CMMC L2 sandboxSample data for 18 of 110 practices. Nothing is saved.
View CMMC package
Acme Defense, Inc. · CMMC L2 self-assessment sandbox

CMMC Level 2 readiness at a glance

All 14 domains and 110 practices from NIST SP 800-171 R2. Toggle statuses to see the readiness score, gap list, and POA&M preview update in real time.

Practices
18 / 110
loaded in sandbox
Met
10
In progress
6
Gaps
2
Sandbox score
56%

Practices

Showing 18 of 18 sampled practices

AC.L2-3.1.1Access Control

Authorized Access Control

Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

Evidence cheat sheet

  • Access control policy (signed)
  • Account provisioning workflow export
  • Quarterly access review report

Implementation status

C3PAO assessor view

Finding: MET · Scoring impact reflected in the sandbox score above.

Framework crosswalk

Every mapped control that matches evidence attached toAC.L2-3.1.1inherits its status automatically. Click a row to open the mapped control detail.

6 satisfied0 awaiting evidenceAccess Control
FrameworkControlMatch driven byStatus
NIST 800-53
AC-2
Account Management
Theme: Access Control
Inherited
NIST 800-171
3.1.1
Authorized Access Control
Theme: Access Control
Inherited
ISO 27001
A.5.15
Access control
Theme: Access Control
Inherited
SOC 2
CC6.1
Logical Access Security
Theme: Access Control
Inherited
HIPAA
§164.308(a)(4)
Information Access Management
Theme: Access Control
Inherited
PCI DSS 4.0
7.2
Access assigned based on need
Theme: Access Control
Inherited

Answer once, satisfy many: in the full product, uploading an artifact here auto-attaches it to every mapped control across frameworks.

POA&M preview

Auto-populated from gaps and in-progress items (8)

Template
  • AC.L2-3.1.20In progress
    External Connections
    Complete evidence
  • AU.L2-3.3.1In progress
    System Auditing
    Complete evidence
  • AU.L2-3.3.5Gap
    Audit Correlation
    Remediate
  • IR.L2-3.6.1In progress
    Incident Handling
    Complete evidence
  • MA.L2-3.7.5Gap
    Nonlocal Maintenance
    Remediate
  • RA.L2-3.11.1In progress
    Risk Assessments
    Complete evidence
  • CA.L2-3.12.1In progress
    Security Control Assessment
    Complete evidence
  • SC.L2-3.13.11In progress
    CUI Encryption
    Complete evidence

Ready to run this on your real environment?

Load all 110 practices, attach real evidence, and generate an audit-grade SSP, SAR, and POA&M package for your C3PAO.