Skip to main content
GuidesBy Jason LeeAugust 28, 202612 min read

CMMC Readiness Assessment: What It Covers and What It Produces

CMMC Readiness Assessment: What It Covers and What It Produces

The direct answer: a CMMC readiness assessment is a private, advisory evaluation of your environment against the 110 security requirements of NIST SP 800-171 Revision 2 and the scoping rules in 32 CFR Part 170, performed before any official assessment. It is for any supplier receiving federal contract information or controlled unclassified information, which reaches far past the primes into machine shops, board houses, and logistics providers. It produces four things: a defensible assessment boundary, a scored gap analysis tied to evidence, a system security plan that reflects reality, and a plan of action with owners and dates. It is not a certification. Only an authorized CMMC Third-Party Assessment Organization performs a certification assessment. Z Cyber is not a C3PAO and cannot certify, attest to, or sign for your CMMC status.

Status verified August 28, 2026. This page is updated when the regulatory status changes.

Readiness assessment or certification assessment

These are different products with different legal weight, and conflating them is the most expensive mistake a small supplier makes when buying help. A readiness assessment is consulting. It carries no official status. A certification assessment is performed by an authorized C3PAO under 32 CFR 170.9, which binds those organizations to the Accreditation Body conflict of interest, professional conduct, and ethics policies. The practical effect is that the firm which prepares you generally cannot be the firm that certifies you. Ask any vendor which side of that line they sit on. We are on the advisory side.

Dimension Readiness assessment C3PAO certification assessment
Who performs itAny advisor or internal teamOnly an authorized C3PAO
Official statusNone. Internal work product.Produces a CMMC status of record
Findings areRecommendations you may act onDeterminations you cannot negotiate
Same firm for bothBarred by the conflict of interest rulesNot for a client it advised
Status todayAvailable nowPhase 2 escalation suspended July 13, 2026

Scoping comes first, and it decides everything downstream

Two determinations set the shape of the engagement. The first is data type. Federal contract information is non-public information generated for or provided under a contract, and the basic safeguarding obligations attach through FAR 52.204-21. Controlled unclassified information is the escalation: controlled technical drawings, engineering specifications, export-controlled data. FCI-only work sits at Level 1. CUI puts you at Level 2 against all 110 requirements.

The second is asset categorization. 32 CFR 170.19 sorts your environment into CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out-of-scope assets, each carrying different documentation and assessment treatment. This is where a readiness assessment earns most of its money. Companies that let CUI spread across general IT end up assessing their whole company. Companies that enclave it assess a bounded environment. Enclaving can break engineering workflows, so make that choice deliberately with both costs on the table.

What the assessment actually covers

After scoping, the work walks all fourteen NIST SP 800-171 Revision 2 families. Rev 2, not Rev 3: the May 2024 class deviation still pins DFARS compliance and scoring to Revision 2, so nobody should be rebuilding an SSP against Rev 3 today.

Requirement family What gets tested
Access ControlWho can reach CUI, least privilege, remote access, session and mobile device controls
Awareness and TrainingRole-based training records, insider threat awareness, evidence of delivery
Audit and AccountabilityWhat is logged, retention, and whether anyone reviews the logs
Configuration ManagementBaselines, change control, least functionality, software allowlisting
Identification and AuthenticationMultifactor coverage, unique identifiers, shared account cleanup
Incident ResponseDocumented plan, tested response, and the 72-hour DIBNet reporting path under DFARS 7012
MaintenanceMaintenance tools, remote sessions, third-party technicians
Media ProtectionMarking, transport, sanitization, removable media, encryption at rest
Personnel SecurityScreening before CUI access, removal on termination or transfer
Physical ProtectionFacility access, visitor logs, escorts, plant floor and shipping exposure
Risk AssessmentRisk assessment cadence, vulnerability scanning, remediation of what it finds
Security AssessmentThe SSP, plans of action, and whether controls are monitored or assumed
System and Communications ProtectionBoundary defense, network separation, FIPS validated cryptography for CUI
System and Information IntegrityFlaw remediation timelines, malicious code protection, monitoring and alerting

Two families produce the ugliest findings in small manufacturers. Identification and authentication, because multifactor coverage on legacy engineering workstations and shop floor systems is genuinely hard. And system and communications protection, because FIPS validated cryptography is a specific claim most IT stacks cannot substantiate on demand.

What triggers a readiness assessment

Five events account for nearly all of them. A prime sends a flow-down letter demanding a current SPRS score, an affirmation, or a certification commitment by a date. A new solicitation carries DFARS 252.204-7021 and you have never scoped your CUI. Your posted score is stale or was calculated by someone who has since left. Your Affirming Official is asked to sign and does not know what they are attesting to. Or an acquirer or insurer runs diligence and asks for the evidence behind your published number.

The Phase 2 suspension changed none of these triggers, because it froze the escalation to third-party certification while leaving Phase 1 intact. The detail is on our Phase 2 suspension status page. Primes have kept writing certification terms into subcontracts regardless of what the government paused.

Not sure whether your posted score would survive scrutiny?

An advisor can walk your scope, test the requirements you have marked implemented against actual evidence, and brief the executive who signs before the next affirmation is due.

Talk to an Advisor →

What you get out of it

Five deliverables, described honestly. First, a documented assessment boundary: which systems, people, facilities, and cloud services are in scope, sorted into the categories at 170.19, with the reasoning written down so it survives a personnel change. Second, a requirement-by-requirement gap analysis naming the evidence behind each implemented finding and the missing artifact behind each one that is not.

Third, a score calculated under the published DoD Assessment Methodology, which is worth reading before you buy anything. It starts you at 110 and subtracts 5, 3, or 1 point per unimplemented requirement depending on impact, which is why a score can fall well below zero. It also states two things people get wrong: a plan of action is not a substitute, so a requirement 75 percent rolled out still scores as not implemented, and the absence of a system security plan means the assessment cannot be completed at all.

Fourth, a system security plan that describes the environment as it exists rather than as you intend it. Fifth, a plan of action with a named owner and a real closure date per gap. Note that 32 CFR 170.21 constrains what may sit on a POA&M at Level 2 and imposes a closeout window, so treating the POA&M as an indefinite parking lot is not a strategy.

What you do not get: a certification, an attestation, or anyone else carrying your risk. The advisor scopes, tests, scores, documents, and briefs. Your executives decide what to remediate, and your named Affirming Official signs the affirmation under 32 CFR 170.22. That is a company role and no vendor can hold it or sign for it. Our page on SPRS self-assessments and annual affirmations covers the exposure attached to that signature.

How it maps to the frameworks that matter

NIST SP 800-171 Rev 2 supplies the controls. CMMC supplies the verification method and the levels. Our comparison of NIST 800-171 and CMMC separates them cleanly. The DFARS clauses are the contractual mechanism: 7012 for safeguarding and 72-hour incident reporting, 7019 for having a current score posted to be eligible for award, 7020 for maintaining that posting, granting government access for a Medium or High assessment, and flowing the requirement to subcontractors, and 7021 for meeting the CMMC level in the contract.

Worth knowing before you buy: SPRS does not host the assessment. It stores the result, including the assessment date, score, scope, plan of action completion date, CAGE codes, SSP name and version, and confidence level. Your readiness assessment generates every one of those fields. The same evidence usually carries into a NIST RMF program or a broader compliance effort, which argues for collecting it once in a system of record rather than four times in spreadsheets.

Timeline, phases, and what you have to supply

We do not publish a duration, because a duration quoted before scoping is a sales number. The work runs in four dependent phases. Scoping and data determination, which cannot start until your prime confirms in writing which data category you receive. Evidence collection and control testing, which moves at the speed your team produces artifacts. Scoring and documentation. Then the briefing to the executives who decide what to fund and who will affirm.

What you supply drives the calendar more than anything the advisor does. Expect to provide the written data determination from your prime, a current network diagram and asset inventory, identity and access configuration, endpoint and logging detail, your existing SSP and POA&M in whatever state they are in, cloud and managed service provider contracts including FedRAMP status claims, training records, and access to the people who run the systems. The biggest schedule risk is a prime that will not put the data category in writing, because everything else waits on it.

Which assessment do you actually need

If you handle CUI and need a defensible SPRS score and affirmation, this is the assessment. If you only handle FCI, you need a narrower Level 1 scope, and our Level 2 self-assessment guide will tell you whether you drew the line correctly. If your problem is program maturity rather than CUI, a NIST CSF maturity assessment answers a different question and satisfies no DFARS clause. If controls exist on paper but nobody has proven they work, that is a controls effectiveness assessment. And if you need a certification of record, you need an authorized C3PAO, which we are not, and which we will help you scope for rather than pretend to be. Our defense and government practice describes how the program runs after the assessment ends.

What to watch next

On or about September 13, 2026: the CMMC Reform Task Force report is due to the Department of War chief information officer, following a request for information that closed August 14, 2026. A report is a recommendation, not a rule.

Mid-October 2026 at the earliest: formal determinations, with real potential to slip into 2027, since a structural change would require new rulemaking. Every scenario under public discussion keeps self-assessment, scoring, and executive attestation, which is why readiness work holds its value under all of them. Separately, NIST SP 800-171 Revision 3 is still not adopted into the DFARS, so Rev 2 remains the assessment baseline until a final rule says otherwise. We update this page when either moves.

Frequently Asked Questions

What is a CMMC readiness assessment?

A CMMC readiness assessment is a private, advisory evaluation of your environment against the 110 security requirements of NIST SP 800-171 Revision 2 and the scoping rules in 32 CFR Part 170. It establishes your assessment boundary, tests each requirement against evidence, produces a scored gap analysis, and reconciles your system security plan and plan of action to what is actually implemented. It is preparation, not certification.

What is the difference between a CMMC readiness assessment and a C3PAO assessment?

A readiness assessment is advisory work that anyone can perform for you and that carries no official status. A certification assessment can only be performed by an authorized CMMC Third-Party Assessment Organization, and under 32 CFR 170.9 that organization must follow the Accreditation Body conflict of interest rules, which means the firm that prepared you generally cannot be the firm that assesses you. Z Cyber is not a C3PAO and cannot certify or attest to your CMMC status.

What does a CMMC readiness assessment cover?

Scope first, then controls. Scoping determines whether you handle federal contract information, controlled unclassified information, or both, and sorts your systems into the asset categories defined in 32 CFR 170.19. The control work then walks all fourteen NIST SP 800-171 families, from access control and configuration management through incident response, media protection, and system and communications protection, testing each requirement against evidence rather than assertion.

How long does a CMMC readiness assessment take?

It depends on scope, and any firm quoting a duration before scoping your environment is guessing. The variables that drive the timeline are how many systems touch controlled unclassified information, whether your CUI environment is enclaved or spread across general IT, how complete your existing system security plan is, and how quickly your team can produce evidence. Scoping decisions made early are what compress or extend everything downstream.

Do I still need a CMMC readiness assessment during the Phase 2 suspension?

The case for one did not weaken. The July 13, 2026 suspension froze the escalation to third-party certification, not Phase 1. Level 1 and Level 2 self-assessments, SPRS score posting under DFARS 252.204-7020, and the annual affirmation by your named Affirming Official all remain mandatory, and primes are still writing certification requirements into subcontracts. A readiness assessment is what makes the score you post defensible.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.