Company, contracts, and scope
  • Contact Information

  • Format: (000) 000-0000.
  • Company, contracts, and scope

  • Compliance status & documentation

  • Do you have a current System Security Plan (SSP) and POA&M?
  • Have you completed a NIST 800-171 / CMMC self-assessment and submitted a score to SPRS? If yes, when and what score?
  • Have you had any third-party or customer/primes’ security audits in the last 2–3 years?
  • Are there any open findings you’re still working on?
  • Data, systems, and network

  • Do you have an up-to-date network diagram, and are engineering/CUI systems segmented from regular office/guest networks?
  • Do production machines (CNC, PLCs, testers, etc.) connect to the corporate network or internet?
  • Identity, accounts, and access control

  • Are all users on unique accounts (no shared logins)?
  • Do you use role-based access so people only see what they need, and how is access to CUI repositories (folders/systems) reviewed?
  • Assets, security tools, and patching

  • Do you maintain a current inventory of key hardware (laptops, desktops, servers, plant PCs, network gear) and critical software?
  • Do you have standard builds or configuration baselines for Windows endpoints/servers, and how are configuration changes tracked?
  • Do you have centralized logging/monitoring, and how do you handle alerts or suspicious activity?
  • Backup and recovery

  • Do you have a written disaster recovery / business continuity plan for events like ransomware or major outages?
  • Policies, training, and incidents

  • Do you have a written incident response plan?
  • Have you had any notable security incidents in the last 3–5 years, and are there customer/prime reporting requirements?
  • Physical security, third parties, cloud, and priorities

  • Should be Empty: