ArcLight6 Consulting home
NIST SP 800-171 · CMMC

Find out where your CUI environment actually stands.

Nineteen plain-language questions across thirteen NIST SP 800-171 control families. It scores in your browser, tells you where you are strong as readily as where you are not, and takes about six minutes.

Answer as things actually are today, not as they are meant to be. “Not sure” is a real answer. It usually means a control exists but nobody can show it, which is its own finding.

{{ progressText }}
{{ qFamily }} {{ qText }}

{{ qWhy }}

Your result

{{ scorePct }}

{{ bandTitle }}

{{ bandSummary }}

{{ n.text }}

Regardless of the score

{{ b.text }}

What you are doing well

{{ strongLine }}

Where to start

  1. {{ w.title }} {{ w.body }}

Every family here scores at or above 75%. The useful next step is evidence: making sure each of these can be shown to an assessor rather than only described.

By control family

{{ f.name }} {{ f.ref }} {{ f.pct }}

{{ coverageNote }}

Send this to ArcLight6

Sending opens your own mail client with these figures. The page itself still transmits nothing. The result link in the address bar reproduces this page exactly.

Scoring runs in the browser and needs JavaScript. The full question set is below, and can be worked through and printed as a worksheet without it.

The questions

Score each answer Yes = 1 · Partially = 0.5 · No = 0 · Not sure = 0, average within each control family, then across all 19 questions. Covers 13 of the 14 SP 800-171 families; Maintenance (3.7) is not assessed here.

  1. Access Control · 3.1.1, 3.1.2

    Do you know every system, application, and cloud service that holds or touches CUI, and is access to each limited to named, authorized people?

    You cannot protect data whose location you cannot list. This is the first control in the standard and the first thing an assessor asks for.

  2. Access Control · 3.1.12, 3.1.20

    Is remote access (VPN, remote desktop, contractor laptops, personal devices) approved in advance and monitored?

    Remote and external connections are the most common route into a small contractor network.

  3. Awareness & Training · 3.2.1, 3.2.2

    Does everyone who handles CUI get security awareness training when they join and at least once a year after that?

    Training is cheap, it is checkable, and its absence is an easy finding against you.

  4. Audit & Accountability · 3.3.1, 3.3.2

    Do your systems keep logs of who did what, and are those logs retained long enough to investigate an incident weeks later?

    Without retained logs an incident cannot be scoped, and an unscoped incident has to be reported at its worst plausible extent.

  5. Audit & Accountability · 3.3.3, 3.3.5

    Does somebody actually review those logs on a schedule, or does an alerting tool review them for you?

    Collecting logs nobody reads satisfies nobody, not the standard and not an incident timeline.

  6. Configuration Management · 3.4.1, 3.4.2

    Do you have a documented standard build for laptops and servers, and do machines actually get built that way?

    A baseline is what makes "is this machine configured correctly?" a question with an answer.

  7. Configuration Management · 3.4.6, 3.4.9

    Do you control what software users can install, and do you have a list of what is approved?

    Unmanaged software is the usual source of both vulnerabilities and license surprises.

  8. Identification & Authentication · 3.5.1, 3.5.2

    Does every person have their own named account, with no shared logins and no shared admin passwords?

    Shared accounts make accountability impossible and break most of the audit family with a single practice.

  9. Identification & Authentication · 3.5.3

    Is multi-factor authentication required for remote access, email, and all privileged accounts?

    MFA is explicitly required, and it is the single highest-value control on this list.

  10. Incident Response · 3.6.1, 3.6.2, 3.6.3

    Is there a written incident response plan that names who to call, and has anyone walked through it in the last year?

    DoD reporting timelines are measured in hours. A plan first read during an incident is not a plan.

  11. Media Protection · 3.8.3, 3.8.7

    Are drives, laptops, and USB media wiped or destroyed before disposal or reuse, and is removable media use controlled?

    Disposal is where CUI most often leaves an organization unnoticed.

  12. Personnel Security · 3.9.1, 3.9.2

    Are people screened before they get access to CUI, and is access removed the same day someone leaves or changes role?

    Stale accounts belonging to former staff are a standard finding and a standard breach path.

  13. Physical Protection · 3.10.1, 3.10.3, 3.10.6

    Is physical access to offices, server rooms, and home-office equipment limited and are visitors escorted?

    Physical protection covers home offices too, which is where most contractor work now happens.

  14. Risk Assessment · 3.11.2, 3.11.3

    Do you scan for vulnerabilities on a schedule and fix what you find within a defined timeframe?

    Scanning without a remediation clock produces a backlog, not a risk reduction.

  15. Security Assessment · 3.12.4

    Do you have a current System Security Plan (SSP) describing your environment and how each requirement is met?

    The SSP is mandatory. Without one there is nothing to assess, and no basis for a SPRS score.

  16. Security Assessment · 3.12.2

    Do you track unmet requirements in a Plan of Action & Milestones (POA&M) with owners and dates?

    A POA&M is how partial compliance is legitimately represented. Its absence turns gaps into misstatements.

  17. System & Communications Protection · 3.13.1, 3.13.5

    Is your network segmented so that systems holding CUI are separated from guest wi-fi, personal devices, and general traffic?

    Segmentation is what keeps the assessment boundary small, and with it the cost of compliance.

  18. System & Communications Protection · 3.13.8, 3.13.11, 3.13.16

    Is CUI encrypted both when stored and when sent, using FIPS-validated cryptography?

    FIPS validation is a specific requirement. "we use encryption" is not the same claim.

  19. System & Information Integrity · 3.14.1, 3.14.2, 3.14.6

    Are security patches applied on a defined schedule, with malware protection and monitoring in place on endpoints?

    Unpatched, unmonitored endpoints are the most exploited weakness in the defense industrial base.

What this is, and what it is not

This is a self-assessment indicator. It is not a formal gap analysis, not a CMMC assessment, and not a SPRS score. It reflects only what you tell it, covers thirteen of the fourteen SP 800-171 families, and nothing you enter is verified against your environment. A real assessment examines evidence; this examines your own view of your environment. That is a useful and honest place to start, and nothing more.

Your answers are not submitted, logged, or stored on any server. They stay in this browser tab so a refresh does not lose your place, and are cleared when you choose “Start again”.

Want the version that examines evidence rather than opinion? That is a scoped gap analysis, and it starts with a conversation.

Schedule a consultation
ArcLight6 Consulting LLC · 2020 N Academy Blvd #290, Colorado Springs, CO 80909 · 1-719-301-6280