The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CSET NIST 800-171 Assessment: How to Use CISA's Free Tool for Your SPRS Score

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

A CSET NIST 800-171 assessment uses the free Cyber Security Evaluation Tool from the Cybersecurity and Infrastructure Security Agency (CISA) to score your system on the 110-point scale used in the Defense Department's Supplier Performance Risk System (SPRS). Choose Level 2 in CSET's Cybersecurity Maturity Model Certification (CMMC) 2.0 module. CSET does the math, not the proof, and two of its answer rules can cost you points.

Where things stand (checked September 23, 2026): Official Department sites now use the name Department of War (DoW), while 32 CFR and the DFARS clauses cited on this page still use Department of Defense (DoD). The Department suspended CMMC Phase II on July 13, 2026. Phase I self-assessment requirements stay in place, and the Department says it will enforce NIST SP 800-171 Revision 2 “through self-assessments and select government-led assessments.” Its implementing procedures allow only CMMC Level 1 (Self) and Level 2 (Self) designations during the suspension and direct amendments or modifications to remove Level 2 (C3PAO) and Level 3 requirements from affected solicitations and contracts. The current DARS index lists Class Deviation 2026-O0025, Revision 3, dated September 3, 2026. No replacement Phase II date has been announced on the official pages checked. DFARS 252.204-7012 remains in force. See the latest program status.

This page is for you if:

  • Your contract includes Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 and a covered contractor information system processes, stores, or transmits covered defense information. That clause requires adequate security under the applicable version of NIST SP 800-171; the current CMMC Level 2 baseline remains Revision 2.
  • You need a NIST SP 800-171 score in SPRS, or your contract names CMMC Level 2 (Self).
  • You want to do the first pass yourself, for free, on your own computer.

Go somewhere else first if:

Example CUI data flow diagram for a CMMC Level 2 scope, showing CUI moving between a prime source, controlled systems, repositories, and external parties.

First: which SPRS record are you building?

CSET can support two different records in SPRS, and your contract decides which one you need. A NIST SP 800-171 Basic Assessment posts one summary score. A CMMC Level 2 (Self) assessment records a compliance status for every requirement, produces a CMMC status only when the rule's conditions are met, and needs an Affirming Official's affirmation at the assessment and every year after that.

Here's the honest part. No web page — including this one — can tell you your required level. Your contract does. Three quick checks settle most cases:

  1. Does your contract include DFARS 252.204-7012? If yes, determine whether a covered contractor information system processes, stores, or transmits covered defense information. The clause applies the NIST SP 800-171 version in effect when the solicitation was issued unless the Contracting Officer authorizes otherwise. Current CMMC Level 2 still uses Revision 2.
  2. Does it include DFARS 252.204-7019 or 252.204-7020? These codified clause numbers may appear in existing solicitations and contracts. They require a current NIST SP 800-171 DoD Assessment record in SPRS; under 252.204-7019, “current” generally means no more than three years old unless the solicitation says less.
  3. Does it include DFARS 252.204-7021, with the 252.204-7025 notice in the solicitation, naming “CMMC Level 2 (Self)”? If yes, you need a CMMC Level 2 (Self) record in SPRS plus the required affirmation.

One wrinkle. Solicitations issued under DoD's Revolutionary FAR Overhaul deviations may use the revised DFARS Part 240 clause set, including DFARS 252.240-7997 for government assessment requirements, instead of the older clause structure. Some contracts carry more than one cybersecurity clause. Follow every requirement actually incorporated into your solicitation, contract, amendment, or modification. Our DFARS 252.204-7019 and 7020 guide walks through the legacy clauses and current renumbering. In the table, a POA&M (Plan of Action and Milestones) is your written plan for closing each gap by a set date.

If your contract names… — You're building… — How it's scored — What goes into SPRS — POA&M rules — How long it stays current
If your contract names…You're building…How it's scoredWhat goes into SPRSPOA&M rulesHow long it stays current
DFARS 252.204-7019 / 252.204-7020, when incorporatedA NIST SP 800-171 Basic AssessmentDoD Assessment Methodology v1.2.1One summary score, assessment date, scope, expected date to reach 110, CAGE codes, SSP name, SSP version, SSP date, and confidence level (SPRS)No CMMC “Conditional” status test. Open gaps affect the score and plan-of-action completion date.No more than 3 years old unless the solicitation says less
DFARS 252.204-7021 naming CMMC Level 2 (Self)CMMC Level 2 (Self) status32 CFR 170.24, assessed under the June 2018 NIST SP 800-171A procedures required by 32 CFR 170.16A Met, Not Met, or N/A status for each requirement in the current SPRS workflow; scope, employee count, CAGE codes, score, POA&M information, and affirmation (SPRS guide)Score of at least 88, with only eligible gaps, for Conditional status (32 CFR 170.21)Final: 3 years, with affirmation at the assessment and annually thereafter. Conditional: 180 days.
DFARS 252.204-7021 naming CMMC Level 1 (Self)CMMC Level 1 (Self) statusAll 15 requirements from FAR 52.204-21 must be MetLevel 1 result plus affirmationNo POA&M allowedAnnual assessment and affirmation (DoW CIO)
Paperwork naming Level 2 (C3PAO) or Level 3 (DIBCAC)Readiness work only; CSET cannot produce the formal resultA C3PAO performs Level 2 certification assessments; DCMA DIBCAC performs Level 3 assessmentsThe formal assessor's results, not a CSET self-scoreThe formal-assessment rules applyDuring the suspension, check for the written amendment or modification the Department directed
No assessment clause yetAn internal gap reviewThe same point values can be used for planningNothingNot an official CMMC POA&M decisionNot an SPRS record

Is a CSET score "official"? Will DoD accept it?

No tool makes a score official, and the CMMC rule doesn't name one. The rule says how to assess and score: against NIST SP 800-171A's applicable objectives, inside your defined scope, scored under 32 CFR 170.24. CSET follows that scoring logic, but the number is still your self-assessment, and your company stands behind it.

SPRS does not perform the Basic Assessment; SPRS states plainly that it stores the results. Its current CMMC Level 2 (Self) guide likewise shows the contractor entering each requirement's status, adding scope and CAGE details, then transferring the record to an Affirming Official when needed. Your CSET project is assessment workpaper, not the government record.

DoD also keeps the right to check your work. Under 32 CFR 170.16(a)(1)(iv), a DIBCAC assessment can follow, and its results take precedence over your self-assessed status. That's why the rest of this page is about getting the answers right, not just getting a number. If you're worried about what an inflated score can cost, read penalty for an inaccurate SPRS score.

Which CSET assessment should you pick for NIST 800-171?

Pick the CMMC 2.0 model and choose Level 2. CSET's tagged source describes that level as calculating a scorecard with the Supplier Performance Risk System score and incorporating the NIST SP 800-171 Revision 2 requirements, the version current CMMC Level 2 still uses. Do not use Revision 3 to calculate a current CMMC Level 2 score.

We read CSET's tagged source for the current release, v12.4.0.4. The SPRS calculation lives in the CMMC 2.0 module (CmmcBusiness.cs). Menu names have shifted between versions, so look for these:

What you need — What to pick in CSET — What you get — Watch out for
What you needWhat to pick in CSETWhat you getWatch out for
A NIST SP 800-171 score for SPRS, or a CMMC Level 2 (Self) assessmentUnder the Cybersecurity Assessment Module category: CMMC 2.0, then Level 2One question for each of the 110 requirements, a CMMC Scoring page, a CMMC Scorecard, and a POA&M template (v12.4.0.3 release notes)Every question you leave blank is deducted as not met in the tagged scoring logic
A CMMC Level 1 (Self) checkCMMC 2.0, then Level 1The 15 basic safeguarding requirements from FAR 52.204-21Level 1 is all-or-nothing, with no POA&M (32 CFR 170.21(a)(1))
A family-by-family gap viewThe Standard-Based Assessment category, then the NIST SP 800-171 standardCompliance results by familyUse it for planning. The tagged 110-point scoring logic is in the CMMC 2.0 Level 2 module.
NIST SP 800-171 Revision 3, if you see itDon't use it for a current CMMC Level 2 scoreA separate future-state viewCMMC Level 2 is tied to Revision 2 (32 CFR 170.24(a)). See Rev. 2 vs. Rev. 3.

One correction to CSET itself. Its built-in Level 2 description says Level 2 “requires annual self-assessment for select contractors” (source). The rule says otherwise. A Level 2 self-assessment happens every three years, with an affirmation at the time of each assessment and every year after that (32 CFR 170.16(a)).

How does CSET score a NIST 800-171 assessment?

CSET starts you at 110 and subtracts 5, 3, or 1 point for each requirement you mark Not Met, the same method 32 CFR 170.24 sets. N/A costs nothing. In the tagged source, an unanswered question is deducted, and the two adjustable controls can use an Incomplete answer that deducts 3 points instead of 5. Your score can drop as low as −203.

Think of CSET like tax software. It does the math on whatever you type in. It never asks to see your receipts.

Codes like SC.L2-3.13.5 in the table are CMMC's labels for each requirement: the family (SC is System and Communications Protection), the level (L2), and the NIST SP 800-171 number (3.13.5).

When you… — CSET does this in tagged v12.4.0.4 source — The rule says — What it means for you
When you…CSET does this in tagged v12.4.0.4 sourceThe rule saysWhat it means for you
StartBegins at 110The maximum score is 110 (170.24(c)(2))Same
Answer MetNo points offMet means all applicable objectives are satisfied with evidence in final form; drafts and unapproved policies don't count (170.24(b)(1))CSET takes your answer. Select Met only when you can show the evidence.
Answer N/ANo points offN/A counts the same as Met when the requirement or objective genuinely does not apply (170.24(b)(3))Document the factual basis; update the SSP when the decision affects scope or system treatment.
Answer Not MetSubtracts that requirement's point value5, 3, or 1 point. The rule lists 42 fixed 5-point requirements and 14 fixed 3-point requirements; 51 are 1 point.Same method
Skip a questionDeducts it. CSET's tutorial says unanswered questions are “calculated as a 'Not' response” (tutorial)Every applicable requirement must receive a supported findingA half-finished run gives a low provisional number. Finish every question.
Answer IncompleteThe tagged scoring code deducts 3 points on the two adjustable CMMC question IDsPartial credit exists only for MFA (IA.L2-3.5.3) and FIPS-validated cryptography (SC.L2-3.13.11). MFA loses 3 points when implemented only for remote and privileged users, or 5 when not implemented for any users. Encryption loses 3 when employed but not FIPS-validated, or 5 when not employed (170.24(c)(2)(i)(B)(4)).Use Incomplete only for those two rule-defined states.
Have no current SSPCSET can still display a numberWithout an up-to-date SSP, the assessment cannot be completed (170.24(c)(2)(i)(B)(5))No current SSP, no completed CMMC Level 2 assessment, whatever CSET shows.

Where does the −203 floor come from? Take 110, subtract 42 requirements at 5 points, 14 at 3, the two adjustable ones at 5, and 51 at 1. The SSP requirement (CA.L2-3.12.4) carries no points. It's a pass-or-stop gate.

What we verified (September 23, 2026). We read the v12.4.0.4 tagged scoring code, interface text, tutorial text, and report labels; checked the official release list and hashes; checked 32 CFR 170.16, 170.21, and 170.24 in eCFR, current through September 21, 2026; and read SPRS's current NIST page and Level 2 Self quick-entry guide. What we could not verify: We did not run a clean Windows installation of v12.4.0.4 or inspect its network traffic. Exact button labels can move between releases. The checker below is anchored to the rule's point values and POA&M gates, not to a screenshot.

What does "Met" actually require?

Met means every applicable assessment objective under a requirement is satisfied, backed by evidence in final form. A policy that says the right thing is a start, not proof. Miss one applicable objective, and the whole requirement is Not Met.

NIST SP 800-171A breaks the 110 requirements into 320 objectives, the specific things an assessor checks. NIST withdrew that June 2018 edition in May 2024 when it published Revision 3. But the CMMC rule still points to the June 2018 version for Level 2 (32 CFR 170.16(c)(1)), so that's the one to use. CSET's tagged tutorial points users to the objectives under Supplemental Guidance. Open them every time.

Here's how that plays out on the first requirement, AC.L2-3.1.1, which limits system access to authorized users, processes, and devices. It has six objectives:

Objective (NIST SP 800-171A, 3.1.1) — Weak answer — Stronger evidence
Objective (NIST SP 800-171A, 3.1.1)Weak answerStronger evidence
[a] Authorized users are identified“Only employees get accounts.”Current list of active accounts, each tied to a named person
[b] Processes acting for users are identified“We don't have any.”List of service accounts and what each one does
[c] Authorized devices are identified“Company laptops only.”Device inventory for the CUI system
[d] Access is limited to authorized usersAccess control policyIdentity settings plus a recent offboarding ticket showing access removed
[e] Access is limited to authorized processesSame policyService account permissions, reviewed and dated
[f] Access is limited to authorized devicesSame policyDevice-control or conditional-access settings that actually block unknown devices

Say you nail [a] through [e] but can't prove [f]. AC.L2-3.1.1 is Not Met, and it's a 5-point requirement. See every objective in plain English on our NIST 800-171A assessment objectives page.

Two more rules matter here:

  • N/A has to be true. It's for a requirement that doesn't apply to your scope, like a public-access-system separation requirement when there are no publicly accessible systems inside the CMMC Assessment Scope. It isn't for “we don't have evidence.”
  • Some documented exceptions or temporary deficiencies can be assessed as Met, but the rule is narrow. An enduring exception must be described, with mitigations, in the SSP. A temporary deficiency must be appropriately addressed in an operational plan of action that includes review and shows progress toward correction (170.24(b)(1)). That operational plan is not the same as a Conditional CMMC POA&M under 170.21, and it is not permission to call an unimplemented requirement Met.

Keep an evidence log next to CSET

CSET records your findings and assessment context, but it does not independently validate the evidence behind them. For a CMMC Level 2 self-assessment, you must keep the artifacts you relied on for six years from your CMMC Status Date (32 CFR 170.16(c)(4)). A simple log, one row per requirement, keeps each CSET answer tied to its proof. Download the blank log below, or copy the table, and store it with your controlled assessment records, not on a shared public drive.

Browser-only worksheet

CSET Evidence Log

One row per requirement. This is a local workpaper, not a submission form. Do not enter CUI, contract text, CAGE codes, system names, network details, or uploaded evidence here.

No row-level flags yet. A blank row is not a finding.

CSET Evidence Log — 110 NIST SP 800-171 Revision 2 requirements. The first row is a clearly fictional example.
RequirementPointsCSET answerObjectives checkedObjectives not metHow checkedEvidence locationEvidence stateEvidence ownerReviewed byFinal findingFix-by datePotentially POA&M-eligibleNotes
AC.L2-3.1.1Limit access to authorized users, processes, devicesfictional example5No
AC.L2-3.1.2Limit access to permitted transactions and functions5
AC.L2-3.1.3Control the flow of CUI1
AC.L2-3.1.4Separate duties of individuals1
AC.L2-3.1.5Employ least privilege3
AC.L2-3.1.6Non-privileged accounts for nonsecurity functions1
AC.L2-3.1.7Prevent and log non-privileged execution of privileged functions1
AC.L2-3.1.8Limit unsuccessful logon attempts1
AC.L2-3.1.9Privacy and security notices1
AC.L2-3.1.10Session lock with pattern-hiding display1
AC.L2-3.1.11Automatic session termination1
AC.L2-3.1.12Monitor and control remote access sessions5
AC.L2-3.1.13Cryptographic protection of remote access5
AC.L2-3.1.14Route remote access through managed control points1
AC.L2-3.1.15Authorize remote privileged commands and access to security-relevant information1
AC.L2-3.1.16Authorize wireless access before connection5
AC.L2-3.1.17Protect wireless with authentication and encryption5
AC.L2-3.1.18Control connection of mobile devices5
AC.L2-3.1.19Encrypt CUI on mobile devices3
AC.L2-3.1.20Verify and control connections to external systems1
AC.L2-3.1.21Limit portable storage use on external systems1
AC.L2-3.1.22Control CUI on publicly accessible systems1
AT.L2-3.2.1Security awareness for managers, admins, users5
AT.L2-3.2.2Role-based training for security duties5
AT.L2-3.2.3Insider threat awareness training1
AU.L2-3.3.1Create and retain system audit logs5
AU.L2-3.3.2Trace user actions uniquely to individual users3
AU.L2-3.3.3Review and update logged events1
AU.L2-3.3.4Alert on audit logging process failure1
AU.L2-3.3.5Correlate audit review, analysis, and reporting5
AU.L2-3.3.6Audit record reduction and report generation1
AU.L2-3.3.7Time stamps synchronized to an authoritative source1
AU.L2-3.3.8Protect audit information and logging tools1
AU.L2-3.3.9Limit audit management to a privileged subset1
CM.L2-3.4.1Baseline configurations and system inventories5
CM.L2-3.4.2Security configuration settings5
CM.L2-3.4.3Track, review, approve, and log changes1
CM.L2-3.4.4Security impact analysis before changes1
CM.L2-3.4.5Access restrictions associated with changes5
CM.L2-3.4.6Least functionality5
CM.L2-3.4.7Restrict nonessential programs, ports, protocols, services5
CM.L2-3.4.8Application allowlisting or denylisting5
CM.L2-3.4.9Control and monitor user-installed software1
IA.L2-3.5.1Identify users, processes, and devices5
IA.L2-3.5.2Authenticate identities before granting access5
IA.L2-3.5.3Multifactor authentication5 (3 if partial)
IA.L2-3.5.4Replay-resistant authentication1
IA.L2-3.5.5Prevent identifier reuse1
IA.L2-3.5.6Disable identifiers after inactivity1
IA.L2-3.5.7Password complexity and character change1
IA.L2-3.5.8Prohibit password reuse1
IA.L2-3.5.9Temporary passwords changed immediately1
IA.L2-3.5.10Store and transmit only protected passwords5
IA.L2-3.5.11Obscure authentication feedback1
IR.L2-3.6.1Operational incident-handling capability5
IR.L2-3.6.2Track, document, and report incidents5
IR.L2-3.6.3Test the incident response capability1
MA.L2-3.7.1Perform maintenance on systems3
MA.L2-3.7.2Control maintenance tools, techniques, and personnel5
MA.L2-3.7.3Sanitize equipment removed for off-site maintenance1
MA.L2-3.7.4Check maintenance media for malicious code3
MA.L2-3.7.5MFA and terminate nonlocal maintenance sessions5
MA.L2-3.7.6Supervise maintenance by uncleared personnel1
MP.L2-3.8.1Protect media containing CUI3
MP.L2-3.8.2Limit access to CUI on media to authorized users3
MP.L2-3.8.3Sanitize or destroy media before disposal or reuse5
MP.L2-3.8.4Mark media with CUI markings and limitations1
MP.L2-3.8.5Control and account for media during transport1
MP.L2-3.8.6Protect CUI on digital media during transport1
MP.L2-3.8.7Control the use of removable media5
MP.L2-3.8.8Prohibit portable storage with no identifiable owner3
MP.L2-3.8.9Protect backup CUI at storage locations1
PS.L2-3.9.1Screen individuals before authorizing access3
PS.L2-3.9.2Protect CUI during and after personnel actions5
PE.L2-3.10.1Limit physical access to systems and environments5
PE.L2-3.10.2Protect and monitor facilities and support infrastructure5
PE.L2-3.10.3Escort visitors and monitor visitor activity1
PE.L2-3.10.4Maintain audit logs of physical access1
PE.L2-3.10.5Control and manage physical access devices1
PE.L2-3.10.6Safeguarding at alternate work sites1
RA.L2-3.11.1Periodically assess risk3
RA.L2-3.11.2Scan for vulnerabilities5
RA.L2-3.11.3Remediate vulnerabilities per risk assessments1
CA.L2-3.12.1Periodically assess security controls5
CA.L2-3.12.2Plans of action to correct deficiencies3
CA.L2-3.12.3Monitor security controls on an ongoing basis5
CA.L2-3.12.4System security planGate (0)
SC.L2-3.13.1Monitor and protect communications at boundaries5
SC.L2-3.13.2Secure architecture, software development, and engineering principles5
SC.L2-3.13.3Separate user functionality from system management1
SC.L2-3.13.4Prevent unauthorized transfer via shared resources1
SC.L2-3.13.5Subnetworks for publicly accessible components5
SC.L2-3.13.6Deny network traffic by default, allow by exception5
SC.L2-3.13.7Prevent split tunneling1
SC.L2-3.13.8Protect CUI during transmission3
SC.L2-3.13.9Terminate connections after sessions or inactivity1
SC.L2-3.13.10Establish and manage cryptographic keys1
SC.L2-3.13.11FIPS-validated cryptography for CUI5 (3 if partial)
SC.L2-3.13.12Block remote activation and indicate collaborative devices in use1
SC.L2-3.13.13Control and monitor mobile code1
SC.L2-3.13.14Control and monitor VoIP1
SC.L2-3.13.15Protect authenticity of communications sessions5
SC.L2-3.13.16Protect confidentiality of CUI at rest1
SI.L2-3.14.1Identify, report, and correct system flaws5
SI.L2-3.14.2Malicious code protection5
SI.L2-3.14.3Monitor and act on security alerts and advisories5
SI.L2-3.14.4Update malicious code protection mechanisms5
SI.L2-3.14.5Periodic and real-time scans3
SI.L2-3.14.6Monitor systems and inbound/outbound traffic5
SI.L2-3.14.7Identify unauthorized use of systems3

Keep the downloaded record in your controlled assessment records. This page does not save, upload, transmit, or retain anything you type.

How to run a CSET NIST 800-171 assessment, step by step

Plan on three stages: get ready, answer honestly against evidence, then check the result against the rule before anything goes into SPRS. CSET handles the middle stage. The first and last are on you, and they're where a score can go wrong without anyone noticing.

1. Get your scope and SSP in hand

Before you open CSET, know which systems, people, and places touch CUI. That's your boundary. The CMMC rule requires a Level 2 self-assessment to follow its scoping rules (32 CFR 170.16(c)(1), which points to 170.19), and every CSET answer depends on it. A CUI enclave works like a locked room inside your building: it can shrink what gets assessed, but only if the walls are real and the doors are controlled.

Then pull up your SSP, the document that describes your system and how you meet each requirement. If you don't have one, NIST publishes a free CUI SSP template, and our CMMC SSP template guide walks through it. If you use a cloud provider or managed IT provider, the rule says the provider's customer responsibility matrix must be documented or referenced in your SSP when applicable (170.16(c)(2)–(3)). For help drawing the boundary, see our CMMC scoping guide and CUI data flow diagram guide.

2. Download CSET from CISA's GitHub page

CSET downloads come from CISA's GitHub releases page, and have been exclusive to GitHub since version 12.2.1.0. As of September 23, 2026, the latest listed release is v12.4.0.4, published July 18, 2025. The release lists a SHA-256 hash. Compare it with your download before you install, so you know the file wasn't altered.

The standalone installer needs Windows 10 or later. CISA's instructions point Mac and Linux users to Docker, which takes some technical setup (README).

3. Protect the file before you fill it in

A finished CSET assessment is a map of your security gaps. Treat it that way. The standalone installation uses a local database. Starting with v12.4.0.3, a Settings option lets users enable password encryption for assessment exports. Turn it on. Name the assessment something plain, without contract numbers or CUI.

4. Start a CMMC 2.0 assessment at Level 2

Create a new assessment, choose CMMC 2.0, and select Level 2. If you have more than one system that handles CUI, decide whether those systems belong to one defined CMMC Assessment Scope or to separate scopes. One assessment can cover multiple information systems when they are part of the same scope; each distinct scope must be documented in the SSP and assessed consistently.

5. Answer every question against its objectives

CSET's tagged source uses Met, Not Met, and N/A, with an Incomplete state for the two adjustable controls. For each requirement:

  • Open Supplemental Guidance and read every applicable objective.
  • Answer Met only when every applicable objective is satisfied and the evidence is final.
  • Log the evidence location in your evidence log as you go.
  • Don't skip anything. A blank is deducted in CSET's tagged scoring logic.

6. Read the results, and know what each one proves

CSET's Results section includes CMMC Scoring and CMMC Scorecard pages, and the Reports area includes CMMC 2.0 reports. Each is useful. None proves your answers are true.

CSET output label in tagged v12.4.0.4 source — Good for — Can't prove
CSET output label in tagged v12.4.0.4 sourceGood forCan't prove
CMMC Scoring page and CMMC ScorecardSeeing which requirements cost you pointsThat the findings behind the score are supported
“CMMC 2.0 - Executive Summary” reportBriefing the owner or Affirming OfficialAnything beyond what you entered
“CMMC 2.0 - Scorecard Report”A printable record of answers and deductions for your filesAn official CMMC status or SPRS submission
“CMMC 2.0 - Comments and Marked for Review” reportHanding open questions to a second reviewerThat your evidence is sufficient
“Export POAM to Excel”Starting a remediation trackerThat a gap is permitted on a Conditional CMMC POA&M

Report names are taken from CSET v12.4.0.4's tagged report labels (source); verify the visible wording in the packaged release you install.

7. Check the score against the rule

Run your answers through the checker below. It recalculates the score from the rule's point values and applies the Conditional-status POA&M screen. Fix any mismatch before you go further.

8. Enter the results in SPRS

SPRS runs through PIEE, the Procurement Integrated Enterprise Environment. A “SPRS Cyber Vendor User” role is required to enter NIST Basic and CMMC assessment information, and SPRS says approval can take multiple business days, so request it early. For a CMMC Level 2 (Self) record, the rule's Affirming Official is the senior-level representative responsible for ensuring compliance and authorized to affirm continuing compliance. Our SPRS score guide walks through the entry screens, and our annual affirmation guide covers what the Affirming Official is signing.

Worked example: a 40-person machine shop runs CSET

Here's how a first CSET pass can come in at 83, climb to 88, and still not qualify for Conditional status. Then what it takes to meet the score-and-gap screen. The shop is hypothetical; the rules are real.

Say you run a 40-person machine shop. You machine parts from drawings marked CUI, and your contract names CMMC Level 2 (Self). Your IT manager spends two afternoons in CSET's CMMC 2.0 Level 2 module. First pass: 92 Met, 3 N/A, 12 Not Met, 1 Incomplete, and 2 questions left blank.

Requirement — CSET answer — Points off under 32 CFR 170.24
RequirementCSET answerPoints off under 32 CFR 170.24
RA.L2-3.11.2 Vulnerability scanningNot Met−5
AU.L2-3.3.5 Audit record correlationLeft blank; deducted as Not Met in CSET−5
SI.L2-3.14.7 Identify unauthorized useLeft blank; deducted as Not Met in CSET−3
IA.L2-3.5.3 MFA for remote and privileged users onlyIncomplete−3
PE.L2-3.10.4 Physical access logsNot Met−1
10 other 1-point requirements: session lock, media marking, backup CUI protection, incident response testing, and six moreNot Met−10
CSET score83

Lesson 1: blanks cost real points. The IT manager checks with the shop's managed security provider. It turns out they already correlate audit logs, with final evidence in hand. AU.L2-3.3.5 moves to Met, and the score rises to 88. SI.L2-3.14.7 really is Not Met.

Lesson 2: 88 isn't enough by itself. A Conditional Level 2 status needs a score of 88 or more and a POA&M that holds only eligible gaps (32 CFR 170.21(a)(2)). Four gaps still block it:

  • The 5-point scanning gap. Only 1-point gaps can ordinarily go on the POA&M.
  • The 3-point SI.L2-3.14.7 gap, for the same reason.
  • Partial MFA. It's worth 3 points, and the only 3-point partial the rule lets you defer is non-FIPS encryption under SC.L2-3.13.11.
  • Physical access logs. PE.L2-3.10.4 is one of six requirements that can never go on the POA&M, even at 1 point.

In SPRS, a gap like that means “No CMMC Status” regardless of the score (SPRS guide).

Lesson 3: fix the four, and the path opens. With scanning running, SI.L2-3.14.7 covered, MFA implemented for the users and access paths the requirement covers, and physical access logs kept, the score is 100. Only 1-point gaps remain, and all 10 are eligible at the requirement level. That meets the rule's score-and-gap screen for Conditional Level 2 (Self). After the assessment is entered and affirmed in SPRS, the shop has 180 days to close the POA&M, perform the closeout self-assessment, and post the closeout results, or the Conditional status expires (32 CFR 170.16(a)(1)(ii)).

The math: 110 − 11 − 5 − 3 − 3 − 5 = 83. Fixing the blank adds 5, for 88. Fixing the four blockers adds 5 + 3 + 3 + 1, for 100.

Check your CSET results before you post them

Enter the findings you recorded in CSET, and this checker recalculates your score from the rule's point values. For a CMMC Level 2 (Self) record, it also tells you whether the answers meet the rule's score-and-gap screen for Final or Conditional status, or why they still produce No CMMC Status. It is an estimate from public rule text. It isn't an official assessment, and it doesn't store or send anything.

If you'd rather work it by hand: start at 110, subtract each Not Met requirement's point value, count blanks as Not Met for comparison with CSET, and give 3 instead of 5 only for the two rule-defined partial cases. Then check three things. Is the score 88 or higher? Is every remaining gap worth 1 point, other than non-FIPS encryption? And is none of the six never-allowed requirements Not Met? If any answer is no, there's no Conditional status yet. The machine shop above is a full walk-through.

Browser-only calculation

CSET Results Checker

This recalculates the 110-point score and applies the CMMC score-and-gap screen. It is an estimate, not an assessment result.

Don't enter CUI, contract text, CAGE codes, system names, or network details. This checker needs only requirement IDs and your findings. Nothing is stored or sent.
3.1 Access Control22 requirements
3.1 Access Control findings
RequirementPointsFinding
AC.L2-3.1.1Limit access to authorized users, processes, devices5
AC.L2-3.1.2Limit access to permitted transactions and functions5
AC.L2-3.1.3Control the flow of CUI1
AC.L2-3.1.4Separate duties of individuals1
AC.L2-3.1.5Employ least privilege3
AC.L2-3.1.6Non-privileged accounts for nonsecurity functions1
AC.L2-3.1.7Prevent and log non-privileged execution of privileged functions1
AC.L2-3.1.8Limit unsuccessful logon attempts1
AC.L2-3.1.9Privacy and security notices1
AC.L2-3.1.10Session lock with pattern-hiding display1
AC.L2-3.1.11Automatic session termination1
AC.L2-3.1.12Monitor and control remote access sessions5
AC.L2-3.1.13Cryptographic protection of remote access5
AC.L2-3.1.14Route remote access through managed control points1
AC.L2-3.1.15Authorize remote privileged commands and access to security-relevant information1
AC.L2-3.1.16Authorize wireless access before connection5
AC.L2-3.1.17Protect wireless with authentication and encryption5
AC.L2-3.1.18Control connection of mobile devices5
AC.L2-3.1.19Encrypt CUI on mobile devices3
AC.L2-3.1.20Verify and control connections to external systems1
AC.L2-3.1.21Limit portable storage use on external systems1
AC.L2-3.1.22Control CUI on publicly accessible systems1
3.2 Awareness and Training3 requirements
3.2 Awareness and Training findings
RequirementPointsFinding
AT.L2-3.2.1Security awareness for managers, admins, users5
AT.L2-3.2.2Role-based training for security duties5
AT.L2-3.2.3Insider threat awareness training1
3.3 Audit and Accountability9 requirements
3.3 Audit and Accountability findings
RequirementPointsFinding
AU.L2-3.3.1Create and retain system audit logs5
AU.L2-3.3.2Trace user actions uniquely to individual users3
AU.L2-3.3.3Review and update logged events1
AU.L2-3.3.4Alert on audit logging process failure1
AU.L2-3.3.5Correlate audit review, analysis, and reporting5
AU.L2-3.3.6Audit record reduction and report generation1
AU.L2-3.3.7Time stamps synchronized to an authoritative source1
AU.L2-3.3.8Protect audit information and logging tools1
AU.L2-3.3.9Limit audit management to a privileged subset1
3.4 Configuration Management9 requirements
3.4 Configuration Management findings
RequirementPointsFinding
CM.L2-3.4.1Baseline configurations and system inventories5
CM.L2-3.4.2Security configuration settings5
CM.L2-3.4.3Track, review, approve, and log changes1
CM.L2-3.4.4Security impact analysis before changes1
CM.L2-3.4.5Access restrictions associated with changes5
CM.L2-3.4.6Least functionality5
CM.L2-3.4.7Restrict nonessential programs, ports, protocols, services5
CM.L2-3.4.8Application allowlisting or denylisting5
CM.L2-3.4.9Control and monitor user-installed software1
3.5 Identification and Authentication11 requirements
3.5 Identification and Authentication findings
RequirementPointsFinding
IA.L2-3.5.1Identify users, processes, and devices5
IA.L2-3.5.2Authenticate identities before granting access5
IA.L2-3.5.3Multifactor authentication5 (3 if partial)
IA.L2-3.5.4Replay-resistant authentication1
IA.L2-3.5.5Prevent identifier reuse1
IA.L2-3.5.6Disable identifiers after inactivity1
IA.L2-3.5.7Password complexity and character change1
IA.L2-3.5.8Prohibit password reuse1
IA.L2-3.5.9Temporary passwords changed immediately1
IA.L2-3.5.10Store and transmit only protected passwords5
IA.L2-3.5.11Obscure authentication feedback1
3.6 Incident Response3 requirements
3.6 Incident Response findings
RequirementPointsFinding
IR.L2-3.6.1Operational incident-handling capability5
IR.L2-3.6.2Track, document, and report incidents5
IR.L2-3.6.3Test the incident response capability1
3.7 Maintenance6 requirements
3.7 Maintenance findings
RequirementPointsFinding
MA.L2-3.7.1Perform maintenance on systems3
MA.L2-3.7.2Control maintenance tools, techniques, and personnel5
MA.L2-3.7.3Sanitize equipment removed for off-site maintenance1
MA.L2-3.7.4Check maintenance media for malicious code3
MA.L2-3.7.5MFA and terminate nonlocal maintenance sessions5
MA.L2-3.7.6Supervise maintenance by uncleared personnel1
3.8 Media Protection9 requirements
3.8 Media Protection findings
RequirementPointsFinding
MP.L2-3.8.1Protect media containing CUI3
MP.L2-3.8.2Limit access to CUI on media to authorized users3
MP.L2-3.8.3Sanitize or destroy media before disposal or reuse5
MP.L2-3.8.4Mark media with CUI markings and limitations1
MP.L2-3.8.5Control and account for media during transport1
MP.L2-3.8.6Protect CUI on digital media during transport1
MP.L2-3.8.7Control the use of removable media5
MP.L2-3.8.8Prohibit portable storage with no identifiable owner3
MP.L2-3.8.9Protect backup CUI at storage locations1
3.9 Personnel Security2 requirements
3.9 Personnel Security findings
RequirementPointsFinding
PS.L2-3.9.1Screen individuals before authorizing access3
PS.L2-3.9.2Protect CUI during and after personnel actions5
3.10 Physical Protection6 requirements
3.10 Physical Protection findings
RequirementPointsFinding
PE.L2-3.10.1Limit physical access to systems and environments5
PE.L2-3.10.2Protect and monitor facilities and support infrastructure5
PE.L2-3.10.3Escort visitors and monitor visitor activity1
PE.L2-3.10.4Maintain audit logs of physical access1
PE.L2-3.10.5Control and manage physical access devices1
PE.L2-3.10.6Safeguarding at alternate work sites1
3.11 Risk Assessment3 requirements
3.11 Risk Assessment findings
RequirementPointsFinding
RA.L2-3.11.1Periodically assess risk3
RA.L2-3.11.2Scan for vulnerabilities5
RA.L2-3.11.3Remediate vulnerabilities per risk assessments1
3.12 Security Assessment4 requirements
3.12 Security Assessment findings
RequirementPointsFinding
CA.L2-3.12.1Periodically assess security controls5
CA.L2-3.12.2Plans of action to correct deficiencies3
CA.L2-3.12.3Monitor security controls on an ongoing basis5
CA.L2-3.12.4System security planGate (0)
3.13 System and Communications Protection16 requirements
3.13 System and Communications Protection findings
RequirementPointsFinding
SC.L2-3.13.1Monitor and protect communications at boundaries5
SC.L2-3.13.2Secure architecture, software development, and engineering principles5
SC.L2-3.13.3Separate user functionality from system management1
SC.L2-3.13.4Prevent unauthorized transfer via shared resources1
SC.L2-3.13.5Subnetworks for publicly accessible components5
SC.L2-3.13.6Deny network traffic by default, allow by exception5
SC.L2-3.13.7Prevent split tunneling1
SC.L2-3.13.8Protect CUI during transmission3
SC.L2-3.13.9Terminate connections after sessions or inactivity1
SC.L2-3.13.10Establish and manage cryptographic keys1
SC.L2-3.13.11FIPS-validated cryptography for CUI5 (3 if partial)
SC.L2-3.13.12Block remote activation and indicate collaborative devices in use1
SC.L2-3.13.13Control and monitor mobile code1
SC.L2-3.13.14Control and monitor VoIP1
SC.L2-3.13.15Protect authenticity of communications sessions5
SC.L2-3.13.16Protect confidentiality of CUI at rest1
3.14 System and Information Integrity7 requirements
3.14 System and Information Integrity findings
RequirementPointsFinding
SI.L2-3.14.1Identify, report, and correct system flaws5
SI.L2-3.14.2Malicious code protection5
SI.L2-3.14.3Monitor and act on security alerts and advisories5
SI.L2-3.14.4Update malicious code protection mechanisms5
SI.L2-3.14.5Periodic and real-time scans3
SI.L2-3.14.6Monitor systems and inbound/outbound traffic5
SI.L2-3.14.7Identify unauthorized use of systems3

Enter findings and choose Calculate. The score is provisional until the record type, SSP, and all applicable findings are reviewed.

If a CMMC Level 2 (Self) check shows gaps you can't close on your own, a score below 88, or a blocker that cannot sit on a Conditional-status POA&M, the next question is who closes them: your own team, your IT provider, or a readiness firm. The Defense Compliance Report's Find My CMMC Path tool asks a few questions about your contract, CUI, environment, timeline, and budget, and shows which kind of help fits.

See which kind of help your gaps call for

What CSET won't do for your NIST 800-171 assessment

CSET turns your findings into a score. It doesn't know whether your boundary is right, doesn't independently validate your evidence, doesn't decide which gaps can wait, and doesn't create the SPRS record. Those are the places an honest self-assessment can still go wrong.

CSET won't… — Why it matters — What to do instead
CSET won't…Why it mattersWhat to do instead
Define your scopeLevel 2 self-assessments must follow the rule's scoping requirements (170.16(c)(1))Map where CUI lives before you answer anything (scoping guide)
Write an SSP that matches your real systemNo current SSP means no completed CMMC assessmentKeep an SSP that describes the actual assessment scope (SSP template guide)
Decide whether your evidence supports MetMet requires final-form evidence for every applicable objectiveUse the evidence log above and the assessment evidence guide
Decide which gaps can go on a CMMC POA&MConditional status requires at least 88, ordinarily only 1-point gaps, one encryption exception, and none of six barred requirements (170.21)Run the checker above and use the POA&M template
Enter or affirm anything in SPRSSPRS stores the results; an authorized user enters them and an Affirming Official affirms a CMMC recordRequest access early and use the SPRS score guide
Tell you which record your contract needsThe incorporated clauses decideUse the three checks at the top of this page
Keep up with rule changesThe latest listed CSET release predates the July 2026 Phase II suspension and September 2026 deviationCheck program status before you post

The right next step after a CSET run isn't the same for every contractor. Whether you keep going on your own, bring in a Registered Practitioner Organization (RPO) for readiness help, lean on a Managed Security Service Provider (MSSP) to close technical gaps, or shrink what gets assessed with a CUI enclave depends on your required CMMC level, whether you handle FCI or CUI, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist and not a CSET score. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes, and do not submit CUI, drawings, or sensitive contract details.

When is CSET enough, and when do you need help?

CSET is a free way to organize the scoring. It is not a complete evidence-management system, a months-long remediation workflow, or an outside second look. Choose help based on the specific gap CSET leaves, not on price alone.

Kind of help — What it adds that CSET can't — Worth it when… — Learn more
Kind of helpWhat it adds that CSET can'tWorth it when…Learn more
Governance, risk, and compliance (GRC) platformA place for evidence, owners, and remediation tracking over timeYou must maintain evidence, affirm annually, and reassess every three years, and the records live in many placesCMMC GRC software
Registered Practitioner Organization (RPO) or readiness consultantA trained second look at scope, evidence, and your SSPYou're unsure your findings would hold up if DIBCAC checkedNIST 800-171 gap analysis
Managed service provider (MSP) or managed security service provider (MSSP)Hands to fix technical gaps like scanning, logging, and MFAYour gaps are technical and your IT team is thinRPO vs. MSP
CUI enclaveA smaller, controlled environment that may reduce the assessment scope when separation and data flows are realCUI is spread across your whole company and scope reduction is feasibleCMMC scoping guide
Free local helpGuidance on getting started, at no costYou're a small business new to DoD requirementsAPEX Accelerator CMMC help

A C3PAO belongs in the process when you are pursuing a formal Level 2 (C3PAO) result, not merely because a CSET score is low. New Level 2 (C3PAO) and Level 3 designations are suspended, but voluntary C3PAO assessments may still be available. CISA also offers free web-based CSET training on running the tool itself. CISA says completing that training does not authorize anyone to conduct assessments on CISA's behalf.

Free tool, paid platform, or outside help: the right mix depends on your contract, where your CUI lives, and how much time you have.

See which path fits your contract

Edge cases to settle before you trust the number

Most CSET runs are straightforward. These situations aren't, and each one can change your answer or your record.

Your paperwork still says C3PAO or Level 3

Phase II is suspended, but a solicitation or contract written earlier may still name Level 2 (C3PAO) or Level 3 (DIBCAC). Don't assume a news release rewrote your contract. The Department directed amendments to affected active solicitations and modifications to affected contracts. Look for the written amendment or modification, and ask your Contracting Officer if none has arrived. CSET can support your readiness either way.

You have more than one system or enclave

Do not automatically create one assessment per server, cloud tenant, or enclave. First define the CMMC Assessment Scope. One assessment may cover multiple information systems and CAGE codes when they are part of the same documented scope; genuinely separate scopes may require separate SSP coverage, assessments, and SPRS records.

A cloud or managed IT provider runs part of your system

Their authorization doesn't erase your duties. For a Level 2 self-assessment, the rule requires the relevant cloud or external service provider customer responsibility matrix to be documented or referenced in your SSP, and the systems connecting to those services can remain in scope (170.16(c)(2)–(3)). See external service provider requirements.

Your encryption relies on a FIPS 140-2 module

NIST's transition schedule placed all FIPS 140-2 certificates on the Historical List on September 22, 2026. NIST says CMVP still supports purchase and use of historical FIPS 140-2 modules for existing systems and that federal agencies decide when they move to FIPS 140-3-only modules. A Historical List entry does not, by itself, settle how SC.L2-3.13.11 applies to your specific module, implementation, contract, or assessment. Record the module and certificate you actually use, check its current CMVP status, and confirm the applicable acquisition direction before choosing Met, Not Met, or the rule's 3-point partial state.

Your team is already working on Revision 3

Keep that as a separate project. Run your current CMMC Level 2 assessment on Revision 2 so the score stays repeatable until the contract or rule actually changes.

You upgrade CSET partway through

Export and password-protect your assessment first. After the upgrade, reopen it and re-check the findings, score, and reports before you rely on them. CISA's release notes describe migration of existing assessments between versions, but a successful migration does not replace your own regression check.

Your MSP runs CSET for you

That's fine. But the findings describe your system, and your company's Affirming Official stands behind the CMMC record in SPRS. Ask to see the evidence behind every Met.

CSET NIST 800-171 assessment FAQ

Is CSET really free?

Yes. CISA and Idaho National Laboratory publish CSET as free software. The repository lists MIT and Apache 2.0 licensing notices, with additional dependency notices. There is no paid CMMC module in the official release list.

Does CSET run on a Mac?

Not through the standalone installer. CISA's repository says local standalone and enterprise deployments require Windows, with Windows 10 or later for local installations. It recommends Docker for Mac and Linux users, which takes some technical setup.

Does CSET send my answers to CISA or DoD?

The standalone version uses a local database, and the official release notes and source we reviewed do not describe direct SPRS submission. Nothing reaches SPRS through the official entry process until an authorized user enters the results there. We did not inspect the app's network traffic, so treat the assessment and exports as sensitive and use the export-password option.

Why doesn't my CSET score match what SPRS shows?

Common causes include a different model or release, a blank question deducted in CSET, an N/A entered differently, or a partial MFA or encryption finding recorded differently. Compare all 110 findings requirement by requirement. When the model and findings match the rule, the arithmetic should reconcile.

Can I use CSET for CMMC Level 1?

Yes. CSET's CMMC 2.0 model includes a Level 1 option covering the 15 FAR 52.204-21 requirements. Level 1 is all-or-nothing, with no POA&M, and the self-assessment and affirmation repeat every year. Our Level 1 checklist covers each requirement.

Is CSET the same as a gap analysis?

It can be the engine of one. A full gap analysis adds scoping, evidence review, an SSP, and a remediation plan around the score. CSET supplies structure and scoring support. The rest is the work in this guide, or the work you'd pay a provider for. See NIST 800-171 gap analysis.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Sources

All checked September 23, 2026.

About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures. We are not affiliated with the Cyber AB, DoD/DoW, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice; confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney.

Find my CMMC path →