This field is for validation purposes and should be left unchanged.
Press Enter
1. Do you currently do business with the U.S. Department of War (DoW), or do you expect to in the future? If so, are you contractually required to comply with DFARS 252.204-7012?(Required)
Doing business with the DoW is the primary trigger for CMMC requirements and determines whether compliance is mandatory for current or future contracts. DFARS 252.204-7012 contractually requires implementation of NIST SP 800-171 and is a key factor in determining the need for CMMC Level 2 compliance.
Press Enter
2. Do you receive, store, or process Federal Contract Information (FCI)?(Required)
Handling FCI establishes a minimum requirement for safeguarding practices and may trigger CMMC Level 1 obligations. FCI is information provided by or generated for the government under a contract that is not intended for public release.
Press Enter
3. Do you receive, store, or process Controlled Unclassified Information (CUI)?(Required)
Handling CUI significantly increases security requirements and typically places the organization under CMMC Level 2.
Press Enter
4. Have you identified where FCI and/or CUI exists in your organization and which systems store, process, or transmit it?(Required)
If FCI and CUI are not fully identified and scoped, the CMMC boundary cannot be accurately defined or assessed.
Press Enter
5. Do you have a System Security Plan (SSP) that documents your environment, CUI boundaries, and how security requirements are met?(Required)
The SSP is the primary artifact assessors use to understand your environment, CUI boundary, and how security requirements are met.
Press Enter
6. Do you maintain an up-to-date inventory of IT assets (hardware, software, and cloud services) that store or process FCI or CUI?(Required)
You can’t secure what you don’t know you have — inventory is fundamental for applying security controls and tracking CUI and FCI locations.
Press Enter
7. What type of system architecture is used to handle DoW-related information within your organization?(Required)
The system architecture (corporate, enclave, cloud, or hybrid) directly impacts scoping, control implementation, and assessment complexity.

Press Enter
8. Have you completed a NIST SP 800-171 self-assessment and, if required, submitted your score to the Supplier Performance Risk System (SPRS)?(Required)
A completed and submitted self-assessment is a contractual requirement and a baseline indicator of CMMC readiness.
Press Enter
9. For your known security gaps, do you maintain a Plan of Action and Milestones (POA&M) to track remediation?(Required)
A POA&M demonstrates formal risk management and is required to track remediation of controls not yet fully implemented.
Press Enter
10. What is your company size?(Required)
Company size matters because it directly affects CMMC scoping, system architecture, staffing models, documentation expectations, and the most practical path to achieving and sustaining compliance.
Press Enter
Press Enter
12. What is your name?(Required)
Press Enter
Press Enter
Press Enter
Press Enter
16. Can Frazier & Deeter follow up with you regarding your answers and comments from this CMMC assessment?(Required)
Press Enter
17. Would you also like to receive our newsletter?
Press Enter
This field is hidden when viewing the form
Press Enter
This field is hidden when viewing the form
Press Enter
This field is hidden when viewing the form
Press Enter
This field is hidden when viewing the form
Press Enter
This field is hidden when viewing the form
Press Enter
This field is hidden when viewing the form
Press Enter
Press Enter
0% Completed!