With the CMMC Program rule (32 CFR Part 170) in effect and the DFARS 252.204-7021 clause phasing into contracts, defense suppliers no longer have the option of a self-attested SPRS score and a good-faith plan. If you handle Controlled Unclassified Information, a Level 2 assessment by a Certified Third-Party Assessment Organization (C3PAO) is coming. Here are the five moves that de-risk the path — in the order that actually saves money.
1. Draw the boundary before you buy anything
The single most expensive mistake in CMMC is assessing the whole company. The CMMC Level 2 Scoping Guide defines five asset categories — CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets — and only the first four are in the assessment. Your job is to make the in-scope set as small as your business allows.
Practically, that means tracing CUI end to end: where it arrives (prime's portal, encrypted email, DoD SAFE), where it is stored (file server, engineering PDM, GCC High SharePoint), who touches it (engineering, quality, contracts), and where it leaves (deliverables, subcontractor flow-down). Document the flow, then decide whether you can enclave it. A 40-person CUI enclave inside a 400-person company is a fundamentally different — and cheaper — assessment than the alternative.
2. Get an honest SPRS score, not a hopeful one
The DoD Assessment Methodology scores NIST SP 800-171 from a maximum of 110, subtracting 1, 3 or 5 points per unimplemented requirement. Most self-assessed scores we review are 20 to 40 points too high, usually because "we have a policy" was counted as "implemented." The assessor will test all 320 objectives in NIST SP 800-171A through examination, interview, and test. Score yourself the same way now, objective by objective, and you will know your real position. Under the rule, knowingly misrepresenting your score is a False Claims Act exposure, not a paperwork problem.
3. Close the 5-point requirements first
Because of the weighting, remediation order matters. The 5-point requirements include multifactor authentication for network and privileged access (3.5.3), FIPS-validated cryptography for CUI at rest and in transit (3.13.11), security-relevant event logging (3.3.1), and vulnerability scanning and remediation (3.11.2, 3.11.3), among others. These are also the requirements that a conditional certification cannot leave open on a POA&M. Sequence the roadmap so your score rises fastest and your POA&M stays inside what 32 CFR 170.21 permits: a minimum score, no open high-weight items with narrow exceptions, and full closure within 180 days.
4. Write the SSP the assessor wants to read
The System Security Plan is the single most-read document in the assessment and the most often wrong. A good SSP describes the boundary and the asset categories, then, for each of the 14 control families, explains how each requirement is implemented in your specific environment — "Conditional Access policy CA-03 enforces MFA for all users accessing the CUI enclave; break-glass accounts are excluded and reviewed monthly" — not a restatement of the requirement. Back each narrative with a named artifact. Pair the SSP with the policies and procedures the assessor will ask to see: access control, configuration management, incident response, media protection, and so on.
5. Build the evidence library and rehearse
Assessors do not accept "we can show you that." Organize evidence by requirement and objective: screenshots with dates, exported configurations, logs, training records, signed policies. Then run a mock assessment. Interview your own administrators the way a C3PAO will, observe the control operating, and note where the answer was uncertain. In our experience the mock assessment surfaces 10 to 20 gaps that the paper review missed — nearly always in the interview and observation components.
What about Level 1?
If you only handle Federal Contract Information and never CUI, you are in Level 1 territory: the 15 requirements of FAR 52.204-21 and an annual self-assessment. Confirm this with your contracts team and your prime before you assume it. Misclassifying CUI as FCI is a common and costly error.
The order matters
Scope, score, sequence, document, rehearse. Organizations that start with a technology purchase — a new firewall, a GCC High migration — before they have drawn the boundary routinely spend more and finish later. Organizations that start with scope typically reach "likely to pass" in six to nine months on a reasonable budget, and the SSP and evidence library they build become the operating manual for staying compliant afterward.
References
- Department of Defense. (2024). Cybersecurity Maturity Model Certification (CMMC) Program, 32 CFR Part 170. Federal Register.
- National Institute of Standards and Technology. (2020). Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (NIST SP 800-171 Rev. 2). https://doi.org/10.6028/NIST.SP.800-171r2
- National Institute of Standards and Technology. (2018). Assessing Security Requirements for Controlled Unclassified Information (NIST SP 800-171A). https://doi.org/10.6028/NIST.SP.800-171A
- Department of Defense. (2024). CMMC Assessment Scope — Level 2 and CMMC Assessment Guide — Level 2. Office of the DoD Chief Information Officer.