Are you NIST-ready? The 2-minute check
Eight questions, two minutes. Scored against the control areas NIST publications emphasize first — access, patching, logging, response, backups, documentation.
What a CPG gap assessment actually includes
An 800-171 readiness assessment is a dry run against the requirement set: a consultant reviews your SSP, tests controls, and hands you a POA&M. This quiz is the 2-minute version — it tells you whether you’re ready for that conversation.
The 2-minute quiz
1. Do you know where your sensitive data (CUI or equivalent) lives and who can access it?
2. Is multi-factor authentication enforced for network access and privileged accounts?
3. Do you remediate vulnerabilities on a defined, tracked cadence?
4. Are audit logs collected, protected, and reviewed?
5. Do you have an incident response capability that has been exercised?
6. Are system backups performed regularly and tested for restore?
7. Do you have a current System Security Plan (SSP) describing your controls?
8. Are open security findings tracked in a Plan of Action & Milestones (POA&M)?
How scoring works
Each answer is worth 0–2 points (max 16). 0–5: foundational gaps — start with CISA's free services plus a gap assessment. 6–11: core controls exist — allow 1–3 months of prep. 12–16: likely ready. This is a self-assessment aid, not an audit opinion.
Know your score? Get quotes
Firms scope fees around readiness. Tell us where you stand and get matched.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.