CMMC 2.0 Level 2 & SPRS Calculator
Assess all 110 NIST SP 800-171 Rev 2 controls across 14 domains.
Client Information
Live SPRS Score
110/110
Compliance: 100% | MET: 110 | NOT MET: 0 | N/A: 0
Access Control
Family 3.1 — 22 controls
Limit system access to authorized users, processes, and devices.
Limit system access to types of transactions and functions that authorized users are permitted to execute.
Control the flow of CUI in accordance with approved authorizations.
Separate the duties of individuals to reduce risk of malevolent activity without collusion.
Employ least privilege to limit access to only what is needed for assigned tasks.
Use non-privileged accounts when accessing nonsecurity functions.
Prevent non-privileged users from executing privileged functions and audit execution.
Limit unsuccessful logon attempts.
Provide privacy and security notices consistent with applicable CUI rules.
Use session lock with pattern-hiding displays to prevent access and viewing after inactivity.
Terminate user session after a defined time period of inactivity.
Monitor and control remote access sessions.
Employ cryptographic mechanisms to protect confidentiality of remote access sessions.
Route remote access via managed access control points.
Authorize remote execution of privileged commands and remote access to security-relevant information.
Authorize remote access to the system prior to allowing such connections.
Protect wireless access using authentication and encryption.
Verify connections of mobile devices and encrypt CUI on such devices.
Encrypt CUI on mobile devices and removable media.
Verify and control connections to external systems.
Limit use of portable storage devices on external systems.
Control CUI posted or processed on publicly accessible systems.
110/110 controls assessed — 0 POA&M items will be generated
