CMMC Assessment Preparation Guide
A practical, step-by-step roadmap for defense contractors preparing for CMMC Level 2 certification β from initial scoping through successful assessment.
6 Steps to CMMC Certification
Scope Your Assessment
Define your CUI boundary β identify every system, application, and network segment that processes, stores, or transmits CUI. Map data flows from ingestion to destruction. Consider implementing a CUI enclave to minimize your assessment scope and reduce costs. Document all external service providers (cloud, MSP, MSSP) that interact with CUI.
Conduct a Gap Assessment
Systematically evaluate your current security posture against all 110 NIST SP 800-171 controls. For each control, determine: Is it fully implemented? Partially implemented? Not implemented? Document evidence of implementation and calculate your current SPRS score. This baseline reveals your remediation workload.
Remediate Gaps
Close identified gaps by implementing missing controls. Common remediation areas include: deploying MFA across all access points, implementing FIPS 140-2 validated encryption, establishing audit logging and SIEM, hardening endpoint configurations, segmenting networks, and creating or updating security policies. Prioritize controls that cannot use POA&Ms.
Prepare Documentation
Build your assessment evidence package: System Security Plan (SSP) describing your boundary and control implementations, Plan of Action & Milestones (POA&M) for any remaining items, current network architecture diagrams, asset inventories, written policies and procedures for each control family, and evidence artifacts (screenshots, configurations, logs).
Conduct Internal Review
Perform a mock assessment using the official CMMC Assessment Guide methodology. Walk through each control as an assessor would β review documentation, interview key personnel, test technical implementations, and examine evidence. Identify any weak areas and address them before the real assessment.
Schedule Your C3PAO Assessment
Engage an authorized C3PAO from the Cyber AB Marketplace. Plan for 1β2 weeks of on-site and remote assessment activities. Prepare your team β assessors will interview system administrators, security staff, and leadership. Ensure all evidence is organized, accessible, and current. Brief your staff on the assessment process and their roles.
Top 10 CMMC Assessment Failures
Based on assessment data and industry reports, these are the most common areas where organizations fail to meet CMMC Level 2 requirements:
1a. SSP missing or not comprehensive: Many organizations lack a comprehensive SSP or have one that doesn't accurately reflect their current environment. Your SSP must describe your system boundary, all in-scope assets, and how each of the 110 controls is implemented β not just state that they exist.
1b. SSP not kept current: An SSP that was accurate at assessment kickoff but is stale by the assessment date is a common finding. Changes to hardware, software, network topology, cloud services, and control implementations must be reflected in near-real time; assessors check that the SSP matches the live environment, not a prior snapshot.
2a. MFA gaps for local and privileged access: MFA must be implemented for all local and network access to privileged accounts AND for all remote access. Many organizations have MFA for remote access (VPN) but lack it for local workstation logins or administrative access.
2b. Non-compliant MFA factors or enforcement: Using factors that don't meet NIST 800-171B requirements (e.g. SMS where a phishing-resistant authenticator is expected), or having MFA configured but not enforced for every in-scope account and entry path, is treated as a control failure even when the underlying solution is deployed.
3a. Insufficient log coverage and retention: Organizations must not only collect audit logs but capture the specific events required by 3.3.1β3.3.2 across all in-scope assets, and retain them for the required period. Missing log sources, incomplete event types, or retention shorter than the policy mandates are frequent findings.
3b. No active review and correlation process: Collecting logs without reviewing them does not satisfy 3.3.3β3.3.4. A SIEM or log management solution with defined review processes, assigned reviewers, documented procedures, and evidence of periodic review is essential β assessors look for review records, not just stored logs.
4a. Non-FIPS cryptography protecting CUI: CMMC requires FIPS-validated cryptography for protecting CUI β both at rest and in transit. Using encryption that isn't FIPS 140-2 validated (like standard TLS without a FIPS module) does not satisfy this requirement.
4b. FIPS mode not enabled or not documented: Even when a FIPS-validated module is present, it must be operating in its validated mode (FIPS mode enabled), and that configuration must be documented and verifiable. Assessors commonly find FIPS-capable products left in non-FIPS mode, or encryption decisions undocumented in the SSP, both of which fail the requirement.
5a. No documented CUI boundary or asset inventory: If you can't clearly define where CUI lives in your environment, you can't protect it. You need documented data flow diagrams showing how CUI enters, moves through, and exits your systems β including cloud services and external partners.
5b. Unmanaged data flows to external systems and subcontractors: CUI flowing to cloud providers, shared services, or subcontractors without documented flow-down requirements, SP 800-171 contract terms, and verified compliance status is a recurring assessment failure. Every external destination for CUI must be identified, contracted, and assessed for compliance β untracked flows are treated as uncontrolled CUI exposure.
Essential Assessment Resources
NIST SP 800-171 Rev 2
The foundational standard defining all 110 security requirements for protecting CUI.
NIST SP 800-171A
Assessment procedures for each control β defines how assessors will evaluate your implementation.
CMMC Assessment Guide L2
Official DoD assessment methodology used by C3PAOs during CMMC Level 2 evaluations.
CMMC Model Overview
DoD CIO's official overview of the CMMC framework, levels, and implementation timeline.
π€ Preparing for your assessment?
Ask ChatCMMC about specific controls, assessment criteria, evidence requirements, or remediation strategies. Get instant answers powered by official documentation. Ask ChatCMMC β