INTERACTIVE TOOL · CMMC & CPCSC READINESS

DEFENCE READINESS STARTS WITH SCOPE.

Answer five questions about your defence market, controlled information, control implementation, evidence and supplier boundaries to frame your likely readiness priorities for CMMC and CPCSC. Free, with no login required.

Which defence market matters?
Do you handle CUI or sensitive defence information?
Low / ad hocStrong / repeatable
How consistently are required safeguards implemented across the actual scoped environment?
Low / ad hocStrong / repeatable
Can you produce current, traceable evidence showing that controls operate as described?
Low / ad hocStrong / repeatable
Are system boundaries, external providers, inherited controls and supplier responsibilities clearly understood?
ABOUT THIS TOOL

WHAT THE RESULT CAN AND CANNOT TELL YOU.

The navigator orients a supplier to likely scope, control gaps and evidence needs, based entirely on your own answers. It is an initial indication, not a certification, assessment or legal conclusion, and it cannot confirm which requirements your contracts impose.

C3SA's value starts where the tool stops: validating your answers, defining the actual assessment boundary and implementing missing controls.

COMMON QUESTIONS
What counts as CUI or sensitive defence information?

Information your defence contracts require you to safeguard, such as Controlled Unclassified Information for U.S. contracts or sensitive unclassified information for Canadian defence contracts. If you are not sure, check your contract clauses or ask your contracting officer.

Why does scope matter so much?

Requirements apply to every system, person and supplier that handles controlled information. A smaller, well-defined boundary is usually cheaper to secure and easier to assess.

Is my information shared?

Your answers are processed in your browser. The site may record an anonymous completion event (tool name and score) in its analytics. Your contact details and full result are only sent to C3SA if you choose to request detailed results through the form. Do not enter sensitive, classified or controlled information into public web forms.

THE C3SA DIFFERENCE

FROM SELF-ASSESSMENT TO EVIDENCE.

WHAT YOU GET NOW

A preliminary gap summary across scope, controls, evidence and suppliers.

WHAT C3SA ADDS

C3SA validates your answers, defines the actual assessment boundary and implements missing controls.

THE NEXT STEP

A scoped readiness engagement with a gap register, evidence plan and roadmap.

UNDER ATTACK? CYBERFIRE →