read on which families you appear to have covered and which are worth looking at first. No score, no form, nothing stored — and an honest statement of what twenty questions cannot tell you.
Turning the Fog Into a Punch List
Most shops do not stall on CMMC because they think they are compliant. They stall because the requirement is a fog — 110 controls means nothing when you cannot tell whether you are near the start or near the end.
This turns the fog into a shape. It will not tell you your score, and it is designed so that it cannot. What it will tell you is which of the fourteen families you appear to have real coverage in, and which ones nothing in your answers touched.
If you have internal IT and a decent tool stack, expect to look strong on identity, access and endpoints — and to find very little under audit logging, security assessment and media protection. That pattern is not a trick in the questions. It is what happens when a market sells products for the controls a product can satisfy, and nobody sells anything for the rest.
Answer Honestly — “Not Sure” Counts
“Not sure” is the most useful answer here. For an assessor it means the same thing as no evidence, so it is worth knowing where yours are.
One question at a time, four answers each, about two minutes. You can stop and close it at any point — nothing is saved, so nothing is held against you either.
- All fourteen NIST SP 800-171 control families
- No score of any kind, and no form to fill in first
- “Not sure” is a real answer — and often the useful one
What Twenty Questions Cannot Tell You
What this is not
This is not an assessment. It is a self-reported snapshot built from twenty questions, and twenty questions cannot cover 110 controls and 320 assessment objectives. It is not a gap assessment, it is not an input to a System Security Plan, it does not follow the scoring methodology in NIST SP 800-171A, and it deliberately produces no score of any kind — nothing here should ever be posted to SPRS or used to support any representation you make to a customer or to the government. It tells you which families are worth looking at first. Nothing more than that.
Why there is no score
The NIST SP 800-171 scoring methodology runs from −203 to 110, and the number it produces goes into SPRS as a representation you make to the government. A twenty-question web form cannot produce that number responsibly, so this one does not produce a number at all.
That is not caution for its own sake. In June 2026 the Department of Justice settled with a defense contractor for $507,144 over a posted score of 110 against an environment a government assessment put at negative 170. A figure from a website is not a defensible basis for anything you post. Getting to a real number means the actual scoring methodology applied to your actual environment.
Book a CMMC Readiness Call
Thirty minutes. We review your contract requirements, identify your top compliance gaps, and give you a realistic timeline to audit readiness. No pitch decks, no obligation.
Book Your Call →