What to Expect From a CMMC Gap Assessment
Cody D. Martin//Updated August 9, 2026
A CMMC gap assessment establishes your boundary, evaluates each applicable practice against what you actually do, and produces a scored result with a prioritized remediation plan. Expect two to six weeks depending on size, and expect the scoping work to take longer than you think.
A gap assessment tells you where you stand against the requirements and what it would take to close the distance. It is the sensible first purchase, because every other decision depends on knowing the answer.
What happens, in order
Scoping. The first and most important phase. Which systems handle FCI, which handle CUI, and where the boundary sits. Expect this to take longer than you expect and to surface things nobody had documented.
Discovery. Interviews with the people who actually run things, review of existing documentation, and inspection of configuration. Not a scan. A scanner cannot tell you whether quarterly access reviews happen.
Evaluation. Each applicable practice assessed against what you actually do, using the assessment objectives in NIST SP 800-171A rather than the one line requirement. A single requirement often decomposes into four or five objectives.
Scoring. An SPRS score you can defend, with the working shown.
Reporting and prioritization. What is missing, what it costs to fix, and what order to do it in.
What you need to have ready
You will move faster if you can produce:
- A network diagram, even a rough one
- A list of systems, including cloud services and anything a department bought on a card
- Existing policies, however dated
- Your contracts, including the clauses
- Access to the people who administer things
The most common delay is not technical. It is that the person who knows how something is configured is on holiday.
How long it takes
| Company size | Typical duration |
|---|---|
| Under 25 people, one location | 2 to 3 weeks |
| 25 to 100 people | 3 to 5 weeks |
| Over 100, or multiple sites | 5 to 8 weeks |
Scope drives this more than headcount. A twenty person engineering firm with three cloud environments and a machine shop takes longer than a hundred person company with one office and one system.
What you should receive
- A defined and documented boundary
- A practice by practice assessment with evidence noted
- An SPRS score, with the calculation shown
- A prioritized remediation plan with effort estimates
- A draft SSP structure, or the SSP itself depending on the engagement
- A POA&M covering what is not yet met
If a provider offers a scored result without a boundary document, ask what the score applies to. It is not a meaningful number without one.
What the July 2026 suspension changed
Not the value of doing this.
CMMC Phase 2 was suspended, pausing third party assessment. DFARS 252.204-7012 was not suspended, so the NIST SP 800-171 self assessment, the SSP, the POA&M, the SPRS score and the annual affirmation all remain required.
A gap assessment produces exactly those artefacts. The only thing that changed is that the result currently feeds a self assessment rather than preparation for a C3PAO audit, and if the reform review restores certification you already have the work.
Expect the score to be bad
First honest assessments frequently land in the negative, because the SPRS model subtracts weighted points and there are more than 110 points of possible deductions.
A negative score is a starting position, not a failure. What matters is the trajectory and whether the POA&M is credible. Assessors are considerably more suspicious of a company claiming 110 than one showing minus 40 with a dated plan.
- CMMC
- gap assessment
- NIST 800-171
- scoping
- SPRS
More on compliance
