Step 1

Determine the requirement before building the solution.

Start with the solicitation, contract, subcontract, statement of work, and customer direction. Identify whether the work involves Federal Contract Information, Controlled Unclassified Information, or neither, and determine the CMMC level and assessment type stated for the information system that will support performance.

ContractWhich clauses, provisions, flowdowns, and CMMC status are stated?
InformationWhat information will be received, created, processed, stored, or transmitted?
SystemWhich people, technologies, facilities, and providers support that information?
AssessmentIs the requirement Level 1, Level 2 self, Level 2 C3PAO, or another status?

Step 2

Define the CMMC assessment scope deliberately.

Scoping determines which assets, people, services, facilities, and external providers become part of the compliance effort. Document asset categories, data flows, boundaries, security-protection assets, specialized assets, and contractor risk-managed assets as applicable.

Common mistake: treating the entire business as the CUI environment before confirming where CUI actually flows. Over-scoping can create unnecessary cost and operational burden; under-scoping creates assessment and contractual risk.

Step 3

Build readiness across five connected layers.

  1. Governance: ownership, approvals, risk decisions, change control, and accountability.
  2. Technical safeguards: identity, access, configuration, logging, encryption, vulnerability management, and incident response.
  3. Documentation: SSP, policies, procedures, diagrams, inventories, plans, and records.
  4. Operations: recurring reviews, user and asset lifecycle processes, monitoring, remediation, and evidence generation.
  5. Assessment preparation: objective evidence, interview readiness, demonstrations, and consistency across the environment.

Step 4

Make the evidence tell the same story as the SSP.

Evidence should demonstrate that the described control is implemented and operating. Organize artifacts by requirement, responsible role, system, date, and review cadence. Avoid relying on screenshots alone when a process record, configuration export, ticket, log, approval, or test result provides stronger evidence.

Evidence typeWhat it should demonstrate
Policies and proceduresApproved expectations, responsibilities, and operating methods
Configuration evidenceThe actual technical state of systems and services
Operational recordsRecurring reviews and processes occur in practice
Assessment recordsTesting, validation, findings, remediation, and approvals

Step 5

Maintain readiness after the submission or assessment.

Assessment status does not replace the underlying contract obligation to protect information. Track changes to personnel, providers, locations, systems, boundaries, vulnerabilities, and contracts. Revalidate the SSP and evidence when the environment changes, not only when the next assessment approaches.

CMMC readiness quick check