An assessment is a structured process for evaluating how well an organization meets cybersecurity requirements defined by CMMC or NIST SP 800-171. The outcome typically includes control implementation status, supporting documentation, and readiness indicators. To learn more about creating and managing assessments, please select from the links below:
Dashboard: This article provides instructions on accessing an existing assessment, as well as a table explaining the different assessment sections.
Create: This article provides instructions on creating a new assessment.
Passphrase: This article provides information on managing passphrases used to access your assessments.
Org Info: This article provides information and instructions on entering and managing your organization’s information and points of contact.
System Info: This article provides information and instructions on entering and managing your information system, leveraged systems, and environments of operation.
Practices: This article provides information and instructions on completing the bulk of your assessment work, such as implementation statements, evidence, and status per control.
POA&Ms: This article provides information and instructions on creating, modifying, reviewing, and deleting Plan of Action and Milestone items.
Evidence: This article provides information and instructions on uploading and managing supporting files for the assessment.
Documentation: This article provides information and instructions on generating and downloading your final deliverables, including your SSP.