Before a prime or auditor asks — score scope, identity, hardening, evidence, incident response, vendors, leadership, and monitoring. Pick what fits NOW (1–12). Optional NEXT for 90 days. Low rows = your gap list, not a certification.
How to score
Read all four stage descriptions in a row.
Choose the one that matches how you operate today — not the policy PDF.
Enter a number 1–12 in Score Now (use low/mid/high of that band if you’re between stages).
Optional: enter Score Next for where leadership intends to be in ~90 days.
Totals update live. This is a readiness signal — not an assessment or certification.
1–3 Pain / reactive
4–6 Firefighting / average
7–9 Controlled / solid
10–12 Multiplier / advantage
Max total: 96 (8 × 12). Many shops score 28–50 before a focused remediation quarter.
Category
1–3 · Pain
4–6 · Average
7–9 · Solid
10–12 · Advantage
Now
Next
1. Scope clarity (FCI/CUI)
Nobody agrees what’s FCI vs CUI vs “just shop data.” Systems, shares, and email treat everything the same. A scoping conversation would start from zero under customer pressure.
You’ve heard the terms and marked a few folders. Boundaries blur on the floor and in ERP exports. Contract language outruns your network diagram. Scope lives in a slide deck.
In-scope assets and data flows are documented enough to walk a buyer through. Out-of-scope is intentional, not accidental. When a new system appears, someone asks the scope question.
FCI/CUI boundaries are clear, maintained, and reflected in how people actually work. Scope changes get reviewed. You can explain what’s in and out in one plant-language paragraph.
2. Access & identity control
Shared accounts, lingering ex-employee access, and “everyone’s a local admin somewhere.” MFA is optional or absent. Privileged access is tribal knowledge, not a list.
Directory exists; joiner/mover/leaver is inconsistent. MFA covers some apps. Floor PCs and service accounts are the weak links. Reviews happen after something goes wrong.
Identity is managed: MFA where it matters, least privilege trending, and periodic access reviews with owners. Privileged accounts are fewer and watched. Exceptions have expiry dates.
Access matches role and scope — including shop-floor and vendors. Privileged paths are deliberate. You can prove who had access to CUI and when, without a scavenger hunt.
3. Endpoint & network hardening
Flat network, unpatched floor machines, and “that Windows box by the press never updates.” Removable media walks freely. Boundary protection is a firewall default from years ago.
Office endpoints are managed; OT-adjacent and shared PCs lag. Segmentation is aspirational. Hardening baselines exist on paper. Vulnerability findings pile up faster than remediations.
Managed endpoints, patch cadence, and meaningful network boundaries around sensitive systems. Floor machines have a hardening path that doesn’t stop production. Findings have owners and dates.
Hardening is continuous and plant-realistic: protected without freezing the line. Segmentation, endpoint control, and config baselines match your CUI scope — and evidence is ready when asked.
4. Evidence & documentation habit
Policies are stale PDFs. Screenshots and tickets that would prove controls don’t exist. An auditor request would mean weeks of reconstructing history nobody recorded.
Some procedures are current; evidence is scattered across email and shares. You collect proof under deadline. SSP / POA&M language (or equivalent) is incomplete or outdated.
Living docs for the controls you claim. Evidence is gathered as work happens — tickets, configs, training logs. Gaps are listed with owners. You’re not inventing artifacts the night before.
Evidence is a habit, not a project. Documentation matches reality on the floor. You can pull proof for scoped controls quickly — same story for primes, assessors, and your own team.
5. Incident response muscle
No playbook. If ransomware or a breach hit tomorrow, you’d be googling and calling friends. Roles, contacts, and “who shuts what down” are unclear. Lessons never get written down.
There’s a document someone wrote once. Contacts are half current. You’ve never tabletopped it with ops. Detection relies on users noticing something weird.
IR plan exists with roles, escalation, and plant considerations. You’ve run at least a tabletop. Logging/alerting covers critical systems. After-action items become real remediations.
Incident response is practiced muscle: detect, contain, communicate, recover — including shop-floor realities. Partners and leadership know their lanes. Evidence of drills and improvements exists.
6. Vendor / supply-chain risk
Vendors get broad access because it’s easier. No inventory of who touches CUI or plant systems. Contracts don’t mention security. A third-party breach would be your problem with no paper trail.
You ask a few questionnaire questions at onboarding. Access reviews for vendors are rare. Cloud and MSPs are trusted on reputation. Flow-down requirements surprise you mid-contract.
Vendors with access are listed, scoped, and reviewed. Contracts and onboarding include security expectations. Offboarding removes access. You know which suppliers sit in your CUI path.
Supply-chain risk is managed: least privilege for partners, flow-downs where required, and periodic review. You’re not the weak link primes worry about — and you can show why.
7. Leadership ownership
CMMC is “an IT thing” until a deal is blocked. No budget owner, no cadence, no decision rights. Leadership hears about gaps when sales is already in the room.
Someone is nominally accountable — usually overloaded. Updates are ad hoc. Risk acceptance is informal. Priorities flip when the next fire or customer email arrives.
Named owner at leadership level. Regular review of gaps, POA&M-style items, and spend. Ops and IT share the same ranked list. Risk acceptance is explicit when you defer a control.
Leadership treats readiness as competitive: funded, scheduled, and tied to wins you care about. IT executes; executives own tradeoffs. The plant isn’t surprised by audit or customer asks.
8. Continuous monitoring & improvement
Security is a project that ended (or never started). No ongoing scan, log review, or control health check. Drift is invisible until failure or an external ask.
Tools generate alerts; humans drown. Reviews are quarterly at best. POA&M items age without progress. You rediscover the same gaps every assessment cycle.
Monitoring covers critical assets. Findings feed a living backlog with due dates. Metrics aren’t vanity — they show control health. Improvements stick after the assessor leaves.
Continuous monitoring and improvement are how you run IT: detect drift, close gaps, prove posture over time. Readiness compounds instead of resetting every customer questionnaire.
Total Score (max 96)
1. Scope clarity (FCI/CUI)
1–3 · Pain
Nobody agrees what’s FCI vs CUI vs “just shop data.” Systems, shares, and email treat everything the same. A scoping conversation would start from zero under customer pressure.
4–6 · Average
You’ve heard the terms and marked a few folders. Boundaries blur on the floor and in ERP exports. Contract language outruns your network diagram. Scope lives in a slide deck.
7–9 · Solid
In-scope assets and data flows are documented enough to walk a buyer through. Out-of-scope is intentional, not accidental. When a new system appears, someone asks the scope question.
10–12 · Advantage
FCI/CUI boundaries are clear, maintained, and reflected in how people actually work. Scope changes get reviewed. You can explain what’s in and out in one plant-language paragraph.
2. Access & identity control
1–3 · Pain
Shared accounts, lingering ex-employee access, and “everyone’s a local admin somewhere.” MFA is optional or absent. Privileged access is tribal knowledge, not a list.
4–6 · Average
Directory exists; joiner/mover/leaver is inconsistent. MFA covers some apps. Floor PCs and service accounts are the weak links. Reviews happen after something goes wrong.
7–9 · Solid
Identity is managed: MFA where it matters, least privilege trending, and periodic access reviews with owners. Privileged accounts are fewer and watched. Exceptions have expiry dates.
10–12 · Advantage
Access matches role and scope — including shop-floor and vendors. Privileged paths are deliberate. You can prove who had access to CUI and when, without a scavenger hunt.
3. Endpoint & network hardening
1–3 · Pain
Flat network, unpatched floor machines, and “that Windows box by the press never updates.” Removable media walks freely. Boundary protection is a firewall default from years ago.
4–6 · Average
Office endpoints are managed; OT-adjacent and shared PCs lag. Segmentation is aspirational. Hardening baselines exist on paper. Vulnerability findings pile up faster than remediations.
7–9 · Solid
Managed endpoints, patch cadence, and meaningful network boundaries around sensitive systems. Floor machines have a hardening path that doesn’t stop production. Findings have owners and dates.
10–12 · Advantage
Hardening is continuous and plant-realistic: protected without freezing the line. Segmentation, endpoint control, and config baselines match your CUI scope — and evidence is ready when asked.
4. Evidence & documentation habit
1–3 · Pain
Policies are stale PDFs. Screenshots and tickets that would prove controls don’t exist. An auditor request would mean weeks of reconstructing history nobody recorded.
4–6 · Average
Some procedures are current; evidence is scattered across email and shares. You collect proof under deadline. SSP / POA&M language (or equivalent) is incomplete or outdated.
7–9 · Solid
Living docs for the controls you claim. Evidence is gathered as work happens — tickets, configs, training logs. Gaps are listed with owners. You’re not inventing artifacts the night before.
10–12 · Advantage
Evidence is a habit, not a project. Documentation matches reality on the floor. You can pull proof for scoped controls quickly — same story for primes, assessors, and your own team.
5. Incident response muscle
1–3 · Pain
No playbook. If ransomware or a breach hit tomorrow, you’d be googling and calling friends. Roles, contacts, and “who shuts what down” are unclear. Lessons never get written down.
4–6 · Average
There’s a document someone wrote once. Contacts are half current. You’ve never tabletopped it with ops. Detection relies on users noticing something weird.
7–9 · Solid
IR plan exists with roles, escalation, and plant considerations. You’ve run at least a tabletop. Logging/alerting covers critical systems. After-action items become real remediations.
10–12 · Advantage
Incident response is practiced muscle: detect, contain, communicate, recover — including shop-floor realities. Partners and leadership know their lanes. Evidence of drills and improvements exists.
6. Vendor / supply-chain risk
1–3 · Pain
Vendors get broad access because it’s easier. No inventory of who touches CUI or plant systems. Contracts don’t mention security. A third-party breach would be your problem with no paper trail.
4–6 · Average
You ask a few questionnaire questions at onboarding. Access reviews for vendors are rare. Cloud and MSPs are trusted on reputation. Flow-down requirements surprise you mid-contract.
7–9 · Solid
Vendors with access are listed, scoped, and reviewed. Contracts and onboarding include security expectations. Offboarding removes access. You know which suppliers sit in your CUI path.
10–12 · Advantage
Supply-chain risk is managed: least privilege for partners, flow-downs where required, and periodic review. You’re not the weak link primes worry about — and you can show why.
7. Leadership ownership
1–3 · Pain
CMMC is “an IT thing” until a deal is blocked. No budget owner, no cadence, no decision rights. Leadership hears about gaps when sales is already in the room.
4–6 · Average
Someone is nominally accountable — usually overloaded. Updates are ad hoc. Risk acceptance is informal. Priorities flip when the next fire or customer email arrives.
7–9 · Solid
Named owner at leadership level. Regular review of gaps, POA&M-style items, and spend. Ops and IT share the same ranked list. Risk acceptance is explicit when you defer a control.
10–12 · Advantage
Leadership treats readiness as competitive: funded, scheduled, and tied to wins you care about. IT executes; executives own tradeoffs. The plant isn’t surprised by audit or customer asks.
8. Continuous monitoring & improvement
1–3 · Pain
Security is a project that ended (or never started). No ongoing scan, log review, or control health check. Drift is invisible until failure or an external ask.
4–6 · Average
Tools generate alerts; humans drown. Reviews are quarterly at best. POA&M items age without progress. You rediscover the same gaps every assessment cycle.
7–9 · Solid
Monitoring covers critical assets. Findings feed a living backlog with due dates. Metrics aren’t vanity — they show control health. Improvements stick after the assessor leaves.
10–12 · Advantage
Continuous monitoring and improvement are how you run IT: detect drift, close gaps, prove posture over time. Readiness compounds instead of resetting every customer questionnaire.
Total Score Now
—
of 96
Total Score Next
—
of 96 · optional 90-day target
Turn low scores into a real plan
Bring your low rows to a conversation — we’ll talk fit and fixed-fee next steps.