CMMC Pre-Assessment Checklist: Are You Actually Ready?

CMMC Pre-Assessment Checklist: Are You Actually Ready?

Quick Answer: Most CMMC assessment failures trace back to five preventable gaps: a System Security Plan that describes intent rather than reality, incomplete scoping, access controls that can't be proven with evidence, disorganized documentation, and compliance programs that exist on paper but were never tested. A structured pre-assessment—run well before the formal CMMC assessment—identifies these gaps while there's still time to fix them.

Only about 1% of defense contractors report feeling fully prepared for their CMMC assessment, and the median self-assessment score sits at just 60 out of 110 required practices, according to the State of the DIB 2025 report. That's a striking gap between confidence and readiness, and it explains why so many organizations walk into a CMMC assessment expecting a formality and walk out with a failed certification.

The good news is that assessment failures rarely stem from exotic threats or unsolvable technical problems. They stem from documentation that doesn't match reality, controls that were implemented but never verified, and evidence that can't be produced on demand. These are fixable issues, but only if you find them before an assessor does.

This checklist walks through the gaps that most commonly stall a CMMC assessment, and what a genuine pre-assessment review should look like before you commit to the formal process.

What Does a CMMC Assessment Actually Evaluate?

A CMMC assessment measures whether your organization has implemented the security requirements tied to your required certification level. For most contractors handling Controlled Unclassified Information (CUI), that means Level 2, which requires meeting all 110 practices in NIST SP 800-171 Rev 2, broken down into roughly 320 individual assessment objectives.

Each requirement is scored MET, NOT MET, or NOT APPLICABLE. A Level 2 assessment passes at 88 of 110 requirements (80%), and while a limited number of lower-severity gaps can be handled through a Plan of Action and Milestones (POA&M) closed within 180 days, a single significant failure can stop certification outright. There's little room for ambiguity, which is exactly why preparation matters so much.

The 5 Gaps That Stall Most CMMC Assessments

1. An SSP That Describes Intent, Not Reality

The System Security Plan (SSP) is the foundation every CMMC assessment is built on. It's the document assessors use to understand your environment, verify your compliance claims, and determine what evidence to request.

The problem is that many SSPs describe a future state rather than a current one. They're copied from templates, written in generic language, or left unchanged after significant system changes. A statement like "we use MFA" tells an assessor nothing useful. A statement like "we enforce multi-factor authentication through Azure AD for all privileged and remote access" gives them something they can actually verify.

If your SSP can't be mapped cleanly to all 320 assessment objectives, and your current environment, you're not ready for a CMMC assessment, regardless of how strong your actual security posture might be.

2. Incomplete or Incorrect Scoping

Scoping determines which systems, assets, and processes fall under CMMC's purview, and it's one of the most expensive mistakes to get wrong. Under 32 CFR §170.19(c), assets must be categorized correctly—CUI Assets, Security Protection Assets, Specialized Assets, and External Service Providers each carry different requirements.

Common scoping errors include missing assets in the inventory, overlooking Security Protection Assets that support the environment, and assuming that a VLAN, folder permission, or basic encryption creates the kind of enclave separation the rule actually requires. Under-scoping creates audit risk. Over-scoping inflates cost and complexity unnecessarily. Getting this step right early prevents both problems downstream.

3. Access Controls That Can't Be Proven

Access control is one of the most heavily scrutinized areas in any CMMC assessment, and it's also where policy and practice most often diverge. An organization may have a well-written access control policy on file, but if privileged accounts aren't consistently managed, multi-factor authentication isn't enforced everywhere it should be, or access logs can't be produced on request, that policy means very little to an assessor.

Assessors validate against live systems and current evidence, not stated intentions. If a control isn't consistently enforced across your environment, it isn't "met," no matter what your documentation says.

4. Evidence That Isn't Assessment-Ready

Even organizations with solid technical controls often stumble here. Assessors accept only approved, final-form evidence that's retrievable and timestamped. Screenshots that are months old, unsigned policy drafts, or evidence scattered across shared drives and inboxes all create friction during an assessment, and friction tends to translate into findings.

Every control you claim as implemented needs a direct, traceable link to supporting evidence: configuration screenshots, log samples, training records, or signed procedures. If that evidence can't be produced quickly and confidently, it's effectively the same as not having it.

5. "Paper" Programs That Were Never Tested

Incident response plans and security awareness training are frequent trouble spots. It's common for these programs to exist as polished documents that were never actually exercised. A CMMC assessment doesn't just check whether a plan exists; it looks for evidence the plan has been used, whether through completed training records, tested response procedures, or documented drills.

A program that only exists on paper will be treated as a gap, not a strength.

What Does a Strong Pre-Assessment Actually Look Like?

A genuine pre-assessment, sometimes called a readiness assessment, is a full dry run of the formal CMMC assessment process. It should include a completeness review of your SSP, verification that evidence actually supports every control you're claiming, staff interviews to confirm that documented procedures match daily practice, and a walk-through of your scoping decisions.

The goal isn't to pass a mock exam. It's to surface every gap while there's still time to remediate it, budget for it, and document a realistic plan of action, rather than discovering it mid-assessment when the options for fixing it are far more limited.

Even With Phase II Suspended, Don't Pause Your Preparation

On July 13, 2026, the Department of Defense suspended CMMC Phase II, meaning contracting officers can currently require only self-assessments rather than formal third-party certification. It's tempting to treat this as a reason to slow down. That would be a mistake.

The underlying obligations under DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain fully in force. An inaccurate self-assessment still carries False Claims Act exposure, and the requirement for third-party CMMC assessments is expected to return in some form once the interim review concludes. Organizations that keep their SSPs current, their evidence organized, and their controls verified during this window will be far better positioned than those who wait for the next deadline to reappear.

Your Next Step Starts Here

A CMMC assessment shouldn't be the first time you find out where your gaps are. The organizations that pass on their first attempt are the ones that treat pre-assessment as a genuine diagnostic step, not a formality on the way to certification.

If you're unsure whether your SSP, scoping, or access controls would hold up under scrutiny, a structured pre-assessment review is the most direct way to find out, while you still have room to fix what needs fixing.

Contact us today to schedule your pre-assessment review and take the first step toward confident CMMC compliance.

Frequently Asked Questions

How long does it take to prepare for a CMMC assessment?

The Department of Defense estimates that achieving CMMC compliance can take as long as 18 months, depending on your required level and organizational size. Starting a pre-assessment review early gives you time to remediate gaps without scrambling against a contract deadline.

What's the difference between a gap assessment and a pre-assessment?

A gap assessment compares your current posture against the 110 NIST SP 800-171 practices and produces an estimated score along with a prioritized remediation plan. A pre-assessment (also called a readiness assessment) comes later and simulates the actual CMMC assessment—reviewing your SSP, verifying evidence, and interviewing staff to confirm you're truly ready.

Can a single unmet requirement fail a CMMC assessment?

Yes. CMMC Level 2 assessments require meeting at least 88 of 110 requirements (80%). A limited number of minor gaps can be addressed through a Plan of Action and Milestones within 180 days, but a significant failure can stop certification outright.

Do I still need to prepare for CMMC now that Phase II is suspended?

Yes. The July 2026 suspension only affects the requirement for third-party CMMC assessments. Self-assessment obligations under DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in force, and the certification requirement is expected to return once the interim review concludes.

What's the most common reason a CMMC assessment fails?

Documentation that doesn't match reality is the most frequent cause. This includes System Security Plans that describe future or intended controls rather than what's actually implemented, and access controls that look sound on paper but can't be verified through evidence during the assessment.

How can we help?

Cancel
Show Policy

Download Checklist

Related Information: CMMC Certification

Latest Resources

See all resources