Guide

CMMC Gap Analysis Process: From Status Map to Honest Report

Last verified: First published:

Quick answer: A gap analysis compares your real environment to the applicable NIST SP 800-171 requirements and produces a control-by-control status, evidence notes, and a prioritized remediation roadmap—not a marketing score. Start from a status register, challenge high-weight marks, then decide DIY templates versus a fixed-scope paid Gap engagement.

Key takeaways

  • Gap analysis input is a scope freeze + status register—not a blank SSP.
  • Workshops beat questionnaire-only theater for shared services and CUI paths.
  • Deliverable shape: status, evidence citation style, priority roadmap, residual risk—not a certificate.
  • Scoring integrity (weights, POA&M rules) is part of the gap, not a later surprise.
  • Paid Gap Analysis ($4,950, up to 28 hours) is for independent 110-control challenge—not for reinventing method docs.

What a gap analysis is for

Operations uses gap analysis to answer:

  1. Where are we against the requirements that actually apply?
  2. What evidence exists for claims of implementation?
  3. What do we fix first given weight, risk, and dependency?
  4. What can we honestly report in SPRS or to a prime—if anything—right now?

It is not a CMMC certification, not legal advice, and not a promise of any score.

Prerequisites (do not skip)

Prerequisite Why
Status mapping skeleton Prevents blank-page workshops
Scope / CUI path inventory Wrong boundary = wrong gaps
Shared-responsibility draft MSP/cloud gaps surface early
Access to owners Rows without owners never close
Baseline clarity Rev 2 vs Rev 3 / assessment method

If those are missing, start with the free Defensibility Check and workbook, not a full 110 sprint.

Process overview

Scope freeze → Status draft → Workshops → Evidence sampling
    → Scoring integrity pass → Gap report → Remediation roadmap → Decision gate

1. Scope freeze (documented)

Write the boundary you are assessing. Multi-site? Either separate assessments or explicit multi-boundary registers.

2. Status draft

Complete first-pass Satisfied / Partial / Not on every applicable control. Prefer red honesty over green theater. Method: status mapping.

Session Focus
1 Boundary, CUI flows, identity, remote access
2 Logging, config, media, physical, personnel
3 Incident response, integrity, training, assessment/POA&M hygiene
Async Evidence links, MSP attestations, ticket pulls

Two working sessions are a common minimum for a single enclave; complex estates need more (and more hours).

4. Evidence sampling

For high-weight Satisfied marks, pull real artifacts (offline). Downgrade anything that cannot be shown. This is where optimistic scores die—and should.

5. Scoring integrity pass

Before any “we’ll submit X to SPRS” talk:

  • Confirm 1/3/5 weights for the methodology you use
  • Separate must-implement vs POA&M expectations under current rules
  • Recompute only after statuses stabilize

See how to calculate your SPRS score.

6. Gap report (deliverable shape)

A useful report includes:

Section Content
Scope statement What was assessed / excluded
Method Workshops, evidence sampling, limitations
Control results Status per control (or family rollup + open detail)
Evidence notes What was seen / missing (no need to paste CUI into email)
Priority roadmap Ordered actions with owners and rough effort
Residual risk What remains if leadership ships a score now
Next path DIY Pack / Review / Readiness / pause signature

7. Decision gate

Outcome Next
Map solid, execution in-house Pro Pack + remediation roadmap
Need independent challenge Gap Analysis SKU
Need SSP/POA&M package help Readiness Package
Score still fiction Do not signFCA guide

DIY vs paid Gap (DefensibleScore / DTS)

DIY Paid Gap (SKU-GAP)
Who challenges marks Your team Facilitated independent review
Hours Unlimited internal Up to 28 hours fixed
Output Your register + notes Written gap report + roadmap
Best for Disciplined ops with time Time-boxed honesty under pressure
Price Free method + optional Pack $199 $4,950 (50/50 payment)

If you already bought a Defensibility Review, a $500 credit may apply to Gap within 90 days (see how-we-help for terms).

Common failure modes

  1. Questionnaire only — no workshops, no evidence.
  2. Tool greenwash — vendor dashboard ≠ control satisfied.
  3. Scope shopping — excluding the system that actually holds CUI.
  4. Score-first — reverse-engineering marks to hit a number.
  5. No owner — roadmap becomes a PDF nobody opens.

After the gap

Move immediately into execution: 30/60/90 remediation roadmap, then program cadence so the report does not rot.

Frequently asked questions

Is a gap analysis the same as a C3PAO assessment?

No. A C3PAO assessment is a formal certification path when required. A gap analysis is readiness work—identifying and prioritizing shortfalls. We are not a C3PAO and do not certify.

Can software alone do our gap analysis?

Tools help track rows. They cannot see whether your marks are true. Garbage in remains confident garbage out.

When should we buy Gap vs only the Pro Pack?

Pack if you will execute documentation in-house and need structured templates. Gap if you need an independent 110-control report and roadmap under a time-boxed engagement.

How long does a fixed Gap engagement take?

Our Gap SKU is capped at 28 hours for a single well-scoped enclave. Multi-site or deep remediation engineering is out of scope and quoted separately.

What this page is / is not: readiness and advisory guidance only. Not legal advice, not a C3PAO assessment, and not a CMMC certification. CUI designation is driven by government requirements and contract language—not by this site. Prefer primary sources when policy text conflicts with any blog (including ours).