CMMC Level 2 assessments fail for predictable reasons. If you're a defense contractor with CUI in scope, here's where organizations most commonly lose points — and a realistic order to work through them before a C3PAO shows up.

1. Scope isn't actually defined

The single biggest predictor of a rough assessment is an unclear CUI boundary. If "where does CUI live" doesn't have a confident, documented answer, nothing else on this list matters yet — you'll either over-scope (expensive) or under-scope (a finding).

  • Data flow diagram showing where CUI enters, moves, and is stored
  • Enclave or network segmentation isolating in-scope systems
  • Explicit list of in-scope assets, people, and external service providers

2. The System Security Plan doesn't match reality

Assessors compare your SSP against what they observe. A plan describing controls that aren't actually implemented — or that's several infrastructure changes out of date — creates credibility problems that extend beyond the specific control in question.

Treat the SSP as a living document tied to change management, not a one-time deliverable written before go-live and never touched again.

3. POA&Ms without real dates or owners

A Plan of Action & Milestones with vague target dates or no named owner reads as unmanaged risk. Every open POA&M item should have a specific remediation date, a responsible party, and evidence of progress if the assessment date is more than a few weeks out.

4. Multi-factor authentication gaps

MFA requirements under CMMC Level 2 are specific and commonly under-implemented — particularly for privileged accounts and remote access into the CUI enclave. This is one of the more common point-loss areas we see in pre-assessment gap analyses.

5. Incident response that's never been tested

A written incident response plan is necessary but not sufficient. Assessors look for evidence of testing — a tabletop exercise, a documented walkthrough — not just a policy document that's never been exercised.

6. Supply chain flow-down isn't documented

If subcontractors or cloud service providers touch CUI, you need documented evidence that DFARS 252.204-7012 requirements flow down to them — not just an assumption that they're handling it.

A realistic sequence

  1. Confirm and document your CUI boundary
  2. Run a full gap assessment against the CMMC Level 2 practices
  3. Fix scope and architecture issues first — they affect everything downstream
  4. Close control gaps in order of assessment weight, not alphabetical order
  5. Update the SSP and POA&M as you go, not at the end
  6. Run an internal mock assessment before the real one

Have a CMMC assessment date on the calendar?