Docs → Client policies

CMMC readiness checklist

The stages we walk defense-supply-chain clients through on the way to a CMMC assessment — in plain English, no scare tactics.

Last updated: August 2026

At a glance

Who this is for — and what to know first

Who this is for
Contractors and subcontractors whose contracts reference CMMC, NIST SP 800-171, or protection of Controlled Unclassified Information. If your primes are asking about CMMC status, this is your map.

Before you start
Two things shape everything: know exactly what your contracts require (level and flowdowns), and know where CUI actually lives — which systems, which people, which vendors.

The readiness stages

1. Scoping — Agree what systems and data are in scope — and shrink that scope where possible. A smaller scope is a cheaper, faster assessment.

2. Gap assessment — Compare current practice against the required controls, honestly. Flattering assessments produce ugly surprises later.

3. Remediation — Close the gaps: technical controls, process changes, training. This is usually the longest stage.

4. Documentation — Policies, the system security plan, and evidence that practices actually happen — assessors read, then verify.

5. Assessment prep — Dry runs so the real assessment holds no surprises for anyone in the room.

Where we fit: we guide and implement — scoping, gap assessment, remediation, documentation. The certification decision belongs to the assessor and the DoD. Anyone who promises you a certification outcome is selling something else.

Common questions

Do we need CMMC if we only sell to a prime, not the DoD directly?+

If your prime’s contract flows CMMC requirements down to you, yes. Check your contract language — that is the authority, not us.

How long does readiness take?+

It depends on where you start and how much CUI touches. The gap assessment gives you a real answer instead of a guess.

Who actually certifies us?+

A C3PAO — a certified third-party assessment organization — conducts the assessment. We prepare you for it; we do not grade our own homework.

Related docs

Security practices
The principles behind how we secure what we manage.

Data handling
What we touch, why, and the discipline around it.

Incident response
What happens when something goes genuinely wrong.

Prime asking about your CMMC status?
Bring the contract language — the first conversation is free and decides everything else.