Features Pricing FAQ About Login Sign Up

Help center Article 12

Starting a CMMC self-assessment

CMMC stands for Cybersecurity Maturity Model Certification. It is a Department of Defense program that requires defense contractors to meet cybersecurity standards. RFI Hawk's free self-assessment walks you through every control in plain English.

Steps

  1. From the dashboard, click CMMC Suite.

  2. Click Start the Assessment.

  3. The first questions help RFI Hawk decide your level:

  4. Do you handle Federal Contract Information (FCI)?
  5. Do you handle Controlled Unclassified Information (CUI)?
  6. What is your IT environment (on-premises, cloud, mixed)?

  7. Based on your answers, the system tells you which level you need (Level 1, Level 2, or Level 3) and starts the relevant control questions.

  8. For each control, the system asks plain-English questions and you answer In Place, Partly In Place, Not In Place, or Does Not Apply.

[screenshot of a CMMC question with the four answer options]

  1. The system saves every answer as you go. You can stop and come back any time.

  2. When you finish, you get:

  3. Your level (1, 2, or 3)
  4. Your supplier score
  5. Your gap list (controls marked Not In Place)
  6. A draft Plan of Action and Milestones for your gaps
  7. A draft System Security Plan

What to do if it does not work

If you are not sure how to answer a question, click "I do not know" and the system gives you guidance. You can come back to the question later.

If a question does not apply to your environment, mark it Does Not Apply. The system requires a brief reason. The reason becomes part of your assessment record.

Related articles