New Client Questionnaire
We look forward to working with you! The information requested below will help us better understand your needs and your environment. This will allow us to provide you with a more accurate price estimate. For questions 2-21, if you are unsure of an answer, you can leave it blank. For questions 5-21, please circle the answer that is most appropriate for your environment.
-
What type(s) of services are you seeking?
-
At how many physical locations (offices, data centers, or other facilities) does your organization handle CUI or FCI? ___________
-
How many employees do you have, and how many are authorized to access government information?
-
Total: ______
-
Government Information Authorized: ________
-
How many accounts of the following types do you have in your organization’s systems?
-
User: ___________
-
Local Administrator: _________
-
Application: __________
-
Service: __________
-
Domain Administrator: ___________
-
Other: __________
-
Do you allow employees to access your systems, including E-mail, collaboration, and cloud resources, from their personal devices (i.e., BYOD)?
-
No
-
Yes
-
Can any of your employees work remotely? If so, can they work remotely using their own equipment or only organization-provided equipment?
-
No
-
Yes - remotely (e.g., from home) with their own equipment
-
Yes - remotely (e.g., from home) with organization-provided equipment
-
Do your organization’s employees periodically receive security awareness training regarding the risks associated with their activities and any applicable policies, procedures, standards, etc. relevant to the systems they use to conduct the activities?
-
No
-
Yes - Administrators and privileged users receive periodic, formal training (3 points)
-
Pre-Assessment Findings Validation/Evidence Collection
-
Complete CMMC/NIST SP 800-171 Gap Analysis
-
Phased Gap Analysis
-
FAR and Above Phases 1-2
-
Phases 1-3
-
Phases 1-4
-
FAR-only (CMMC Level 1) Gap Analysis
-
Gap Remediation
-
Managed IT Services
-
IT Consulting (independent from Managed IT Services)
-
Managed Cybersecurity Services
-
Cybersecurity Consulting (independent from Managed Cybersecurity Services)
-
Data Privacy Consulting
-
Other (please describe):
_________________________________________________________________________
-
Yes - All employees, including senior management, receive periodic, formal training (5 points)
-
Is your staff trained to recognize and properly handle sensitive information, such as bank accounts, social security numbers, design specifications, blueprints, Federal Contract Information (‘FCI’) and Controlled Unclassified Information (‘CUI’)?
-
No
-
Yes (3 points)
-
Do you have a comprehensive list of all of the types of sensitive information (including FCI, CUI by type, and non-government information) in received, created, processed, stored, and/or transmitted by your organization? (If yes, we will ask you for a copy once a nondisclosure agreement is in place)
-
No
-
Yes (5 points)
-
Do you have a comprehensive list of all hardware (including laptops, mobile devices, workstations, servers, printers, networking equipment, ‘smart devices’ (like TVs, Alexas, etc.)) in use by your organization? (If yes, we will ask you for a copy once a nondisclosure agreement is in place)
-
No
-
Yes (3 points)
-
Do you have a comprehensive list of all software (including operating systems, end-user software, and drivers) installed on the organization’s equipment? (If yes, we will ask you for a copy once a nondisclosure agreement is in place)
-
No
-
Yes (5 points)
-
Do you have a comprehensive list of all cloud resources (including E-mail, file sharing, chat, collaboration, HR, payroll, and other resources) used by the organization? (If yes, we will ask you for a copy once a nondisclosure agreement is in place)
-
No
-
Yes (5 points)
-
Do you have a network diagram? (If yes, we will ask you for a copy once a nondisclosure agreement is in place)
-
No
-
Yes (5 points)
-
Can you show how and where sensitive information, and in particular FCI and CUI, is received, processed, stored, and transmitted within your organization? (If yes, we will ask you for a copy once a nondisclosure agreement is in place)
-
No
-
Yes (10 points)
-
Do you have a list of all of your employees and contractors that includes their roles? If so, have you defined which roles are authorized to handle different categories of information (e.g., CUI vs FCI)?
-
No
-
Yes - without role-based access definitions (3 points)
-
Yes - with role-based information access definitions (5 points)
-
Do all of your users have administrative privileges on their local computer (i.e., they are local administrators)?
-
No (5 points)
-
Yes
-
Does your organization require multifactor authentication for:
-
Remote administration:
-
No
-
Yes (5 points)
-
All user remote access:
-
No
-
Yes (3 points)
-
All administrator logins:
-
No
-
Yes (5 points)
-
All user logins:
-
No
-
Yes (3 points)
-
Administrator access to cloud resources:
-
No
-
Yes (5 points)
-
Access to cloud resources:
-
No
-
Yes (3 points)
-
Does your organization deploy WiFi? If so, is the WiFi network part of your corporate network or external to it?
-
No (3 points)
-
Yes - WiFi is part of our network
-
Yes - WiFi goes to a guest network separate from our internal network (3 points)
-
Does your organization have an incident response plan that describes roles and responsibilities? If so, do you routinely test the plan? (If you have a plan, we will ask for a copy once a nondisclosure agreement is in place)
-
Plan:
-
No
-
Yes (3 points)
-
Roles and Responsibilities:
-
No
-
Yes (3 points)
-
Testing:
-
No
-
Yes (5 points)
-
Has your organization already performed a self-assessment against NIST SP 800-171? If so, did your assessment consider only the requirements themselves or also the objectives defined in NIST SP 800-171A? (If yes, we will ask for the results once a nondisclosure agreement is in place)
-
No
-
Yes - without objectives (3 points)
-
Yes - with objectives (8 points)
-
Do you have a comprehensive set of policies, procedures, plans, and/or other documents that define your IT and cybersecurity programs? (If yes, we will ask you for copies once a nondisclosure agreement is in place)
-
No
-
Yes - Partial/incomplete (3 points)
-
Yes - Comprehensive (8 points)
This form is based on the client engagement questionnaire published by the CMMC Information Institute.
Referenced Terms
- CUI
- Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.
Revision History
- 2026-08-20 — Darren Rush
- Merge pull request #2 from safire-dev/dev (
16cb681)