When defense subcontractors think about a CMMC assessment, they often picture technical scanning. In practice, much of the work is evidence: showing an assessor that each required practice is implemented, who is responsible for it, and how you know it is working. Companies that organize evidence early find assessments smoother and less stressful.
This post gives a practical approach for the preparation phase. The CMMC program is defined in federal rules, and requirements depend on the level and contract, so confirm what applies to you with your prime, your contract documents, and the official program materials.
Start with scope
Everything depends on defining what is in scope: the systems, people, facilities, and external services that process, store, or transmit controlled unclassified information, plus assets that provide security protection to them. Document the boundary clearly with a network diagram and a data flow description. A smaller, well-defined scope is easier to defend and assess.
For cloud services in scope, confirm that they meet applicable requirements and keep their documentation, including the responsibility split between you and the provider.
Know the framework you are measured against
For many contractors, the requirements derive from NIST SP 800-171. Walk through each requirement and determine whether it is implemented, partly implemented, or not implemented. Be honest. Gaps recorded in an action plan are better than gaps discovered during the assessment.
The core documents
Organize a set of documents that an assessor will expect to see.
- System security plan: describes the environment, boundary, and how each requirement is met.
- Plan of action and milestones: lists gaps, owners, and dates, where permitted under the rules for your level.
- Policies and procedures: written statements covering areas such as access control, incident response, media protection, and configuration management.
- Network and data flow diagrams.
- Asset inventory: hardware, software, and services in scope.
- Roles and responsibilities: who owns each practice.
Documents should reflect reality. A beautiful policy nobody follows hurts more than it helps.
Gather evidence by practice
Assessors typically look for a combination of documents, observed configurations, and interviews. For each practice, collect artifacts such as:
- Access control: account lists, role definitions, screenshots of MFA settings, remote access configurations, access review records.
- Awareness and training: training materials, attendance records, role-based training for administrators.
- Audit and accountability: log settings, retention evidence, examples of log review.
- Configuration management: baseline configurations, change records, approved software lists.
- Identification and authentication: password and MFA configurations, account lifecycle procedures.
- Incident response: the plan, contact lists, exercise records, sample incident tickets.
- Maintenance and media: procedures for controlled maintenance, sanitization records, removable media rules.
- Physical protection: visitor logs, badge or key controls, facility photos.
- Risk and security assessment: vulnerability scan results and remediation tracking.
- System and communications protection: firewall rules, encryption settings, network segmentation.
- System and information integrity: patch records, malware protection, alert handling.
Date everything, and record who collected it.
Build an evidence index
Create a simple spreadsheet or folder structure mapping each practice to its evidence, owner, location, and last review date. This index helps you respond quickly to assessor requests and highlights gaps.
Prepare your people
Assessors interview staff, so train employees on what they do and why. Administrators should be able to explain how access is granted, how incidents are handled, and where logs are kept. Staff should know basic policies such as handling of controlled information and reporting suspicious activity. Honest, specific answers matter more than rehearsed ones.
Run a mock assessment
Before the real one, have someone independent, such as an experienced consultant or a team member not involved in implementation, walk through the practices and request evidence as an assessor would. Track what is missing or weak and correct it.
Keep evidence alive
Compliance is ongoing. Schedule recurring activities: access reviews, training, vulnerability scans, backup tests, incident exercises, and policy reviews. Keep dated records so that evidence stays current between assessments.
Common pitfalls
- Defining scope too broadly or too vaguely.
- Policies that do not match practice.
- Evidence gathered in a rush and undated.
- Relying on a single person who holds all the knowledge.
- Treating the provider's marketing claims as proof of compliance for cloud services.
Support from Ironfield Cyber
Ironfield Cyber supports defense subcontractors with scoping, gap analysis, documentation, and evidence organization ahead of CMMC assessments. If you are not sure where to begin, we can start with a scoping conversation and a short readiness review.