Most defense contractors we talk to are not starting from zero. They have a system security plan. They have policies. Someone has already walked through the NIST SP 800-171 requirements at least once. So when an assessment stalls or a self-assessment score comes in lower than expected, it is rarely because a control was never attempted. It is because the control exists on paper but was never tested against real evidence.
Here are the gaps we run into most often, in the order they tend to surface during a readiness review.
The System Security Plan Describes the Network You Meant to Build
An SSP is a snapshot, and networks change faster than documentation does. A new cloud service gets added, a legacy server gets decommissioned late, or a contractor brings in a personal device for a two-week sprint, and the SSP is not updated to match. An assessor is not grading the document. They are grading whether the document matches what is actually running, and a mismatch here is one of the fastest ways to lose confidence in everything else in the package.
The fix is not a bigger document. It is a habit: every time the environment changes in a way that touches CUI, the SSP gets a same-week update, not a pre-assessment scramble.
Access Control Policies Exist, But Access Reviews Do Not
Almost every organization we assess has a written access control policy. Far fewer can produce evidence that access was actually reviewed on a schedule. Someone left the company eight months ago and their account is still active. A shared service account has admin rights nobody remembers granting. The policy said this would be reviewed quarterly, but the last review anyone can point to was during initial rollout.
CMMC assessors ask for evidence, not intent. A signed policy proves you planned to do something. A dated access review log, with names of who reviewed it and what changed, proves you did it.
Incident Response Has Never Actually Been Tested
The incident response plan is often one of the most polished documents in the package, and one of the least exercised. Nobody has run a tabletop. Nobody can say, with confidence, who gets called first if CUI is potentially exposed at 6 p.m. on a Friday. A plan that has never been tested is a plan you are hoping works, not one you know works, and that distinction matters to an assessor evaluating whether your organization can actually execute under pressure.
Where This Leaves You
None of this requires a bigger budget or a longer timeline. It requires an honest look at which of your controls are backed by dated, specific evidence and which are backed by a policy that was written once and never revisited. That is the review we run before a formal assessment: not another policy rewrite, but a evidence-first walk through what a C3PAO assessor will actually ask to see.
If you want a second set of eyes on where your own package would hold up, our CMMC Readiness & RPO Advisory team can walk through it with you before an assessor does.
