Docs → Client policies

CMMC readiness checklist

The stages we walk defense-supply-chain clients through on the way to a CMMC assessment — in plain English, no scare tactics.

Last updated: August 2026

At a glance

Who this is for — and what to know first

Who this is for
Contractors and subcontractors whose contracts reference CMMC, NIST SP 800-171, or protection of Controlled Unclassified Information. If your primes are asking about CMMC status, this is your map.

Before you start
Two things shape everything: know exactly what your contracts require (level and flowdowns), and know where CUI actually lives — which systems, which people, which vendors.

The readiness stages

1. Scoping — Agree what systems and data are in scope — and shrink that scope where possible. A smaller scope is a cheaper, faster assessment.

2. Gap assessment — Compare current practice against the required controls, honestly. Flattering assessments produce ugly surprises later.

3. Remediation — Close the gaps: technical controls, process changes, training. This is usually the longest stage.

4. Documentation — Policies, the system security plan, and evidence that practices actually happen — assessors read, then verify.

5. Assessment prep — Dry runs so the real assessment holds no surprises for anyone in the room.

Where we fit: we guide and implement — scoping, gap assessment, remediation, documentation. The certification decision belongs to the assessor and the DoD. Anyone who promises you a certification outcome is selling something else.

Common questions

Do we need CMMC if we only sell to a prime, not the DoD directly?+

If your prime’s contract flows CMMC requirements down to you, yes. Check your contract language — that is the authority, not us.

How long does readiness take?+

It depends on where you start and how much CUI touches. The gap assessment gives you a real answer instead of a guess.

Who actually certifies us?+

A C3PAO — a certified third-party assessment organization — conducts the assessment. We prepare you for it; we do not grade our own homework.

Related docs

Security practices →
The principles behind how we secure what we manage.

Data handling →
What we touch, why, and the discipline around it.

Incident response →
What happens when something goes genuinely wrong.

Prime asking about your CMMC status?
Bring the contract language — the first conversation is free and decides everything else.