APTSecurity Management

What Happens After Your CMMC Gap Assessment

Cody D. Martin//Updated August 9, 2026

After a gap assessment you have a scored result and a remediation list. The work that follows is sequencing by SPRS point value and business impact, closing high value practices first, documenting as you go, and keeping the SSP current rather than writing it once at the end.

The assessment is the easy part. You now have a score, a list of gaps, and a quantity of work that is usually larger than expected.

What separates companies that get there from companies that stall is sequencing.

Sequence by point value, not by ease

The SPRS model weights requirements at 5, 3 or 1 points. Closing five one point items feels productive and moves your score by five. Closing one five point item moves it by five for a fifth of the paperwork.

Work the five point items first. They cluster predictably:

  • Multifactor authentication for privileged and remote access
  • Boundary protection and network segmentation
  • Flaw remediation, meaning a patching process you actually meet
  • Audit logging that is collected, retained and reviewed
  • Media protection including encryption at rest

There is a second consideration that occasionally overrides this. Some low point items are trivially cheap, and clearing them in the first week is worth it purely for the momentum.

A realistic twelve month shape

Months one to two. Quick wins and foundations. Individual accounts, remove standing local administrator, MFA where it is straightforward, asset inventory. Start the SSP now rather than at the end.

Months three to six. The expensive items. Segmentation, logging infrastructure, encryption, formal patching. This is where budget gets spent and where projects stall if nobody owns them.

Months six to nine. Documentation and process. Policies that describe what you actually do. Access reviews running on a schedule. Incident response that has been tested rather than written.

Months nine to twelve. Verification, evidence collection, SSP finalisation, POA&M cleanup, and a re score.

Compressing this below six months is possible and usually means buying tools instead of building process, which shows up later.

Write the SSP as you go

The most common mistake is treating the SSP as a deliverable to produce at the end.

Written at the end, it is a documentation exercise performed from memory about changes made eight months earlier. Written as you go, it is a record of decisions made while the reasoning is fresh, and the person who made the change is the one describing it.

Keep the POA&M honest

Every item needs a named person, a real date, and a specific remediation. Not a department, not “ongoing”, not “implement controls”.

Dates will slip. Move them deliberately and record why. A POA&M with three date changes and a reason for each reads as a functioning program. One with the same item silently repushed for two years does not.

What the suspension means for the roadmap

CMMC Phase 2 was suspended in July 2026, pausing third party assessment. That removes an external deadline, which is precisely the risk.

The obligations under DFARS 252.204-7012 did not change. You still self assess, still maintain the SSP and POA&M, still post an SPRS score, and still affirm annually with a company official’s signature on it.

The roadmap above is unchanged. What changed is that nobody is coming to check, which makes it easier to let slide, and the annual affirmation is what makes letting it slide a problem with a name attached.

When to bring help in

Bring someone in for the scoping and the SSP structure, because both are expensive to correct later. Do the remediation yourself where you have the skills, since you will be maintaining it.

Be wary of anyone who wants to own your SSP permanently. A plan you cannot maintain without a consultant is a plan that goes stale the moment the engagement ends.

  • CMMC
  • POA&M
  • SSP
  • remediation
  • SPRS

More on compliance