Full CMMC Level 2 / NIST SP 800-171 Mock Assessment

Itwerx is a Seattle-area managed IT provider, and this mock assessment walks businesses through all 14 NIST SP 800-171 control families in plain language. It is an indicative self-assessment, not an assessment of record.

This is an indicative self-assessment, not an assessment of record. It walks through all fourteen NIST SP 800-171 control families in plain language, so you can get an honest read on where you stand before a real assessment is ever on the table. Answer as best you can without looking anything up: not knowing an answer is itself useful information. A genuine CMMC Level 2 assessment is a different thing entirely, performed by an accredited third-party assessment organization against the actual control language, with evidence, and this questionnaire does not replace, certify, or substitute for that process.

Access Control

1. Does every employee log in with their own username and password, rather than a shared login?

Practice reference: AC.L2-3.1.1 – identify and authenticate each user individually.

2. Do people only have access to the systems and folders their job actually needs, or can everyone see everything?

Practice reference: AC.L2-3.1.2 and AC.L2-3.1.5 – limit access to what a role requires.

3. Do the people with administrator rights use a separate admin account only when doing admin work, rather than being logged in as admin all day?

Practice reference: AC.L2-3.1.5 – separate privileged accounts from everyday accounts.

4. When people connect to your systems from outside the office, is that connection encrypted and controlled, rather than open to anyone on the internet?

Practice reference: AC.L2-3.1.12 through 3.1.14 – monitor and control remote access sessions.

5. Do computers lock automatically after a few minutes of not being used?

Practice reference: AC.L2-3.1.10 – session lock with pattern-hiding display.

6. Are personal or unknown USB drives blocked or restricted from connecting to work computers?

Practice reference: AC.L2-3.1.21 – limit use of portable storage devices.

7. Is your guest wifi, the one visitors use, kept separate from the network your business systems run on?

Practice reference: AC.L2-3.1.20 – control connections from external systems.

Awareness and Training

8. Do new employees get any security training when they start, such as which emails to distrust?

Practice reference: AT.L2-3.2.1 – security awareness as part of onboarding.

9. Do all employees get refresher security training at least once a year?

Practice reference: AT.L2-3.2.1 – periodic security awareness training.

10. Have you ever run a practice phishing test to see how employees respond?

Practice reference: AT.L2-3.2.2 – role-based and insider-threat awareness training.

Audit and Accountability

11. Do your systems keep logs of who logged in and what they did?

Practice reference: AU.L2-3.3.1 – create and retain system audit logs.

12. Does anyone actually look at those logs, or do they just sit there unread?

Practice reference: AU.L2-3.3.5 – review and investigate audit records.

13. How long are those logs kept before they get deleted?

Practice reference: AU.L2-3.3.1 – retain audit records for a defined period.

14. Are your logs protected from being changed or deleted by a regular employee?

Practice reference: AU.L2-3.3.8 – protect audit information from unauthorized modification.

15. Are your systems' clocks synchronized, so that log timestamps actually line up with each other?

Practice reference: AU.L2-3.3.7 – use an authoritative time source for audit records.

Configuration Management

16. Do new computers get set up from a standard, secure configuration, rather than however IT feels that day?

Practice reference: CM.L2-3.4.1 – establish and maintain baseline configurations.

17. Are changes to important systems reviewed by someone before they go live?

Practice reference: CM.L2-3.4.3 – track, review, approve and log changes.

18. Is there anything stopping employees from installing whatever software they want on a work computer?

Practice reference: CM.L2-3.4.8 and 3.4.9 – restrict and control software installation.

19. Do you have an up to date list of every computer, server and device on your network?

Practice reference: CM.L2-3.4.1 – inventory of organizational systems.

Identification and Authentication

20. Is multi-factor authentication required for email and any remote access to your systems?

Practice reference: IA.L2-3.5.3 – multifactor authentication for local and network access.

21. Are employees required to use strong, unique passwords, rather than something like Password1 or the same one everywhere?

Practice reference: IA.L2-3.5.7 through 3.5.10 – password complexity and reuse rules.

22. Do employees use a password manager, rather than sticky notes or a shared spreadsheet?

A password manager is the single easiest way to make a strong-password rule actually stick.

23. How many logins at your company are shared between more than one person?

Practice reference: IA.L2-3.5.1 – identify each user, process and device uniquely.

24. Do only company-approved devices connect to your business systems, or can any personal device log in?

Practice reference: IA.L2-3.5.2 – authenticate devices before establishing a connection.

25. When a vendor or IT provider needs remote access, do they use a unique, time-limited login rather than a permanent shared one?

Practice reference: IA.L2-3.5.1 – unique identification extends to external maintainers too.

Incident Response

26. Is there a written plan for what to do if you suspect a breach or a ransomware attack?

Practice reference: IR.L2-3.6.1 – establish an operational incident-handling capability.

27. Has that plan ever actually been walked through or tested, even informally?

Practice reference: IR.L2-3.6.2 – track, document and report incidents; a plan nobody has run through is untested.

28. Do employees know who to tell immediately if they click a bad link or think something is wrong?

Practice reference: IR.L2-3.6.1 – a plan only works if people know to trigger it.

29. Would you know who to call, such as law enforcement, a forensics firm, or your insurer, within the first hour of a real incident?

Practice reference: IR.L2-3.6.1 – the external-contacts half of incident handling.

30. After a security incident, even a near miss, do you review what happened and change anything as a result?

Practice reference: IR.L2-3.6.2 – lessons learned as part of incident tracking and reporting.

Maintenance

31. Is there a regular schedule for maintaining and patching servers and network equipment, not just laptops?

Practice reference: MA.L2-3.7.1 – perform maintenance on organizational systems.

32. When your IT provider does remote maintenance, is that access logged and time-limited?

Practice reference: MA.L2-3.7.5 – require multifactor authentication and session termination for remote maintenance.

33. Do you track which hardware and software are approaching the end of vendor support, so they get replaced before they become a liability?

Practice reference: MA.L2-3.7.1 – maintenance planning depends on knowing what is aging out.

Media Protection

34. Are laptop hard drives encrypted, so a lost or stolen laptop cannot just be read by whoever finds it?

Practice reference: MP.L2-3.8.6 – cryptographic protection of data at rest on portable media.

35. Is there a policy controlling how sensitive data can be copied onto USB drives or other removable media?

Practice reference: MP.L2-3.8.1 and 3.8.7 – protect and control system media.

36. When old computers, drives or copiers are retired, is the data on them destroyed or wiped before disposal?

Practice reference: MP.L2-3.8.3 – sanitize or destroy media before disposal or reuse.

37. If you keep backup copies of data, are those backups protected as carefully as the live data, meaning encrypted and access controlled?

Practice reference: MP.L2-3.8.9 – protect backup information at storage locations.

Personnel Security

38. Do employees who will handle sensitive data or systems go through any kind of background check before they start?

Practice reference: PS.L2-3.9.1 – screen individuals before authorizing access.

39. When someone leaves the company, is their access shut off the same day?

Practice reference: PS.L2-3.9.2 – protect systems during and after personnel actions like termination.

40. Do employees sign anything acknowledging their responsibility to protect sensitive data?

Practice reference: PS.L2-3.9.1 – part of screening and onboarding accountability.

Physical Protection

41. Is access to your office or facility controlled, with locked doors, badges, or sign-in, so a stranger cannot just walk in?

Practice reference: PE.L2-3.10.1 – limit physical access to organizational systems and facilities.

42. Are your servers and network equipment kept in a locked room or cabinet that only a few people can access?

Practice reference: PE.L2-3.10.1 – physical access control for critical equipment specifically.

43. Are visitors to areas with sensitive equipment or paperwork logged or escorted?

Practice reference: PE.L2-3.10.3 – escort visitors and monitor visitor activity.

44. Is sensitive paperwork secured, locked away, when nobody is at the desk, rather than left out?

Practice reference: PE.L2-3.10.1 – physical protection extends to documents, not just equipment.

Risk Assessment

45. When was your last written assessment of your security risks?

Practice reference: RA.L2-3.11.1 – periodically assess risk to operations and assets.

46. Do you run any kind of scan to look for known weaknesses in your systems, even a basic one?

Practice reference: RA.L2-3.11.2 – scan for vulnerabilities periodically.

47. When a risk or weakness is found, is there a process to track it until it is actually fixed?

Practice reference: RA.L2-3.11.3 – remediate vulnerabilities in accordance with assessments.

Security Assessment

48. Aside from this questionnaire, has anyone reviewed your security controls against a recognized standard in the last year?

Practice reference: CA.L2-3.12.1 – periodically assess security controls.

49. If gaps were found, is there a written plan, with target dates, to close them?

Practice reference: CA.L2-3.12.2 – plans of action to correct deficiencies.

50. Has an outside party ever tested or reviewed your security, such as a scan, an audit, or a penetration test?

Practice reference: CA.L2-3.12.1 – independent assessment strengthens a self-assessment.

System and Communications Protection

51. Is there a properly configured firewall between your office network and the internet, beyond just what came built into the router?

Practice reference: SC.L2-3.13.1 – monitor and control communications at external boundaries.

52. Are more sensitive systems, such as servers holding client data, kept on a separate part of the network from everyday user computers?

Practice reference: SC.L2-3.13.2 and 3.13.5 – architecturally separate publicly accessible and sensitive components.

53. Is sensitive data encrypted while it travels over the internet, such as HTTPS or a secure file transfer, rather than plain email?

Practice reference: SC.L2-3.13.8 – cryptographic protection of data in transit.

54. Is sensitive data encrypted while it is stored, whether on servers, in the cloud, or on backups?

Practice reference: SC.L2-3.13.16 – protect the confidentiality of CUI at rest.

55. Are employees prevented from reaching business systems over open public wifi without a secure connection?

Practice reference: SC.L2-3.13.1 – control of remote and untrusted network connections.

56. Are your cloud services, like email and file storage, configured and reviewed by someone who understands the security settings, rather than left on defaults?

Practice reference: SC.L2-3.13.1 – most real-world CUI exposure now happens in cloud misconfiguration, not on-premises breaches.

System and Information Integrity

57. Is there managed antivirus or endpoint protection on every computer and server?

Practice reference: SI.L2-3.14.2 – malicious code protection at designated locations.

58. If malware or suspicious activity is detected, does anyone actually get an alert, or does it just log silently?

Practice reference: SI.L2-3.14.6 – monitor systems and alert on indicators of compromise.

59. When a critical security patch is released, how quickly does it typically get applied?

Practice reference: SI.L2-3.14.1 – identify, report and correct system flaws in a timely manner.

60. Is there filtering in place to catch malicious email attachments and links before they reach an inbox?

Practice reference: SI.L2-3.14.2 – malicious code protection extends to email gateways.

61. For any system that accepts data from outside your company, such as web forms, uploads, or EDI feeds, is that data checked before it is trusted?

Practice reference: SI.L2-3.14.4 and 3.14.5 – update protection mechanisms and scan inbound data.