CMMC 2.0 Readiness Check
Phase 1: Scope Definition
- Identify CUI and FCI within the organization
- Controlled Unclassified Information (CUI) types
- Federal Contract Information (FCI) locations
- Systems processing, storing, or transmitting CUI/FCI
- Personnel with CUI access
- External partners and subcontractors handling CUI
- Define the CMMC assessment boundary
- Document data flows for CUI/FCI
- Determine target CMMC level based on contract requirements
CMMC Level Requirements
| Level | Practices | Assessment Type | Applies To |
|---|---|---|---|
| Level 1 | 17 (FAR 52.204-21) | Annual Self-Assessment | FCI only |
| Level 2 | 110 (NIST 800-171) | Triennial C3PAO Assessment | CUI |
| Level 3 | 110+ (NIST 800-172) | Government-led Assessment | Critical CUI |
| Target |
Phase 2: Practice Assessment (Level 1 - FCI Protection)
- AC.L1-3.1.1 - Limit system access to authorized users
- AC.L1-3.1.2 - Limit system access to authorized functions/transactions
- AC.L1-3.1.20 - Verify and control connections to external systems
- AC.L1-3.1.22 - Control information posted publicly
- IA.L1-3.5.1 - Identify system users and processes
- IA.L1-3.5.2 - Authenticate users, processes, or devices
- MP.L1-3.8.3 - Sanitize or destroy media before disposal
- PE.L1-3.10.1 - Limit physical access to authorized individuals
- PE.L1-3.10.3 - Escort visitors and monitor activity
- PE.L1-3.10.4 - Maintain audit logs of physical access
- PE.L1-3.10.5 - Control and manage physical access devices
- SC.L1-3.13.1 - Monitor and protect communications at boundaries
- SC.L1-3.13.5 - Implement subnetworks for public components
- SI.L1-3.14.1 - Identify and repair information system flaws
- SI.L1-3.14.2 - Provide protection from malicious code
- SI.L1-3.14.4 - Update malicious code protection mechanisms
- SI.L1-3.14.5 - Perform system and file scans periodically
Phase 3: Practice Assessment (Level 2 - CUI Protection)
- Assess all 110 NIST SP 800-171 Rev 2 practices across 14 families
- Access Control (22 practices)
- Awareness and Training (3 practices)
- Audit and Accountability (9 practices)
- Configuration Management (9 practices)
- Identification and Authentication (11 practices)
- Incident Response (3 practices)
- Maintenance (6 practices)
- Media Protection (9 practices)
- Personnel Security (2 practices)
- Physical Protection (6 practices)
- Risk Assessment (3 practices)
- Security Assessment (4 practices)
- System and Communications Protection (16 practices)
- System and Information Integrity (7 practices)
Assessment Summary
| Family | Practices | Met | Not Met | Partially Met | N/A |
|---|---|---|---|---|---|
| Access Control | 22 | ||||
| Audit & Accountability | 9 | ||||
| Configuration Mgmt | 9 | ||||
| ID & Authentication | 11 | ||||
| SC Protection | 16 | ||||
| Other families | 43 | ||||
| Total | 110 |
Phase 4: SSP & POA&M Development
- Develop or update System Security Plan (SSP)
- Document control implementation for each practice
- Create Plan of Action & Milestones (POA&M) for gaps
- Define remediation timelines (POA&M must close within 180 days)
- Calculate SPRS score based on current implementation
SPRS Score Calculation
- Maximum score: 110
- Current score: ___ (110 minus weighted unmet practices)
- Minimum required for contract award: varies by contract
Phase 5: Remediation
- Prioritize gaps by SPRS weight and risk
- Implement technical controls (MFA, encryption, logging)
- Develop required policies and procedures
- Train personnel on CUI handling requirements
- Document evidence for each implemented practice
Phase 6: Assessment Preparation
- Prepare evidence artifacts per practice
- Conduct internal mock assessment
- Engage C3PAO for Level 2 assessment (if applicable)
- Prepare staff for assessor interviews
- Submit self-assessment to SPRS (Level 1) or schedule C3PAO visit
Counter-Rationalizations
| Shortcut | Counter | Why |
|---|---|---|
| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |
| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |
| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |
| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |
| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |
Output Format
- Scope Documentation: CUI boundary and data flow diagrams
- Practice Assessment: Status per practice with evidence references
- SPRS Score: Current calculated score with breakdown
- POA&M: Remediation plan for unmet practices
- Assessment Readiness Report: Preparation status and timeline
Action Items
- Identify and document all CUI within the organization
- Define CMMC assessment boundary
- Assess all practices for target level
- Calculate and submit SPRS score
- Develop POA&M for unmet practices
- Remediate gaps within 180-day timeline
- Schedule assessment (self or C3PAO)