A CMMC readiness assessment should answer three questions:
- What requirement and assessment path apply to us?
- What is true about our current implementation and evidence?
- What must we change, in what order, before the required assessment or affirmation?
If the engagement produces only a generic score and a long spreadsheet of gaps, it has not finished the job. A useful CMMC readiness assessment connects contractual requirements, CUI scope, implementation, evidence, remediation, ownership, and business decisions.
This checklist is designed for small and midsize defense contractors evaluating a CMMC gap assessment, preparing for CMMC Level 2, or trying to determine what kind of help they need.
Before the assessment: clarify why you are doing it
Start with the trigger, not the control list.
Gather the contracts, solicitations, prime-contractor communications, and flowdowns that are driving the request. Record the relevant clauses and any stated CMMC level or assessment type. If the requirement is not clear, make clarification an explicit task rather than building a program around an assumption.
The assessment team should also identify who can answer questions about contracts, CUI, business processes, IT administration, security operations, facilities, and outside providers.
Your preparation checklist should include:
- relevant contracts, solicitations, and security clauses;
- existing SPRS and NIST SP 800-171 assessment information;
- known CUI types and business owners;
- network and system diagrams;
- data-flow diagrams, if available;
- asset, user, and provider inventories;
- current SSP, policies, and procedures;
- recent risk, vulnerability, and security-assessment results; and
- a list of people who can demonstrate how safeguards operate.
Do not delay the entire review because every artifact is not yet perfect. Missing or unreliable artifacts are themselves useful readiness findings.
Step 1: determine the assessment path
CMMC is implemented through defined levels and assessment types. The applicable obligation depends on the relevant contract or solicitation and the information the organization handles.
The readiness assessment should document:
- whether the organization handles Federal Contract Information, CUI, or both;
- the CMMC level stated or expected for the opportunity;
- whether the expected path is a self-assessment, C3PAO assessment, or government assessment;
- which legal entity and business unit are in scope; and
- which unresolved contract questions need written clarification.
Avoid universal statements such as “every defense contractor needs Level 2.” The requirement must be tied to the contractor's work and the applicable acquisition documents.
Step 2: trace CUI and define the assessment boundary
CUI scoping is often the highest-leverage part of readiness. A narrow but accurate boundary can reduce unnecessary complexity. A boundary that excludes real dependencies can create a serious assessment problem.
The readiness team should trace how CUI is:
- received or created;
- viewed and edited;
- stored and backed up;
- transmitted internally and externally;
- accessed remotely;
- printed or handled physically;
- shared with subcontractors and service providers; and
- retained or destroyed.
The review should identify CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and out-of-scope assets as applicable. It should also document why each category assignment is supportable.
Ask for a boundary narrative and data-flow view that an executive, technical administrator, and assessor can all understand.
Step 3: identify external service providers and shared responsibilities
Small businesses rarely operate every safeguard themselves. Cloud platforms, MSPs, managed security providers, backup services, identity providers, email platforms, and other external service providers may affect the CUI environment or protect it.
For each provider, determine:
- what service it performs;
- whether it stores, processes, or transmits CUI;
- whether it provides a security protection function;
- which requirements it supports;
- what contract or agreement governs the service;
- what evidence it must provide; and
- what remains the contractor's responsibility.
A product name or provider logo is not evidence that a requirement is satisfied. Readiness depends on the actual configuration, responsibilities, and retained proof.
Step 4: assess implementation against the applicable requirements
For a CMMC Level 2 readiness assessment, the review should examine how the organization implements the applicable NIST SP 800-171 requirements used by the CMMC program.
The interviewer should ask people to explain and, where appropriate, demonstrate the process. Useful evidence may include configurations, tickets, logs, access reviews, training records, contracts, screenshots, exports, reports, meeting records, and other artifacts that show the safeguard operates.
Each requirement should have a clear readiness conclusion, such as:
- implemented with sufficient evidence;
- implemented but evidence needs improvement;
- partially implemented;
- not implemented;
- not applicable, with a defensible rationale; or
- unresolved pending validation.
The exact labels may vary. The important point is to avoid hiding uncertainty inside a simple percentage.
Step 5: test whether the SSP matches reality
The System Security Plan should describe the current environment and how the requirements are implemented. It should not be a future-state marketing document.
Compare the SSP against:
- actual system architecture;
- current technologies and providers;
- administrative practices;
- written procedures;
- observed demonstrations; and
- evidence retained by control owners.
When the document and the environment disagree, decide whether the implementation, the documentation, or both must change.
This is one of the most valuable distinctions a readiness assessment can make. A documentation correction and a technical remediation should not enter the plan as if they were the same work.
Step 6: evaluate the evidence—not just the control statement
Evidence should be relevant, attributable, current enough for its purpose, and consistent with the SSP. A screenshot without context may show that a setting existed once. It may not show who owned it, which systems it covered, or whether the process continues to operate.
For each evidence item, ask:
- What requirement or assessment objective does this support?
- What system, group, or process does it cover?
- Who produced or approved it?
- When was it generated?
- Can the organization reproduce it?
- Does it agree with the SSP and other evidence?
Good evidence management reduces last-minute searching and reveals control drift before an assessor does.
Step 7: add the external attacker view
The formal readiness review is primarily inside-out. A threat-informed layer can help decide what to validate first.
A passive CMMC Cyber Snapshot may surface public-facing services, credential exposure records, email-security signals, technology associations, subdomains, or vulnerability context. Those observations cannot independently determine whether a CMMC requirement is met. They can reveal questions the internal assessment should resolve.
For example:
- Does an externally visible service appear in the asset inventory?
- Is the inferred technology and version accurate?
- Is a corporate credential record current, relevant, or already remediated?
- Does a remote-access path affect the proposed CUI boundary?
- Do email-trust settings match the documented security design?
HostBreach uses its proprietary Cyber Intel Engine to provide this passive context. We do not use an outside-in observation as proof of compromise, exploitability, or noncompliance.
Step 8: build a prioritized remediation plan
The plan should be more useful than “close all gaps.”
For every remediation item, record:
- the affected requirement and system;
- the business and security consequence;
- the required decision or change;
- dependencies;
- accountable owner;
- target date;
- expected evidence; and
- how completion will be verified.
Sequence work based on scope, assessment impact, exposure, dependency, and effort. Some decisions—such as changing the CUI architecture or replacing a provider—can affect dozens of downstream tasks and should be resolved early.
Where POA&Ms are used, confirm that the treatment is permitted under the applicable CMMC rules and contract context. Do not assume every gap can remain open until after an assessment.
Step 9: brief leadership on decisions, not just findings
Executives need to understand:
- the requirement and business opportunity at stake;
- the proposed boundary;
- the most consequential gaps;
- major architecture or provider decisions;
- estimated work, dependencies, and internal capacity;
- risks that require acceptance or escalation; and
- who will affirm the organization's status when required.
The briefing should distinguish verified facts, assumptions, and open questions. That clarity is more valuable than a falsely precise readiness score.
Step 10: define what “ready” means
Readiness should have an exit criterion.
Before moving to the next stage, confirm that:
- the contractual requirement and assessment path are understood;
- the CUI boundary is documented and supportable;
- applicable requirements have been evaluated;
- gaps have owners and an executable remediation path;
- the SSP reflects the current environment;
- required evidence can be produced and explained;
- providers understand their responsibilities;
- leadership understands unresolved risk; and
- the organization has a plan to maintain the implementation after the assessment.
A mock-assessment-style review can test those conditions, but it is still not an official certification assessment.
How much does a CMMC readiness assessment cost?
There is no defensible universal price. Cost is usually driven by the CMMC level and assessment path, CUI boundary, number of sites and users, provider model, existing documentation, technical complexity, evidence quality, and the amount of remediation or implementation support included.
When comparing proposals, ask every provider to state:
- assumptions about scope;
- included interviews and technical validation;
- named deliverables;
- remediation support included or excluded;
- travel and third-party costs;
- change-control terms if the boundary expands; and
- what work remains before an official assessment.
A low-cost gap scan and a principal-led readiness engagement may both be legitimate offerings. They are not equivalent products.
What a useful final package should include
Depending on the scope of work, the final package should give you a defensible combination of:
- requirement and assessment-path summary;
- CUI scope and data-flow findings;
- asset and provider responsibility analysis;
- requirement-level readiness results;
- evidence-quality findings;
- SSP corrections or development plan;
- prioritized remediation roadmap;
- leadership decision log; and
- next-step recommendation.
The work should make the next decision easier: remediate internally, engage technical support, refine the boundary, continue evidence development, or prepare for the appropriate assessment path.
Why consider HostBreach for CMMC readiness
HostBreach was ranked first in The Tech National's 2025 roundup of ten CMMC compliance companies, based on the publication's stated review of experience, service range, and value for organizations of different sizes.
That recognition is not a government endorsement or certification. It is independent editorial recognition of an approach built for organizations that need practical, senior-level help.
HostBreach Threat-Informed CMMC Advisory supports requirement clarification, CUI scoping, NIST SP 800-171 gap analysis, SSP and evidence development, remediation planning, and pre-assessment preparation. HostBreach provides advisory and readiness services; it is not a C3PAO and does not perform certification assessments.
Talk with Franco Velasquez about your CMMC readiness path.
