How mature is your IT, really? A Architecture & Engineering self-assessment

25 questions, about seven minutes, no email address required. The scoring happens right here in your browser either way. By default we also record your answers so we can see how this lands – one click on the checkbox below the score button turns that off, and the score still shows exactly the same.

Running an Architecture & Engineering business

1. Which design tools are central to your work?
2. Are live project models and CAD files backed up in a way you could roll back by the hour?

A corrupted central model at 4pm on a deadline is the scenario that decides whether the backup design was good enough.

3. How do you exchange models with consultants and contractors?
4. Can staff work on large models from home without it being painful?
5. If a project architect left tomorrow, would you know what they took with them?
6. Do you take federal, defence or critical-infrastructure work that carries NIST 800-171 / CMMC flow-down?

The DFARS clause activating CMMC took effect in November 2025, and third-party assessment becomes mandatory for most Level 2 contracts from November 2026.

7. Do your federal contracts involve controlled unclassified information, or only federal contract information?

This is the question that sets your scope, and getting it wrong is expensive in both directions. FCI points at CMMC Level 1 and a short list of practices; CUI points at Level 2 and NIST 800-171 in full.

8. If you handle CUI, is it kept inside a defined boundary rather than spread across the network?

An enclave or a GCC High tenancy keeps the assessment to the part of the business that touches the work. Without one, the scope is everything you own, which is what makes Level 2 unaffordable for firms your size.

The basics

9. Are your systems and data backed up automatically, every day?

File sync is not backup. OneDrive, Dropbox, Google Drive and SharePoint copy your mistakes and your ransomware to the cloud just as faithfully as your work. What counts here is a separate, versioned copy you could restore from after the original was encrypted.

10. When did somebody last actually RESTORE from a backup to prove it works?

A backup nobody has restored from is a hypothesis, not a backup.

11. Is multi-factor authentication switched on for email and remote access?

Partial MFA is not partial compliance. Almost every rule that applies to you treats this as a yes or no, so this answer can cap the whole result on its own.

12. Do you carry cyber-liability insurance?
13. How do computers and servers get their security updates?
14. What protects the laptops and desktops?
15. Is there anything in front of your email beyond the built-in spam filter?

Phishing is still how most of these firms actually get hit.

16. When somebody leaves, how quickly do their accounts get shut off?
17. Who owns IT day to day?
18. If your main systems were unavailable tomorrow morning, is there a written plan?
19. Do people here get security training, and does anyone test whether it stuck?

Almost every incident starts with somebody being convinced to do something reasonable-looking. Training that is watched once at induction and never tested is a record that it happened, not a defence.

20. When did somebody last check WHO can reach what, and take away the access they no longer need?

Access accumulates. People change roles and keep the old permissions, and the account that gets compromised is usually the one that could reach far more than that person's job required.

21. Do you know which apps and cloud services your team signed up for without telling anyone?

Not a discipline question. Client data ends up in whatever tool made somebody's week easier, and you cannot protect, back up or hand back data you do not know exists.

Where you stand on compliance

22. Where do you operate?

We are Seattle based, so where a rule below is named, it is the Washington one. If you work elsewhere there is almost always a state equivalent and the question is the same. This answer is not scored.

23. Do you have a written information security program covering NIST 800-171 / CMMC (federal subset only)?
24. When was your last written risk assessment?
25. If a client, an auditor or an insurer asked you to evidence your controls this week, could you?

Not whether the controls exist – whether you can PROVE they do.

26. Is there an incident-response plan naming who does what, and by when?
27. Do you check the security of the vendors who touch your client data?