A CMMC readiness assessment shows you where you stand against CMMC Level 1 and Level 2 before an assessor does. If you do work for the Department of Defense, directly or as a subcontractor, your contracts may require you to protect federal contract information and controlled unclassified information (CUI). The Cybersecurity Maturity Model Certification (CMMC) is how that protection is checked. Finding out about gaps during a formal assessment is expensive. Finding out beforehand is much cheaper.

Zippie IT, a veteran-owned company in Meridian, Idaho, performs the CMMC readiness assessment for small businesses. We measure your current position, tell you plainly what is missing and give you a plan to close the gaps.
Which level do you need?
Your contract decides. The prime contractor or the contracting officer should tell you which level applies.
- Level 1 covers federal contract information. It has 15 basic safeguarding requirements from FAR 52.204-21, such as limiting access to authorized users, keeping software updated and using antivirus. It is a yearly self-assessment, and a company official affirms the result.
- Level 2 covers CUI. It is built on the 110 requirements in NIST SP 800-171 Revision 2, and some contracts require an assessment by an authorized third-party assessor (a C3PAO).
If you are not sure which applies, send us the contract clause and we will help you read it.
What the CMMC readiness assessment includes
- A scoped boundary. We work out which systems, people, locations and cloud services handle federal information, because the boundary decides how much work you face.
- A requirement-by-requirement review. Level 1: all 15 requirements. Level 2: all 110, using the DoD scoring method that gives a score from 110 down to -203.
- An estimated score and a gap list. You see what each missing item costs you in points and which ones can wait on a plan of action and milestones (POA&M) and which cannot.
- A draft System Security Plan and POA&M for Level 2. Without a current plan, a Level 2 assessment cannot be completed.
- A written report and a roadmap in priority order, with owners and target dates.
Why the score matters
Under the DoD method, every unmet Level 2 requirement subtracts 1, 3 or 5 points from 110. To qualify for a conditional status that allows a plan of action, a company needs a score of at least 88, and the open items must be of a kind the rules allow. Some requirements can never be left open. Those are the gaps we flag first, because they block everything else.
What happens after the CMMC readiness assessment
We can fix the gaps for you, or work alongside your own staff. Common projects include multi-factor authentication, encryption, device management, logging, backups, written policies and security awareness training. Our managed IT services and cybersecurity services cover much of the day-to-day work, and a vCIO can keep your documentation and plan current.
What this is not
This CMMC readiness assessment is not a CMMC assessment by an authorized assessor. Only an authorized third-party assessor or the government can produce an official result, and only an authorized company official can sign the required affirmation. We are not a C3PAO. We help you walk in prepared, and we do not guarantee any outcome. The rules and timelines for CMMC have changed more than once, so we check the current requirements for your contract before we begin.
Get started
To book a CMMC readiness assessment, tell us which contract you are working under and roughly how many people and locations are involved. We will explain the fee, which is fixed by company size, and the timeline. Contact us or call (208) 810-1795. You can also start with a free network review.
We use your details to respond to your request. If you want details, see our Privacy Policy.
Frequently asked questions
Do I need CMMC if I am a subcontractor?
If the contract passes down a clause that requires it, yes. Requirements flow from the prime contractor to subcontractors that handle federal contract information or CUI, so check your subcontract.
What is the difference between Level 1 and Level 2?
Level 1 protects federal contract information with 15 basic practices and a yearly self-assessment. Level 2 protects CUI with the 110 requirements of NIST SP 800-171 and may require a third-party assessment.
Can you certify us for CMMC?
No. Only an authorized third-party assessor or the government can produce an official CMMC result. We assess your readiness and help you fix the gaps beforehand.
What is an SPRS score?
It is the score you report to the Department of Defense for NIST SP 800-171 compliance. It starts at 110 and subtracts points for each requirement that is not met, down to a minimum of -203.
How long does a readiness assessment take?
A Level 1 assessment takes a few weeks. A Level 2 assessment takes longer because it covers 110 requirements and a draft security plan. We give you a timeline once we know your size and scope.
Can we use Microsoft 365 for CUI?
Often only certain Microsoft cloud offerings meet the requirements for CUI, and the right choice depends on your contract. We review this during scoping.
