Assessment Readiness

Top CMMC Level 2 Readiness Gaps Across DIB Contractors

Industry data puts DIB readiness at roughly 1%. Here are the gaps that keep showing up across small defense contractors — and what fixing them actually looks like.

Published April 7, 2026

Where Things Stand Documentation Gaps Technical Gaps Scope Gaps Process Gaps What to Do First

Where the DIB Actually Stands

Phase 2 of the CMMC rollout begins November 10, 2026. At that point, C3PAO-assessed Level 2 certification becomes the standard requirement for contracts involving Controlled Unclassified Information. Self-assessment alone is no longer sufficient. The clock is running.

Industry readiness data paints a stark picture. Survey data from 2025 put fully-prepared organizations at roughly 1% of the DIB. Fewer than half of contractors have completed foundational documentation — a System Security Plan or a POA&M. The average SPRS score across the DIB sits around 60, well below the 110 maximum that represents full implementation.

These are not numbers from organizations that haven't started. Many of these contractors have been working on CMMC compliance for a year or more. The gaps are not from inattention — they are from specific, recurring problem areas that trip up small contractors who don't have dedicated security staff and are building a compliance program for the first time.

The Real Risk Right Now
With C3PAO assessment slots filling up and a realistic 6-9 month prep runway required before assessment, contractors who have not identified and begun closing their gaps today are at risk of missing Phase 2 — not because they didn't try, but because they ran out of time. Your next contract opportunity may be your real deadline, not November 10.

Gap 1 — Documentation

Documentation is consistently the largest gap category and the most underestimated. Most contractors think documentation means writing down what they do. C3PAO assessors think documentation means evidence that what you wrote down is actually happening. Those are different things.

No SSP or an SSP that doesn't reflect reality

The System Security Plan is the primary document a C3PAO assessor reviews. It must describe your system boundary, your environment, and your implementation of all 110 requirements with specificity. Generic template SSPs — where every control says "the organization implements best practices" — do not pass assessment. Assessors probe implementation statements during interviews and test them against observed evidence. An SSP that doesn't reflect how your systems actually work generates findings even when the underlying controls are solid.

Missing or incomplete POA&M

If you have any unmet requirements at assessment time — and almost every small contractor does — you need a POA&M that documents each gap with a remediation owner, a schedule, and interim mitigations. A missing POA&M signals to assessors that you don't know where your gaps are, which is worse than having documented gaps. An honest, well-structured POA&M demonstrates program maturity. An absent one raises questions about everything else.

Policies that exist but aren't followed

Many contractors have policies — acceptable use, password, incident response, configuration management. Far fewer have evidence that those policies are being followed. Assessors will ask for training records showing employees read the acceptable use policy, change logs showing the configuration management policy is being applied, and incident response test records showing the IR policy has been exercised. A policy on paper with no evidence of execution is not a passing control.

Evidence not linked to requirements

Even contractors who have solid controls and good documentation frequently cannot produce organized evidence on assessment day. Assessors ask for specific artifacts — a screenshot showing MFA enforced on the VPN, a log entry showing an access review was completed, a signed acknowledgment from a new hire. If evidence exists but lives in email threads, shared drives, and people's heads rather than organized by requirement, assessment day becomes a scramble. Unproduced evidence is treated the same as missing evidence.

Gap 2 — Technical Controls

Technical gaps vary by environment, but certain requirements generate findings disproportionately across small contractors. These are the controls that are either commonly misconfigured, commonly misunderstood, or commonly assumed to be covered when they are not.

MFA not enforced for all three cases

IA.L2-3.5.3 requires MFA for local access to privileged accounts, network access to privileged accounts, and network access to non-privileged accounts. Most contractors have MFA on VPN and remote access. Far fewer have it enforced for local privileged login — an administrator sitting at a server console authenticating with only a password. That is a 5-point finding and one of the non-deferrable requirements that cannot go on a POA&M.

FIPS-validated encryption gaps

SC.L2-3.13.10 requires FIPS-validated cryptographic modules to protect CUI. The word "validated" is doing significant work here. Using an approved algorithm like AES-256 is not the same as using a FIPS 140-2 validated implementation. Many small contractors use encryption tools that implement strong algorithms but are not on the CMMC validated modules list. BitLocker is FIPS-validated when properly configured. Many third-party encryption tools are not, even when they use the same underlying algorithms.

Audit logging not comprehensive

AU.L2-3.3.1 requires logging of a specific set of events: logons and logoffs, account management, object access for CUI, policy changes, privilege use, and system events. Most small contractors have Windows Event logging enabled, but default configurations do not capture everything required. Object access auditing for CUI files is rarely enabled. Assessors will review your audit policy configuration and verify that required event types are being captured and retained.

Vulnerability scanning not documented or acted on

RA.L2-3.11.2 requires periodic scanning for vulnerabilities in systems and applications. Running a scan satisfies the scanning requirement. Documenting the results, triaging findings, and showing a remediation process satisfies the full control. Many contractors run scans — far fewer have a documented process for what happens with the results. Assessors want to see scan reports, triage decisions, and evidence that critical findings are remediated within a defined timeframe.

Configuration baselines not documented

CM.L2-3.4.1 requires established and maintained baseline configurations for all in-scope systems. This means a documented standard configuration for each system type — what software is installed, what services are running, what ports are open, what security settings are applied. Most small contractors configure systems consistently but have never written down what "configured correctly" means. Without a documented baseline, you cannot demonstrate that your systems conform to it or that changes from it are controlled.

Gap 3 — Scoping

Scoping errors are among the most consequential gaps because they affect the entire compliance program. A wrong boundary means wrong controls, wrong documentation, and potentially wrong results at assessment time.

CUI in systems not included in scope

The dangerous scoping error. A contractor draws their CUI boundary around their engineering workstations and file server, but CUI is also flowing through their Microsoft 365 environment, their project management tool, or a shared drive that wasn't considered. When an assessor finds CUI in a system that isn't documented in the SSP boundary, they have found a gap that wasn't controlled — because nobody knew to control it. This is a finding that can fail an assessment.

Cloud services not addressed

Small contractors frequently underestimate how many cloud services touch CUI. Microsoft 365, SharePoint, OneDrive, Teams, Dropbox, Google Drive — if CUI exists in any of these, they are in scope. Cloud services that process or store CUI must be FedRAMP Moderate authorized or equivalent. Many small contractors are using commercial Microsoft 365 plans rather than GCC High, which does not meet this requirement for CUI. Finding this during an assessment rather than before it is an expensive problem.

The MSSP is in scope but not documented

If your managed service provider has administrative access to in-scope systems — through an RMM agent, remote desktop, or a monitoring tool — they are part of your environment. Their access must be documented in your SSP, controlled through your access management processes, and their CMMC posture considered. An undocumented MSSP with privileged access to every in-scope endpoint is a finding waiting to happen.

Gap 4 — Operational Processes

Technical controls and documentation can both be solid while operational processes remain gaps. These are the compliance disciplines that require ongoing execution rather than one-time implementation.

No annual access review

AC.L2-3.1.1 requires that access to CUI systems is limited to authorized users. Most contractors set up access controls correctly at the start. Far fewer conduct formal periodic reviews to verify that access is still appropriate. Employees who changed roles, contractors who finished their engagement, accounts that should have been disabled — these accumulate over time. Assessors will ask for evidence of your last access review and what you found. "We haven't done one" is not an acceptable answer.

Security awareness training with no completion records

AT.L2-3.2.1 requires that personnel are aware of security risks. AT.L2-3.2.2 requires that they are trained to carry out their responsibilities. Most small contractors do some form of security awareness. Very few have verifiable completion records that show who was trained, on what, and when. Assessors need to see records — not a description of training that happens. Training that cannot be evidenced is training that did not happen from an assessment standpoint.

Incident response plan never tested

IR.L2-3.6.3 requires that you test your incident response capability. Having an IR plan is not sufficient — you must have tested it. A tabletop exercise, a simulated incident walkthrough, or a formal drill all satisfy this requirement. Most small contractors write an IR plan and never revisit it. Assessors will ask when it was last tested and what the results were. "We haven't tested it" is a finding under 3.6.3.

SPRS score not submitted or not current

Since November 10, 2025, annual self-assessment and senior official affirmation in SPRS has been required. Contractors whose SPRS score is stale, was never submitted, or does not reflect their current posture are out of compliance with Phase 1 requirements today — before Phase 2 even begins. Annual affirmation is not optional and does not require a new full assessment; it requires a review and a signed attestation that the information remains accurate.

What to Do First

If you recognize your organization in the gaps above, the priority order matters. Not all gaps carry equal weight and not all are fixable in the same timeframe.

Priority Action Why First
1 Run a gap assessment against all 110 requirements You cannot close gaps you haven't identified. This is the starting point for everything else.
2 Address non-POA&M-eligible requirements immediately 5-point requirements — including MFA (IA.L2-3.5.3) — cannot be deferred. They must be fully implemented before assessment.
3 Build or update your SSP with specific implementation statements The SSP drives the entire assessment. Generic language fails. Every control needs a specific, verifiable description.
4 Open POA&M items for everything not yet fully implemented An honest POA&M with realistic timelines is better than pretending gaps don't exist. It also demonstrates program maturity to assessors.
5 Organize evidence by requirement Controls with no producible evidence fail assessment the same as controls not implemented. Evidence must be findable on demand.
6 Book your C3PAO assessment slot Assessor capacity is tightening. You can book a slot while still remediating. Waiting until you feel "ready" may mean no slots are available.

The contractors who make it through Phase 2 in good shape are not the ones who started with the best security posture. They are the ones who identified their gaps earliest, built a credible remediation plan, and executed against it systematically. That process starts with knowing exactly where you stand.

Engineered for the DIB.

1TEN tracks your control implementation, calculates your live SPRS score, and organizes your evidence package. On-premises, air-gapped.

Request a Demo