Self-score · 8 categories · 5 minutes · readiness signal, not a certification

CMMC Readiness Scorecard

Where does your defense / regulated manufacturing posture really sit — binder theater, or controls that stick on the shop floor? Pick the statement that fits NOW for each row (score 1–12). Optionally score NEXT for ~90 days out. Honest scores beat hopeful ones.

How to score

  1. Read all four stage descriptions in a row.
  2. Choose the one that matches how you operate today — not the policy PDF.
  3. Enter a number 1–12 in Score Now (use low/mid/high of that band if you’re between stages).
  4. Optional: enter Score Next for where leadership intends to be in ~90 days.
  5. Totals update live. This is a readiness signal — not an assessment or certification.

Max total: 96 (8 × 12). Many shops score 28–50 before a focused remediation quarter.

Category 1–3 · Pain 4–6 · Average 7–9 · Solid 10–12 · Advantage Now Next
1. Scope clarity (FCI/CUI) Nobody agrees what’s FCI vs CUI vs “just shop data.” Systems, shares, and email treat everything the same. A scoping conversation would start from zero under customer pressure. You’ve heard the terms and marked a few folders. Boundaries blur on the floor and in ERP exports. Contract language outruns your network diagram. Scope lives in a slide deck. In-scope assets and data flows are documented enough to walk a buyer through. Out-of-scope is intentional, not accidental. When a new system appears, someone asks the scope question. FCI/CUI boundaries are clear, maintained, and reflected in how people actually work. Scope changes get reviewed. You can explain what’s in and out in one plant-language paragraph.
2. Access & identity control Shared accounts, lingering ex-employee access, and “everyone’s a local admin somewhere.” MFA is optional or absent. Privileged access is tribal knowledge, not a list. Directory exists; joiner/mover/leaver is inconsistent. MFA covers some apps. Floor PCs and service accounts are the weak links. Reviews happen after something goes wrong. Identity is managed: MFA where it matters, least privilege trending, and periodic access reviews with owners. Privileged accounts are fewer and watched. Exceptions have expiry dates. Access matches role and scope — including shop-floor and vendors. Privileged paths are deliberate. You can prove who had access to CUI and when, without a scavenger hunt.
3. Endpoint & network hardening Flat network, unpatched floor machines, and “that Windows box by the press never updates.” Removable media walks freely. Boundary protection is a firewall default from years ago. Office endpoints are managed; OT-adjacent and shared PCs lag. Segmentation is aspirational. Hardening baselines exist on paper. Vulnerability findings pile up faster than remediations. Managed endpoints, patch cadence, and meaningful network boundaries around sensitive systems. Floor machines have a hardening path that doesn’t stop production. Findings have owners and dates. Hardening is continuous and plant-realistic: protected without freezing the line. Segmentation, endpoint control, and config baselines match your CUI scope — and evidence is ready when asked.
4. Evidence & documentation habit Policies are stale PDFs. Screenshots and tickets that would prove controls don’t exist. An auditor request would mean weeks of reconstructing history nobody recorded. Some procedures are current; evidence is scattered across email and shares. You collect proof under deadline. SSP / POA&M language (or equivalent) is incomplete or outdated. Living docs for the controls you claim. Evidence is gathered as work happens — tickets, configs, training logs. Gaps are listed with owners. You’re not inventing artifacts the night before. Evidence is a habit, not a project. Documentation matches reality on the floor. You can pull proof for scoped controls quickly — same story for primes, assessors, and your own team.
5. Incident response muscle No playbook. If ransomware or a breach hit tomorrow, you’d be googling and calling friends. Roles, contacts, and “who shuts what down” are unclear. Lessons never get written down. There’s a document someone wrote once. Contacts are half current. You’ve never tabletopped it with ops. Detection relies on users noticing something weird. IR plan exists with roles, escalation, and plant considerations. You’ve run at least a tabletop. Logging/alerting covers critical systems. After-action items become real remediations. Incident response is practiced muscle: detect, contain, communicate, recover — including shop-floor realities. Partners and leadership know their lanes. Evidence of drills and improvements exists.
6. Vendor / supply-chain risk Vendors get broad access because it’s easier. No inventory of who touches CUI or plant systems. Contracts don’t mention security. A third-party breach would be your problem with no paper trail. You ask a few questionnaire questions at onboarding. Access reviews for vendors are rare. Cloud and MSPs are trusted on reputation. Flow-down requirements surprise you mid-contract. Vendors with access are listed, scoped, and reviewed. Contracts and onboarding include security expectations. Offboarding removes access. You know which suppliers sit in your CUI path. Supply-chain risk is managed: least privilege for partners, flow-downs where required, and periodic review. You’re not the weak link primes worry about — and you can show why.
7. Leadership ownership CMMC is “an IT thing” until a deal is blocked. No budget owner, no cadence, no decision rights. Leadership hears about gaps when sales is already in the room. Someone is nominally accountable — usually overloaded. Updates are ad hoc. Risk acceptance is informal. Priorities flip when the next fire or customer email arrives. Named owner at leadership level. Regular review of gaps, POA&M-style items, and spend. Ops and IT share the same ranked list. Risk acceptance is explicit when you defer a control. Leadership treats readiness as competitive: funded, scheduled, and tied to wins you care about. IT executes; executives own tradeoffs. The plant isn’t surprised by audit or customer asks.
8. Continuous monitoring & improvement Security is a project that ended (or never started). No ongoing scan, log review, or control health check. Drift is invisible until failure or an external ask. Tools generate alerts; humans drown. Reviews are quarterly at best. POA&M items age without progress. You rediscover the same gaps every assessment cycle. Monitoring covers critical assets. Findings feed a living backlog with due dates. Metrics aren’t vanity — they show control health. Improvements stick after the assessor leaves. Continuous monitoring and improvement are how you run IT: detect drift, close gaps, prove posture over time. Readiness compounds instead of resetting every customer questionnaire.
Total Score (max 96)

1. Scope clarity (FCI/CUI)

1–3 · Pain

Nobody agrees what’s FCI vs CUI vs “just shop data.” Systems, shares, and email treat everything the same. A scoping conversation would start from zero under customer pressure.

4–6 · Average

You’ve heard the terms and marked a few folders. Boundaries blur on the floor and in ERP exports. Contract language outruns your network diagram. Scope lives in a slide deck.

7–9 · Solid

In-scope assets and data flows are documented enough to walk a buyer through. Out-of-scope is intentional, not accidental. When a new system appears, someone asks the scope question.

10–12 · Advantage

FCI/CUI boundaries are clear, maintained, and reflected in how people actually work. Scope changes get reviewed. You can explain what’s in and out in one plant-language paragraph.

2. Access & identity control

1–3 · Pain

Shared accounts, lingering ex-employee access, and “everyone’s a local admin somewhere.” MFA is optional or absent. Privileged access is tribal knowledge, not a list.

4–6 · Average

Directory exists; joiner/mover/leaver is inconsistent. MFA covers some apps. Floor PCs and service accounts are the weak links. Reviews happen after something goes wrong.

7–9 · Solid

Identity is managed: MFA where it matters, least privilege trending, and periodic access reviews with owners. Privileged accounts are fewer and watched. Exceptions have expiry dates.

10–12 · Advantage

Access matches role and scope — including shop-floor and vendors. Privileged paths are deliberate. You can prove who had access to CUI and when, without a scavenger hunt.

3. Endpoint & network hardening

1–3 · Pain

Flat network, unpatched floor machines, and “that Windows box by the press never updates.” Removable media walks freely. Boundary protection is a firewall default from years ago.

4–6 · Average

Office endpoints are managed; OT-adjacent and shared PCs lag. Segmentation is aspirational. Hardening baselines exist on paper. Vulnerability findings pile up faster than remediations.

7–9 · Solid

Managed endpoints, patch cadence, and meaningful network boundaries around sensitive systems. Floor machines have a hardening path that doesn’t stop production. Findings have owners and dates.

10–12 · Advantage

Hardening is continuous and plant-realistic: protected without freezing the line. Segmentation, endpoint control, and config baselines match your CUI scope — and evidence is ready when asked.

4. Evidence & documentation habit

1–3 · Pain

Policies are stale PDFs. Screenshots and tickets that would prove controls don’t exist. An auditor request would mean weeks of reconstructing history nobody recorded.

4–6 · Average

Some procedures are current; evidence is scattered across email and shares. You collect proof under deadline. SSP / POA&M language (or equivalent) is incomplete or outdated.

7–9 · Solid

Living docs for the controls you claim. Evidence is gathered as work happens — tickets, configs, training logs. Gaps are listed with owners. You’re not inventing artifacts the night before.

10–12 · Advantage

Evidence is a habit, not a project. Documentation matches reality on the floor. You can pull proof for scoped controls quickly — same story for primes, assessors, and your own team.

5. Incident response muscle

1–3 · Pain

No playbook. If ransomware or a breach hit tomorrow, you’d be googling and calling friends. Roles, contacts, and “who shuts what down” are unclear. Lessons never get written down.

4–6 · Average

There’s a document someone wrote once. Contacts are half current. You’ve never tabletopped it with ops. Detection relies on users noticing something weird.

7–9 · Solid

IR plan exists with roles, escalation, and plant considerations. You’ve run at least a tabletop. Logging/alerting covers critical systems. After-action items become real remediations.

10–12 · Advantage

Incident response is practiced muscle: detect, contain, communicate, recover — including shop-floor realities. Partners and leadership know their lanes. Evidence of drills and improvements exists.

6. Vendor / supply-chain risk

1–3 · Pain

Vendors get broad access because it’s easier. No inventory of who touches CUI or plant systems. Contracts don’t mention security. A third-party breach would be your problem with no paper trail.

4–6 · Average

You ask a few questionnaire questions at onboarding. Access reviews for vendors are rare. Cloud and MSPs are trusted on reputation. Flow-down requirements surprise you mid-contract.

7–9 · Solid

Vendors with access are listed, scoped, and reviewed. Contracts and onboarding include security expectations. Offboarding removes access. You know which suppliers sit in your CUI path.

10–12 · Advantage

Supply-chain risk is managed: least privilege for partners, flow-downs where required, and periodic review. You’re not the weak link primes worry about — and you can show why.

7. Leadership ownership

1–3 · Pain

CMMC is “an IT thing” until a deal is blocked. No budget owner, no cadence, no decision rights. Leadership hears about gaps when sales is already in the room.

4–6 · Average

Someone is nominally accountable — usually overloaded. Updates are ad hoc. Risk acceptance is informal. Priorities flip when the next fire or customer email arrives.

7–9 · Solid

Named owner at leadership level. Regular review of gaps, POA&M-style items, and spend. Ops and IT share the same ranked list. Risk acceptance is explicit when you defer a control.

10–12 · Advantage

Leadership treats readiness as competitive: funded, scheduled, and tied to wins you care about. IT executes; executives own tradeoffs. The plant isn’t surprised by audit or customer asks.

8. Continuous monitoring & improvement

1–3 · Pain

Security is a project that ended (or never started). No ongoing scan, log review, or control health check. Drift is invisible until failure or an external ask.

4–6 · Average

Tools generate alerts; humans drown. Reviews are quarterly at best. POA&M items age without progress. You rediscover the same gaps every assessment cycle.

7–9 · Solid

Monitoring covers critical assets. Findings feed a living backlog with due dates. Metrics aren’t vanity — they show control health. Improvements stick after the assessor leaves.

10–12 · Advantage

Continuous monitoring and improvement are how you run IT: detect drift, close gaps, prove posture over time. Readiness compounds instead of resetting every customer questionnaire.

Total Score Now

of 96

Total Score Next

of 96 · optional 90-day target

Turn low scores into a real plan

Bring this scorecard to a Free Manufacturing IT Risk Audit. We’ll map CMMC-ready gaps in plant language and hand you a written plan you keep — certification theater not included.

Book Your Free Manufacturing IT Risk Audit