Step 1
Determine the requirement before building the solution.
Start with the solicitation, contract, subcontract, statement of work, and customer direction. Identify whether the work involves Federal Contract Information, Controlled Unclassified Information, or neither, and determine the CMMC level and assessment type stated for the information system that will support performance.
Step 2
Define the CMMC assessment scope deliberately.
Scoping determines which assets, people, services, facilities, and external providers become part of the compliance effort. Document asset categories, data flows, boundaries, security-protection assets, specialized assets, and contractor risk-managed assets as applicable.
Step 3
Build readiness across five connected layers.
- Governance: ownership, approvals, risk decisions, change control, and accountability.
- Technical safeguards: identity, access, configuration, logging, encryption, vulnerability management, and incident response.
- Documentation: SSP, policies, procedures, diagrams, inventories, plans, and records.
- Operations: recurring reviews, user and asset lifecycle processes, monitoring, remediation, and evidence generation.
- Assessment preparation: objective evidence, interview readiness, demonstrations, and consistency across the environment.
Step 4
Make the evidence tell the same story as the SSP.
Evidence should demonstrate that the described control is implemented and operating. Organize artifacts by requirement, responsible role, system, date, and review cadence. Avoid relying on screenshots alone when a process record, configuration export, ticket, log, approval, or test result provides stronger evidence.
| Evidence type | What it should demonstrate |
|---|---|
| Policies and procedures | Approved expectations, responsibilities, and operating methods |
| Configuration evidence | The actual technical state of systems and services |
| Operational records | Recurring reviews and processes occur in practice |
| Assessment records | Testing, validation, findings, remediation, and approvals |
Step 5
Maintain readiness after the submission or assessment.
Assessment status does not replace the underlying contract obligation to protect information. Track changes to personnel, providers, locations, systems, boundaries, vulnerabilities, and contracts. Revalidate the SSP and evidence when the environment changes, not only when the next assessment approaches.