Assessments

Track how your organization meets each CMMC practice and objective — set an implementation status and narrative for every objective, watch them roll up into practices, your SPRS score, and your open gaps.

An assessment is your organization's self-assessment against CMMC. It's the working record of how you meet each requirement — not a one-time questionnaire but a living document you build up objective by objective, revisit as your environment changes, and hand to an assessor when you're ready.

CMMC is built on NIST SP 800-171. A Level 2 assessment covers all 110 practices, and each practice breaks down into one or more assessment objectives — the individual, testable statements you must satisfy. There are 320 objectives in total across the 110 Level-2 practices. You record where you stand on each one, and the platform rolls those answers up into a practice-by-practice picture, your SPRS score, and your list of open gaps.

Find it in the sidebar under Assessments (/dashboard/assessments). It's visible to every role that can read compliance data; recording statuses and narratives requires an editing role — see Permissions.

Key concepts

Level 1 vs Level 2

CMMC has two self-assessable levels, and an assessment is scoped to one of them.

LevelScope
Level 1The foundational practices protecting Federal Contract Information (FCI)
Level 2All 110 practices protecting Controlled Unclassified Information (CUI), across the 320 objectives
Most defense-contractor journeys target Level 2. Start there if you handle CUI; the Level-2 set fully contains the Level-1 practices.

The requirement hierarchy

Everything in an assessment is organized as a hierarchy, from broad domains down to the single statements you actually answer.

LevelWhat it is
Family (domain)One of the 14 CMMC control families — e.g. Access Control, Audit & Accountability, Configuration Management
PracticeA single CMMC requirement inside a family (110 of them at Level 2), identified like AC.L2-3.1.1
ObjectiveA discrete, testable statement inside a practice — the row you set a status on (320 in total)

Objective status

Every objective carries one status. This is the atom of the whole assessment — practices, your score, and your gaps are all derived from these.

StatusMeaning
ImplementedThe objective is fully met
Partially implementedSome, but not all, of the objective is in place — counts as not met
Not implementedThe objective is not met
Not applicableThe objective is out of scope for your environment, with a documented reason
UnassessedYou haven't recorded a status yet — counts as not met
Partially implemented and unassessed both count as not met for scoring and gap purposes. A half-done control earns no partial credit toward CMMC — an objective is either fully satisfied or it isn't.

How objectives roll up into practices

A practice is met only when every in-scope objective under it is met. A single partial, not-implemented, or unassessed objective leaves the whole practice failing. Objectives you mark Not applicable (with a reason) are removed from scope and don't hold the practice back.


Using an assessment

An assessment opens on an overview with your headline metrics, then lets you drill into each family and work through its objectives.

Read the overview

Open the assessment

From the Assessments list, open the assessment you want to work in. The overview loads first.

Read the metrics

The overview summarizes where you stand: how many objectives are met, how many are failing (not implemented or partially implemented), and how many are unassessed (not yet touched). Together with your not-applicable count, these add up to the full objective set.

Check your score and gaps

The overview also surfaces your SPRS score and your open gaps — the practices that aren't fully implemented yet. Use these to decide where to focus next.

"Failing," "met," and "unassessed" are counted at the objective grain on the overview. Elsewhere in the platform the same words may be counted at the practice grain (for example, your open-gaps list is practices, not objectives), so the totals won't always line up — they're answering slightly different questions.

Work through objectives

Pick a family

Browse the requirement hierarchy and choose a control family to work on. Each family shows its practices and how many of their objectives are still open.

Open a practice

Expand a practice to see its objectives — the individual statements you'll assess. Each objective shows the exact NIST wording so you know precisely what's being asked.

Set each objective's status

For every objective, choose Implemented, Partially implemented, Not implemented, or Not applicable. This is the single most important action in an assessment — it drives every downstream number.

Write the narrative

Record how you meet the objective — the plain-language explanation an assessor reads to understand your implementation. A good narrative describes what's in place, not just that a box is checked.

Record a reason for anything not applicable

If an objective doesn't apply to your environment, mark it Not applicable and document why. The reason is retained as evidence of a complete, defensible assessment.

Attach evidence to objectives as you go — the artifacts that back up each narrative. Working an objective and its evidence together saves you a second pass before an assessment.

Permissions

Access follows the compliance-data permissions in the role matrix.

CapabilityWho
View assessments, the overview, and objective statusesEvery non-platform role, including Assessor
Set objective statuses, write narratives, mark not-applicableOrg Admin, Org User, MSP Super, MSP Admin

Assessors have read-only access — they can review your entire assessment, its narratives, and its evidence, but they can't change a status or a score.

The number of assessments you can create is governed by your subscription plan. Foundation includes 1 assessment, Professional includes 3, and Enterprise is unlimited. When you reach your plan's limit, creating another assessment prompts an upgrade.

How it works

Extra detail on how the assessment behaves — product behavior, not internals.

What an objective holds

Each objective is a single record inside a practice.

Objective statement
The exact NIST SP 800-171 wording of the testable requirement.
Practice & family
The practice it belongs to (e.g. AC.L2-3.1.1) and its CMMC control family.
Status
Implemented, Partially implemented, Not implemented, Not applicable, or (by default) Unassessed.
Narrative
Your plain-language explanation of how the objective is met.
Not-applicable reason
The documented justification recorded when an objective is marked Not applicable.
Evidence
The artifacts linked to the objective as proof of implementation.

How the score is calculated

Your SPRS score starts at 110 and subtracts a weight for every in-scope practice that isn't fully met. Practices carry different weights depending on how important the underlying control is, so not every gap costs the same. Because a practice is met only when all of its in-scope objectives are met, an unassessed or partially implemented objective quietly holds its whole practice — and its weight — against your score until you close it.

Objectives you mark Not applicable are excluded from the math entirely — they neither earn nor deduct points. That's why documenting scope decisions matters: it keeps your score reflecting only what genuinely applies to you.

What "open gaps" means

Your open gaps are the practices that aren't fully implemented yet — including practices where you simply haven't assessed the objectives. Clearing a gap means bringing every in-scope objective under that practice to Implemented (or Not applicable with a reason). Watching your open-gaps count fall is the most direct measure of assessment progress.

AI assistant access

When the AI Connector is enabled, assistants can read (never change) your assessment data — your objective statuses, practice rollups, SPRS score, and open gaps — so you can ask questions about your posture in plain language. Access follows the same permissions as the app: an assistant only ever sees what the connected user's role is allowed to see.


Evidence

Attach the artifacts that prove each objective is implemented.

POA&M

Track the remediation of open gaps as milestones.

AI Connector

Read your assessment statuses, score, and gaps through an AI assistant.