Part 2 of 3 in the CMMC for Small Defense Contractors series. 

Part 1: CMMC for Small Defense Subcontractors: Level 1, Level 2, and How to Know Which Path You're On 

Part 3: What Is CUI Scoping, and How Can It Cut Your CMMC Compliance Costs in Half?


Two manufacturers. Forty employees each. Both handling CUI under a defense subcontract. Both facing the same November 2026 enforcement deadline.

Company A hired an RPO in January 2026 to run a formal gap assessment before doing anything else. Score came back: 54 out of 110. Eleven non-deferrable gaps. Twelve months of controlled remediation, prioritized around the blockers. C3PAO assessment scheduled for this September. They know exactly what they're walking into.

Company B hired an MSP in January 2026 and started building. GCC High tenant, Intune, MFA rollout, SSP drafted. Spent $180,000 in six months. Then they ran a gap assessment in June to prep for their August C3PAO. Score: 61 out of 110. Four non-deferrable 5-point gaps still open — SC.3.177 (FIPS-validated encryption), SC.3.187 (organization-controlled key management), and two MFA gaps that the MSP had marked as partial. August assessment is now postponed. They're back in the remediation queue.

The difference wasn't budget. Both spent similar amounts. The difference was sequencing. Company A knew their actual score before they started building. Company B found out what their score was six weeks before their assessment.

CMMC assessment readiness isn't a feeling. It's a number, and you need to calculate it honestly before a C3PAO calculates it for you.

Stop Guessing Your Compliance Readiness Score

Running an automated, file-level security model means your non-deferrable 3-point and 5-point encryption hurdles are secured from day one. Before you schedule an expensive independent C3PAO evaluation, learn how a data-centric approach removes the fear from your gap assessment.

See How Theodosian Accelerates Your C3PAO Readiness

What Does "CMMC Assessment Ready" Actually Mean?

Ready for a CMMC Level 2 assessment means you can walk into a C3PAO evaluation with reasonable confidence that you'll exit with either a Final CMMC Certificate or a Conditional CMMC Certificate. Those are the two acceptable outcomes. Everything else is a failed assessment with a 6–9 month delay and a second assessment budget.

For a Final Certificate: All 110 NIST SP 800-171 practices are fully implemented and documented. Your score is 110 out of 110. Your SSP accurately describes every system, component, and person in your CUI environment. Your assessor can verify every control through configuration review, log analysis, or interview.

For a Conditional Certificate: Your score is 88 or above out of 110. All 3-point and 5-point controls are fully implemented; these are non-deferrable by rule. Your open gaps are limited to 1-point controls that are legitimately eligible for POA&M deferral. Your Plan of Action & Milestones is credible, specific, and achievable within 180 days.

Below 88 is a failed assessment. No conditional status, no 180-day window, no partial credit. You leave without a certificate, reschedule, and spend the remediation period and the second assessment fee before you get another shot.

"Ready" means knowing which category you're in before the C3PAO starts their clock.

What Is a CMMC Self-Assessment, and How Is It Different from a C3PAO Assessment?

A CMMC self-assessment is an internal evaluation of your implementation against all 110 NIST SP 800-171 requirements using the DoD's published scoring methodology. You conduct it. You report the result to the SPRS portal. You own the legal accuracy of what you submit.

A C3PAO assessment is a formal evaluation conducted by a Certified Third-Party Assessment Organization. They examine your actual environment, interview your people, review configurations, pull logs, test controls, and independently calculate your score. That score is what appears on your CMMC certificate.

The relationship between the two matters for two reasons:

First: Your SPRS self-assessment score is a legal declaration. Under DFARS 252.204-7019, you're required to assess your implementation of NIST 800-171, submit the score to the SPRS portal, and maintain a System Security Plan. The score you submit is visible to prime contractors and DoD contracting officers. It affects your ability to win work. And — per the MorseCorp False Claims Act settlement in March 2025 — a materially inflated SPRS score that you continue to bill against is not an administrative error. It's the sequence that produced the first cybersecurity FCA settlement. 

💡
For the full picture of what's at stake, see What Is Your SPRS Score and Why It Determines Your CMMC Outcome.

Second: The gap between self-reported SPRS scores and C3PAO-calculated scores is real and consistently large. CyberSheath's 2025 State of the Defense Industrial Base report puts the median self-reported SPRS score at 60 — but assessment practitioners report that contractors routinely discover 30–50 point gaps between what they submitted and what an independent assessor finds. The reason is predictable: partial implementations get scored as Met in self-assessments. Assessors score partial implementations as Not Met.

A pre-assessment gap analysis — an honest, structured self-assessment run before you schedule your C3PAO — is the mechanism that closes that gap before it becomes a surprise.

Which Controls Must Be Done Before Your C3PAO Walks In?

This is the question that separates a controlled remediation program from an emergency rebuild.

Under 32 CFR 170.21, the CMMC POA&M eligibility rule has one clear threshold: only 1-point controls are eligible for deferral to a POA&M. All 3-point and 5-point controls must be fully implemented before your assessment starts. No exceptions, no Conditional Certificate possible with these open.

Sixty-three of 110 NIST SP 800-171 requirements are non-deferrable. That's the majority of the controls, and they cluster in exactly the domains where small contractors most commonly have gaps:

💡
The full breakdown of which controls are POA&M-eligible and which are assessment blockers is covered in CMMC Level 2 POA&M: Which Controls You Can Defer, and Which Will Fail Your Assessment on Day One.

SC.3.177 — FIPS 140-3 Validated Encryption (5 points, non-deferrable): CUI at rest and in transit must be encrypted using FIPS 140-3 validated cryptographic modules. "We use BitLocker" or "SharePoint encrypts everything" is not sufficient — you need to identify the specific validated module, reference its CMVP certificate number, and demonstrate it's operating in FIPS-approved mode. Files that travel outside your primary CUI environment — downloaded to a laptop, shared with a subcontractor — are encrypted by whatever the receiving device provides. That gap is where most enclave-based architectures break down. 

💡

SC.3.187 — Organization-Controlled Key Management (3 points, non-deferrable): Your encryption keys must be under your organizational control. Default GCC High environments use Microsoft-managed encryption keys — Microsoft can technically access your encrypted content without your active authorization. Microsoft Customer Key moves the architecture closer to organizational control, but whether it fully satisfies SC.3.187 is an active assessment question. Some C3PAOs accept it; others scrutinize the specific key management architecture.

Multi-Factor Authentication — IA Domain (3–5 points across multiple controls, all non-deferrable): MFA for all privileged access and all access to systems containing CUI. Partial MFA deployment — enforced for some users or some systems but not all — is a failed control, not a partially met one. A single CUI-connected system without enforced MFA is an assessment blocker.

System Security Plan Completeness: Your SSP must document every system, component, connection, and individual within your CUI boundary. Undocumented assets don't receive the benefit of your implemented controls; they're automatic gaps. If your employees use AI tools from systems that touch CUI, those tools may be in your boundary, whether or not you intended them to be. 

💡
Learn more about why undocumented AI tool usage creates SSP scope problems: AI Acceptable Use Policy for Defense Contractors: What Your CMMC Program Must Include.

How Do You Score Your Own CMMC Readiness Before the C3PAO Does?

The DoD publishes the NIST SP 800-171 DoD Assessment Methodology with point weights for all 110 requirements. You can run the calculation yourself. Here's how to do it in a way that produces a number you can actually trust:

Step 1: Define your CUI scope first

Before scoring anything, document every system, location, and individual that processes, stores, or transmits CUI. This is your assessment boundary — the universe of everything the C3PAO will examine. Underscoping your boundary inflates your score artificially. If you're not sure what counts as CUI, start with Part 1 of this series — specifically the CUI determination section.

Step 2: Score each control as Met, Not Met, or Not Applicable, nothing in between

The DoD methodology has three statuses. "Partially implemented" doesn't exist. If you've deployed MFA for 90% of users but not all CUI-connected systems, that control is Not Met. If your SSP documents 95 of 110 requirements but leaves five undocumented, those five are Not Met. Assessors apply this binary standard. Your self-assessment needs to apply it too, or the number you produce won't predict your assessment outcome.

Step 3: Apply the weights and calculate your score

Start at 110. Subtract 5 for each Not Met 5-point control, 3 for each Not Met 3-point control, and 1 for each Not Met 1-point control. The CMMC Compliance Checklist has all 110 controls mapped with point weights, POA&M eligibility, and implementation priority; use it to run this calculation rather than building a spreadsheet from scratch.

Step 4: Separate your gaps into two buckets

Bucket 1: 3-point and 5-point controls that are Not Met. These are non-deferrable. They must be remediated before your assessment. These drive your timeline.

Bucket 2: 1-point controls that are Not Met and are not among the six explicitly excluded controls under 32 CFR 170.21(a)(2). These are POA&M-eligible. They drive your conditional certificate strategy.

Step 5: Compare your score to the 88/110 threshold

If your honest score is 88 or above and your Bucket 1 is empty, you're in conditional certificate territory; your POA&M items are genuinely deferrable. If your score is below 88 or Bucket 1 has items in it, you have assessment blockers that need remediation before you schedule a C3PAO.

What Does Your System Security Plan Need to Include Before Assessment?

Your SSP is the foundational document your C3PAO uses during the assessment. It defines the scope they examine, the controls they test, and the claims they verify. An incomplete SSP is not just a documentation gap; it's a scope problem that affects every control tied to undocumented components.

For a small contractor, an assessment-ready SSP needs:

System inventory and boundary diagram: Every system that processes, stores, or transmits CUI. This includes cloud environments (GCC High tenant), managed endpoints, mobile devices, network components, and any external service providers (including your MSP) that touch the CUI environment. A C3PAO will ask about anything they can find in your logs that isn't in your diagram.

Control implementation descriptions: For each of the 110 NIST 800-171 requirements, a description of how the control is implemented in your specific environment, not a copy of the NIST requirement text. "Multi-factor authentication is enforced through Conditional Access policies in Azure AD, requiring MFA for all users accessing SharePoint, Teams, and Exchange in the GCC High tenant" is a control description. "We use MFA" is not.

POA&M for open gaps: Every Not Met control that is eligible for deferral needs a corresponding POA&M item in your SSP. The POA&M item must include the specific gap, the remediation steps, an assigned owner, required resources, and a milestone date within 180 days of your assessment. "TBD" or "pending budget approval" on a milestone date tells an assessor your remediation isn't real.

User access list and CUI authorization documentation: Who has access to your CUI environment, under what role, and based on what authorization decision. Your access control documentation needs to show that every person with access was authorized, not just that access exists.

External service provider documentation: If your MSP manages your GCC High environment, they may be in your assessment boundary as an External Service Provider. Their configurations are your configurations. Their gaps are your gaps. Your SSP needs to document what they manage and how their implementation satisfies each relevant control. 

💡
For a full picture of what your MSP can and can't do for your CMMC program, see What a CMMC MSP Can and Can't Do for Your Compliance Program.

What Are the Most Common CMMC Readiness Gaps for Small Contractors?

Based on pre-assessment gap analyses run across DIB contractors, the gaps that appear most frequently in small-to-mid contractor programs:

Incomplete MFA deployment: MFA enforced for primary work applications but not all — legacy systems, VPN access, or helpdesk accounts with privileged access often get missed. Assessors check all privileged access paths, not just the obvious ones.

Unvalidated encryption: Encryption tools in use but not confirmed as FIPS 140-3 validated, or validated but not operating in FIPS-approved mode. Demonstrating FIPS compliance requires more than confirming encryption is enabled.

Audit log gaps: Logging enabled but not actively managed — no regular review process, retention below the required duration, or insufficient log coverage across the CUI boundary. The AU domain requires demonstrating active log management, not just log collection.

SSP scope undercount: Systems documented in the SSP but missing connected components — a SharePoint site that syncs to personal devices, a Teams channel that's accessible from personal phones, an AI tool built into an already-authorized application. Assessors look for data flows, not just listed systems.

CUI handling training: CMMC requires that individuals who handle CUI receive security awareness training specific to CUI requirements. Many small contractors have general security awareness training programs but nothing specific to CUI identification, marking, and handling.

Incident response plan that describes a plan but doesn't reflect actual capability: IR plans that would require resources or personnel the company doesn't have, or that assign roles to people who don't know they have those roles. Assessors test whether people know the plan, not just whether the document exists.

How Much Time Does It Take to Get Ready for a CMMC Level 2 Assessment?

For a small contractor relying on traditional infrastructure upgrades, climbing from a median SPRS score of 60 to full compliance is an incredibly slow process. Under a standard perimeter-based model, the realistic timeline before a C3PAO assessment spans 9 to 18 months of active disruption. This lengthy runway is consumed by rebuilding a network, migrating to an expensive cloud enclave, reconfiguring mobile endpoints, and navigating months-long consulting cycles.

However, you don't have to overhaul your entire IT environment to meet the deadline. By shifting from an infrastructure-heavy model to a data-centric security model with Theodosian, small defense contractors can get CMMC certified 4 to 6 times faster.

Instead of spending a year forcing your team into a new, locked-down cloud ecosystem, Theodosian embeds FIPS 140-3 validated encryption and automated access controls directly into individual CUI files. Because the protection travels with the data itself across your existing commercial M365 endpoints, SharePoint, and local devices, you bypass the core infrastructure bottlenecks that trigger massive audit delays. This architecture allows small businesses to deploy the platform in weeks and achieve absolute C3PAO readiness in just 1 to 3 months, transforming a looming, multi-year compliance risk into a rapid competitive advantage.

accelerated cmmc readiness path

What Should Your POA&M Look Like Before Your CMMC Assessment?

Your POA&M is a compliance document your assessor will evaluate, not a project management artifact you keep internally. It needs to meet specific criteria to support a Conditional Certificate:

Only 1-point controls: Every item on your POA&M at assessment time must be a 1-point control that is not among the six specifically excluded controls under 32 CFR 170.21(a)(2)(iii). If a 3-point or 5-point control is on your POA&M when the assessor arrives, it's a blocker — not a deferred item.

Credible milestones within 180 days: A POA&M submitted with "remediate by November 2026" on an item assessed in September 2026 gives you 60 days of your 180-day window on day one. Every milestone needs to be achievable in the remaining time given your actual remediation capacity.

Discrete items, not bundled gaps: Each unmet control should be a separate POA&M item. Bundling multiple requirements into a single entry makes it harder to demonstrate closure at your closeout assessment and may be flagged as insufficiently specific.

Documented current state: For each open item, include what you have in place today alongside the remaining gap. "Partial implementation — MFA enforced for 47 of 52 user accounts; three contractor accounts and two service accounts excluded pending legacy system update" is documentable. "MFA not complete" is not.

Real resource allocation: Assigned owners, documented budget or resources, specific remediation steps. An assessor who reads your POA&M should be able to tell whether remediation is genuinely in motion or aspirationally planned.

Cut Your CMMC Audit Prep Timeline by up to 80%

You don't have to wait 12 to 18 months or endure a disruptive cloud tenant migration to walk into your C3PAO assessment with total confidence. Discover how securing your CUI at the file level gets your business fully audit-ready in a fraction of the time.

Explore the Fast Track to CMMC Level 2 Compliance

FAQ’s: CMMC Assessment for Small Contractors

What is a CMMC gap assessment, and do I need one?

A CMMC gap assessment is a formal evaluation of your current security implementation against all 110 NIST SP 800-171 requirements, conducted before your C3PAO assessment to identify deficiencies. For a small contractor who hasn't done a previous honest self-assessment, a gap assessment run by an RPO (Registered Practitioner Organization) is essentially required before scheduling a C3PAO — not because it's mandated, but because scheduling a C3PAO without knowing your gap is how contractors show up with non-deferrable blockers they didn't know about. An RPO can conduct advisory gap assessments; a C3PAO cannot assist you with remediation if they're also your assessor.

Can I do my CMMC self-assessment myself, or do I need an RPO?

You can conduct your own self-assessment using the DoD's published NIST SP 800-171 Assessment Methodology. The CMMC Compliance Checklist walks through all 110 requirements with implementation guidance. Whether you should involves two questions: Do you have the internal expertise to accurately evaluate whether controls are genuinely Met vs. partially implemented? And do you have someone who can critically challenge your own assessments rather than optimistically rounding up? Many small contractors benefit from RPO involvement specifically for the second question — an outside evaluation catches the gaps internal staff have normalized.

What happens if I schedule my C3PAO assessment and then discover I have non-deferrable gaps?

Postpone. Rescheduling a C3PAO is costly in time and potentially in fees, but it's better than a failed assessment. A failed assessment — where non-deferrable controls block the assessment from proceeding — produces the same outcome as a postponement, plus the cost of the failed assessment itself. If you discover a 5-point non-deferrable gap the week before your assessment date, that gap needs remediation before the assessor arrives. The C3PAO queue for rescheduling then adds another 6–9 months. Run your honest gap assessment early enough that postponements don't put you past the November 2026 deadline.

If I get a Conditional Certificate, can I still perform contracts requiring CMMC Level 2?

Generally, yes — a Conditional CMMC Status satisfies the CMMC Level 2 requirement for contract performance while the 180-day remediation period is active. However, the specific contract clause governs. Some prime contractors have flowdown requirements that specify Final CMMC Status rather than Conditional. Confirm with your prime what their requirement is before assuming a Conditional Certificate clears you for all work.

Does my SPRS score need to match my C3PAO assessment score?

Yes. After a C3PAO assessment, you're required to update your SPRS portal submission to reflect the assessed score. This is where the MorseCorp FCA liability arose — they failed to update their SPRS score after a third-party assessment showed a lower number and continued billing against DoD contracts. Once you have an independently assessed score, your SPRS submission must reflect it. The SPRS portal takes whatever number you submit — but what you submit is a legal declaration.