CMMC Level 2 readiness scan

Estimate your SPRS score in Excel. No cost, and nothing leaves your computer.

Download DARS Compass (.xlsx)

✓ Your answers stay on your computer
✓ No signup required
✓ Works in desktop Excel on Windows

What it is

DARS Compass walks you through all 110 NIST SP 800-171 Rev. 2 controls, the requirements behind CMMC Level 2. You get 113 questions instead of 110 because one control, 3.5.3 on multi-factor authentication, is split into four parts: privileged local access, privileged network access, standard staff access, and blocked legacy authentication. That way you see which scope is missing, not just that "MFA is broken somewhere."

Dashboard showing an SPRS score of 42 in an orange band, a below-threshold message, and answer counts by state
Dashboard: an estimated SPRS score and your answers by state (sample data). Tap to open full size.

What you get

Questions sheet, family 3.3 Audit and Accountability, nine plain-English evidence questions with Yes, Partial or Not Yet answers and a status mark
Questions: one plain-English evidence question per control (sample data). Tap to open full size.
Gap Report listing failing controls in NIST order with state, point deduction and a remediation hint
Gap Report: what is failing and a practical next step for each (sample data). Tap to open full size.

How it works

Answer Yes, Partial or Not Yet for each question. Say Yes only if you could hand an auditor the evidence today. For almost every control, DoD scoring gives no partial credit, so Partial and Not Yet cost the same points. The Gap Report still tells them apart: Partial means formalize what you have, Not Yet means build it from scratch. Two controls are the exception: MFA (3.5.3) and FIPS-validated encryption (3.13.11) cost 3 points instead of 5 when they're partly in place. Compass doesn't model that, so if either is partly in place, your Compass score can run up to 2 points lower for each than an official score.

A perfect score is 110. Under the CMMC rule, 88 (80%) is the minimum for conditional Level 2 status, and only certain controls can be left open on a POA&M. Unanswered questions count as Not Yet, so the workbook shows "SSP Required" until you confirm you have a System Security Plan (control 3.12.4), then shows the lowest possible score. It's an honest starting point, not a flattering one.

What it is not

This is an estimate for planning. It is not an assessment, not a C3PAO result, and it certifies nothing. It also doesn't recommend products. Tooling changes too fast for a free workbook to keep up, and choosing tools is a conversation for a paid engagement.

Your data stays with you

The workbook runs entirely in Excel on your machine. Nothing is uploaded, and DARS never sees your answers unless you choose to send them.

What you need

Desktop Excel on Windows. Compass is designed and tested there. Google Drive, Excel Online and other converters can show scores that look right and are wrong, so keep the file on your machine. Don't sort or reorder the answer rows, because the Gap Report depends on their order.

Welcome sheet with a red warning to open the file in desktop Excel only and six how-to steps
Welcome: how to use the workbook, and why it must open in desktop Excel. Tap to open full size.

Download

DARS_Compass_CMMC_Readiness_Scan_v1.0.xlsx
One Excel file, about 97 KB (99,120 bytes).

Download DARS Compass (.xlsx)

Frequently asked questions

QWhat is an SPRS score?

It is the score DoD contractors report in the Supplier Performance Risk System to show how well they have implemented NIST SP 800-171. It runs from 110 down to −203.

QWhy 113 questions for 110 controls?

Control 3.5.3 is split into four scoped questions so you can see exactly which part of MFA is missing.

QWhy does Partial score the same as Not Yet?

Almost every control in the DoD method is all or nothing, and Compass treats every Partial as Not Yet. The two exceptions, MFA (3.5.3) and FIPS-validated encryption (3.13.11), lose 3 points instead of 5 when partly in place. Compass doesn't model those, so it can show your score slightly lower than the official method would.

QWhat does "SSP Required" mean?

Without a System Security Plan (control 3.12.4) the assessment can't be completed, so the workbook won't show a number until you confirm you have one.

QCan I use it on a Mac?

We haven't tested it there, so we don't recommend it. Use desktop Excel on Windows.

QIs it really free?

Yes. The workbook is free to download and use.

Version and file check

Tool version 1.0. Content library v1.29.2 (locked October 4, 2026). File size 99,120 bytes.

SHA-256:

dc2528fe711f56905fdbd73a3d73393d0f0bb8bee0fb9de3d88b4d49970861e0

To check your download on Windows, open Command Prompt in your Downloads folder and run certutil -hashfile DARS_Compass_CMMC_Readiness_Scan_v1.0.xlsx SHA256. Or in PowerShell, run Get-FileHash DARS_Compass_CMMC_Readiness_Scan_v1.0.xlsx -Algorithm SHA256. Compare the result with the value above (capital or small letters, it doesn't matter). If they don't match, don't open the file, and email info@darsgrc.com.

About sheet showing coverage, scoring rules, data handling, methodology and version information
About: how answers map to the DoD scoring method, and where your data stays. Tap to open full size.

Related reading

What CMMC 2.0 Actually Means for Small Contractors

Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated October 2026.

Want help with the next step?

If you want a formal System Security Plan and POA&M built from your answers, a review of your evidence for audit readiness, or ongoing help with DFARS and CMMC questions, contact DARS.

Contact DARS