A CMMC gap assessment measures the exact distance between how your environment operates today and what the 110 requirements of CMMC Level 2 demand, then turns that distance into two things you can act on: a score and a plan. It is the analytical core of getting compliant, the step that replaces a vague sense of being behind with a precise, itemized account of every requirement you do not yet meet. This guide covers what a gap assessment covers, what it delivers, how its findings feed your SPRS score and your remediation plan, and what drives its cost.
It is worth drawing one distinction at the outset, because the terms get used interchangeably and should not be. A gap assessment is not the same as a broad readiness assessment. A readiness assessment is the wider evaluation of whether you are prepared for a formal assessment, covering scope, evidence, timing, and how the process compares to a mock or a C3PAO audit. A gap assessment is the engine inside it: the focused analysis that produces the scored baseline and the remediation plan the readiness evaluation depends on. This piece goes deep on that engine and its outputs.
What a CMMC Gap Assessment Is
A CMMC gap assessment is a structured comparison of your current security posture against the 110 requirements in NIST SP 800-171 Revision 2, requirement by requirement, to identify precisely where you fall short. The word gap is literal: for each requirement, the assessment establishes whether it is fully implemented, partially implemented, or absent, and the collection of everything that is not fully implemented is the gap you have to close. The output is not an impression of your maturity; it is an itemized ledger tied to specific requirements.
What makes the gap assessment the analytical core rather than the whole journey is that it does two jobs a broad readiness review only summarizes. It quantifies your position as a score that the government will see, and it converts each shortfall into a discrete item on a remediation plan. Where a readiness assessment answers whether you are ready and when to proceed, the gap assessment answers exactly what is wrong and what closing it is worth. That is why the two are complementary: the readiness evaluation is the umbrella, and the gap assessment is the measurement and planning that give it substance.
What a CMMC Gap Assessment Covers
A gap assessment covers four things, and the value depends on doing all four rather than stopping at a control checklist. Each builds on the one before it, from establishing what is true today to confirming that the analysis rests on a valid scope.
The Current-State Baseline
The assessment begins by documenting how security is actually implemented across the in-scope environment right now, not how it is supposed to work on paper. This baseline is the honest starting point, and establishing it well is what separates a useful gap assessment from an optimistic self-review. The goal is a factual picture of the present state that every gap can be measured against.
Comparison Against the 110 Requirements
With the baseline set, each of the 110 requirements is examined against it and classified as met, partially met, or not met. This is the heart of the exercise, and the discipline is in refusing to round up: a control that mostly works is not a control that is met, and treating it as met is how organizations carry hidden gaps into a formal assessment. The comparison produces the itemized list of shortfalls that everything downstream depends on.
The Evidence Check
A gap is not only a missing control; it is also a control that works but cannot be proven. The assessment therefore checks whether each implemented requirement is supported by the documentation an assessor would expect, principally the System Security Plan and its underlying policies. Requirements that are technically satisfied but undocumented are recorded as gaps, because in any assessment an unprovable control is treated as an absent one.
The Scope Dependency
A gap assessment is only as valid as the scope it runs against, because comparing the wrong environment to the 110 requirements produces a precise answer to the wrong question. The analysis assumes that the boundary of controlled unclassified information has been correctly drawn, so an incorrect scope quietly invalidates every finding. Confirming the boundary, using the principles in the CMMC scoping guide, is a precondition for a gap assessment worth trusting.
Common Gaps a CMMC Gap Assessment Surfaces
Across defense suppliers the same shortfalls recur, and knowing the usual suspects helps you anticipate where your own gap assessment is likely to land. None of these are exotic; they are the practical places where real environments drift from the 110 requirements, and most of them are fixable once they are named.
Access control is one of the most frequent problem areas, and multi-factor authentication is the specific requirement that trips organizations up most often. Companies commonly apply multi-factor authentication to some access paths but not all of them, which under requirement 3.5.3 leaves a partial implementation rather than a met control, and the related principle of least privilege is often enforced loosely rather than strictly. Because access control carries significant weight, gaps here tend to hit both security and score hard.
Audit logging and monitoring is a second recurring weakness. Many environments collect logs but never review them, or log some events and miss others, so the requirement to monitor and analyze activity is only partially satisfied. A gap assessment frequently finds that the technical capability exists but the disciplined, documented monitoring the requirement expects does not.
Encryption is a third common finding, and the nuance catches people out. Organizations often encrypt controlled unclassified information but use cryptography that is not FIPS-validated, which under requirement 3.13.11 does not count as meeting the control. Real encryption that is not FIPS-validated is one of the most common partial-credit gaps a gap assessment records.
Handling of the regulated data itself is a fourth area, covering how controlled unclassified information is marked, stored, and protected on media. Inconsistent marking, regulated data sitting on systems that were never meant to hold it, and weak media protection all show up regularly, and they often point back to a scope that was drawn too loosely in the first place.
Documentation is the most common category of all. Incomplete System Security Plans, policies that do not exist or do not map cleanly to the control families, and a missing or stale Plan of Action and Milestones appear in a large share of assessments, and they are the gaps most easily closed by starting from proven artifacts rather than a blank page. Configuration management rounds out the list, where the absence of established secure baselines and formal change control leaves several requirements unmet at once. Each of these findings flows directly into the two outputs that follow: they reduce your score and they populate your remediation plan.
How Gap Findings Feed Your SPRS Score
The first output of a gap assessment is a defensible score for the Supplier Performance Risk System, calculated under the DoD Assessment Methodology. This is the number the government relies on and the number you attest to, so understanding how your gaps produce it is central to the exercise. A fully compliant environment yields the maximum score, and each unmet requirement reduces it from there, which means your gap list is not just a to-do list; it is the direct input to the number that represents your posture.
Not every gap moves the score equally. The methodology weights requirements so that some shortfalls reduce the score more than others, which is why a gap assessment does not just count your gaps but ranks them by their effect on the number. This is the information that lets you close the gaps that most improve both your security and your score first, rather than working through them in an arbitrary order. For the detail of how the scoring works and what a perfect baseline requires, the SPRS score and the perfect 110 guide walks through the mechanics, and the self-scoring resource lets you translate your own findings into a score. Working out your defensible score before you attest to it is one of the strongest reasons to run a gap assessment at all.
How Gap Findings Become a Remediation Plan
The second output is a Plan of Action and Milestones, and this is where a gap assessment stops being a diagnosis and becomes a project. Each gap the assessment records is converted into a discrete remediation item with an owner, a target, and a milestone, so that closing the gap becomes a tracked task rather than a vague intention. A gap assessment that produces findings without a structured plan to resolve them has done only half its job.
The plan is most useful when it is prioritized rather than merely listed, ordering the work by a combination of score impact and feasibility so that limited budget and engineering time go where they matter most. The discipline of sequencing gap closure is covered in detail in the five-step CMMC readiness roadmap, which turns a raw findings list into an ordered program of work. A well-built remediation plan is the deliverable that carries you from knowing your gaps to actually closing them.
Deliverables of a CMMC Gap Assessment
The tangible output of a gap assessment is a small set of documents that together define where you stand and what to do next. Understanding what you are paying for helps you judge whether an engagement is thorough or superficial.
| Deliverable | What it is | What you do with it |
|---|---|---|
| Gap report | The itemized list of met, partial, and unmet requirements | Your factual account of every shortfall |
| Scored SPRS baseline | Your current score under the DoD Assessment Methodology | The defensible number you attest to and aim to improve |
| Remediation plan (POA&M) | Each gap as an owned, scheduled task | The project plan that closes the gaps |
| Prioritized roadmap | The remediation items sequenced by impact and effort | The order in which to spend budget and time |
The four deliverables reinforce each other: the gap report is the raw finding, the scored baseline quantifies it, the remediation plan makes it actionable, and the roadmap makes it efficient. A recurring theme across all of them is documentation, because so many gaps are documentation gaps at heart, which is why starting from tailored, pre-built policy artifacts closes a meaningful share of findings quickly. Elevate’s CMMC Level 2 Master Policy Compendium gives you a policy foundation mapped to the requirements, so documentation gaps become a tailoring exercise rather than a writing project.
What a CMMC Gap Assessment Costs
The cost of a gap assessment is driven by the same factors that drive the work itself: the size and complexity of the in-scope environment, the footprint of controlled unclassified information, the current maturity of your controls and documentation, and how deep a remediation plan you want the engagement to produce. A tightly-scoped environment with reasonable existing hygiene is a far lighter engagement than a sprawling one where regulated data has never been mapped, so the most honest cost answer is a scoped one produced after your environment is understood.
The relative ranges follow from those drivers rather than from a fixed price list, and the useful comparison is against what the assessment prevents: finding and pricing your gaps early is consistently cheaper than discovering them during a formal assessment or carrying them into a false attestation. For a structured breakdown of how the numbers compare across engagement types and a realistic view of budgeting gap closure, see the CMMC audit versus internal assessment cost and timeline comparison and the guide to financial planning for CMMC Level 2 gap closure. Elevate scopes each gap assessment to the environment in front of it as part of its CMMC advisory services, keeping the advisory role separate from the accredited assessor who certifies.
Conclusion
A CMMC gap assessment is the measurement that makes everything else possible: it establishes your current-state baseline, compares it requirement by requirement against the 110 controls of Level 2, and produces the two outputs you build the rest of your compliance work on, a defensible SPRS score and a prioritized remediation plan. It is the analytical engine inside a broader readiness evaluation, and its value is in precision, replacing a general sense of being behind with an itemized account of exactly what to fix and what fixing it is worth.
The organizations that get the most from a gap assessment treat its findings as the start of a managed project rather than a report to file, closing gaps in the order that most improves both security and score. To run a gap assessment scoped to your environment and turn its findings into a plan you can execute, book a call with an Elevate advisor.
Key Takeaways
A CMMC gap assessment measures the distance between your current posture and the 110 Level 2 requirements, and converts it into a score and a plan.
- It is the analytical engine, not the whole journey: a gap assessment is the focused analysis inside a broader readiness evaluation, producing the scored baseline and remediation plan the readiness review depends on.
- It covers four things: a factual current-state baseline, a requirement-by-requirement comparison against the 110 controls, an evidence check, and confirmation that the scope it runs against is valid.
- Findings feed your SPRS score: a fully compliant environment yields the maximum, each unmet requirement reduces it, and because requirements are weighted, gaps are ranked by their effect on the number.
- Findings become a POA&M: each gap is converted into an owned, scheduled remediation item, prioritized by score impact and feasibility so budget and time go where they matter most.
- Cost tracks drivers, not templates: scope, CUI footprint, control maturity, and remediation depth set the price, and finding gaps early is consistently cheaper than discovering them in a formal assessment or a false attestation.
FAQs
Q1. What is a CMMC gap assessment? A CMMC gap assessment is a structured, requirement-by-requirement comparison of your current security posture against the 110 requirements in NIST SP 800-171 Revision 2, which underpin CMMC Level 2. For each requirement it establishes whether you fully meet it, partially meet it, or do not meet it, producing an itemized list of shortfalls. That list becomes the basis for two outputs: your SPRS score and your remediation plan.
Q2. What is the difference between a gap assessment and a readiness assessment? A readiness assessment is the broad evaluation of whether you are prepared for a formal assessment, covering scope, evidence, timing, and how the process compares to a mock or a C3PAO audit. A gap assessment is the focused analysis inside it that measures your position against the 110 requirements and produces a scored baseline and a remediation plan. In short, the readiness assessment is the umbrella and the gap assessment is the measurement engine, and the two are complementary rather than interchangeable.
Q3. How does a gap assessment affect my SPRS score? A gap assessment produces your score under the DoD Assessment Methodology, which is the number submitted to the Supplier Performance Risk System. A fully compliant environment yields the maximum score, and each unmet requirement reduces it, so your list of gaps is the direct input to the number. Because the methodology weights requirements, some gaps reduce the score more than others, which lets a good assessment rank your remediation by the effect each fix has on the score.
Q4. What does a CMMC gap assessment deliver? A thorough gap assessment delivers four things: a gap report listing every met, partial, and unmet requirement; a scored SPRS baseline showing where you currently stand; a remediation plan, or Plan of Action and Milestones, that turns each gap into an owned and scheduled task; and a prioritized roadmap that sequences the work by impact and effort. Together these move you from knowing your gaps to having a concrete plan to close them.
Q5. How much does a CMMC gap assessment cost? There is no single figure, because cost is driven by the size and complexity of the in-scope environment, the footprint of controlled unclassified information, the maturity of your existing controls and documentation, and how detailed a remediation plan you want. A tightly-scoped environment with reasonable existing hygiene costs far less than a sprawling, unmapped one. The most reliable number is a scoped estimate produced after your environment is understood, and finding gaps early is consistently cheaper than discovering them in a formal assessment.