A Comprehensive Guide to CMMC Gap Assessment

Business professional reviewing a CMMC gap assessment guide

Updated:

September 28, 2026

Table of Contents

    A CMMC gap assessment compares an organization’s current safeguards and supporting evidence against the requirements of its applicable Cybersecurity Maturity Model Certification (CMMC) level. It helps defense contractors determine what needs correction before a formal assessment.

    CMMC requirements already appear in federal regulations and covered defense contracts. For small and medium-sized businesses supporting defense contractors, a gap assessment supports preparation through reviews of assessment scope, documentation, and implemented controls.

    The findings help prioritize remediation, assign responsibilities, and plan resources. A gap assessment supports readiness but does not itself confer CMMC status.

    What is a CMMC Gap Assessment?

    A CMMC gap assessment compares an organization’s existing cybersecurity safeguards and supporting evidence against the requirements of its applicable CMMC level. It highlights missing controls, incomplete implementation, and documentation gaps so contractors can prioritize corrective actions before their required assessment.

    The findings support a remediation plan with assigned responsibilities and target dates. A gap assessment helps establish readiness but does not itself provide CMMC certification.

    What is CMMC?

    The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense (DoD) program that verifies whether contractors and subcontractors implement required safeguards for sensitive unclassified information.

    Its three levels reflect different information protection needs. Level 1 covers basic safeguards for Federal Contract Information (FCI). Level 2 protects Controlled Unclassified Information (CUI) through 110 security requirements from NIST SP 800-171 Revision 2. Level 3 adds 24 selected requirements from NIST SP 800-172 to address advanced threats.

    CMMC is a U.S. Department of Defense cybersecurity standard for defense contractors, with CMMC 2.0 organizing requirements into three levels.
    What Is CMMC

    Contractors must achieve the CMMC status specified in applicable solicitations to qualify for those awards. The required level depends on contractual requirements and the information handled, so CMMC does not apply uniformly to every defense contractor or contract.

    CMMC Level 1 Requirements

    CMMC Level 1 requires contractors to implement the 15 basic safeguarding requirements in Federal Acquisition Regulation (FAR) clause 52.204-21 to protect systems that process, store, or transmit Federal Contract Information (FCI). These requirements cover six security areas:

    1. Access Control: Restrict system access and permitted functions to authorized users, processes, and devices. Control external system connections and information on publicly accessible systems.
    2. Identification and Authentication: Establish and verify the identities of users, processes, and devices before granting system access.
    3. Media Protection: Sanitize or destroy media containing FCI before disposal or release for reuse.
    4. Physical Protection: Restrict physical access, escort and monitor visitors, retain physical access logs, and manage access devices.
    5. System and Communications Protection: Protect communications at external and key internal system boundaries. Separate publicly accessible system components from internal networks.
    6. System and Information Integrity: Detect, report, and correct system flaws promptly. Maintain malicious code protection, update it when new releases become available, and conduct periodic system scans and real-time scans of external files.

    A gap assessment helps contractors review existing safeguards and prioritize corrective work. Achieving CMMC Level 1 requires meeting every applicable requirement, completing an annual self-assessment, and submitting results and a compliance affirmation in the Supplier Performance Risk System (SPRS). Level 1 does not permit conditional status with outstanding requirements documented in a Plan of Action and Milestones (POA&M).

    CMMC Level 2 Requirements

    CMMC Level 2 requires organizations handling Controlled Unclassified Information (CUI) to implement the 110 security requirements in NIST SP 800-171 Revision 2. A gap assessment compares existing safeguards and supporting evidence against these requirements, documenting missing controls, incomplete implementation, and corrective actions needed for assessment readiness.

    The 14 Security Families of NIST SP 800-171 Revision 2

    The NIST requirements fall into 14 security families that address technical safeguards, personnel responsibilities, and security management:

    1. Access Control: Restrict system permissions and access to authorized users, processes, and devices.
    2. Awareness and Training: Train personnel on security risks, responsibilities, and insider threats.
    3. Audit and Accountability: Maintain protected activity logs that support investigations and user accountability.
    4. Configuration Management: Maintain system inventories, secure configurations, and controlled changes.
    5. Identification and Authentication: Verify identities and apply required authentication safeguards, including multifactor authentication.
    6. Incident Response: Prepare for, detect, contain, recover from, and report security incidents.
    7. Maintenance: Control system maintenance activities, tools, and personnel.
    8. Media Protection: Safeguard CUI media during storage, transport, reuse, and disposal.
    9. Personnel Security: Screen personnel and protect systems during transfers and terminations.
    10. Physical Protection: Restrict physical access and monitor visitors.
    11. Risk Assessment: Evaluate security risks, scan for vulnerabilities, and prioritize remediation.
    12. Security Assessment: Evaluate controls, address deficiencies, monitor effectiveness, and maintain system security plans.
    13. System and Communications Protection: Protect system boundaries and communications, including CUI confidentiality.
    14. System and Information Integrity: Correct system flaws, maintain malware defenses, and monitor security alerts.

    The Role of Gap Assessment in CMMC Compliance

    A CMMC gap assessment compares an organization’s security controls and supporting evidence against the requirements of its applicable CMMC level. It highlights missing safeguards, incomplete implementation, and documentation gaps, helping contractors prioritize corrective actions before their required assessment.

    The findings support a remediation plan with assigned responsibilities, target dates, and resource needs. Reviewing these findings helps organizations direct spending and staff effort toward specific compliance deficiencies and verify that corrective measures work.

    A gap assessment supports preparation but does not itself establish CMMC status or guarantee a contract award. Contractors must complete the applicable CMMC assessment and meet the associated program and contractual requirements.

    Preparing for a CMMC Gap Assessment

    Preparing for a CMMC gap assessment involves confirming the applicable requirements, defining the systems under review, gathering evidence, and coordinating the people responsible for security controls.

    Preparing for a CMMC gap assessment includes confirming the required level and scope, reviewing controls and evidence, assigning staff responsibilities, and selecting a qualified assessment partner.
    Preparing for a CMMC Gap Assessment

    The following four steps cover assessment scope, internal documentation, staff responsibilities, and partner selection.

    1. Confirm the Applicable Level and Assessment Scope

    The applicable CMMC level determines which requirements the gap assessment should examine. Review contractual requirements and establish where Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) is processed, stored, or transmitted. Document relevant systems, personnel, facilities, and service providers. For Level 2, account for systems that provide security functions even when they do not handle CUI directly. Apply the scoping rules for the relevant level rather than assuming every asset receives the same evaluation.

    2. Review Controls and Gather Supporting Evidence

    An internal review establishes what safeguards currently exist and what evidence supports them. Gather policies, procedures, configuration records, access reviews, and other operational records relevant to the applicable requirements. For Levels 2 and 3, include the System Security Plan (SSP), asset inventory, and network diagrams. Map evidence to assessment objectives and record missing safeguards, outdated documents, and incomplete implementation. Draft policies may reveal preparation gaps, but formal CMMC assessments require final, approved evidence.

    3. Assign Responsibilities and Prepare Staff

    Clear responsibilities help reviewers obtain accurate evidence and explanations. Name a coordinator and designate staff who can demonstrate technical controls, explain procedures, and answer questions about daily operations. Confirm which safeguards service providers operate and which remain the contractor’s responsibility. Schedule interviews and demonstrations, arrange appropriate evidence access, and involve leadership in decisions about remediation resources.

    4. Select a Qualified Gap Assessment Partner

    A qualified gap assessment partner should have experience with the applicable CMMC level and comparable technical environments. Review relevant credentials, client references, assessment methods, and sample reports. Agree on scope, confidentiality, evidence handling, scheduling, and deliverables before work begins. The report should connect deficiencies to specific requirements and recommend practical corrective actions that help your organization prepare for its required CMMC assessment. Confirm how the provider addresses conflicts of interest when discussing subsequent certification services.

    Conducting a CMMC Gap Assessment

    A CMMC gap assessment compares an organization’s implemented safeguards and supporting evidence with the requirements of its applicable CMMC level. It evaluates cybersecurity readiness and produces findings that guide corrective work.

    Conducting a CMMC gap assessment includes confirming scope and requirements, reviewing evidence, testing controls, documenting findings, prioritizing gaps, and verifying remediation.
    Conducting a CMMC Gap Assessment

    The following six steps cover scope confirmation, evidence review, control evaluation, reporting, remediation planning, and follow-up validation.

    1. Confirm the Scope and Applicable Requirements

    A defined scope establishes which assets, services, and requirements the review covers. Confirm that the documented environment matches actual operations, including relevant service providers and systems that protect sensitive information. Apply the scoping rules for the required CMMC level. Resolve missing assets or unclear provider responsibilities before evaluating controls, since an incomplete scope can leave significant gaps outside the review.

    2. Examine Documentation and Supporting Evidence

    Evidence review connects each applicable assessment objective to documented policies, procedures, and operational records. Examine configuration settings, access records, training records, and other materials relevant to the required level. Check the System Security Plan for Levels 2 and 3 against the actual environment. Record outdated, missing, or contradictory evidence. Draft documents can reveal preparation needs, but formal CMMC assessments require final, approved evidence.

    3. Interview Personnel and Test Control Operation

    Interviews and testing establish whether security controls operate as described. Ask responsible personnel to explain their duties and demonstrate relevant safeguards. For example, verify that access permissions match authorized roles or that account removal procedures work. Compare demonstrations with documented procedures and retained records. A purchased tool or written policy alone does not demonstrate effective implementation; record discrepancies and unresolved evidence gaps.

    4. Document Findings in a Gap Assessment Report

    The gap assessment report explains what was reviewed, where evidence supports implementation, and what corrective work remains. Include four components:

    • Executive Summary: Describe the scope, major deficiencies, and overall readiness concerns.
    • Detailed Findings: Map each deficiency to the relevant requirement and assessment objective, with supporting evidence.
    • Remediation Recommendations: Explain the corrective action and evidence needed to resolve each finding.
    • Readiness Summary: State the methodology and limitations of any implementation rating or estimated score.

    Formal CMMC assessments use MET, NOT MET, and NOT APPLICABLE findings. A consultant’s readiness rating does not confer official CMMC status.

    5. Prioritize Gaps and Assign Corrective Work

    A remediation plan converts findings into tasks with accountable owners, resources, dependencies, and completion criteria. Prioritize security exposure, assessment consequences, and work that enables other controls. An internal plan can track preparation at any level. Conditional CMMC status has separate restrictions: Level 1 permits no assessment Plan of Action and Milestones (POA&M), while Levels 2 and 3 permit only qualifying deficiencies under specified conditions.

    6. Set Milestones and Verify Remediation

    Remediation milestones should account for staff capacity, procurement, technical complexity, and validation time. Confirm completion through updated evidence and appropriate retesting, then revise the gap register and readiness summary. For conditional CMMC status, permitted POA&M items require a successful closeout assessment within 180 days of the conditional status date. A preparatory gap assessment does not start that deadline.

    Moving Forward: From Gap Assessment to CMMC Certification

    Moving from a gap assessment to CMMC certification requires correcting deficiencies, demonstrating that safeguards work, and completing the applicable certification assessment.

    CMMC certification path after a gap assessment: implement and verify corrective actions, complete the applicable assessment, then maintain controls and affirm continuing compliance.
    Moving Forward From Gap Assessment to CMMC Certification

    Organizations whose contracts permit self-assessment follow that assessment route. The following three steps cover remediation, assessment completion, and maintaining compliance.

    1. Implement and Verify Corrective Actions

    A remediation action plan converts gap assessment findings into work with defined owners, deadlines, budgets, and completion criteria. Prioritize security risks, assessment requirements, and dependencies between controls.

    Implement necessary technology changes, approve revised policies, and train responsible personnel. Verify each correction through operational evidence and appropriate testing before closing the finding. A planned fix or purchased tool does not establish that the relevant assessment objectives are satisfied.

    2. Complete the Applicable CMMC Assessment

    The applicable solicitation or contract specifies the CMMC status the organization must hold. Confirm the required assessment type and scope before scheduling the assessment.

    For Level 2 certification, use an authorized or accredited CMMC Third-Party Assessment Organization (C3PAO). Provide current, approved evidence and personnel who can explain and demonstrate control operation.

    Address findings under the rules for the applicable level, complete any permitted closeout assessment, and confirm that the resulting status and required affirmation appear in the Supplier Performance Risk System (SPRS).

    3. Maintain Controls and Affirm Continuing Compliance

    Maintaining CMMC status requires continued implementation of applicable safeguards across the assessed environment. Monitor control effectiveness, address vulnerabilities, update documentation after relevant changes, and maintain role-appropriate training.

    An authorized senior official must affirm continuing compliance in SPRS upon achievement of conditional or final status, following applicable closeout assessments, and annually following final status.

    Track reassessment deadlines separately from annual affirmations. Retain current evidence so leadership can support each affirmation with an accurate account of implemented safeguards.

    Preparing for the Required CMMC Assessment

    The following six steps help organizations turn completed remediation into assessment readiness:

    • Confirm the assessment requirements. Check the applicable solicitation or contract for the required CMMC level and assessment type. A self-assessment and a certification assessment follow different processes.
    • Organize supporting evidence. Maintain current, approved policies, procedures, configuration records, and operational evidence. Connect each item to the relevant assessment objectives.
    • Select the appropriate assessor. For a Level 2 certification assessment, engage an authorized or accredited CMMC Third-Party Assessment Organization (C3PAO). Confirm its status and address potential conflicts of interest before engagement.
    • Prepare responsible personnel. Brief control owners, technical staff, and leadership on their responsibilities. Staff should be able to explain and demonstrate how safeguards operate.
    • Validate completed remediation. Conduct an internal readiness review using document examination, interviews, and testing. Resolve unsupported findings and incomplete implementation before the required assessment.
    • Maintain compliance after assessment. Track assessment findings, complete any permitted closeout activities, submit required affirmations, and schedule subsequent assessments. Retain evidence that safeguards continue to operate within the assessed environment.

    Final Thoughts

    A CMMC gap assessment helps defense contractors understand where their safeguards and supporting evidence fall short of applicable requirements. Its findings provide a basis for prioritizing remediation, assigning responsibilities, and preparing for the required assessment.

    The value comes from completing corrective work, verifying that controls operate effectively, and maintaining those safeguards over time. Bright Defense supports CMMC Level 1 and Level 2 readiness through gap analysis, risk assessments, policy development, remediation, and continuous compliance services.

    Organizations can use this support to turn assessment findings into practical security improvements and prepare to meet contractual cybersecurity obligations.

    Additional CMMC Resources:Additional CMMC Resources

    CMMC resources help contractors understand requirements, prepare assessment evidence, and locate qualified support. The following three categories cover official guidance, preparation resources, and training.

    Official CMMC Documentation and Resources

    • CMMC Resources and Documentation: The official program website provides assessment guides, scoping guidance, FAQs, and regulatory information. (DoW CIO)
    • Defense Industrial Base Cybersecurity Assessment Center (DIBCAC): DIBCAC provides information about government cybersecurity assessments, including its role in CMMC Level 3 assessments. (dcma.mil)
    • NIST SP 800-171 DoD Assessment Methodology: This document explains the methodology for evaluating contractor implementation of NIST SP 800-171 under related defense contracting requirements. It is separate from NIST SP 800-53 and the CMMC assessment guides. (acq.osd.mil)

    Resources for Gap Assessment and Compliance

    • CMMC Assessment and Scoping Guides: These documents explain assessment boundaries, objectives, and evaluation procedures for the applicable CMMC level. (dodcio.defense.gov)
    • DIB SCC CyberAssist: This industry resource provides cybersecurity guidance and tools to help defense suppliers implement safeguards and address contractual requirements. (DIB SCC CyberAssist)
    • The Cyber AB Marketplace: The directory helps organizations locate CMMC ecosystem participants, including authorized or accredited CMMC Third-Party Assessment Organizations (C3PAOs). Check each provider’s listed status and services before engagement. (cyberab.org)

    Webinars and Training Resources

    DIB SCC Supply Chain Cyber Training: These training materials address cybersecurity and CMMC preparation for defense suppliers. (ndisac.org)

    The Cyber AB Town Halls: Recorded sessions provide program updates and discussions about assessment and implementation topics. (CyberAB)

    Additional Tips:

    • Subscribe to the CMMC newsletter for updates and announcements.
    • Follow CMMC-related social media accounts to stay informed.
    • Network with other organizations working on CMMC compliance to share best practices.

    John Minnix is Co-Founder of Bright Defense, specializing in cybersecurity compliance solutions for frameworks including SOC 2, ISO 27001, HIPAA, and CMMC. With over 20 years of industry experience, John brings practical strategies to help organizations achieve continuous compliance and reduce cybersecurity risks. Previously, he co-founded VPLS Solutions, a successful technology consultancy acquired in 2019.

    Get In Touch

      Group 1298 (1)-min