Skip to main content
New InterSec is now ISO/IEC 42001 certified for AI management systems Read the announcement
CMMC Readiness Assessment & Gap Analysis · Cyber-AB RPO

CMMC Readiness Assessment and Gap Analysis

Know exactly where you stand before the assessor does. We review your environment against all 110 NIST 800-171 controls, calculate your honest SPRS score, and hand you a prioritized roadmap to close the gaps, so there are no surprises when the C3PAO walks in.

4
Months left
Until CMMC Phase 2 enforcement. A readiness assessment now leaves time to remediate before you need to pass.

What your assessment includes

All 110 NIST 800-171 controlsReviewed against your real environment
SPRS baseline scoreWhere you actually stand today
CUI scope boundaryWhat is in scope, and what we keep out
Prioritized remediation roadmapWhat to fix, in what order, by when
POA&M starterGaps tracked the way an assessor expects
Quick answer

A CMMC readiness assessment measures your current state against the CMMC Level 1 or Level 2 controls and produces a gap list, an SSP, and a POA&M before your formal assessment. It is preparation work, performed by an RPO, and separate from the official C3PAO Level 2 assessment. Doing it early de-risks the November 10, 2026 requirement.

What the assessment covers

Four steps from "we are not sure" to a roadmap you can budget.

A readiness assessment is not a checklist someone emails you. It is a structured review of your real environment that ends with a number you can report and a plan you can act on.

STEP 01

Scope your CUI

We map every system, person, and data flow that touches Controlled Unclassified Information, and what we can defensibly keep out of scope to hold cost down.

CUI boundary diagram Asset and data-flow inventory In-scope vs out-of-scope log
STEP 02

Assess all 110 controls

A control-by-control review against the full NIST SP 800-171 R2 practice set. Every existing process mapped to a control, every gap flagged with evidence.

Gap report vs 110 practices Evidence-readiness check Quick wins identified
STEP 03

Baseline your SPRS score

We calculate your honest SPRS score the way the DoD scoring methodology does, so the number you report is one you can defend.

Current SPRS score Score by control family Path to your target score
STEP 04

Build the roadmap

A prioritized plan that turns the gaps into an ordered sequence of work, with effort and cost ranges so you can budget before you commit.

Prioritized remediation roadmap POA&M starter Effort and cost ranges
Readiness vs the official assessment

Two different jobs, two different organizations.

This trips up a lot of contractors, so we say it plainly: the company that gets you ready cannot be the company that certifies you.

A readiness / gap assessment is what we do

As a Cyber-AB RPO, we run the pre-assessment that finds your gaps before an assessor does. You get your SPRS baseline, a gap report against all 110 controls, and a roadmap to close them. This is the work that gets you ready.

A C3PAO assessment is what we get you ready for

The official CMMC Level 2 certification assessment is run by a C3PAO, a separate, certified third-party organization. We are not your assessor, and by Cyber-AB rules we cannot be. Keeping the two roles separate protects you and keeps the certification clean.

What you walk away with

Your numbers, your documents, and your plan.

Every readiness assessment ends with the same three things: an honest baseline, the documents an assessor will ask for, and a prioritized plan to close the distance.

Your numbers

  • An honest SPRS baseline score
  • A scorecard against all 110 controls
  • Score broken down by control family

Your documents

  • A gap report mapped to each control
  • A POA&M starter for the open gaps
  • The CUI scope and boundary defined

Your plan

  • A prioritized remediation roadmap
  • Effort and cost ranges to budget
  • A realistic timeline to your target level
Proof it works

Real SPRS movement, from real assessments.

A readiness assessment is only worth the remediation it sets up. Here is where two clients started, and what the plan delivered.

Calibration and machine work
CMMC L22-person team
Calibration & Fabrication Contractor · Near Norfolk

A right-sized scope put a 2-person shop on track to a passing SPRS.

No prior security program and no IT staff. The assessment scoped a lean CUI footprint, two encrypted laptops, segregated Wi-Fi, and a GCC subdomain, with milestone pricing tied to SPRS gates.

100–110
Target SPRS on track
Owned
By the client team
170+
NIST 800-171 SSP, POA&M, and SPRS deliveries
200+
CMMC Level 1 advisory engagements
50+
CMMC Level 2 advisory & MSSP engagements
90%
Client retention rate
Frequently asked

CMMC readiness assessment questions

What is a CMMC gap assessment?

A CMMC gap assessment is a control-by-control review of your environment against the NIST SP 800-171 standard CMMC is built on. It shows where you meet each requirement, where you fall short, and what it will take to close the gap. For Level 2 that means all 110 practices. You walk away with your SPRS baseline score, a prioritized remediation roadmap, and a POA&M starter.

What is the difference between a readiness assessment and a C3PAO assessment?

A readiness or gap assessment is the preparation. A C3PAO assessment is the official certification. We are a Cyber-AB RPO (Registered Practitioner Organization): we run the readiness work that finds and fixes gaps. A C3PAO is the certified third-party organization that performs the actual CMMC Level 2 assessment. We get you ready, then a separate C3PAO certifies you. See how our full CMMC consulting engagement works.

How long does a CMMC gap assessment take?

For most small and mid-size contractors, the assessment itself runs two to four weeks from kickoff to roadmap, depending on the size of your CUI footprint and how many systems and sites are in scope. A sole proprietor moves faster, a multi-site operation takes longer. We tell you the honest timeline in the first call.

How much does a CMMC readiness assessment cost?

Pricing is scoped to your CUI footprint and the number of systems and sites in scope. We offer fixed-fee and milestone-priced options so you know the number before you commit. The 30-minute consultation includes a rough order-of-magnitude estimate. For how the full program is priced, see our guide to what CMMC compliance actually costs.

Will the gap assessment tell me my SPRS score?

Yes. Calculating your honest SPRS baseline is a core deliverable. We score you the way the DoD methodology does, so the number you submit to the Supplier Performance Risk System is one you can defend if it is ever questioned.

Do you also perform the official CMMC assessment?

No, and that is by design. As an RPO we get you assessment-ready. The official Level 2 assessment is performed by a C3PAO, a separate certified organization. Cyber-AB requires these roles to stay separate, which also means our only incentive is to get you genuinely ready, not to rubber-stamp our own work.

Do I need a readiness assessment for Level 1 or only Level 2?

Both levels benefit. For Level 1, a readiness check confirms you meet the 15 requirements before you self-assess. For Level 2, it is close to essential, because you need the SSP and POA&M in hand before a C3PAO assessment. The deeper your likely gaps, the more it saves you.

Find out where you stand.

Book a 30-minute readiness consult and we will baseline where you are, where an assessor will look first, and what a realistic path to a passing SPRS looks like for your business. Or send your details below and we will reply within one business day.

Free 30-min consult · NDA on request · Zero obligation
Request your readiness consult
Tell us where you are. We'll come prepared with next steps.
Cybersecurity ServicesCMMC & ComplianceSecure AIManaged Security (MSSP)Staffing & TalentPartnership
Your details stay confidential