Interactive quiz

Are you NIST-ready? The 2-minute check

Eight questions, two minutes. Scored against the control areas NIST publications emphasize first — access, patching, logging, response, backups, documentation.

What a CPG gap assessment actually includes

An 800-171 readiness assessment is a dry run against the requirement set: a consultant reviews your SSP, tests controls, and hands you a POA&M. This quiz is the 2-minute version — it tells you whether you’re ready for that conversation.

The 2-minute quiz

1. Do you know where your sensitive data (CUI or equivalent) lives and who can access it?

2. Is multi-factor authentication enforced for network access and privileged accounts?

3. Do you remediate vulnerabilities on a defined, tracked cadence?

4. Are audit logs collected, protected, and reviewed?

5. Do you have an incident response capability that has been exercised?

6. Are system backups performed regularly and tested for restore?

7. Do you have a current System Security Plan (SSP) describing your controls?

8. Are open security findings tracked in a Plan of Action & Milestones (POA&M)?

How scoring works

Each answer is worth 0–2 points (max 16). 0–5: foundational gaps — start with CISA's free services plus a gap assessment. 6–11: core controls exist — allow 1–3 months of prep. 12–16: likely ready. This is a self-assessment aid, not an audit opinion.

This quiz is an educational self-assessment. It is not an audit, a readiness assessment, or a guarantee of any outcome.

Know your score? Get quotes

Firms scope fees around readiness. Tell us where you stand and get matched.

Get a free quote