What Defense Contractors Most Commonly Get Wrong in CMMC Assessments

< Back to Q&A

Defense contractors often approach a Cybersecurity Maturity Model Certification (CMMC) assessment as if the goal is to produce enough policies, screenshots, and technical controls to satisfy an assessor. That is usually where the trouble starts.

The assessment is designed to determine whether the organization can consistently demonstrate how Controlled Unclassified Information (CUI) is protected across people, systems, and processes.

The recurring failures are often not a missing tool or document. They are mismatches between the stated environment and operating reality. For contractors accustomed to other federal compliance exercises, including Certified Cost or Pricing Data requirements, CMMC demands a different kind of proof: technical configuration, documentation, evidence, and employee interviews need to tell the same story.

What Does a CMMC Assessment Actually Evaluate?

At CMMC Level 2, assessors evaluate implementation of 110 NIST SP 800-171 Revision 2 security requirements. They do not rely on documents alone. NIST SP 800-171A uses three methods: Examine, Interview, and Test. Assessors compare policies and the System Security Plan with configurations, artifacts, workflows, and people operating controls. Some contractors call this a CMMC audit, but the test is broader than document review. Final Level 2 status requires all applicable requirements to be MET. A Conditional Level 2 status may be available when the assessment score is at least 80% and the remaining deficiencies meet CMMC’s Plan of Action and Milestones (POA&M) eligibility rules.

Where Are Contractors Typically Underprepared When the Assessor Arrives?

Problems arise when organizations scope based on how they want CUI to move rather than how it actually moves. CUI may be emailed outside the approved environment, saved to local devices, printed, backed up, or shared with subcontractors through systems that were never included in the scope. Employees may also use cloud applications or other tools that were overlooked during planning. These gaps can create differences between the System Security Plan (SSP), network diagrams, policies, interviews, and technical evidence. Assessors may then question whether the organization truly understands where CUI resides and how it is handled. The result is more than a scoping error; it can become a credibility problem during the assessment.

Which Practice Areas Generate the Most Findings During a CMMC Assessment?

Findings cluster where responsibility crosses systems or teams. Scoping and access control are frequent trouble spots because CUI moves through more places than contractors initially realize. System Security Plans create findings when implementation statements repeat the requirement or no longer reflect the environment. Incident response and risk assessment also cause problems when plans exist but have not been exercised or updated. Logging, identity controls, and third-party responsibilities can expose similar gaps. The difficulty is rarely understanding the policy statement. It is proving the control operates consistently, has an identifiable owner, produces evidence, and remains accurate as systems and personnel change.

What Happens After a Failed Assessment and How Do Contractors Recover?

A failed Level 2 assessment does not necessarily end the path to CMMC certification. If an organization meets the applicable scoring threshold and its remaining deficiencies qualify for a POA&M, it may receive Conditional Level 2 status. Those deficiencies must be remediated and the POA&M successfully closed within 180 days. Current Department of Defense (DoD) acquisition rules allow a contract to be awarded with Conditional Level 2 status when the solicitation requires Level 2 and the other applicable requirements are satisfied. If the POA&M is not successfully closed within the 180-day period, the Conditional status cannot continue

What Should Contractors Be Doing Right Now to Improve Their Assessment Readiness?

Start with the CUI, not the network diagram. Map where it enters, moves, resides, and leaves the organization, then confirm every related asset and service is properly scoped. Next, perform a requirement-by-requirement gap analysis against the 110 Level 2 requirements and reconcile the results to the SSP. Assign owners for controls, evidence, and assessor interviews. Build an organized evidence package, test incident response, update the risk assessment, and verify that recurring activities occur on schedule. Finally, conduct mock interviews and technical validation. Strong CMMC compliance means the documented process is the process people actually follow, consistently and with evidence available.

How BT Can Help

For more than four decades, Bennett Thrasher has provided businesses and individuals with strategic business guidance and solutions through professional tax, audit, advisory, and business process outsourcing services. Contact Jim Dougherty partner in Bennett Thrasher’s Technology Services, or call us at 770.396.2200.

Back to Q&A

Stay Ahead with Expert Tax & Advisory Insights

Never miss an update. Sign up to receive our monthly newsletter to unlock our experts' insights.

Subscribe Now