Why Passing CMMC Starts With Finding the Gaps First?

CMMC gap assessment identifying compliance gaps before a CMMC Level 2 certification assessment

A CMMC gap assessment checks your environment against all 320 assessment objectives behind the 110 NIST SP 800-171 controls that make up Cybersecurity Maturity Model Certification (CMMC) Level 2, not just the surface-level checklist most shops use to self-assess. That’s usually why the number that comes back is lower than expected. It’s rarely a sign you missed something obvious. It’s a sign the objectives require more explicit proof than a self-assessment tends to catch. 

This applies specifically to CMMC Level 2, the tier built around protecting Controlled Unclassified Information (CUI). CMMC Level 1, by contrast, covers Federal Contract Information (FCI) and is a simpler pass/fail checklist with no numeric score at all — if your shop only handles FCI, most of what follows here won’t apply to you. 

Related Topic: CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

What a Gap Assessment Actually Checks, Versus What Self-Assessment Assumes?

Most shops self-assess by walking through the 110 controls and asking a simple question for each one: do we have this, yes or no. It’s a reasonable way to approach it. It’s also not how the assessment actually works underneath. 

Each of those 110 controls is really a shorthand for several assessment objectives, and there are 320 of them in total. An objective doesn’t just ask whether you’ve technically implemented something. In a lot of cases, it asks whether you’ve defined it, in writing, in a way that’s specific enough for an assessor to point to. You can have the right technical control running in your environment and still get zero credit, because the paperwork behind it doesn’t say what it needs to say. 

A gap assessment walks all 320 objectives, not the 110-item summary. That’s the entire reason the number it produces tends to look different from what a shop expected going in. 

Related Topic: What Is a Passing CMMC Score and How Is It Calculated?

Why This Difference Actually Matters?

This isn’t a technicality that only matters to an assessor. It’s the difference between believing you’re close to ready and finding out, months later during a formal third-party assessment, that you weren’t. Catching that gap during a gap assessment costs you a conversation and a remediation plan. Catching it during your actual C3PAO audit costs you the certification level you were counting on, plus everything you already spent trying to meet CMMC requirements along the way. 

The Real Story: 34 of 110 Controls, a Score of Negative 107 

Here’s what that actually looks like in practice. A small manufacturer supporting Department of Defense subcontracts completed a CMMC gap assessment to accurately measure its compliance readiness.

Of the 110 controls, only 34 came back as fully implemented. The calculated SPRS score landed at negative 107, against a goal of positive 110. 

That’s a big gap. But it wasn’t the worst version of this either. The floor on that scoring system goes down to negative 203, and shops land closer to that floor more often than you’d think on a first honest look. 

It Wasn’t Mostly a Technology Problem 

Here’s the part that surprised the shop most. Most of the missing points weren’t missing technology. They were missing documentation, and documentation that was specific enough to satisfy an assessment objective, not just documentation in general. 

Take encryption. The shop had BitLocker enabled on some of their devices. That’s a real technical control, actually running. But the assessment objective also requires FIPS-validated cryptography, which means a specific registry setting has to be enabled on top of BitLocker itself. Partial implementation doesn’t earn partial credit. Either the full requirement is met, or the control counts as not implemented at all. 

Same story with their backups. CUI was being backed up, which felt like the responsible thing to do. The organization backed up data to a non-FedRAMP cloud, causing the CMMC control to fail despite significant implementation effort.

Related Topic: Department of War Suspends CMMC Phase II Certification: What It Means for Defense Contractors

Where Most of the Missing Points Actually Come From?

Once you see the pattern, it shows up everywhere. If you want a closer look at how missing or not-yet-applicable documentation actually factors into scoring, we’ve written separately about documenting non-applicable controls, which covers a related piece of this same problem. 

Policies That Exist But Don’t Say Enough 

The shop had policies. What they didn’t have was policies with enough specific content to satisfy the assessment objectives sitting underneath each control. Wherever an objective uses the word “define,” it needs a document that actually defines the thing, not a general statement that gestures at it. 

The fix here isn’t complicated, but it takes real effort. One policy per domain, across all fourteen domains, from access control to media protection, written with enough specificity that an assessor can find the answer to a given question without guessing. That single change resolves a surprising share of a low score, because so much of the deduction comes from documentation gaps rather than technical ones. 

Controls That Are Partly There

A second, smaller category is controls that are technically running but not fully configured. A SIEM tool that’s deployed but not capturing logs from every system in scope. A data flow diagram or network diagram that was never built, even though the underlying environment could support one. An incident response plan that exists but is missing the specific sections an assessor expects to see, or that’s never been tested with an actual tabletop exercise. 

None of these are exotic problems. They’re the kind of thing that happens when a shop is doing real work and compliance documentation isn’t the top priority day to day. A gap assessment’s job is to surface exactly which of these apply before an assessor finds them for you. 

Related Topic: CMMC Audit Preparation: Avoid Common Compliance Mistakes

The Gaps That Don’t Show Up Until Someone Looks Closely

A few categories of findings are easy to miss entirely, because on the surface it looks like something is already being handled. 

Training is a good example. Most shops already run some form of general security awareness training, and it’s tempting to assume that covers the CMMC training requirement. It doesn’t, at least not fully. CMMC expects training targeted to specific roles, plus a CUI-specific training module that’s distinct from general phishing-and-passwords awareness content. A shop can have strong general training and still have a real gap here, simply because the training was never built to address CUI handling specifically. 

Physical security documentation is another one. A shop might have a locked door and a sign-in sheet and feel reasonably covered. What’s often missing is a documented list of who holds physical keys or access credentials, and a clear visitor policy that’s actually written down rather than just practiced informally. 

The last category is proof of ongoing practice, not just the existence of a plan. Having a policy that says you’ll review your security controls annually is not the same as being able to show that you did it. Assessors want evidence: tickets, timestamps, records of who did what and when. A shop that’s actually been doing the work all along still needs a way to prove it, or that work doesn’t count toward the score any more than if it had never happened. 

Related Topic: C3PAO: What It Is and How to Choose One for CMMC Level 2

What Happens After the Gap Assessment?

The output of a gap assessment isn’t just a score. It’s a roadmap, and it usually breaks into three stages. 

Near Term: Fix What’s Fastest to Fix 

Prioritize quick technical fixes by migrating noncompliant cloud data, completing partial implementations, and accurately defining your CMMC assessment scope. This stage also typically produces the first draft of a Plan of Action and Milestones, which gives you a working list of every open gap along with who owns closing it. 

Midterm: Build the Documentation Layer

Around the 60-day mark, the focus shifts to the piece that caused most of the missing points in the first place: policies and the System Security Plan. Draft documentation alongside remediation, expand role-specific CUI training, assign employees, and build assessment-ready records before certification assessments begin successfully today.

Longer Term: Prove It’s Working, Not Just Built

Past 90 days, the work shifts from building controls to proving they hold up over time. Expand monitoring to capture logs across all in-scope systems, assess CUI data flow risks, and test your incident response plan regularly. Begin collecting tickets, timestamps, and completed work records to prove you consistently maintain CMMC controls before your formal assessment.

None of that is meant to be discouraging. A negative score from an honest gap assessment isn’t a failing grade. It’s an accurate starting point, and an accurate starting point is worth more than an optimistic guess about your cybersecurity posture that you find out is wrong later, in front of an assessor instead of in front of a plan. If you want the deeper mechanics of how the scoring itself works, including what separates a Conditional outcome from Final CMMC certification, our breakdown of how SPRS scoring works covers that in detail. 

Related Topic: What Is CUI in Cybersecurity and Why Is It Important?

What To Do With This?

Validate your readiness with a formal gap assessment that evaluates all 320 objectives before CMMC compliance affects your next DoD contract.

>Schedule a free consultation with our CMMC-certified team to talk through what a gap assessment would look like for your environment and your broader cybersecurity practices. If you’re already working through CMMC compliance services with us, this is exactly the kind of conversation worth having early, before a formal assessment is on the calendar.

Related Topic: DIBCAC: What Defense Contractors Need to Know

FAQ 

What’s the difference between a self-assessment and a CMMC gap assessment? 

A self-assessment typically checks the 110 controls at a surface level. A formal CMMC gap assessment evaluates all 320 assessment objectives, revealing compliance gaps and producing a more accurate readiness score.

Why did my gap assessment score come back negative? 

Negative scores are common on a first honest assessment, especially when documentation hasn’t kept pace with technical implementation. Missing or incomplete policies, not missing technology, usually account for the largest share of lost points. 

How much does a CMMC gap assessment cost? 

Gap assessment costs vary by environment size and documentation, but early findings reduce remediation expenses before formal CMMC certification assessments begin.

Our Blog

Why Passing CMMC Starts With Finding the Gaps First?

Why Passing CMMC Starts With Finding the Gaps First?

A CMMC gap assessment checks your environment against all 320 assessment objectives behind the 110 NIST…

CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

A CMMC enclave separates the systems and people who handle Controlled Unclassified Information (CUI)…

Why Every Business Needs an IT Risk Assessment?

Why Every Business Needs an IT Risk Assessment?

An IT risk assessment identifies where client data actually lives, who can reach it, and…