Gap analysis tool covering all 110 NIST SP 800-171 Rev 2 controls required for CMMC Level 2 certification. Built for defense contractors preparing for C3PAO assessment. No signup, no install, no data leaves your browser.
This is a free, browser-based gap analysis tool. Looking for full compliance management? Our Pro Assessment Tool adds SPRS scoring, POA&M management, evidence tracking, and executive reporting — all in your browser.
Need More?
The free tool is a browser-based gap analysis. The Professional Toolkit is an Excel workbook built for C3PAO assessment preparation.
| Feature | Free Tool | Professional |
|---|---|---|
| All 110 controls across 14 families | ✓ | ✓ |
| Basic SPRS scoring | ✓ | ✓ |
| Evidence notes per control | ✓ | ✓ |
| Save progress & export to CSV | ✓ | ✓ |
| Automated SPRS scoring with point values | — | ✓ |
| POA&M management with milestones | — | ✓ |
| Evidence tracker with control ownership | — | ✓ |
| Family-level gap analysis dashboard | — | ✓ |
| C3PAO readiness indicators | — | ✓ |
| Executive dashboard with charts | — | ✓ |
Or get all tools: Complete Assessment Suite — $1,299
What's Included
Complete coverage of NIST SP 800-171 Rev 2 controls across all 14 security families required for CMMC Level 2.
Weighted point values per control with automatic calculation against the 110-point maximum and 88-point certification threshold.
Plan of Action & Milestones tracking for controls not yet fully implemented.
Attach notes and evidence references to each control for C3PAO assessment readiness.
Save progress as JSON to continue later. Export to CSV for reporting and SSP documentation.
Runs entirely in your browser. No server connection — CUI-safe for preliminary assessments.
Methodology
CMMC Level 2 requires implementation of all 110 NIST SP 800-171 Rev 2 controls. The Supplier Performance Risk System (SPRS) uses weighted point values.
| Score | Status | Description |
|---|---|---|
| 110 | Met | Control is fully implemented and operational |
| 88+ | Conditional | Minimum threshold for certification with POA&Ms |
| < 88 | Not Met | Below certification threshold — remediation required |
| 0 | Not Assessed | Control has not been evaluated |
Getting Started
Click "Launch Tool" above. Everything runs in your browser — no CUI data is transmitted.
Start with any of the 14 NIST SP 800-171 security families.
Mark implementation status for each of the 110 controls.
Check your weighted score against the 88-point certification threshold.
Document plans of action for controls not yet fully implemented.
Save as JSON to continue later, or export to CSV for SSP documentation.
Free Assessment Tools