1. Scope & CUI Definition (This Is the #1 Failure Point)
-
How have you formally defined and documented CUI within your organization?
-
Do you have documented CUI data flow diagrams?
-
Can you clearly demonstrate where CUI enters, lives, and exits your environment?
-
Is your CMMC scope boundary documented and approved by leadership?
If they struggle here, everything else collapses.
2. System Security Plan (SSP) Reality Check
-
Do you have a fully completed SSP mapped to all 110 Controls AND 320 Control Objectives?
-
When was it last updated?
-
Is the SSP reflective of your current environment, or based on a template?
-
Can you show objective evidence for at least 10 randomly selected controls?
This exposes template compliance vs real compliance.
3. Evidence & Repeatability
-
What objective evidence do you maintain for control performance?
-
How long is log data retained?
-
Can you demonstrate enforcement of least privilege?
-
How do you document control reviews and approvals?
Most IT people “do” things but don’t document them in audit-ready format.
4. Governance & Ownership
-
Who outside IT owns cybersecurity risk?
-
Does leadership review cybersecurity metrics quarterly?
-
Is there documented risk acceptance from leadership?
-
Is cybersecurity included in business planning discussions?
CMMC Level 2 is not IT compliance. It is organizational compliance.
5. POA&M & Gap Management
-
Do you maintain a formal POA&M?
-
Are remediation timelines tracked and approved?
-
Who approves risk exceptions?
If there is no disciplined POA&M process, the audit will be painful.
6. Access Control & Privileged Accounts
-
How do you enforce MFA for privileged access?
-
How often are privileged accounts reviewed?
-
Can you demonstrate account review documentation?
-
Are service accounts documented and controlled?
This is a common assessor deep dive.
7. Configuration & Change Management
-
Is there a documented baseline configuration for workstations and servers?
-
How are changes approved and logged?
-
Can you show change records from the past 90 days?
Most small shops fail here because change management is informal.
8. Incident Response & Testing
-
When was your last tabletop exercise?
-
Were findings documented and remediated?
-
Can you show evidence of IR training for staff?
Tabletop without documentation equals no tabletop.
9. Vendor & External Service Providers
-
Have you documented all External Service Providers?
-
Do you have flow-down clauses in contracts?
-
How do you validate their CMMC alignment?
Huge blind spot for solo IT teams.




