CMMC Gap Assessment Checklist for Defense Suppliers Find the gaps before you buy the fix

CMMC gap assessment checklist

CMMC Gap Assessment Checklist for Defense Suppliers
Find the gaps before you buy the fix

A useful CMMC gap assessment is not a 110-row spreadsheet with a parade of green checkmarks. It is a disciplined comparison between the cybersecurity requirements that actually apply to your contract environment and the controls, evidence, people, cloud services, subcontractors, and facilities that can prove those requirements are working.

That distinction matters even more in 2026. The Department’s official CMMC site announced on July 13, 2026 that Phase II implementation, previously scheduled to begin November 10, 2026, was suspended while Phase I self-assessment requirements remain in place. Defense suppliers should therefore keep improving Level 1 or Level 2 readiness where applicable, but should not purchase a third-party certification engagement merely because an older implementation calendar said November 2026.

The practical goal is narrower and more useful: determine what information you handle, define the assessment boundary, test implementation against the applicable requirements, collect defensible evidence, rank remediation, and know what must be checked again before an authorized official makes an affirmation.

Scope correctly

Separate FCI, CUI, security assets, service providers, and genuinely out-of-scope systems.

Test evidence

Move beyond policy documents to configurations, records, interviews, and technical verification.

Spend in order

Fix boundary and eligibility problems before buying software that may not solve the real gap.

The cheapest control to remediate is often the one you discover before it spreads across the entire CUI boundary. 🔐

Snapshot

Who this is for: Defense primes, subcontractors, manufacturers, engineering firms, technology suppliers, and small businesses that need to evaluate CMMC readiness.

Problem solved: Turn CMMC requirements into a practical scope, evidence, remediation, and ownership checklist instead of a vague compliance project.

What you can do next: Identify your likely Level 1 or Level 2 scope, rank the most consequential gaps, and decide whether the work belongs in-house, in software, or with specialist help.

CMMC gap assessment checklist

What a CMMC gap assessment should establish in 2026

A gap assessment answers a deceptively simple question: What would prevent this specific environment from satisfying the CMMC requirements that apply to it?

It is not itself a CMMC certification, and a consultant’s readiness report does not create an official CMMC status. Think of it as the diagnostic scan before treatment. Done well, it tells you what is in scope, what is implemented, what is missing, what cannot yet be proved, and what deserves money first.

Start with the level that actually applies

Under the codified CMMC framework, Level 1 is based on 15 safeguarding requirements associated with FAR 52.204-21. Level 2 uses the 110 security requirements incorporated from NIST SP 800-171 Revision 2. The current CMMC rules continue to reference Revision 2 even though NIST has separately published Revision 3, so quietly switching your checklist to Revision 3 would not reproduce the current CMMC Level 2 assessment basis.

SituationCurrent gap-assessment starting pointPrimary question
Supplier handles FCI but not CUILevel 1 safeguardsCan you demonstrate all applicable basic safeguarding requirements?
Supplier processes, stores, or transmits CUILevel 2, NIST SP 800-171 Rev. 2Are the 110 requirements implemented across the correctly scoped CUI environment?
Supplier is unsure whether data is CUIContract and data classification review firstWhat information is actually being provided or generated under the contract?
Supplier planned for a 2026 C3PAO assessmentRecheck current official implementation guidanceDoes the current solicitation or contract actually require that assessment now?

Before You Act

CMMC applicability can turn on contract language, data classification, subcontract flow-downs, system architecture, cloud services, and current Department implementation policy. Use this article as a readiness framework, not as individualized legal or contracting advice. Confirm material bid, certification, affirmation, and contractual decisions against the current solicitation, contract clauses, 32 CFR Part 170, DFARS requirements, and qualified professional advice where needed.

The distinction is especially important during the current Phase I pause. The regulatory framework still describes Level 2 C3PAO and Level 3 assessment structures, while current program guidance has suspended Phase II implementation. Treat the contract and the current official program page as your operational compass rather than relying on a saved webinar slide from six months ago.

CMMC gap assessment checklist

The CMMC gap assessment master checklist

The most useful checklist follows the order in which errors become expensive. Scope comes first. Evidence comes next. Technology purchases come surprisingly late.

CheckWhat “ready” should look likeUseful evidence
1. Contract inventoryRelevant prime contracts and subcontracts are identified with applicable cybersecurity clauses and data obligations.Contract matrix, clauses, statements of work
2. FCI and CUI identificationThe team can explain what FCI and CUI it receives, creates, stores, or transmits.Data inventory, markings, contract references
3. Required CMMC levelThe level used for the assessment is tied to actual contractual requirements and current program guidance.Solicitation, contract, prime flow-down
4. Data-flow mapFCI or CUI movement from receipt through storage, processing, sharing, backup, and disposal is known.Data-flow diagram, interviews
5. Asset inventoryEndpoints, servers, network devices, security systems, cloud services, and specialized assets are categorized.CMDB, inventory export, asset list
6. Network boundaryThe assessment boundary can be explained without relying on tribal knowledge.Current network diagram
7. Identity and accessUsers, administrators, service accounts, access paths, and least-privilege decisions are controlled.Directory exports, access reviews, role matrix
8. MFAMulti-factor authentication is implemented wherever the applicable Level 2 requirement calls for it.Identity configuration, test results
9. Configuration managementSecure baselines exist and changes are authorized and traceable.Baseline documents, change records
10. Audit and loggingRequired activity is logged, reviewed, protected, and tied to responsible processes.Log samples, alert rules, review records
11. Vulnerability and patch processFlaws are identified, prioritized, remediated, and verified.Scan results, tickets, patch reports
12. Media protectionRemovable media, backups, disposal, and physical movement of sensitive data are controlled.Media procedures, sanitization records
13. CUI encryptionEncryption implementation and cryptographic requirements are verified rather than assumed from a product brochure.Configuration evidence, architecture records
14. Incident responseRoles, escalation, investigation, reporting, and exercises are defined and operational.IR plan, exercise record, incident tickets
15. Physical protectionFacilities containing in-scope systems have controlled physical access and appropriate records.Visitor records, access lists, facility procedures
16. System Security PlanThe SSP describes the actual environment and implementation, not an aspirational future state.Version-controlled SSP
17. Cloud providersCUI-hosting cloud services are evaluated against applicable FedRAMP requirements and shared responsibilities are documented.Authorization/equivalency evidence, CRM
18. External service providersMSSPs, managed IT providers, SOC providers, backup providers, and others handling CUI or security protection data are correctly scoped.Contracts, service descriptions, CRM
19. SubcontractorsRelevant CMMC requirements and information-handling obligations are flowed down where required.Subcontracts, supplier questionnaires
20. Evidence ownershipEvery requirement has an accountable owner who knows how to retrieve current evidence.Control-owner matrix
21. Assessment objectivesTesting goes below the requirement headline to the applicable assessment objectives.Objective-level workbook
22. Gap registerEvery NOT MET or unverified item has a reason, owner, priority, and remediation path.Remediation register
23. POA&M eligibilityThe team knows which deficiencies may qualify for a conditional status and which cannot simply be deferred.Scored gap register
24. Affirmation ownershipA senior official understands what continuing compliance affirmation means and what evidence supports it.Governance record, approval process
25. Change monitoringNew systems, locations, providers, acquisitions, and workflows trigger a scope and control review.Change-management workflow

A six-step gap assessment that stays out of its own way

1. Contract

Identify FCI, CUI, clauses, and flow-down obligations.

2. Scope

Draw the real boundary and categorize assets and providers.

3. Test

Evaluate requirements and applicable assessment objectives.

4. Prove

Collect technical, documentary, interview, and record evidence.

5. Fix

Rank blockers, high-impact deficiencies, and evidence debt.

6. Retest

Verify remediation and establish continuing governance.

Scope the environment before testing controls

Scope is where a small defense supplier can accidentally turn a manageable project into an enterprise-wide rebuild.

If CUI exists on ordinary email, employee laptops, shared file storage, backup platforms, support tools, security monitoring systems, and unmanaged collaboration services, each additional path can pull more technology and more people into the assessment conversation.

Map where CUI can actually go

  • How does CUI enter the company?
  • Which users can view or modify it?
  • Which endpoints can download it?
  • Which servers or SaaS platforms store it?
  • Where is it backed up?
  • Does it reach ticketing, monitoring, support, or collaboration systems?
  • Can administrators or managed service providers access systems containing it?
  • Does it reach manufacturing equipment, test equipment, OT, or government-furnished equipment?
  • Which subcontractors receive it?

Classify Level 2 assets instead of calling everything “in scope”

The Level 2 framework distinguishes CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Those categories affect documentation and assessment treatment. For example, a firewall or identity platform may be a Security Protection Asset even when it does not serve as a normal CUI repository, while an asset claimed as out of scope must genuinely be unable to process, store, or transmit CUI and must not provide protection for CUI assets.

Decision rule: Do not shrink scope on paper. Shrink the actual technical pathways that allow CUI to spread. An enclave is useful only when architecture, permissions, workflows, backups, support access, and user behavior respect the boundary.

Cloud and service providers can change the boundary

For Level 2, a cloud service processing, storing, or transmitting CUI must satisfy the applicable FedRAMP Moderate or higher requirement or the permitted equivalent under Department policy. Customer responsibilities also need to be reflected in the SSP. Non-cloud external service providers can likewise enter the assessment scope when their services process CUI or security protection data.

This is why “our IT is outsourced” is not a scope answer. Outsourcing operations can move responsibilities, but it does not make contractual responsibility evaporate into the cloud.

Build evidence that can survive verification

A policy can explain what should happen. A gap assessment must also determine whether the environment shows that it does happen.

Level 2 assessments use the assessment procedures tied to NIST SP 800-171A. The practical consequence is important: a single NIST SP 800-171 requirement can contain multiple assessment objectives. A checkbox beside the requirement number is therefore a poor substitute for objective-level testing.

Evidence typeWhat it can demonstrateWeak substitute to avoid
ConfigurationHow a security control is technically implementedA policy saying the control should exist
RecordThat a recurring activity has actually occurredA blank template
InterviewThat responsible personnel understand and perform the processA procedure nobody follows
Technical testThat a control behaves as intendedA product feature list
DiagramBoundary, trust relationships, and data movementAn outdated network drawing
Ticket or approvalOperational execution and traceabilityAn undocumented verbal practice

Create an evidence index, not an evidence attic

For every applicable requirement or assessment objective, record the control owner, implementation description, evidence source, system or asset, evidence date, testing method, and current status.

A tidy evidence structure also makes change visible. If an identity setting changes, the evidence index tells you which requirements may need to be retested instead of waiting for compliance archaeology three days before an assessment.

High-value check: Pick five controls currently marked “implemented.” Ask the control owner to produce current evidence in five minutes. If the evidence is missing, stale, contradictory, or depends on one person’s memory, record an evidence gap even if the technology appears correct.

Use a readiness scorecard before chasing a CMMC score

The official CMMC scoring method matters, but it is not the best first management tool. A company can have a respectable numerical control score while still carrying a broken boundary, unknown cloud dependency, weak SSP, or unowned affirmation process.

The following Kioptrix readiness score is an editorial planning tool, not an official CMMC score. Give each gate 0, 1, or 2 points.

Gate0 points1 point2 points
Contract and dataUnknownPartially mappedContract, FCI, and CUI obligations documented
ScopeBoundary unclearInventory exists but has gapsAssets, data flows, providers, and exclusions defensible
ControlsMajor implementation gapsMixed implementationApplicable controls implemented and internally retested
EvidenceMostly narrativeEvidence exists inconsistentlyObjective-level current evidence retrievable
GovernanceNo clear ownersOwners exist informallyOwners, change process, remediation, and affirmation governance established

0 to 3: Stop thinking about assessment dates. Fix the operating model.

4 to 6: You have a remediation program, not yet a readiness program.

7 to 8: Concentrate on evidence quality, boundary exceptions, and repeatability.

9 to 10: Run an internal mock assessment using fresh evidence and skeptical testers who were not responsible for implementing every control.

Real-world example: the small machine shop

Imagine an 18-person machining supplier receiving drawings and routine contract information from a prime. Its first temptation is to buy a “CMMC platform” and import a hundred controls.

The better first move is to classify the information. If the supplier handles FCI but not CUI under the relevant work, its readiness path may center on Level 1 rather than a Level 2 project.

That changes the economics completely. The supplier still needs real security controls and a defensible self-assessment, but it avoids building a Level 2 compliance machine for information it does not actually receive.

The lesson is wonderfully unglamorous: data classification can save more money than a software discount.

Prioritize gaps that can block readiness

Do not remediate in checklist order. Fix gaps according to the damage they do to eligibility, scope, security, and evidence.

Priority 0: boundary and eligibility failures

  • You cannot determine whether data is FCI or CUI.
  • The SSP does not describe the actual system.
  • CUI is flowing through undocumented SaaS or personal services.
  • A cloud or external provider requirement has not been evaluated.
  • A subcontractor receives protected information but flow-down responsibilities are unresolved.
  • Systems called “out of scope” can still process or store CUI.

Priority 1: gaps with heavy security or scoring consequences

The Level 2 scoring methodology assigns different point consequences to different requirements, with certain deficiencies carrying more weight. MFA and CUI encryption also have specific partial-implementation scoring treatment. If MFA is a known weakness in your environment, a structured rollout plan is often more useful than buying another compliance dashboard. See the Kioptrix MFA rollout guide for implementation planning.

Priority 2: evidence and operating consistency

A technically correct control can still become an assessment problem when the procedure, SSP, configuration, diagram, and employee explanation disagree.

Use one sentence to test consistency: “Show me where this is documented, where it is configured, and where you prove it happened.” If those three answers point in different directions, keep the gap open.

What a POA&M does not rescue

Level 1 does not permit a POA&M for achieving status. For Level 2, conditional status can permit selected deficiencies only under defined restrictions. The current rule requires a score of at least 80% of the maximum and restricts which deficiencies can remain open. For example, certain requirements involving external connections, public information, the SSP, and physical access cannot simply be placed on the qualifying POA&M. Conditional items must be closed within 180 days or the conditional status expires.

Do not build a readiness plan around the POA&M ceiling. Treat conditional status as a constrained exception path, not permission to schedule important controls for “later.”

DIY, software, or professional help?

A gap assessment does not automatically require a platform, consultant, or assessor. The right purchase depends on what is actually slowing the organization down.

ApproachGood fit whenWhat it solvesWhat it does not solve
DIYScope is small, internal staff understand the systems, and official documentation is manageableLow-cost baseline analysis and control ownershipIndependent challenge, specialist architecture problems, staffing shortages
Compliance softwareEvidence, recurring tasks, ownership, mappings, and reporting are becoming difficult to manage manuallyWorkflow, centralization, repeatability, remindersBad architecture, incorrect scope, weak controls, automatic compliance
Specialist consultantScope is uncertain, CUI architecture is complex, cloud/ESP questions are material, or internal expertise is thinInterpretation, architecture review, remediation planning, independent challengeContractual guarantees or automatic official status
Formal assessment providerA current contractual requirement makes an authorized independent assessment necessaryThe applicable formal assessment functionSubstituting for readiness work you have not completed

Pay for software when the bottleneck is coordination

Software becomes useful when evidence has to be refreshed repeatedly, dozens of owners need reminders, multiple frameworks share controls, and the organization needs a persistent audit trail.

If your biggest problem is that nobody knows where CUI is stored, the platform risks becoming an expensive filing cabinet built before the house has walls.

Pay for expertise when the bottleneck is judgment

Professional help earns its keep when you need someone to challenge asset classifications, cloud architecture, FedRAMP assumptions, subcontractor dependencies, specialized assets, encryption decisions, assessment-objective interpretation, or a large remediation plan.

That is different from paying someone to copy requirement language into a spreadsheet. A polished spreadsheet is still just a spreadsheet wearing cufflinks.

Budget and schedule the gap assessment realistically

The cost of CMMC readiness is driven less by employee count than many buyers expect. The larger variables are the width of the technical boundary, the number of systems and providers touching protected data, current control maturity, evidence quality, and the remediation backlog.

Cost driverWhy it expands workHow to control it responsibly
CUI spread across normal corporate ITMore endpoints, identities, applications, and controls enter scopeEvaluate a purpose-built architecture or enclave where operationally sensible
Multiple cloud and service providersShared responsibility and provider evidence multiplyReduce unnecessary services and document CRMs early
Weak asset inventoryTesting begins with discovery instead of verificationComplete asset and data-flow mapping first
Large control backlogGap assessment turns into engineering and process redesignSeparate diagnosis from remediation budgeting
Evidence debtImplemented controls require reconstruction of proofAssign evidence owners and automate collection selectively
OT and specialized assetsStandard IT assumptions may not fit operational systemsClassify and document specialized assets early

A useful budget therefore looks like this:

Gap assessment + architecture or scope correction + control remediation + documentation and evidence work + recurring governance + any formally required external assessment = realistic readiness budget.

For a deeper breakdown of cost categories and quote drivers, use the Kioptrix guide to CMMC compliance cost. Keeping the checklist and the cost model on separate pages avoids turning either into a mile-wide shopping list.

Real-world example: a 70-person engineering supplier

Consider a hypothetical engineering company with 70 employees, CUI in a collaboration platform, remote engineers, managed endpoints, outsourced security monitoring, and an external backup service.

The control count is not its first cost driver. The real work begins with the shared data boundary: which cloud service hosts CUI, whether local endpoints can retain copies, what security data the external provider sees, who administers the environment, and how backup data is handled.

If those relationships are documented well, the technical testing becomes bounded. If they are vague, each interview uncovers another system, and the gap assessment grows tentacles.

How to buy outside help without overbuying

Because the current CMMC implementation position changed in July 2026, the first procurement question is no longer “Which C3PAO has an opening?” It is “What service do we actually need under our present contract requirement?”

If the need is readiness, buy readiness. If the need is architecture remediation, buy engineering. If a future or current contractual requirement calls for a formal assessment, verify the current program rules and provider status at that point.

Provider questionWhy it matters
Which CMMC level and assessment basis will you use?Prevents work against the wrong standard or revision.
What assumptions are you making about our CUI boundary?Exposes scope assumptions before they become billable surprises.
Will you test assessment objectives or only requirement statements?Separates real readiness analysis from a superficial checklist.
How will cloud providers and ESPs be evaluated?These dependencies can materially change scope.
What deliverables will we own?You should know whether you receive the gap register, evidence map, recommendations, and revised documentation.
What work is explicitly excluded?Gap assessment, remediation, penetration testing, policy drafting, and formal assessment are different services.
How are findings prioritized?A flat list of 47 gaps is less useful than a remediation sequence tied to risk and eligibility.
How is our sensitive assessment evidence protected?The readiness project itself may contain sensitive architecture and security data.
What happens when our environment changes?CMMC readiness is not a one-day photograph.

For the security requirements themselves, the current CMMC Level 2 basis continues to incorporate NIST SP 800-171 Revision 2. For contract-level implementation language, also review the current DFARS CMMC clause. The DFARS currently requires contracting officers to verify the required current CMMC status in SPRS where the applicable CMMC requirement is included.

Common CMMC gap assessment mistakes

Mistake 1: starting with all 110 requirements before confirming CUI

If Level 2 is not actually the applicable requirement, the organization may spend months solving the wrong problem. Contract and data review should precede control testing.

Mistake 2: treating policy language as implementation

“The organization requires MFA” and “MFA is enabled for the correct users and systems” are different statements. Test the second one.

Mistake 3: forgetting security protection data

Security providers and platforms can matter even when they do not host normal business CUI. Logs, configurations, and other security protection data can affect ESP and Security Protection Asset scoping.

Mistake 4: designing the checklist around the old Phase II date

The November 10, 2026 Phase II date was overtaken by the July 2026 suspension announcement. Keep the security work moving, but verify the current contractual trigger before committing money to a formal third-party assessment schedule.

Mistake 5: buying tools before reducing scope

If sensitive data is spread across ten services, automating evidence from all ten may be less sensible than first determining whether five of those services should ever touch CUI.

Mistake 6: assessing your intentions instead of your present state

Future projects belong in remediation plans. Your current gap status should describe what is implemented and provable today.

The technical detail that matters: A mature gap assessment records three different failure modes separately: not implemented, implemented but not adequately evidenced, and unable to determine because scope or ownership is unclear. Those problems require different fixes and different budgets.

CMMC gap assessment checklist

FAQ

Should we still perform a CMMC Level 2 gap assessment while Phase II is suspended?

Yes when your contracts, expected procurements, CUI obligations, or cybersecurity requirements make Level 2 relevant. The suspension changes the immediate implementation path, not the value of knowing whether your CUI environment actually satisfies NIST SP 800-171 Revision 2 requirements. Confirm the current contractual requirement before purchasing a formal certification service.

Should our checklist use NIST SP 800-171 Revision 2 or Revision 3?

For a current CMMC Level 2 gap assessment, follow the version incorporated into the CMMC program requirements, which is Revision 2. NIST Revision 3 is newer as a NIST publication, but a newer publication is not automatically the assessment basis incorporated into an existing regulatory program.

Can a consultant certify that we are CMMC compliant?

A readiness consultant can evaluate gaps and help with remediation, but a readiness opinion is not the same thing as an official CMMC status. Official assessment and status processes depend on the applicable CMMC level, current program implementation rules, and authorized assessment mechanisms.

Do we need compliance software for a CMMC gap assessment?

No. A small, well-scoped environment can use spreadsheets, document repositories, ticketing, configuration exports, and existing security tools. Dedicated software becomes more attractive when evidence refresh, control ownership, multiple systems, recurring tasks, and reporting become difficult to manage manually.

What if we cannot tell whether information from a prime contractor is CUI?

Do not guess and do not quietly upgrade everything to CUI as a substitute for clarification. Review contract documents and markings, identify the information and its source, document the question, and seek clarification through the appropriate contracting or prime-contractor channel.

How often should the gap assessment be refreshed?

Refresh it when material scope or control changes occur, not only when a calendar reminder fires. New cloud services, acquisitions, network redesigns, remote-access changes, new subcontractors, facility moves, and changes in CUI workflows are all sensible triggers for targeted reassessment.

Your 15-minute next step: draw the smallest truthful boundary

Do one thing before opening a 110-control workbook.

  1. Choose one active DoD contract, subcontract, or realistic upcoming opportunity.
  2. Write down whether it involves FCI, CUI, or information whose status still needs clarification.
  3. List every system, cloud service, endpoint type, facility, external provider, and subcontractor that can receive that information.
  4. Circle the systems you believe are out of scope and write one sentence explaining why they cannot process, store, transmit, or protect the relevant information.
  5. Name one person responsible for validating the map against the contract and current CMMC guidance.

That single sheet of paper will expose more useful CMMC questions than starting with a sea of control IDs. Once the boundary is truthful, the checklist becomes smaller, the evidence becomes easier to find, and remediation money has somewhere intelligent to go.

Final decision rule: Scope before software. Evidence before confidence. Current contract language before old implementation dates.

Last reviewed: 2026-09

Stay Updated with Kioptrix

Get practical guides, useful resources, and new articles delivered to your inbox.

No spam. Unsubscribe anytime. Read our Privacy Policy.