Nebby by Yinzer IT

Free self-check

Are you ready for CMMC Level 1?

Fifteen plain-English questions, about five minutes. You get a readiness summary, the gaps ranked, and what to do about each one. Nothing is sent to the government, and this is not an assessment or a certification.

About your company (optional)
1/15 Only authorized people and devices can get in

Does every person have their own account, with accounts removed when someone leaves?

Shared logins and forgotten accounts are the most common way small companies get breached.

What counts as proof
  • User list from Microsoft 365 or Active Directory
  • Offboarding checklist showing accounts disabled

Requirement (i) of FAR 52.204-21, AC.L1-b.1.i.

2/15 People can only do what their job needs

Are permissions limited by role, so most staff are not administrators?

If everyday accounts have admin rights, one phishing click compromises everything.

What counts as proof
  • Group or role membership list
  • Count of admin accounts

Requirement (ii) of FAR 52.204-21, AC.L1-b.1.ii.

3/15 Outside systems and devices are controlled

Do you control personal devices, home computers and outside cloud services that touch company information?

Contract information sitting on an unmanaged home PC or a personal Dropbox is outside your control.

What counts as proof
  • Policy on personal devices
  • List of approved cloud services
  • Intune or MDM enrollment list

Requirement (iii) of FAR 52.204-21, AC.L1-b.1.iii.

4/15 Public postings are reviewed first

Does someone review what goes on your website and social media before it's published?

Drawings, part numbers and customer names posted publicly can leak contract information.

What counts as proof
  • Named approver for public content
  • Review step in your posting process

Requirement (iv) of FAR 52.204-21, AC.L1-b.1.iv.

5/15 Users and devices are identified

Can you tell exactly who did what, with no anonymous or generic accounts in use?

If several people share one login, you can't tell who opened the bad attachment.

What counts as proof
  • Account list showing named users
  • Inventory of computers and who uses them

Requirement (v) of FAR 52.204-21, IA.L1-b.1.v.

6/15 Identities are verified before access

Do accounts require a password that meets a policy, plus multi-factor authentication for email and remote access?

Passwords alone are routinely stolen. MFA stops nearly all account takeovers.

What counts as proof
  • MFA report from Microsoft 365 or Google
  • Password policy settings

Requirement (vi) of FAR 52.204-21, IA.L1-b.1.vi.

7/15 Old drives and paper are destroyed properly

Are hard drives wiped or shredded, and sensitive paper shredded, before anything is thrown out or donated?

Old computers and file cabinets leaving the building are an easy source of contract information.

What counts as proof
  • Disposal log
  • Certificate of destruction from a shredding vendor

Requirement (vii) of FAR 52.204-21, MP.L1-b.1.vii.

8/15 Physical access is limited

Are servers, network gear and workstations in areas where only authorized people can reach them?

A switch in an unlocked closet or a server under a desk undoes your other controls.

What counts as proof
  • Photos of locked server room or rack
  • List of who holds keys or badges

Requirement (viii) of FAR 52.204-21, PE.L1-b.1.viii.

9/15 Visitors are escorted and access is logged

Are visitors signed in and escorted, and do you track who has keys, badges and door codes?

Assessors look for a visitor log and a key list. These are easy points to lose without one.

What counts as proof
  • Visitor log
  • Key and badge assignment list
  • Door or camera access records

Requirement (ix) of FAR 52.204-21, PE.L1-b.1.ix.

10/15 The network boundary is protected

Is there a business-grade firewall, with remote access restricted and no unnecessary ports open to the internet?

Exposed remote desktop and old VPN appliances are how most ransomware gets in.

What counts as proof
  • Firewall rule export
  • External port scan results

Requirement (x) of FAR 52.204-21, SC.L1-b.1.x.

11/15 Public-facing systems are separated

Are public things like guest Wi-Fi and any public web server on a separate network from company systems?

Guest Wi-Fi on the same network as the shop floor gives visitors a path into your systems.

What counts as proof
  • VLAN or network diagram
  • Guest network settings

Requirement (xi) of FAR 52.204-21, SC.L1-b.1.xi.

12/15 Problems get fixed promptly

Do computers and servers get security updates on a schedule, with someone responsible for checking?

Most breaches use holes that were patched months earlier.

What counts as proof
  • Patch report from your management tool
  • Patch schedule with an owner

Requirement (xii) of FAR 52.204-21, SI.L1-b.1.xii.

13/15 Anti-malware is in place

Is antivirus or endpoint protection installed and running on every computer and server?

One unprotected machine is enough for ransomware to spread.

What counts as proof
  • Endpoint protection console showing all devices
  • List of devices with protection off

Requirement (xiii) of FAR 52.204-21, SI.L1-b.1.xiii.

14/15 Anti-malware stays current

Do those protections update themselves automatically?

Out-of-date protection misses current threats and is an easy finding.

What counts as proof
  • Definition or version status from the console

Requirement (xiv) of FAR 52.204-21, SI.L1-b.1.xiv.

15/15 Scans run regularly

Are scheduled scans running, with real-time scanning on for downloads and email attachments?

Real-time scanning catches the file the moment someone opens it.

What counts as proof
  • Scan schedule and recent scan results
  • Real-time protection setting

Requirement (xv) of FAR 52.204-21, SI.L1-b.1.xv.

Where should we send your results? (optional)