Docs → Client policies
CMMC readiness checklist
The stages we walk defense-supply-chain clients through on the way to a CMMC assessment — in plain English, no scare tactics.
Last updated: August 2026
At a glance
- Your contracts decide your level, scope, and deadline
- Five readiness stages — we guide and implement all of them
- Certification is decided by the assessor, not by us
- Bring your contract language to the first conversation
Who this is for — and what to know first
Who this is for
Contractors and subcontractors whose contracts reference CMMC, NIST SP 800-171, or protection of Controlled Unclassified Information. If your primes are asking about CMMC status, this is your map.
Before you start
Two things shape everything: know exactly what your contracts require (level and flowdowns), and know where CUI actually lives — which systems, which people, which vendors.
The readiness stages
1. Scoping — Agree what systems and data are in scope — and shrink that scope where possible. A smaller scope is a cheaper, faster assessment.
2. Gap assessment — Compare current practice against the required controls, honestly. Flattering assessments produce ugly surprises later.
3. Remediation — Close the gaps: technical controls, process changes, training. This is usually the longest stage.
4. Documentation — Policies, the system security plan, and evidence that practices actually happen — assessors read, then verify.
5. Assessment prep — Dry runs so the real assessment holds no surprises for anyone in the room.
Where we fit: we guide and implement — scoping, gap assessment, remediation, documentation. The certification decision belongs to the assessor and the DoD. Anyone who promises you a certification outcome is selling something else.
Common questions
Do we need CMMC if we only sell to a prime, not the DoD directly?+
If your prime’s contract flows CMMC requirements down to you, yes. Check your contract language — that is the authority, not us.
How long does readiness take?+
It depends on where you start and how much CUI touches. The gap assessment gives you a real answer instead of a guess.
Who actually certifies us?+
A C3PAO — a certified third-party assessment organization — conducts the assessment. We prepare you for it; we do not grade our own homework.
Related docs
Security practices →
The principles behind how we secure what we manage.
Data handling →
What we touch, why, and the discipline around it.
Incident response →
What happens when something goes genuinely wrong.
Prime asking about your CMMC status?
Bring the contract language — the first conversation is free and decides everything else.