
CMMC Gap Assessment Checklist for Defense Suppliers
Find the gaps before you buy the fix
A useful CMMC gap assessment is not a 110-row spreadsheet with a parade of green checkmarks. It is a disciplined comparison between the cybersecurity requirements that actually apply to your contract environment and the controls, evidence, people, cloud services, subcontractors, and facilities that can prove those requirements are working.
That distinction matters even more in 2026. The Department’s official CMMC site announced on July 13, 2026 that Phase II implementation, previously scheduled to begin November 10, 2026, was suspended while Phase I self-assessment requirements remain in place. Defense suppliers should therefore keep improving Level 1 or Level 2 readiness where applicable, but should not purchase a third-party certification engagement merely because an older implementation calendar said November 2026.
The practical goal is narrower and more useful: determine what information you handle, define the assessment boundary, test implementation against the applicable requirements, collect defensible evidence, rank remediation, and know what must be checked again before an authorized official makes an affirmation.
Separate FCI, CUI, security assets, service providers, and genuinely out-of-scope systems.
Move beyond policy documents to configurations, records, interviews, and technical verification.
Fix boundary and eligibility problems before buying software that may not solve the real gap.
The cheapest control to remediate is often the one you discover before it spreads across the entire CUI boundary. 🔐
Snapshot
Who this is for: Defense primes, subcontractors, manufacturers, engineering firms, technology suppliers, and small businesses that need to evaluate CMMC readiness.
Problem solved: Turn CMMC requirements into a practical scope, evidence, remediation, and ownership checklist instead of a vague compliance project.
What you can do next: Identify your likely Level 1 or Level 2 scope, rank the most consequential gaps, and decide whether the work belongs in-house, in software, or with specialist help.
Table of Contents

What a CMMC gap assessment should establish in 2026
A gap assessment answers a deceptively simple question: What would prevent this specific environment from satisfying the CMMC requirements that apply to it?
It is not itself a CMMC certification, and a consultant’s readiness report does not create an official CMMC status. Think of it as the diagnostic scan before treatment. Done well, it tells you what is in scope, what is implemented, what is missing, what cannot yet be proved, and what deserves money first.
Start with the level that actually applies
Under the codified CMMC framework, Level 1 is based on 15 safeguarding requirements associated with FAR 52.204-21. Level 2 uses the 110 security requirements incorporated from NIST SP 800-171 Revision 2. The current CMMC rules continue to reference Revision 2 even though NIST has separately published Revision 3, so quietly switching your checklist to Revision 3 would not reproduce the current CMMC Level 2 assessment basis.
| Situation | Current gap-assessment starting point | Primary question |
|---|---|---|
| Supplier handles FCI but not CUI | Level 1 safeguards | Can you demonstrate all applicable basic safeguarding requirements? |
| Supplier processes, stores, or transmits CUI | Level 2, NIST SP 800-171 Rev. 2 | Are the 110 requirements implemented across the correctly scoped CUI environment? |
| Supplier is unsure whether data is CUI | Contract and data classification review first | What information is actually being provided or generated under the contract? |
| Supplier planned for a 2026 C3PAO assessment | Recheck current official implementation guidance | Does the current solicitation or contract actually require that assessment now? |
Before You Act
CMMC applicability can turn on contract language, data classification, subcontract flow-downs, system architecture, cloud services, and current Department implementation policy. Use this article as a readiness framework, not as individualized legal or contracting advice. Confirm material bid, certification, affirmation, and contractual decisions against the current solicitation, contract clauses, 32 CFR Part 170, DFARS requirements, and qualified professional advice where needed.
The distinction is especially important during the current Phase I pause. The regulatory framework still describes Level 2 C3PAO and Level 3 assessment structures, while current program guidance has suspended Phase II implementation. Treat the contract and the current official program page as your operational compass rather than relying on a saved webinar slide from six months ago.

The CMMC gap assessment master checklist
The most useful checklist follows the order in which errors become expensive. Scope comes first. Evidence comes next. Technology purchases come surprisingly late.
| Check | What “ready” should look like | Useful evidence |
|---|---|---|
| 1. Contract inventory | Relevant prime contracts and subcontracts are identified with applicable cybersecurity clauses and data obligations. | Contract matrix, clauses, statements of work |
| 2. FCI and CUI identification | The team can explain what FCI and CUI it receives, creates, stores, or transmits. | Data inventory, markings, contract references |
| 3. Required CMMC level | The level used for the assessment is tied to actual contractual requirements and current program guidance. | Solicitation, contract, prime flow-down |
| 4. Data-flow map | FCI or CUI movement from receipt through storage, processing, sharing, backup, and disposal is known. | Data-flow diagram, interviews |
| 5. Asset inventory | Endpoints, servers, network devices, security systems, cloud services, and specialized assets are categorized. | CMDB, inventory export, asset list |
| 6. Network boundary | The assessment boundary can be explained without relying on tribal knowledge. | Current network diagram |
| 7. Identity and access | Users, administrators, service accounts, access paths, and least-privilege decisions are controlled. | Directory exports, access reviews, role matrix |
| 8. MFA | Multi-factor authentication is implemented wherever the applicable Level 2 requirement calls for it. | Identity configuration, test results |
| 9. Configuration management | Secure baselines exist and changes are authorized and traceable. | Baseline documents, change records |
| 10. Audit and logging | Required activity is logged, reviewed, protected, and tied to responsible processes. | Log samples, alert rules, review records |
| 11. Vulnerability and patch process | Flaws are identified, prioritized, remediated, and verified. | Scan results, tickets, patch reports |
| 12. Media protection | Removable media, backups, disposal, and physical movement of sensitive data are controlled. | Media procedures, sanitization records |
| 13. CUI encryption | Encryption implementation and cryptographic requirements are verified rather than assumed from a product brochure. | Configuration evidence, architecture records |
| 14. Incident response | Roles, escalation, investigation, reporting, and exercises are defined and operational. | IR plan, exercise record, incident tickets |
| 15. Physical protection | Facilities containing in-scope systems have controlled physical access and appropriate records. | Visitor records, access lists, facility procedures |
| 16. System Security Plan | The SSP describes the actual environment and implementation, not an aspirational future state. | Version-controlled SSP |
| 17. Cloud providers | CUI-hosting cloud services are evaluated against applicable FedRAMP requirements and shared responsibilities are documented. | Authorization/equivalency evidence, CRM |
| 18. External service providers | MSSPs, managed IT providers, SOC providers, backup providers, and others handling CUI or security protection data are correctly scoped. | Contracts, service descriptions, CRM |
| 19. Subcontractors | Relevant CMMC requirements and information-handling obligations are flowed down where required. | Subcontracts, supplier questionnaires |
| 20. Evidence ownership | Every requirement has an accountable owner who knows how to retrieve current evidence. | Control-owner matrix |
| 21. Assessment objectives | Testing goes below the requirement headline to the applicable assessment objectives. | Objective-level workbook |
| 22. Gap register | Every NOT MET or unverified item has a reason, owner, priority, and remediation path. | Remediation register |
| 23. POA&M eligibility | The team knows which deficiencies may qualify for a conditional status and which cannot simply be deferred. | Scored gap register |
| 24. Affirmation ownership | A senior official understands what continuing compliance affirmation means and what evidence supports it. | Governance record, approval process |
| 25. Change monitoring | New systems, locations, providers, acquisitions, and workflows trigger a scope and control review. | Change-management workflow |
A six-step gap assessment that stays out of its own way
Identify FCI, CUI, clauses, and flow-down obligations.
Draw the real boundary and categorize assets and providers.
Evaluate requirements and applicable assessment objectives.
Collect technical, documentary, interview, and record evidence.
Rank blockers, high-impact deficiencies, and evidence debt.
Verify remediation and establish continuing governance.
Scope the environment before testing controls
Scope is where a small defense supplier can accidentally turn a manageable project into an enterprise-wide rebuild.
If CUI exists on ordinary email, employee laptops, shared file storage, backup platforms, support tools, security monitoring systems, and unmanaged collaboration services, each additional path can pull more technology and more people into the assessment conversation.
Map where CUI can actually go
- How does CUI enter the company?
- Which users can view or modify it?
- Which endpoints can download it?
- Which servers or SaaS platforms store it?
- Where is it backed up?
- Does it reach ticketing, monitoring, support, or collaboration systems?
- Can administrators or managed service providers access systems containing it?
- Does it reach manufacturing equipment, test equipment, OT, or government-furnished equipment?
- Which subcontractors receive it?
Classify Level 2 assets instead of calling everything “in scope”
The Level 2 framework distinguishes CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Those categories affect documentation and assessment treatment. For example, a firewall or identity platform may be a Security Protection Asset even when it does not serve as a normal CUI repository, while an asset claimed as out of scope must genuinely be unable to process, store, or transmit CUI and must not provide protection for CUI assets.
Decision rule: Do not shrink scope on paper. Shrink the actual technical pathways that allow CUI to spread. An enclave is useful only when architecture, permissions, workflows, backups, support access, and user behavior respect the boundary.
Cloud and service providers can change the boundary
For Level 2, a cloud service processing, storing, or transmitting CUI must satisfy the applicable FedRAMP Moderate or higher requirement or the permitted equivalent under Department policy. Customer responsibilities also need to be reflected in the SSP. Non-cloud external service providers can likewise enter the assessment scope when their services process CUI or security protection data.
This is why “our IT is outsourced” is not a scope answer. Outsourcing operations can move responsibilities, but it does not make contractual responsibility evaporate into the cloud.
Build evidence that can survive verification
A policy can explain what should happen. A gap assessment must also determine whether the environment shows that it does happen.
Level 2 assessments use the assessment procedures tied to NIST SP 800-171A. The practical consequence is important: a single NIST SP 800-171 requirement can contain multiple assessment objectives. A checkbox beside the requirement number is therefore a poor substitute for objective-level testing.
| Evidence type | What it can demonstrate | Weak substitute to avoid |
|---|---|---|
| Configuration | How a security control is technically implemented | A policy saying the control should exist |
| Record | That a recurring activity has actually occurred | A blank template |
| Interview | That responsible personnel understand and perform the process | A procedure nobody follows |
| Technical test | That a control behaves as intended | A product feature list |
| Diagram | Boundary, trust relationships, and data movement | An outdated network drawing |
| Ticket or approval | Operational execution and traceability | An undocumented verbal practice |
Create an evidence index, not an evidence attic
For every applicable requirement or assessment objective, record the control owner, implementation description, evidence source, system or asset, evidence date, testing method, and current status.
A tidy evidence structure also makes change visible. If an identity setting changes, the evidence index tells you which requirements may need to be retested instead of waiting for compliance archaeology three days before an assessment.
High-value check: Pick five controls currently marked “implemented.” Ask the control owner to produce current evidence in five minutes. If the evidence is missing, stale, contradictory, or depends on one person’s memory, record an evidence gap even if the technology appears correct.
Use a readiness scorecard before chasing a CMMC score
The official CMMC scoring method matters, but it is not the best first management tool. A company can have a respectable numerical control score while still carrying a broken boundary, unknown cloud dependency, weak SSP, or unowned affirmation process.
The following Kioptrix readiness score is an editorial planning tool, not an official CMMC score. Give each gate 0, 1, or 2 points.
| Gate | 0 points | 1 point | 2 points |
|---|---|---|---|
| Contract and data | Unknown | Partially mapped | Contract, FCI, and CUI obligations documented |
| Scope | Boundary unclear | Inventory exists but has gaps | Assets, data flows, providers, and exclusions defensible |
| Controls | Major implementation gaps | Mixed implementation | Applicable controls implemented and internally retested |
| Evidence | Mostly narrative | Evidence exists inconsistently | Objective-level current evidence retrievable |
| Governance | No clear owners | Owners exist informally | Owners, change process, remediation, and affirmation governance established |
0 to 3: Stop thinking about assessment dates. Fix the operating model.
4 to 6: You have a remediation program, not yet a readiness program.
7 to 8: Concentrate on evidence quality, boundary exceptions, and repeatability.
9 to 10: Run an internal mock assessment using fresh evidence and skeptical testers who were not responsible for implementing every control.
Real-world example: the small machine shop
Imagine an 18-person machining supplier receiving drawings and routine contract information from a prime. Its first temptation is to buy a “CMMC platform” and import a hundred controls.
The better first move is to classify the information. If the supplier handles FCI but not CUI under the relevant work, its readiness path may center on Level 1 rather than a Level 2 project.
That changes the economics completely. The supplier still needs real security controls and a defensible self-assessment, but it avoids building a Level 2 compliance machine for information it does not actually receive.
The lesson is wonderfully unglamorous: data classification can save more money than a software discount.
Prioritize gaps that can block readiness
Do not remediate in checklist order. Fix gaps according to the damage they do to eligibility, scope, security, and evidence.
Priority 0: boundary and eligibility failures
- You cannot determine whether data is FCI or CUI.
- The SSP does not describe the actual system.
- CUI is flowing through undocumented SaaS or personal services.
- A cloud or external provider requirement has not been evaluated.
- A subcontractor receives protected information but flow-down responsibilities are unresolved.
- Systems called “out of scope” can still process or store CUI.
Priority 1: gaps with heavy security or scoring consequences
The Level 2 scoring methodology assigns different point consequences to different requirements, with certain deficiencies carrying more weight. MFA and CUI encryption also have specific partial-implementation scoring treatment. If MFA is a known weakness in your environment, a structured rollout plan is often more useful than buying another compliance dashboard. See the Kioptrix MFA rollout guide for implementation planning.
Priority 2: evidence and operating consistency
A technically correct control can still become an assessment problem when the procedure, SSP, configuration, diagram, and employee explanation disagree.
Use one sentence to test consistency: “Show me where this is documented, where it is configured, and where you prove it happened.” If those three answers point in different directions, keep the gap open.
What a POA&M does not rescue
Level 1 does not permit a POA&M for achieving status. For Level 2, conditional status can permit selected deficiencies only under defined restrictions. The current rule requires a score of at least 80% of the maximum and restricts which deficiencies can remain open. For example, certain requirements involving external connections, public information, the SSP, and physical access cannot simply be placed on the qualifying POA&M. Conditional items must be closed within 180 days or the conditional status expires.
Do not build a readiness plan around the POA&M ceiling. Treat conditional status as a constrained exception path, not permission to schedule important controls for “later.”
DIY, software, or professional help?
A gap assessment does not automatically require a platform, consultant, or assessor. The right purchase depends on what is actually slowing the organization down.
| Approach | Good fit when | What it solves | What it does not solve |
|---|---|---|---|
| DIY | Scope is small, internal staff understand the systems, and official documentation is manageable | Low-cost baseline analysis and control ownership | Independent challenge, specialist architecture problems, staffing shortages |
| Compliance software | Evidence, recurring tasks, ownership, mappings, and reporting are becoming difficult to manage manually | Workflow, centralization, repeatability, reminders | Bad architecture, incorrect scope, weak controls, automatic compliance |
| Specialist consultant | Scope is uncertain, CUI architecture is complex, cloud/ESP questions are material, or internal expertise is thin | Interpretation, architecture review, remediation planning, independent challenge | Contractual guarantees or automatic official status |
| Formal assessment provider | A current contractual requirement makes an authorized independent assessment necessary | The applicable formal assessment function | Substituting for readiness work you have not completed |
Pay for software when the bottleneck is coordination
Software becomes useful when evidence has to be refreshed repeatedly, dozens of owners need reminders, multiple frameworks share controls, and the organization needs a persistent audit trail.
If your biggest problem is that nobody knows where CUI is stored, the platform risks becoming an expensive filing cabinet built before the house has walls.
Pay for expertise when the bottleneck is judgment
Professional help earns its keep when you need someone to challenge asset classifications, cloud architecture, FedRAMP assumptions, subcontractor dependencies, specialized assets, encryption decisions, assessment-objective interpretation, or a large remediation plan.
That is different from paying someone to copy requirement language into a spreadsheet. A polished spreadsheet is still just a spreadsheet wearing cufflinks.
Budget and schedule the gap assessment realistically
The cost of CMMC readiness is driven less by employee count than many buyers expect. The larger variables are the width of the technical boundary, the number of systems and providers touching protected data, current control maturity, evidence quality, and the remediation backlog.
| Cost driver | Why it expands work | How to control it responsibly |
|---|---|---|
| CUI spread across normal corporate IT | More endpoints, identities, applications, and controls enter scope | Evaluate a purpose-built architecture or enclave where operationally sensible |
| Multiple cloud and service providers | Shared responsibility and provider evidence multiply | Reduce unnecessary services and document CRMs early |
| Weak asset inventory | Testing begins with discovery instead of verification | Complete asset and data-flow mapping first |
| Large control backlog | Gap assessment turns into engineering and process redesign | Separate diagnosis from remediation budgeting |
| Evidence debt | Implemented controls require reconstruction of proof | Assign evidence owners and automate collection selectively |
| OT and specialized assets | Standard IT assumptions may not fit operational systems | Classify and document specialized assets early |
A useful budget therefore looks like this:
Gap assessment + architecture or scope correction + control remediation + documentation and evidence work + recurring governance + any formally required external assessment = realistic readiness budget.
For a deeper breakdown of cost categories and quote drivers, use the Kioptrix guide to CMMC compliance cost. Keeping the checklist and the cost model on separate pages avoids turning either into a mile-wide shopping list.
Real-world example: a 70-person engineering supplier
Consider a hypothetical engineering company with 70 employees, CUI in a collaboration platform, remote engineers, managed endpoints, outsourced security monitoring, and an external backup service.
The control count is not its first cost driver. The real work begins with the shared data boundary: which cloud service hosts CUI, whether local endpoints can retain copies, what security data the external provider sees, who administers the environment, and how backup data is handled.
If those relationships are documented well, the technical testing becomes bounded. If they are vague, each interview uncovers another system, and the gap assessment grows tentacles.
How to buy outside help without overbuying
Because the current CMMC implementation position changed in July 2026, the first procurement question is no longer “Which C3PAO has an opening?” It is “What service do we actually need under our present contract requirement?”
If the need is readiness, buy readiness. If the need is architecture remediation, buy engineering. If a future or current contractual requirement calls for a formal assessment, verify the current program rules and provider status at that point.
| Provider question | Why it matters |
|---|---|
| Which CMMC level and assessment basis will you use? | Prevents work against the wrong standard or revision. |
| What assumptions are you making about our CUI boundary? | Exposes scope assumptions before they become billable surprises. |
| Will you test assessment objectives or only requirement statements? | Separates real readiness analysis from a superficial checklist. |
| How will cloud providers and ESPs be evaluated? | These dependencies can materially change scope. |
| What deliverables will we own? | You should know whether you receive the gap register, evidence map, recommendations, and revised documentation. |
| What work is explicitly excluded? | Gap assessment, remediation, penetration testing, policy drafting, and formal assessment are different services. |
| How are findings prioritized? | A flat list of 47 gaps is less useful than a remediation sequence tied to risk and eligibility. |
| How is our sensitive assessment evidence protected? | The readiness project itself may contain sensitive architecture and security data. |
| What happens when our environment changes? | CMMC readiness is not a one-day photograph. |
For the security requirements themselves, the current CMMC Level 2 basis continues to incorporate NIST SP 800-171 Revision 2. For contract-level implementation language, also review the current DFARS CMMC clause. The DFARS currently requires contracting officers to verify the required current CMMC status in SPRS where the applicable CMMC requirement is included.
Common CMMC gap assessment mistakes
Mistake 1: starting with all 110 requirements before confirming CUI
If Level 2 is not actually the applicable requirement, the organization may spend months solving the wrong problem. Contract and data review should precede control testing.
Mistake 2: treating policy language as implementation
“The organization requires MFA” and “MFA is enabled for the correct users and systems” are different statements. Test the second one.
Mistake 3: forgetting security protection data
Security providers and platforms can matter even when they do not host normal business CUI. Logs, configurations, and other security protection data can affect ESP and Security Protection Asset scoping.
Mistake 4: designing the checklist around the old Phase II date
The November 10, 2026 Phase II date was overtaken by the July 2026 suspension announcement. Keep the security work moving, but verify the current contractual trigger before committing money to a formal third-party assessment schedule.
Mistake 5: buying tools before reducing scope
If sensitive data is spread across ten services, automating evidence from all ten may be less sensible than first determining whether five of those services should ever touch CUI.
Mistake 6: assessing your intentions instead of your present state
Future projects belong in remediation plans. Your current gap status should describe what is implemented and provable today.
The technical detail that matters: A mature gap assessment records three different failure modes separately: not implemented, implemented but not adequately evidenced, and unable to determine because scope or ownership is unclear. Those problems require different fixes and different budgets.

FAQ
Should we still perform a CMMC Level 2 gap assessment while Phase II is suspended?
Yes when your contracts, expected procurements, CUI obligations, or cybersecurity requirements make Level 2 relevant. The suspension changes the immediate implementation path, not the value of knowing whether your CUI environment actually satisfies NIST SP 800-171 Revision 2 requirements. Confirm the current contractual requirement before purchasing a formal certification service.
Should our checklist use NIST SP 800-171 Revision 2 or Revision 3?
For a current CMMC Level 2 gap assessment, follow the version incorporated into the CMMC program requirements, which is Revision 2. NIST Revision 3 is newer as a NIST publication, but a newer publication is not automatically the assessment basis incorporated into an existing regulatory program.
Can a consultant certify that we are CMMC compliant?
A readiness consultant can evaluate gaps and help with remediation, but a readiness opinion is not the same thing as an official CMMC status. Official assessment and status processes depend on the applicable CMMC level, current program implementation rules, and authorized assessment mechanisms.
Do we need compliance software for a CMMC gap assessment?
No. A small, well-scoped environment can use spreadsheets, document repositories, ticketing, configuration exports, and existing security tools. Dedicated software becomes more attractive when evidence refresh, control ownership, multiple systems, recurring tasks, and reporting become difficult to manage manually.
What if we cannot tell whether information from a prime contractor is CUI?
Do not guess and do not quietly upgrade everything to CUI as a substitute for clarification. Review contract documents and markings, identify the information and its source, document the question, and seek clarification through the appropriate contracting or prime-contractor channel.
How often should the gap assessment be refreshed?
Refresh it when material scope or control changes occur, not only when a calendar reminder fires. New cloud services, acquisitions, network redesigns, remote-access changes, new subcontractors, facility moves, and changes in CUI workflows are all sensible triggers for targeted reassessment.
Your 15-minute next step: draw the smallest truthful boundary
Do one thing before opening a 110-control workbook.
- Choose one active DoD contract, subcontract, or realistic upcoming opportunity.
- Write down whether it involves FCI, CUI, or information whose status still needs clarification.
- List every system, cloud service, endpoint type, facility, external provider, and subcontractor that can receive that information.
- Circle the systems you believe are out of scope and write one sentence explaining why they cannot process, store, transmit, or protect the relevant information.
- Name one person responsible for validating the map against the contract and current CMMC guidance.
That single sheet of paper will expose more useful CMMC questions than starting with a sea of control IDs. Once the boundary is truthful, the checklist becomes smaller, the evidence becomes easier to find, and remediation money has somewhere intelligent to go.
Final decision rule: Scope before software. Evidence before confidence. Current contract language before old implementation dates.
Last reviewed: 2026-09