CSET NIST 800-171 Assessment: How to Use CISA's Free Tool for Your SPRS Score
By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026
A CSET NIST 800-171 assessment uses the free Cyber Security Evaluation Tool from the Cybersecurity and Infrastructure Security Agency (CISA) to score your system on the 110-point scale used in the Defense Department's Supplier Performance Risk System (SPRS). Choose Level 2 in CSET's Cybersecurity Maturity Model Certification (CMMC) 2.0 module. CSET does the math, not the proof, and two of its answer rules can cost you points.
Where things stand (checked September 23, 2026): Official Department sites now use the name Department of War (DoW), while 32 CFR and the DFARS clauses cited on this page still use Department of Defense (DoD). The Department suspended CMMC Phase II on July 13, 2026. Phase I self-assessment requirements stay in place, and the Department says it will enforce NIST SP 800-171 Revision 2 “through self-assessments and select government-led assessments.” Its implementing procedures allow only CMMC Level 1 (Self) and Level 2 (Self) designations during the suspension and direct amendments or modifications to remove Level 2 (C3PAO) and Level 3 requirements from affected solicitations and contracts. The current DARS index lists Class Deviation 2026-O0025, Revision 3, dated September 3, 2026. No replacement Phase II date has been announced on the official pages checked. DFARS 252.204-7012 remains in force. See the latest program status.
This page is for you if:
- Your contract includes Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 and a covered contractor information system processes, stores, or transmits covered defense information. That clause requires adequate security under the applicable version of NIST SP 800-171; the current CMMC Level 2 baseline remains Revision 2.
- You need a NIST SP 800-171 score in SPRS, or your contract names CMMC Level 2 (Self).
- You want to do the first pass yourself, for free, on your own computer.
Go somewhere else first if:
- You handle only Federal Contract Information (FCI), not CUI. You need the 15-requirement Level 1 check: CMMC Level 1 self-assessment checklist.
- You don't know yet whether you hold CUI. Start with FCI vs. CUI.
- You'd rather hire the whole job out. Start with NIST 800-171 gap analysis.

First: which SPRS record are you building?
CSET can support two different records in SPRS, and your contract decides which one you need. A NIST SP 800-171 Basic Assessment posts one summary score. A CMMC Level 2 (Self) assessment records a compliance status for every requirement, produces a CMMC status only when the rule's conditions are met, and needs an Affirming Official's affirmation at the assessment and every year after that.
Here's the honest part. No web page — including this one — can tell you your required level. Your contract does. Three quick checks settle most cases:
- Does your contract include DFARS 252.204-7012? If yes, determine whether a covered contractor information system processes, stores, or transmits covered defense information. The clause applies the NIST SP 800-171 version in effect when the solicitation was issued unless the Contracting Officer authorizes otherwise. Current CMMC Level 2 still uses Revision 2.
- Does it include DFARS 252.204-7019 or 252.204-7020? These codified clause numbers may appear in existing solicitations and contracts. They require a current NIST SP 800-171 DoD Assessment record in SPRS; under 252.204-7019, “current” generally means no more than three years old unless the solicitation says less.
- Does it include DFARS 252.204-7021, with the 252.204-7025 notice in the solicitation, naming “CMMC Level 2 (Self)”? If yes, you need a CMMC Level 2 (Self) record in SPRS plus the required affirmation.
One wrinkle. Solicitations issued under DoD's Revolutionary FAR Overhaul deviations may use the revised DFARS Part 240 clause set, including DFARS 252.240-7997 for government assessment requirements, instead of the older clause structure. Some contracts carry more than one cybersecurity clause. Follow every requirement actually incorporated into your solicitation, contract, amendment, or modification. Our DFARS 252.204-7019 and 7020 guide walks through the legacy clauses and current renumbering. In the table, a POA&M (Plan of Action and Milestones) is your written plan for closing each gap by a set date.
| If your contract names… | You're building… | How it's scored | What goes into SPRS | POA&M rules | How long it stays current |
|---|---|---|---|---|---|
| DFARS 252.204-7019 / 252.204-7020, when incorporated | A NIST SP 800-171 Basic Assessment | DoD Assessment Methodology v1.2.1 | One summary score, assessment date, scope, expected date to reach 110, CAGE codes, SSP name, SSP version, SSP date, and confidence level (SPRS) | No CMMC “Conditional” status test. Open gaps affect the score and plan-of-action completion date. | No more than 3 years old unless the solicitation says less |
| DFARS 252.204-7021 naming CMMC Level 2 (Self) | CMMC Level 2 (Self) status | 32 CFR 170.24, assessed under the June 2018 NIST SP 800-171A procedures required by 32 CFR 170.16 | A Met, Not Met, or N/A status for each requirement in the current SPRS workflow; scope, employee count, CAGE codes, score, POA&M information, and affirmation (SPRS guide) | Score of at least 88, with only eligible gaps, for Conditional status (32 CFR 170.21) | Final: 3 years, with affirmation at the assessment and annually thereafter. Conditional: 180 days. |
| DFARS 252.204-7021 naming CMMC Level 1 (Self) | CMMC Level 1 (Self) status | All 15 requirements from FAR 52.204-21 must be Met | Level 1 result plus affirmation | No POA&M allowed | Annual assessment and affirmation (DoW CIO) |
| Paperwork naming Level 2 (C3PAO) or Level 3 (DIBCAC) | Readiness work only; CSET cannot produce the formal result | A C3PAO performs Level 2 certification assessments; DCMA DIBCAC performs Level 3 assessments | The formal assessor's results, not a CSET self-score | The formal-assessment rules apply | During the suspension, check for the written amendment or modification the Department directed |
| No assessment clause yet | An internal gap review | The same point values can be used for planning | Nothing | Not an official CMMC POA&M decision | Not an SPRS record |
Is a CSET score "official"? Will DoD accept it?
No tool makes a score official, and the CMMC rule doesn't name one. The rule says how to assess and score: against NIST SP 800-171A's applicable objectives, inside your defined scope, scored under 32 CFR 170.24. CSET follows that scoring logic, but the number is still your self-assessment, and your company stands behind it.
SPRS does not perform the Basic Assessment; SPRS states plainly that it stores the results. Its current CMMC Level 2 (Self) guide likewise shows the contractor entering each requirement's status, adding scope and CAGE details, then transferring the record to an Affirming Official when needed. Your CSET project is assessment workpaper, not the government record.
DoD also keeps the right to check your work. Under 32 CFR 170.16(a)(1)(iv), a DIBCAC assessment can follow, and its results take precedence over your self-assessed status. That's why the rest of this page is about getting the answers right, not just getting a number. If you're worried about what an inflated score can cost, read penalty for an inaccurate SPRS score.
Which CSET assessment should you pick for NIST 800-171?
Pick the CMMC 2.0 model and choose Level 2. CSET's tagged source describes that level as calculating a scorecard with the Supplier Performance Risk System score and incorporating the NIST SP 800-171 Revision 2 requirements, the version current CMMC Level 2 still uses. Do not use Revision 3 to calculate a current CMMC Level 2 score.
We read CSET's tagged source for the current release, v12.4.0.4. The SPRS calculation lives in the CMMC 2.0 module (CmmcBusiness.cs). Menu names have shifted between versions, so look for these:
| What you need | What to pick in CSET | What you get | Watch out for |
|---|---|---|---|
| A NIST SP 800-171 score for SPRS, or a CMMC Level 2 (Self) assessment | Under the Cybersecurity Assessment Module category: CMMC 2.0, then Level 2 | One question for each of the 110 requirements, a CMMC Scoring page, a CMMC Scorecard, and a POA&M template (v12.4.0.3 release notes) | Every question you leave blank is deducted as not met in the tagged scoring logic |
| A CMMC Level 1 (Self) check | CMMC 2.0, then Level 1 | The 15 basic safeguarding requirements from FAR 52.204-21 | Level 1 is all-or-nothing, with no POA&M (32 CFR 170.21(a)(1)) |
| A family-by-family gap view | The Standard-Based Assessment category, then the NIST SP 800-171 standard | Compliance results by family | Use it for planning. The tagged 110-point scoring logic is in the CMMC 2.0 Level 2 module. |
| NIST SP 800-171 Revision 3, if you see it | Don't use it for a current CMMC Level 2 score | A separate future-state view | CMMC Level 2 is tied to Revision 2 (32 CFR 170.24(a)). See Rev. 2 vs. Rev. 3. |
One correction to CSET itself. Its built-in Level 2 description says Level 2 “requires annual self-assessment for select contractors” (source). The rule says otherwise. A Level 2 self-assessment happens every three years, with an affirmation at the time of each assessment and every year after that (32 CFR 170.16(a)).
How does CSET score a NIST 800-171 assessment?
CSET starts you at 110 and subtracts 5, 3, or 1 point for each requirement you mark Not Met, the same method 32 CFR 170.24 sets. N/A costs nothing. In the tagged source, an unanswered question is deducted, and the two adjustable controls can use an Incomplete answer that deducts 3 points instead of 5. Your score can drop as low as −203.
Think of CSET like tax software. It does the math on whatever you type in. It never asks to see your receipts.
Codes like SC.L2-3.13.5 in the table are CMMC's labels for each requirement: the family (SC is System and Communications Protection), the level (L2), and the NIST SP 800-171 number (3.13.5).
| When you… | CSET does this in tagged v12.4.0.4 source | The rule says | What it means for you |
|---|---|---|---|
| Start | Begins at 110 | The maximum score is 110 (170.24(c)(2)) | Same |
| Answer Met | No points off | Met means all applicable objectives are satisfied with evidence in final form; drafts and unapproved policies don't count (170.24(b)(1)) | CSET takes your answer. Select Met only when you can show the evidence. |
| Answer N/A | No points off | N/A counts the same as Met when the requirement or objective genuinely does not apply (170.24(b)(3)) | Document the factual basis; update the SSP when the decision affects scope or system treatment. |
| Answer Not Met | Subtracts that requirement's point value | 5, 3, or 1 point. The rule lists 42 fixed 5-point requirements and 14 fixed 3-point requirements; 51 are 1 point. | Same method |
| Skip a question | Deducts it. CSET's tutorial says unanswered questions are “calculated as a 'Not' response” (tutorial) | Every applicable requirement must receive a supported finding | A half-finished run gives a low provisional number. Finish every question. |
| Answer Incomplete | The tagged scoring code deducts 3 points on the two adjustable CMMC question IDs | Partial credit exists only for MFA (IA.L2-3.5.3) and FIPS-validated cryptography (SC.L2-3.13.11). MFA loses 3 points when implemented only for remote and privileged users, or 5 when not implemented for any users. Encryption loses 3 when employed but not FIPS-validated, or 5 when not employed (170.24(c)(2)(i)(B)(4)). | Use Incomplete only for those two rule-defined states. |
| Have no current SSP | CSET can still display a number | Without an up-to-date SSP, the assessment cannot be completed (170.24(c)(2)(i)(B)(5)) | No current SSP, no completed CMMC Level 2 assessment, whatever CSET shows. |
Where does the −203 floor come from? Take 110, subtract 42 requirements at 5 points, 14 at 3, the two adjustable ones at 5, and 51 at 1. The SSP requirement (CA.L2-3.12.4) carries no points. It's a pass-or-stop gate.
What we verified (September 23, 2026). We read the v12.4.0.4 tagged scoring code, interface text, tutorial text, and report labels; checked the official release list and hashes; checked 32 CFR 170.16, 170.21, and 170.24 in eCFR, current through September 21, 2026; and read SPRS's current NIST page and Level 2 Self quick-entry guide. What we could not verify: We did not run a clean Windows installation of v12.4.0.4 or inspect its network traffic. Exact button labels can move between releases. The checker below is anchored to the rule's point values and POA&M gates, not to a screenshot.
What does "Met" actually require?
Met means every applicable assessment objective under a requirement is satisfied, backed by evidence in final form. A policy that says the right thing is a start, not proof. Miss one applicable objective, and the whole requirement is Not Met.
NIST SP 800-171A breaks the 110 requirements into 320 objectives, the specific things an assessor checks. NIST withdrew that June 2018 edition in May 2024 when it published Revision 3. But the CMMC rule still points to the June 2018 version for Level 2 (32 CFR 170.16(c)(1)), so that's the one to use. CSET's tagged tutorial points users to the objectives under Supplemental Guidance. Open them every time.
Here's how that plays out on the first requirement, AC.L2-3.1.1, which limits system access to authorized users, processes, and devices. It has six objectives:
| Objective (NIST SP 800-171A, 3.1.1) | Weak answer | Stronger evidence |
|---|---|---|
| [a] Authorized users are identified | “Only employees get accounts.” | Current list of active accounts, each tied to a named person |
| [b] Processes acting for users are identified | “We don't have any.” | List of service accounts and what each one does |
| [c] Authorized devices are identified | “Company laptops only.” | Device inventory for the CUI system |
| [d] Access is limited to authorized users | Access control policy | Identity settings plus a recent offboarding ticket showing access removed |
| [e] Access is limited to authorized processes | Same policy | Service account permissions, reviewed and dated |
| [f] Access is limited to authorized devices | Same policy | Device-control or conditional-access settings that actually block unknown devices |
Say you nail [a] through [e] but can't prove [f]. AC.L2-3.1.1 is Not Met, and it's a 5-point requirement. See every objective in plain English on our NIST 800-171A assessment objectives page.
Two more rules matter here:
- N/A has to be true. It's for a requirement that doesn't apply to your scope, like a public-access-system separation requirement when there are no publicly accessible systems inside the CMMC Assessment Scope. It isn't for “we don't have evidence.”
- Some documented exceptions or temporary deficiencies can be assessed as Met, but the rule is narrow. An enduring exception must be described, with mitigations, in the SSP. A temporary deficiency must be appropriately addressed in an operational plan of action that includes review and shows progress toward correction (170.24(b)(1)). That operational plan is not the same as a Conditional CMMC POA&M under 170.21, and it is not permission to call an unimplemented requirement Met.
Keep an evidence log next to CSET
CSET records your findings and assessment context, but it does not independently validate the evidence behind them. For a CMMC Level 2 self-assessment, you must keep the artifacts you relied on for six years from your CMMC Status Date (32 CFR 170.16(c)(4)). A simple log, one row per requirement, keeps each CSET answer tied to its proof. Download the blank log below, or copy the table, and store it with your controlled assessment records, not on a shared public drive.
Browser-only worksheet
CSET Evidence Log
One row per requirement. This is a local workpaper, not a submission form. Do not enter CUI, contract text, CAGE codes, system names, network details, or uploaded evidence here.
No row-level flags yet. A blank row is not a finding.
| Requirement | Points | CSET answer | Objectives checked | Objectives not met | How checked | Evidence location | Evidence state | Evidence owner | Reviewed by | Final finding | Fix-by date | Potentially POA&M-eligible | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
AC.L2-3.1.1Limit access to authorized users, processes, devicesfictional example | 5 | No | |||||||||||
AC.L2-3.1.2Limit access to permitted transactions and functions | 5 | — | |||||||||||
AC.L2-3.1.3Control the flow of CUI | 1 | — | |||||||||||
AC.L2-3.1.4Separate duties of individuals | 1 | — | |||||||||||
AC.L2-3.1.5Employ least privilege | 3 | — | |||||||||||
AC.L2-3.1.6Non-privileged accounts for nonsecurity functions | 1 | — | |||||||||||
AC.L2-3.1.7Prevent and log non-privileged execution of privileged functions | 1 | — | |||||||||||
AC.L2-3.1.8Limit unsuccessful logon attempts | 1 | — | |||||||||||
AC.L2-3.1.9Privacy and security notices | 1 | — | |||||||||||
AC.L2-3.1.10Session lock with pattern-hiding display | 1 | — | |||||||||||
AC.L2-3.1.11Automatic session termination | 1 | — | |||||||||||
AC.L2-3.1.12Monitor and control remote access sessions | 5 | — | |||||||||||
AC.L2-3.1.13Cryptographic protection of remote access | 5 | — | |||||||||||
AC.L2-3.1.14Route remote access through managed control points | 1 | — | |||||||||||
AC.L2-3.1.15Authorize remote privileged commands and access to security-relevant information | 1 | — | |||||||||||
AC.L2-3.1.16Authorize wireless access before connection | 5 | — | |||||||||||
AC.L2-3.1.17Protect wireless with authentication and encryption | 5 | — | |||||||||||
AC.L2-3.1.18Control connection of mobile devices | 5 | — | |||||||||||
AC.L2-3.1.19Encrypt CUI on mobile devices | 3 | — | |||||||||||
AC.L2-3.1.20Verify and control connections to external systems | 1 | — | |||||||||||
AC.L2-3.1.21Limit portable storage use on external systems | 1 | — | |||||||||||
AC.L2-3.1.22Control CUI on publicly accessible systems | 1 | — | |||||||||||
AT.L2-3.2.1Security awareness for managers, admins, users | 5 | — | |||||||||||
AT.L2-3.2.2Role-based training for security duties | 5 | — | |||||||||||
AT.L2-3.2.3Insider threat awareness training | 1 | — | |||||||||||
AU.L2-3.3.1Create and retain system audit logs | 5 | — | |||||||||||
AU.L2-3.3.2Trace user actions uniquely to individual users | 3 | — | |||||||||||
AU.L2-3.3.3Review and update logged events | 1 | — | |||||||||||
AU.L2-3.3.4Alert on audit logging process failure | 1 | — | |||||||||||
AU.L2-3.3.5Correlate audit review, analysis, and reporting | 5 | — | |||||||||||
AU.L2-3.3.6Audit record reduction and report generation | 1 | — | |||||||||||
AU.L2-3.3.7Time stamps synchronized to an authoritative source | 1 | — | |||||||||||
AU.L2-3.3.8Protect audit information and logging tools | 1 | — | |||||||||||
AU.L2-3.3.9Limit audit management to a privileged subset | 1 | — | |||||||||||
CM.L2-3.4.1Baseline configurations and system inventories | 5 | — | |||||||||||
CM.L2-3.4.2Security configuration settings | 5 | — | |||||||||||
CM.L2-3.4.3Track, review, approve, and log changes | 1 | — | |||||||||||
CM.L2-3.4.4Security impact analysis before changes | 1 | — | |||||||||||
CM.L2-3.4.5Access restrictions associated with changes | 5 | — | |||||||||||
CM.L2-3.4.6Least functionality | 5 | — | |||||||||||
CM.L2-3.4.7Restrict nonessential programs, ports, protocols, services | 5 | — | |||||||||||
CM.L2-3.4.8Application allowlisting or denylisting | 5 | — | |||||||||||
CM.L2-3.4.9Control and monitor user-installed software | 1 | — | |||||||||||
IA.L2-3.5.1Identify users, processes, and devices | 5 | — | |||||||||||
IA.L2-3.5.2Authenticate identities before granting access | 5 | — | |||||||||||
IA.L2-3.5.3Multifactor authentication | 5 (3 if partial) | — | |||||||||||
IA.L2-3.5.4Replay-resistant authentication | 1 | — | |||||||||||
IA.L2-3.5.5Prevent identifier reuse | 1 | — | |||||||||||
IA.L2-3.5.6Disable identifiers after inactivity | 1 | — | |||||||||||
IA.L2-3.5.7Password complexity and character change | 1 | — | |||||||||||
IA.L2-3.5.8Prohibit password reuse | 1 | — | |||||||||||
IA.L2-3.5.9Temporary passwords changed immediately | 1 | — | |||||||||||
IA.L2-3.5.10Store and transmit only protected passwords | 5 | — | |||||||||||
IA.L2-3.5.11Obscure authentication feedback | 1 | — | |||||||||||
IR.L2-3.6.1Operational incident-handling capability | 5 | — | |||||||||||
IR.L2-3.6.2Track, document, and report incidents | 5 | — | |||||||||||
IR.L2-3.6.3Test the incident response capability | 1 | — | |||||||||||
MA.L2-3.7.1Perform maintenance on systems | 3 | — | |||||||||||
MA.L2-3.7.2Control maintenance tools, techniques, and personnel | 5 | — | |||||||||||
MA.L2-3.7.3Sanitize equipment removed for off-site maintenance | 1 | — | |||||||||||
MA.L2-3.7.4Check maintenance media for malicious code | 3 | — | |||||||||||
MA.L2-3.7.5MFA and terminate nonlocal maintenance sessions | 5 | — | |||||||||||
MA.L2-3.7.6Supervise maintenance by uncleared personnel | 1 | — | |||||||||||
MP.L2-3.8.1Protect media containing CUI | 3 | — | |||||||||||
MP.L2-3.8.2Limit access to CUI on media to authorized users | 3 | — | |||||||||||
MP.L2-3.8.3Sanitize or destroy media before disposal or reuse | 5 | — | |||||||||||
MP.L2-3.8.4Mark media with CUI markings and limitations | 1 | — | |||||||||||
MP.L2-3.8.5Control and account for media during transport | 1 | — | |||||||||||
MP.L2-3.8.6Protect CUI on digital media during transport | 1 | — | |||||||||||
MP.L2-3.8.7Control the use of removable media | 5 | — | |||||||||||
MP.L2-3.8.8Prohibit portable storage with no identifiable owner | 3 | — | |||||||||||
MP.L2-3.8.9Protect backup CUI at storage locations | 1 | — | |||||||||||
PS.L2-3.9.1Screen individuals before authorizing access | 3 | — | |||||||||||
PS.L2-3.9.2Protect CUI during and after personnel actions | 5 | — | |||||||||||
PE.L2-3.10.1Limit physical access to systems and environments | 5 | — | |||||||||||
PE.L2-3.10.2Protect and monitor facilities and support infrastructure | 5 | — | |||||||||||
PE.L2-3.10.3Escort visitors and monitor visitor activity | 1 | — | |||||||||||
PE.L2-3.10.4Maintain audit logs of physical access | 1 | — | |||||||||||
PE.L2-3.10.5Control and manage physical access devices | 1 | — | |||||||||||
PE.L2-3.10.6Safeguarding at alternate work sites | 1 | — | |||||||||||
RA.L2-3.11.1Periodically assess risk | 3 | — | |||||||||||
RA.L2-3.11.2Scan for vulnerabilities | 5 | — | |||||||||||
RA.L2-3.11.3Remediate vulnerabilities per risk assessments | 1 | — | |||||||||||
CA.L2-3.12.1Periodically assess security controls | 5 | — | |||||||||||
CA.L2-3.12.2Plans of action to correct deficiencies | 3 | — | |||||||||||
CA.L2-3.12.3Monitor security controls on an ongoing basis | 5 | — | |||||||||||
CA.L2-3.12.4System security plan | Gate (0) | — | |||||||||||
SC.L2-3.13.1Monitor and protect communications at boundaries | 5 | — | |||||||||||
SC.L2-3.13.2Secure architecture, software development, and engineering principles | 5 | — | |||||||||||
SC.L2-3.13.3Separate user functionality from system management | 1 | — | |||||||||||
SC.L2-3.13.4Prevent unauthorized transfer via shared resources | 1 | — | |||||||||||
SC.L2-3.13.5Subnetworks for publicly accessible components | 5 | — | |||||||||||
SC.L2-3.13.6Deny network traffic by default, allow by exception | 5 | — | |||||||||||
SC.L2-3.13.7Prevent split tunneling | 1 | — | |||||||||||
SC.L2-3.13.8Protect CUI during transmission | 3 | — | |||||||||||
SC.L2-3.13.9Terminate connections after sessions or inactivity | 1 | — | |||||||||||
SC.L2-3.13.10Establish and manage cryptographic keys | 1 | — | |||||||||||
SC.L2-3.13.11FIPS-validated cryptography for CUI | 5 (3 if partial) | — | |||||||||||
SC.L2-3.13.12Block remote activation and indicate collaborative devices in use | 1 | — | |||||||||||
SC.L2-3.13.13Control and monitor mobile code | 1 | — | |||||||||||
SC.L2-3.13.14Control and monitor VoIP | 1 | — | |||||||||||
SC.L2-3.13.15Protect authenticity of communications sessions | 5 | — | |||||||||||
SC.L2-3.13.16Protect confidentiality of CUI at rest | 1 | — | |||||||||||
SI.L2-3.14.1Identify, report, and correct system flaws | 5 | — | |||||||||||
SI.L2-3.14.2Malicious code protection | 5 | — | |||||||||||
SI.L2-3.14.3Monitor and act on security alerts and advisories | 5 | — | |||||||||||
SI.L2-3.14.4Update malicious code protection mechanisms | 5 | — | |||||||||||
SI.L2-3.14.5Periodic and real-time scans | 3 | — | |||||||||||
SI.L2-3.14.6Monitor systems and inbound/outbound traffic | 5 | — | |||||||||||
SI.L2-3.14.7Identify unauthorized use of systems | 3 | — |
Keep the downloaded record in your controlled assessment records. This page does not save, upload, transmit, or retain anything you type.
How to run a CSET NIST 800-171 assessment, step by step
Plan on three stages: get ready, answer honestly against evidence, then check the result against the rule before anything goes into SPRS. CSET handles the middle stage. The first and last are on you, and they're where a score can go wrong without anyone noticing.
1. Get your scope and SSP in hand
Before you open CSET, know which systems, people, and places touch CUI. That's your boundary. The CMMC rule requires a Level 2 self-assessment to follow its scoping rules (32 CFR 170.16(c)(1), which points to 170.19), and every CSET answer depends on it. A CUI enclave works like a locked room inside your building: it can shrink what gets assessed, but only if the walls are real and the doors are controlled.
Then pull up your SSP, the document that describes your system and how you meet each requirement. If you don't have one, NIST publishes a free CUI SSP template, and our CMMC SSP template guide walks through it. If you use a cloud provider or managed IT provider, the rule says the provider's customer responsibility matrix must be documented or referenced in your SSP when applicable (170.16(c)(2)–(3)). For help drawing the boundary, see our CMMC scoping guide and CUI data flow diagram guide.
2. Download CSET from CISA's GitHub page
CSET downloads come from CISA's GitHub releases page, and have been exclusive to GitHub since version 12.2.1.0. As of September 23, 2026, the latest listed release is v12.4.0.4, published July 18, 2025. The release lists a SHA-256 hash. Compare it with your download before you install, so you know the file wasn't altered.
The standalone installer needs Windows 10 or later. CISA's instructions point Mac and Linux users to Docker, which takes some technical setup (README).
3. Protect the file before you fill it in
A finished CSET assessment is a map of your security gaps. Treat it that way. The standalone installation uses a local database. Starting with v12.4.0.3, a Settings option lets users enable password encryption for assessment exports. Turn it on. Name the assessment something plain, without contract numbers or CUI.
4. Start a CMMC 2.0 assessment at Level 2
Create a new assessment, choose CMMC 2.0, and select Level 2. If you have more than one system that handles CUI, decide whether those systems belong to one defined CMMC Assessment Scope or to separate scopes. One assessment can cover multiple information systems when they are part of the same scope; each distinct scope must be documented in the SSP and assessed consistently.
5. Answer every question against its objectives
CSET's tagged source uses Met, Not Met, and N/A, with an Incomplete state for the two adjustable controls. For each requirement:
- Open Supplemental Guidance and read every applicable objective.
- Answer Met only when every applicable objective is satisfied and the evidence is final.
- Log the evidence location in your evidence log as you go.
- Don't skip anything. A blank is deducted in CSET's tagged scoring logic.
6. Read the results, and know what each one proves
CSET's Results section includes CMMC Scoring and CMMC Scorecard pages, and the Reports area includes CMMC 2.0 reports. Each is useful. None proves your answers are true.
| CSET output label in tagged v12.4.0.4 source | Good for | Can't prove |
|---|---|---|
| CMMC Scoring page and CMMC Scorecard | Seeing which requirements cost you points | That the findings behind the score are supported |
| “CMMC 2.0 - Executive Summary” report | Briefing the owner or Affirming Official | Anything beyond what you entered |
| “CMMC 2.0 - Scorecard Report” | A printable record of answers and deductions for your files | An official CMMC status or SPRS submission |
| “CMMC 2.0 - Comments and Marked for Review” report | Handing open questions to a second reviewer | That your evidence is sufficient |
| “Export POAM to Excel” | Starting a remediation tracker | That a gap is permitted on a Conditional CMMC POA&M |
Report names are taken from CSET v12.4.0.4's tagged report labels (source); verify the visible wording in the packaged release you install.
7. Check the score against the rule
Run your answers through the checker below. It recalculates the score from the rule's point values and applies the Conditional-status POA&M screen. Fix any mismatch before you go further.
8. Enter the results in SPRS
SPRS runs through PIEE, the Procurement Integrated Enterprise Environment. A “SPRS Cyber Vendor User” role is required to enter NIST Basic and CMMC assessment information, and SPRS says approval can take multiple business days, so request it early. For a CMMC Level 2 (Self) record, the rule's Affirming Official is the senior-level representative responsible for ensuring compliance and authorized to affirm continuing compliance. Our SPRS score guide walks through the entry screens, and our annual affirmation guide covers what the Affirming Official is signing.
Worked example: a 40-person machine shop runs CSET
Here's how a first CSET pass can come in at 83, climb to 88, and still not qualify for Conditional status. Then what it takes to meet the score-and-gap screen. The shop is hypothetical; the rules are real.
Say you run a 40-person machine shop. You machine parts from drawings marked CUI, and your contract names CMMC Level 2 (Self). Your IT manager spends two afternoons in CSET's CMMC 2.0 Level 2 module. First pass: 92 Met, 3 N/A, 12 Not Met, 1 Incomplete, and 2 questions left blank.
| Requirement | CSET answer | Points off under 32 CFR 170.24 |
|---|---|---|
| RA.L2-3.11.2 Vulnerability scanning | Not Met | −5 |
| AU.L2-3.3.5 Audit record correlation | Left blank; deducted as Not Met in CSET | −5 |
| SI.L2-3.14.7 Identify unauthorized use | Left blank; deducted as Not Met in CSET | −3 |
| IA.L2-3.5.3 MFA for remote and privileged users only | Incomplete | −3 |
| PE.L2-3.10.4 Physical access logs | Not Met | −1 |
| 10 other 1-point requirements: session lock, media marking, backup CUI protection, incident response testing, and six more | Not Met | −10 |
| CSET score | 83 |
Lesson 1: blanks cost real points. The IT manager checks with the shop's managed security provider. It turns out they already correlate audit logs, with final evidence in hand. AU.L2-3.3.5 moves to Met, and the score rises to 88. SI.L2-3.14.7 really is Not Met.
Lesson 2: 88 isn't enough by itself. A Conditional Level 2 status needs a score of 88 or more and a POA&M that holds only eligible gaps (32 CFR 170.21(a)(2)). Four gaps still block it:
- The 5-point scanning gap. Only 1-point gaps can ordinarily go on the POA&M.
- The 3-point SI.L2-3.14.7 gap, for the same reason.
- Partial MFA. It's worth 3 points, and the only 3-point partial the rule lets you defer is non-FIPS encryption under SC.L2-3.13.11.
- Physical access logs. PE.L2-3.10.4 is one of six requirements that can never go on the POA&M, even at 1 point.
In SPRS, a gap like that means “No CMMC Status” regardless of the score (SPRS guide).
Lesson 3: fix the four, and the path opens. With scanning running, SI.L2-3.14.7 covered, MFA implemented for the users and access paths the requirement covers, and physical access logs kept, the score is 100. Only 1-point gaps remain, and all 10 are eligible at the requirement level. That meets the rule's score-and-gap screen for Conditional Level 2 (Self). After the assessment is entered and affirmed in SPRS, the shop has 180 days to close the POA&M, perform the closeout self-assessment, and post the closeout results, or the Conditional status expires (32 CFR 170.16(a)(1)(ii)).
The math: 110 − 11 − 5 − 3 − 3 − 5 = 83. Fixing the blank adds 5, for 88. Fixing the four blockers adds 5 + 3 + 3 + 1, for 100.
Check your CSET results before you post them
Enter the findings you recorded in CSET, and this checker recalculates your score from the rule's point values. For a CMMC Level 2 (Self) record, it also tells you whether the answers meet the rule's score-and-gap screen for Final or Conditional status, or why they still produce No CMMC Status. It is an estimate from public rule text. It isn't an official assessment, and it doesn't store or send anything.
If you'd rather work it by hand: start at 110, subtract each Not Met requirement's point value, count blanks as Not Met for comparison with CSET, and give 3 instead of 5 only for the two rule-defined partial cases. Then check three things. Is the score 88 or higher? Is every remaining gap worth 1 point, other than non-FIPS encryption? And is none of the six never-allowed requirements Not Met? If any answer is no, there's no Conditional status yet. The machine shop above is a full walk-through.
Browser-only calculation
CSET Results Checker
This recalculates the 110-point score and applies the CMMC score-and-gap screen. It is an estimate, not an assessment result.
3.1 Access Control22 requirements
| Requirement | Points | Finding |
|---|---|---|
AC.L2-3.1.1Limit access to authorized users, processes, devices | 5 | |
AC.L2-3.1.2Limit access to permitted transactions and functions | 5 | |
AC.L2-3.1.3Control the flow of CUI | 1 | |
AC.L2-3.1.4Separate duties of individuals | 1 | |
AC.L2-3.1.5Employ least privilege | 3 | |
AC.L2-3.1.6Non-privileged accounts for nonsecurity functions | 1 | |
AC.L2-3.1.7Prevent and log non-privileged execution of privileged functions | 1 | |
AC.L2-3.1.8Limit unsuccessful logon attempts | 1 | |
AC.L2-3.1.9Privacy and security notices | 1 | |
AC.L2-3.1.10Session lock with pattern-hiding display | 1 | |
AC.L2-3.1.11Automatic session termination | 1 | |
AC.L2-3.1.12Monitor and control remote access sessions | 5 | |
AC.L2-3.1.13Cryptographic protection of remote access | 5 | |
AC.L2-3.1.14Route remote access through managed control points | 1 | |
AC.L2-3.1.15Authorize remote privileged commands and access to security-relevant information | 1 | |
AC.L2-3.1.16Authorize wireless access before connection | 5 | |
AC.L2-3.1.17Protect wireless with authentication and encryption | 5 | |
AC.L2-3.1.18Control connection of mobile devices | 5 | |
AC.L2-3.1.19Encrypt CUI on mobile devices | 3 | |
AC.L2-3.1.20Verify and control connections to external systems | 1 | |
AC.L2-3.1.21Limit portable storage use on external systems | 1 | |
AC.L2-3.1.22Control CUI on publicly accessible systems | 1 |
3.2 Awareness and Training3 requirements
| Requirement | Points | Finding |
|---|---|---|
AT.L2-3.2.1Security awareness for managers, admins, users | 5 | |
AT.L2-3.2.2Role-based training for security duties | 5 | |
AT.L2-3.2.3Insider threat awareness training | 1 |
3.3 Audit and Accountability9 requirements
| Requirement | Points | Finding |
|---|---|---|
AU.L2-3.3.1Create and retain system audit logs | 5 | |
AU.L2-3.3.2Trace user actions uniquely to individual users | 3 | |
AU.L2-3.3.3Review and update logged events | 1 | |
AU.L2-3.3.4Alert on audit logging process failure | 1 | |
AU.L2-3.3.5Correlate audit review, analysis, and reporting | 5 | |
AU.L2-3.3.6Audit record reduction and report generation | 1 | |
AU.L2-3.3.7Time stamps synchronized to an authoritative source | 1 | |
AU.L2-3.3.8Protect audit information and logging tools | 1 | |
AU.L2-3.3.9Limit audit management to a privileged subset | 1 |
3.4 Configuration Management9 requirements
| Requirement | Points | Finding |
|---|---|---|
CM.L2-3.4.1Baseline configurations and system inventories | 5 | |
CM.L2-3.4.2Security configuration settings | 5 | |
CM.L2-3.4.3Track, review, approve, and log changes | 1 | |
CM.L2-3.4.4Security impact analysis before changes | 1 | |
CM.L2-3.4.5Access restrictions associated with changes | 5 | |
CM.L2-3.4.6Least functionality | 5 | |
CM.L2-3.4.7Restrict nonessential programs, ports, protocols, services | 5 | |
CM.L2-3.4.8Application allowlisting or denylisting | 5 | |
CM.L2-3.4.9Control and monitor user-installed software | 1 |
3.5 Identification and Authentication11 requirements
| Requirement | Points | Finding |
|---|---|---|
IA.L2-3.5.1Identify users, processes, and devices | 5 | |
IA.L2-3.5.2Authenticate identities before granting access | 5 | |
IA.L2-3.5.3Multifactor authentication | 5 (3 if partial) | |
IA.L2-3.5.4Replay-resistant authentication | 1 | |
IA.L2-3.5.5Prevent identifier reuse | 1 | |
IA.L2-3.5.6Disable identifiers after inactivity | 1 | |
IA.L2-3.5.7Password complexity and character change | 1 | |
IA.L2-3.5.8Prohibit password reuse | 1 | |
IA.L2-3.5.9Temporary passwords changed immediately | 1 | |
IA.L2-3.5.10Store and transmit only protected passwords | 5 | |
IA.L2-3.5.11Obscure authentication feedback | 1 |
3.6 Incident Response3 requirements
| Requirement | Points | Finding |
|---|---|---|
IR.L2-3.6.1Operational incident-handling capability | 5 | |
IR.L2-3.6.2Track, document, and report incidents | 5 | |
IR.L2-3.6.3Test the incident response capability | 1 |
3.7 Maintenance6 requirements
| Requirement | Points | Finding |
|---|---|---|
MA.L2-3.7.1Perform maintenance on systems | 3 | |
MA.L2-3.7.2Control maintenance tools, techniques, and personnel | 5 | |
MA.L2-3.7.3Sanitize equipment removed for off-site maintenance | 1 | |
MA.L2-3.7.4Check maintenance media for malicious code | 3 | |
MA.L2-3.7.5MFA and terminate nonlocal maintenance sessions | 5 | |
MA.L2-3.7.6Supervise maintenance by uncleared personnel | 1 |
3.8 Media Protection9 requirements
| Requirement | Points | Finding |
|---|---|---|
MP.L2-3.8.1Protect media containing CUI | 3 | |
MP.L2-3.8.2Limit access to CUI on media to authorized users | 3 | |
MP.L2-3.8.3Sanitize or destroy media before disposal or reuse | 5 | |
MP.L2-3.8.4Mark media with CUI markings and limitations | 1 | |
MP.L2-3.8.5Control and account for media during transport | 1 | |
MP.L2-3.8.6Protect CUI on digital media during transport | 1 | |
MP.L2-3.8.7Control the use of removable media | 5 | |
MP.L2-3.8.8Prohibit portable storage with no identifiable owner | 3 | |
MP.L2-3.8.9Protect backup CUI at storage locations | 1 |
3.9 Personnel Security2 requirements
| Requirement | Points | Finding |
|---|---|---|
PS.L2-3.9.1Screen individuals before authorizing access | 3 | |
PS.L2-3.9.2Protect CUI during and after personnel actions | 5 |
3.10 Physical Protection6 requirements
| Requirement | Points | Finding |
|---|---|---|
PE.L2-3.10.1Limit physical access to systems and environments | 5 | |
PE.L2-3.10.2Protect and monitor facilities and support infrastructure | 5 | |
PE.L2-3.10.3Escort visitors and monitor visitor activity | 1 | |
PE.L2-3.10.4Maintain audit logs of physical access | 1 | |
PE.L2-3.10.5Control and manage physical access devices | 1 | |
PE.L2-3.10.6Safeguarding at alternate work sites | 1 |
3.11 Risk Assessment3 requirements
| Requirement | Points | Finding |
|---|---|---|
RA.L2-3.11.1Periodically assess risk | 3 | |
RA.L2-3.11.2Scan for vulnerabilities | 5 | |
RA.L2-3.11.3Remediate vulnerabilities per risk assessments | 1 |
3.12 Security Assessment4 requirements
| Requirement | Points | Finding |
|---|---|---|
CA.L2-3.12.1Periodically assess security controls | 5 | |
CA.L2-3.12.2Plans of action to correct deficiencies | 3 | |
CA.L2-3.12.3Monitor security controls on an ongoing basis | 5 | |
CA.L2-3.12.4System security plan | Gate (0) |
3.13 System and Communications Protection16 requirements
| Requirement | Points | Finding |
|---|---|---|
SC.L2-3.13.1Monitor and protect communications at boundaries | 5 | |
SC.L2-3.13.2Secure architecture, software development, and engineering principles | 5 | |
SC.L2-3.13.3Separate user functionality from system management | 1 | |
SC.L2-3.13.4Prevent unauthorized transfer via shared resources | 1 | |
SC.L2-3.13.5Subnetworks for publicly accessible components | 5 | |
SC.L2-3.13.6Deny network traffic by default, allow by exception | 5 | |
SC.L2-3.13.7Prevent split tunneling | 1 | |
SC.L2-3.13.8Protect CUI during transmission | 3 | |
SC.L2-3.13.9Terminate connections after sessions or inactivity | 1 | |
SC.L2-3.13.10Establish and manage cryptographic keys | 1 | |
SC.L2-3.13.11FIPS-validated cryptography for CUI | 5 (3 if partial) | |
SC.L2-3.13.12Block remote activation and indicate collaborative devices in use | 1 | |
SC.L2-3.13.13Control and monitor mobile code | 1 | |
SC.L2-3.13.14Control and monitor VoIP | 1 | |
SC.L2-3.13.15Protect authenticity of communications sessions | 5 | |
SC.L2-3.13.16Protect confidentiality of CUI at rest | 1 |
3.14 System and Information Integrity7 requirements
| Requirement | Points | Finding |
|---|---|---|
SI.L2-3.14.1Identify, report, and correct system flaws | 5 | |
SI.L2-3.14.2Malicious code protection | 5 | |
SI.L2-3.14.3Monitor and act on security alerts and advisories | 5 | |
SI.L2-3.14.4Update malicious code protection mechanisms | 5 | |
SI.L2-3.14.5Periodic and real-time scans | 3 | |
SI.L2-3.14.6Monitor systems and inbound/outbound traffic | 5 | |
SI.L2-3.14.7Identify unauthorized use of systems | 3 |
Enter findings and choose Calculate. The score is provisional until the record type, SSP, and all applicable findings are reviewed.
If a CMMC Level 2 (Self) check shows gaps you can't close on your own, a score below 88, or a blocker that cannot sit on a Conditional-status POA&M, the next question is who closes them: your own team, your IT provider, or a readiness firm. The Defense Compliance Report's Find My CMMC Path tool asks a few questions about your contract, CUI, environment, timeline, and budget, and shows which kind of help fits.
What CSET won't do for your NIST 800-171 assessment
CSET turns your findings into a score. It doesn't know whether your boundary is right, doesn't independently validate your evidence, doesn't decide which gaps can wait, and doesn't create the SPRS record. Those are the places an honest self-assessment can still go wrong.
| CSET won't… | Why it matters | What to do instead |
|---|---|---|
| Define your scope | Level 2 self-assessments must follow the rule's scoping requirements (170.16(c)(1)) | Map where CUI lives before you answer anything (scoping guide) |
| Write an SSP that matches your real system | No current SSP means no completed CMMC assessment | Keep an SSP that describes the actual assessment scope (SSP template guide) |
| Decide whether your evidence supports Met | Met requires final-form evidence for every applicable objective | Use the evidence log above and the assessment evidence guide |
| Decide which gaps can go on a CMMC POA&M | Conditional status requires at least 88, ordinarily only 1-point gaps, one encryption exception, and none of six barred requirements (170.21) | Run the checker above and use the POA&M template |
| Enter or affirm anything in SPRS | SPRS stores the results; an authorized user enters them and an Affirming Official affirms a CMMC record | Request access early and use the SPRS score guide |
| Tell you which record your contract needs | The incorporated clauses decide | Use the three checks at the top of this page |
| Keep up with rule changes | The latest listed CSET release predates the July 2026 Phase II suspension and September 2026 deviation | Check program status before you post |
The right next step after a CSET run isn't the same for every contractor. Whether you keep going on your own, bring in a Registered Practitioner Organization (RPO) for readiness help, lean on a Managed Security Service Provider (MSSP) to close technical gaps, or shrink what gets assessed with a CUI enclave depends on your required CMMC level, whether you handle FCI or CUI, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist and not a CSET score. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes, and do not submit CUI, drawings, or sensitive contract details.
When is CSET enough, and when do you need help?
CSET is a free way to organize the scoring. It is not a complete evidence-management system, a months-long remediation workflow, or an outside second look. Choose help based on the specific gap CSET leaves, not on price alone.
| Kind of help | What it adds that CSET can't | Worth it when… | Learn more |
|---|---|---|---|
| Governance, risk, and compliance (GRC) platform | A place for evidence, owners, and remediation tracking over time | You must maintain evidence, affirm annually, and reassess every three years, and the records live in many places | CMMC GRC software |
| Registered Practitioner Organization (RPO) or readiness consultant | A trained second look at scope, evidence, and your SSP | You're unsure your findings would hold up if DIBCAC checked | NIST 800-171 gap analysis |
| Managed service provider (MSP) or managed security service provider (MSSP) | Hands to fix technical gaps like scanning, logging, and MFA | Your gaps are technical and your IT team is thin | RPO vs. MSP |
| CUI enclave | A smaller, controlled environment that may reduce the assessment scope when separation and data flows are real | CUI is spread across your whole company and scope reduction is feasible | CMMC scoping guide |
| Free local help | Guidance on getting started, at no cost | You're a small business new to DoD requirements | APEX Accelerator CMMC help |
A C3PAO belongs in the process when you are pursuing a formal Level 2 (C3PAO) result, not merely because a CSET score is low. New Level 2 (C3PAO) and Level 3 designations are suspended, but voluntary C3PAO assessments may still be available. CISA also offers free web-based CSET training on running the tool itself. CISA says completing that training does not authorize anyone to conduct assessments on CISA's behalf.
Free tool, paid platform, or outside help: the right mix depends on your contract, where your CUI lives, and how much time you have.
Edge cases to settle before you trust the number
Most CSET runs are straightforward. These situations aren't, and each one can change your answer or your record.
Your paperwork still says C3PAO or Level 3
Phase II is suspended, but a solicitation or contract written earlier may still name Level 2 (C3PAO) or Level 3 (DIBCAC). Don't assume a news release rewrote your contract. The Department directed amendments to affected active solicitations and modifications to affected contracts. Look for the written amendment or modification, and ask your Contracting Officer if none has arrived. CSET can support your readiness either way.
You have more than one system or enclave
Do not automatically create one assessment per server, cloud tenant, or enclave. First define the CMMC Assessment Scope. One assessment may cover multiple information systems and CAGE codes when they are part of the same documented scope; genuinely separate scopes may require separate SSP coverage, assessments, and SPRS records.
A cloud or managed IT provider runs part of your system
Their authorization doesn't erase your duties. For a Level 2 self-assessment, the rule requires the relevant cloud or external service provider customer responsibility matrix to be documented or referenced in your SSP, and the systems connecting to those services can remain in scope (170.16(c)(2)–(3)). See external service provider requirements.
Your encryption relies on a FIPS 140-2 module
NIST's transition schedule placed all FIPS 140-2 certificates on the Historical List on September 22, 2026. NIST says CMVP still supports purchase and use of historical FIPS 140-2 modules for existing systems and that federal agencies decide when they move to FIPS 140-3-only modules. A Historical List entry does not, by itself, settle how SC.L2-3.13.11 applies to your specific module, implementation, contract, or assessment. Record the module and certificate you actually use, check its current CMVP status, and confirm the applicable acquisition direction before choosing Met, Not Met, or the rule's 3-point partial state.
Your team is already working on Revision 3
Keep that as a separate project. Run your current CMMC Level 2 assessment on Revision 2 so the score stays repeatable until the contract or rule actually changes.
You upgrade CSET partway through
Export and password-protect your assessment first. After the upgrade, reopen it and re-check the findings, score, and reports before you rely on them. CISA's release notes describe migration of existing assessments between versions, but a successful migration does not replace your own regression check.
Your MSP runs CSET for you
That's fine. But the findings describe your system, and your company's Affirming Official stands behind the CMMC record in SPRS. Ask to see the evidence behind every Met.
CSET NIST 800-171 assessment FAQ
Is CSET really free?
Yes. CISA and Idaho National Laboratory publish CSET as free software. The repository lists MIT and Apache 2.0 licensing notices, with additional dependency notices. There is no paid CMMC module in the official release list.
Does CSET run on a Mac?
Not through the standalone installer. CISA's repository says local standalone and enterprise deployments require Windows, with Windows 10 or later for local installations. It recommends Docker for Mac and Linux users, which takes some technical setup.
Does CSET send my answers to CISA or DoD?
The standalone version uses a local database, and the official release notes and source we reviewed do not describe direct SPRS submission. Nothing reaches SPRS through the official entry process until an authorized user enters the results there. We did not inspect the app's network traffic, so treat the assessment and exports as sensitive and use the export-password option.
Why doesn't my CSET score match what SPRS shows?
Common causes include a different model or release, a blank question deducted in CSET, an N/A entered differently, or a partial MFA or encryption finding recorded differently. Compare all 110 findings requirement by requirement. When the model and findings match the rule, the arithmetic should reconcile.
Can I use CSET for CMMC Level 1?
Yes. CSET's CMMC 2.0 model includes a Level 1 option covering the 15 FAR 52.204-21 requirements. Level 1 is all-or-nothing, with no POA&M, and the self-assessment and affirmation repeat every year. Our Level 1 checklist covers each requirement.
Is CSET the same as a gap analysis?
It can be the engine of one. A full gap analysis adds scoping, evidence review, an SSP, and a remediation plan around the score. CSET supplies structure and scoring support. The rest is the work in this guide, or the work you'd pay a provider for. See NIST 800-171 gap analysis.
Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.
Sources
All checked September 23, 2026.
- CISA and Idaho National Laboratory, CSET repository and README; CSET releases, v11.2.0.0 through v12.4.0.4; v12.4.0.4 tagged source: CmmcBusiness.cs, CMMC 2.0 tutorial text, interface text, and report labels
- CISA, CSET fact sheet; CSET training
- eCFR, 32 CFR 170.4, 170.14, 170.16, 170.19, 170.21, and 170.24 (eCFR current through September 21, 2026)
- Federal Register, 32 CFR Part 170 CMMC Program final rule and DFARS CMMC acquisition final rule
- Acquisition.gov, FAR 52.204-21; DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025; DPCAP, current Revolutionary FAR Overhaul class-deviation index
- DoD, NIST SP 800-171 DoD Assessment Methodology v1.2.1
- Department of War, July 13, 2026 release suspending CMMC Phase II, implementing procedures, and About CMMC
- SPRS, NIST SP 800-171 page, CMMC Level 2 Self-Assessment Quick Entry Guide v4.0, and access instructions
- NIST, SP 800-171 Revision 2, SP 800-171A June 2018, SP 800-172 February 2021, and FIPS 140-3 transition
About The Defense Compliance Report
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures. We are not affiliated with the Cyber AB, DoD/DoW, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice; confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney.