Assessments
An assessment is your organization's self-assessment against CMMC. It's the working record of how you meet each requirement — not a one-time questionnaire but a living document you build up objective by objective, revisit as your environment changes, and hand to an assessor when you're ready.
CMMC is built on NIST SP 800-171. A Level 2 assessment covers all 110 practices, and each practice breaks down into one or more assessment objectives — the individual, testable statements you must satisfy. There are 320 objectives in total across the 110 Level-2 practices. You record where you stand on each one, and the platform rolls those answers up into a practice-by-practice picture, your SPRS score, and your list of open gaps.
/dashboard/assessments). It's visible to every role that can read compliance data; recording statuses and narratives requires an editing role — see Permissions.Key concepts
Level 1 vs Level 2
CMMC has two self-assessable levels, and an assessment is scoped to one of them.
| Level | Scope |
|---|---|
| Level 1 | The foundational practices protecting Federal Contract Information (FCI) |
| Level 2 | All 110 practices protecting Controlled Unclassified Information (CUI), across the 320 objectives |
The requirement hierarchy
Everything in an assessment is organized as a hierarchy, from broad domains down to the single statements you actually answer.
| Level | What it is |
|---|---|
| Family (domain) | One of the 14 CMMC control families — e.g. Access Control, Audit & Accountability, Configuration Management |
| Practice | A single CMMC requirement inside a family (110 of them at Level 2), identified like AC.L2-3.1.1 |
| Objective | A discrete, testable statement inside a practice — the row you set a status on (320 in total) |
Objective status
Every objective carries one status. This is the atom of the whole assessment — practices, your score, and your gaps are all derived from these.
| Status | Meaning |
|---|---|
| Implemented | The objective is fully met |
| Partially implemented | Some, but not all, of the objective is in place — counts as not met |
| Not implemented | The objective is not met |
| Not applicable | The objective is out of scope for your environment, with a documented reason |
| Unassessed | You haven't recorded a status yet — counts as not met |
How objectives roll up into practices
A practice is met only when every in-scope objective under it is met. A single partial, not-implemented, or unassessed objective leaves the whole practice failing. Objectives you mark Not applicable (with a reason) are removed from scope and don't hold the practice back.
Using an assessment
An assessment opens on an overview with your headline metrics, then lets you drill into each family and work through its objectives.
Read the overview
Open the assessment
From the Assessments list, open the assessment you want to work in. The overview loads first.
Read the metrics
The overview summarizes where you stand: how many objectives are met, how many are failing (not implemented or partially implemented), and how many are unassessed (not yet touched). Together with your not-applicable count, these add up to the full objective set.
Check your score and gaps
The overview also surfaces your SPRS score and your open gaps — the practices that aren't fully implemented yet. Use these to decide where to focus next.
Work through objectives
Pick a family
Browse the requirement hierarchy and choose a control family to work on. Each family shows its practices and how many of their objectives are still open.
Open a practice
Expand a practice to see its objectives — the individual statements you'll assess. Each objective shows the exact NIST wording so you know precisely what's being asked.
Set each objective's status
For every objective, choose Implemented, Partially implemented, Not implemented, or Not applicable. This is the single most important action in an assessment — it drives every downstream number.
Write the narrative
Record how you meet the objective — the plain-language explanation an assessor reads to understand your implementation. A good narrative describes what's in place, not just that a box is checked.
Record a reason for anything not applicable
If an objective doesn't apply to your environment, mark it Not applicable and document why. The reason is retained as evidence of a complete, defensible assessment.
Permissions
Access follows the compliance-data permissions in the role matrix.
| Capability | Who |
|---|---|
| View assessments, the overview, and objective statuses | Every non-platform role, including Assessor |
| Set objective statuses, write narratives, mark not-applicable | Org Admin, Org User, MSP Super, MSP Admin |
Assessors have read-only access — they can review your entire assessment, its narratives, and its evidence, but they can't change a status or a score.
How it works
Extra detail on how the assessment behaves — product behavior, not internals.
What an objective holds
Each objective is a single record inside a practice.
AC.L2-3.1.1) and its CMMC control family.How the score is calculated
Your SPRS score starts at 110 and subtracts a weight for every in-scope practice that isn't fully met. Practices carry different weights depending on how important the underlying control is, so not every gap costs the same. Because a practice is met only when all of its in-scope objectives are met, an unassessed or partially implemented objective quietly holds its whole practice — and its weight — against your score until you close it.
What "open gaps" means
Your open gaps are the practices that aren't fully implemented yet — including practices where you simply haven't assessed the objectives. Clearing a gap means bringing every in-scope objective under that practice to Implemented (or Not applicable with a reason). Watching your open-gaps count fall is the most direct measure of assessment progress.
AI assistant access
When the AI Connector is enabled, assistants can read (never change) your assessment data — your objective statuses, practice rollups, SPRS score, and open gaps — so you can ask questions about your posture in plain language. Access follows the same permissions as the app: an assistant only ever sees what the connected user's role is allowed to see.

