# Assess Your CMMC Compliance and Readiness

Many organizations pursuing Cybersecurity Maturity Model Certification (CMMC) lack visibility into SBOM generation, open source risk, and software traceability across the development lifecycle. If you support Department of Defense (DoD) contracts or work with organizations that do, you need to ensure your controls can withstand CMMC compliance audits.

Take the CMMC Readiness Assessment to evaluate your current capabilities, identify potential gaps, and understand how prepared your organization is to meet CMMC requirements.

[Start Assessment](/content/resources/cmmc-assessment#cmmcAssessment/index.html) [Learn More About CMMC](/content/blog/cmmc-2.0-in-action-operationalizing-secure-software-practices-across-the-defense-industrial-base/index.html)

### Start the CMMC Readiness Assessment

This is a free, 5-minute assessment designed for organizations that support the Department of Defense (DoD). Answer a few questions and get results immediately.

### Questions

1. **Do you currently generate SBOMs for your applications?**  
   - No  
   - Yes, manually  
   - Yes, automatically for every build

2. **Are SBOMs integrated into your CI/CD pipeline?**  
   - Not integrated  
   - Partially integrated  
   - Fully automated

3. **How much visibility do you have into your open source components?**  
   - Limited or none  
   - Partial visibility  
   - Full inventory

4. **How do you identify vulnerabilities in dependencies?**  
   - We do not currently scan  
   - Periodic/manual scans  
   - Continuous monitoring

5. **Do you enforce security policies in development workflows?**  
   - No enforcement  
   - Alerts only  
   - Automated enforcement

6. **Can you trace components from SBOM to deployed environment?**  
   - No  
   - Limited  
   - Full traceability

7. **How are SBOMs stored and managed?**  
   - Not stored  
   - Stored inconsistently  
   - Centrally managed and accessible

8. **How do you track remediation of vulnerabilities?**  
   - No tracking  
   - Manual tracking  
   - Automated tracking

9. **Are developers trained on secure open source usage?**  
   - No  
   - Informal guidance  
   - Formal training program

10. **Can you produce an SBOM on demand for customers, auditors, or internal reviews?**  
    - No  
    - With significant effort  
    - Immediately/automatically

### What You Get

- Observations based on your responses
- Prioritized action list of areas for improvement
- Recommended next steps and resources
- Personalized software supply chain insights

### Assessment Criteria

- SBOM generation and management
- Open source component visibility
- Vulnerability monitoring and remediation
- Policy enforcement
- Software traceability and audit support

### Questions About CMMC?

[Speak to an Expert](/content/contactus/index.html)
