CMMC Gap Analysis Process: From Status Map to Honest Report
Quick answer: A gap analysis compares your real environment to the applicable NIST SP 800-171 requirements and produces a control-by-control status, evidence notes, and a prioritized remediation roadmap—not a marketing score. Start from a status register, challenge high-weight marks, then decide DIY templates versus a fixed-scope paid Gap engagement.
Key takeaways
- Gap analysis input is a scope freeze + status register—not a blank SSP.
- Workshops beat questionnaire-only theater for shared services and CUI paths.
- Deliverable shape: status, evidence citation style, priority roadmap, residual risk—not a certificate.
- Scoring integrity (weights, POA&M rules) is part of the gap, not a later surprise.
- Paid Gap Analysis ($4,950, up to 28 hours) is for independent 110-control challenge—not for reinventing method docs.
What a gap analysis is for
Operations uses gap analysis to answer:
- Where are we against the requirements that actually apply?
- What evidence exists for claims of implementation?
- What do we fix first given weight, risk, and dependency?
- What can we honestly report in SPRS or to a prime—if anything—right now?
It is not a CMMC certification, not legal advice, and not a promise of any score.
Prerequisites (do not skip)
| Prerequisite | Why |
|---|---|
| Status mapping skeleton | Prevents blank-page workshops |
| Scope / CUI path inventory | Wrong boundary = wrong gaps |
| Shared-responsibility draft | MSP/cloud gaps surface early |
| Access to owners | Rows without owners never close |
| Baseline clarity | Rev 2 vs Rev 3 / assessment method |
If those are missing, start with the free Defensibility Check and workbook, not a full 110 sprint.
Process overview
Scope freeze → Status draft → Workshops → Evidence sampling
→ Scoring integrity pass → Gap report → Remediation roadmap → Decision gate
1. Scope freeze (documented)
Write the boundary you are assessing. Multi-site? Either separate assessments or explicit multi-boundary registers.
2. Status draft
Complete first-pass Satisfied / Partial / Not on every applicable control. Prefer red honesty over green theater. Method: status mapping.
3. Workshops (recommended shape)
| Session | Focus |
|---|---|
| 1 | Boundary, CUI flows, identity, remote access |
| 2 | Logging, config, media, physical, personnel |
| 3 | Incident response, integrity, training, assessment/POA&M hygiene |
| Async | Evidence links, MSP attestations, ticket pulls |
Two working sessions are a common minimum for a single enclave; complex estates need more (and more hours).
4. Evidence sampling
For high-weight Satisfied marks, pull real artifacts (offline). Downgrade anything that cannot be shown. This is where optimistic scores die—and should.
5. Scoring integrity pass
Before any “we’ll submit X to SPRS” talk:
- Confirm 1/3/5 weights for the methodology you use
- Separate must-implement vs POA&M expectations under current rules
- Recompute only after statuses stabilize
See how to calculate your SPRS score.
6. Gap report (deliverable shape)
A useful report includes:
| Section | Content |
|---|---|
| Scope statement | What was assessed / excluded |
| Method | Workshops, evidence sampling, limitations |
| Control results | Status per control (or family rollup + open detail) |
| Evidence notes | What was seen / missing (no need to paste CUI into email) |
| Priority roadmap | Ordered actions with owners and rough effort |
| Residual risk | What remains if leadership ships a score now |
| Next path | DIY Pack / Review / Readiness / pause signature |
7. Decision gate
| Outcome | Next |
|---|---|
| Map solid, execution in-house | Pro Pack + remediation roadmap |
| Need independent challenge | Gap Analysis SKU |
| Need SSP/POA&M package help | Readiness Package |
| Score still fiction | Do not sign — FCA guide |
DIY vs paid Gap (DefensibleScore / DTS)
| DIY | Paid Gap (SKU-GAP) | |
|---|---|---|
| Who challenges marks | Your team | Facilitated independent review |
| Hours | Unlimited internal | Up to 28 hours fixed |
| Output | Your register + notes | Written gap report + roadmap |
| Best for | Disciplined ops with time | Time-boxed honesty under pressure |
| Price | Free method + optional Pack $199 | $4,950 (50/50 payment) |
If you already bought a Defensibility Review, a $500 credit may apply to Gap within 90 days (see how-we-help for terms).
Common failure modes
- Questionnaire only — no workshops, no evidence.
- Tool greenwash — vendor dashboard ≠ control satisfied.
- Scope shopping — excluding the system that actually holds CUI.
- Score-first — reverse-engineering marks to hit a number.
- No owner — roadmap becomes a PDF nobody opens.
After the gap
Move immediately into execution: 30/60/90 remediation roadmap, then program cadence so the report does not rot.
Related free tools
Frequently asked questions
Is a gap analysis the same as a C3PAO assessment?
No. A C3PAO assessment is a formal certification path when required. A gap analysis is readiness work—identifying and prioritizing shortfalls. We are not a C3PAO and do not certify.
Can software alone do our gap analysis?
Tools help track rows. They cannot see whether your marks are true. Garbage in remains confident garbage out.
When should we buy Gap vs only the Pro Pack?
Pack if you will execute documentation in-house and need structured templates. Gap if you need an independent 110-control report and roadmap under a time-boxed engagement.
How long does a fixed Gap engagement take?
Our Gap SKU is capped at 28 hours for a single well-scoped enclave. Multi-site or deep remediation engineering is out of scope and quoted separately.
What this page is / is not: readiness and advisory guidance only. Not legal advice, not a C3PAO assessment, and not a CMMC certification. CUI designation is driven by government requirements and contract language—not by this site. Prefer primary sources when policy text conflicts with any blog (including ours).