CMMC Level 2 Readiness: What to Fix Before Your Assessment
CMMC Level 2 assessments fail for predictable reasons. If you're a defense contractor with CUI in scope, here's where organizations most commonly lose points — and a realistic order to work through them before a C3PAO shows up.
1. Scope isn't actually defined
The single biggest predictor of a rough assessment is an unclear CUI boundary. If "where does CUI live" doesn't have a confident, documented answer, nothing else on this list matters yet — you'll either over-scope (expensive) or under-scope (a finding).
- Data flow diagram showing where CUI enters, moves, and is stored
- Enclave or network segmentation isolating in-scope systems
- Explicit list of in-scope assets, people, and external service providers
2. The System Security Plan doesn't match reality
Assessors compare your SSP against what they observe. A plan describing controls that aren't actually implemented — or that's several infrastructure changes out of date — creates credibility problems that extend beyond the specific control in question.
3. POA&Ms without real dates or owners
A Plan of Action & Milestones with vague target dates or no named owner reads as unmanaged risk. Every open POA&M item should have a specific remediation date, a responsible party, and evidence of progress if the assessment date is more than a few weeks out.
4. Multi-factor authentication gaps
MFA requirements under CMMC Level 2 are specific and commonly under-implemented — particularly for privileged accounts and remote access into the CUI enclave. This is one of the more common point-loss areas we see in pre-assessment gap analyses.
5. Incident response that's never been tested
A written incident response plan is necessary but not sufficient. Assessors look for evidence of testing — a tabletop exercise, a documented walkthrough — not just a policy document that's never been exercised.
6. Supply chain flow-down isn't documented
If subcontractors or cloud service providers touch CUI, you need documented evidence that DFARS 252.204-7012 requirements flow down to them — not just an assumption that they're handling it.
A realistic sequence
- Confirm and document your CUI boundary
- Run a full gap assessment against the CMMC Level 2 practices
- Fix scope and architecture issues first — they affect everything downstream
- Close control gaps in order of assessment weight, not alphabetical order
- Update the SSP and POA&M as you go, not at the end
- Run an internal mock assessment before the real one