Mark each of the 110 controls Met, Not met, or N/A. Your score updates live, from 110 down to -203, using the DoD Assessment Methodology v1.2.1 weights. Every control is explained in plain English.
Unanswered controls count as Not met, the way DoD scores them. Controls marked N/A deduct nothing, but only if your SSP explains why they do not apply. Rows tinted gold are also CMMC Level 1 controls.
Biggest deductions first. Fixing the 5-point controls moves the score fastest, and they are the ones DoD will not let you leave open on a POA&M.
The Supplier Performance Risk System score is DoD's shorthand for how much of NIST SP 800-171 Revision 2 you have actually implemented. It is a self-assessment: you score it, your Affirming Official signs it, and it goes into SPRS under DFARS 252.204-7019 and 7020 before any contract that involves CUI can be awarded.
Only two controls earn partial credit, and only while a plan is in progress: multi-factor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) deduct 3 instead of 5. Control 3.12.4, the System Security Plan, carries no points at all because DoD will not accept a submission without a current SSP. It is the document every other answer hangs on.
A score below 110 is allowed only with a Plan of Action and Milestones that gives every open control a date. Under the CMMC Level 2 self-assessment rules, 5-point and 3-point controls cannot stay on a POA&M at all. So "we're at 74 with a POA&M" can still be a failing self-assessment. And because certification is paused and the score is signed, an overstated score is a False Claims Act exposure rather than an audit finding.
CMMC Map walks the same 110 controls with evidence checklists, keeps your answers, and writes the System Security Plan, POA&M and 14 policies from them. The assessment is free.
Free to assess · No credit card · Documents from $149/mo