Preparing for CMMC Certification: A Pre-Assessment Security Testing Checklist

Key Takeaways

  • Only 4% of defense contractors passed third-party Cybersecurity Maturity Model Certification (CMMC) assessments. Yet 75% thought they were compliant based on self-assessment. Pre-assessment security testing closes that gap before your official Certified Third-Party Assessment Organization (C3PAO) review begins.
  • About 25% of firms seeking CMMC certification hit false starts when a pre-assessment fails. The median Supplier Performance Risk System (SPRS) score sits at just 60 out of a required 110. A clear security testing checklist helps you avoid costly rework.
  • A full pre-assessment testing program covers all 14 control families in National Institute of Standards and Technology (NIST) Special Publication 800-171. That runs from access control and audit logging to incident response and system integrity. It can compress the typical 6–18-month remediation timeline and lift first-attempt pass rates.

The defense industrial base is staring down a deadline. Many contractors are still not ready. The CMMC 2.0 program rollout began on November 10, 2025.

Contract solicitations now require defense contractors to prove cybersecurity compliance to win awards. The phased rollout has hard dates.

Level 2 third-party assessments become mandatory by November 2026. Full enforcement across all Department of Defense (DoD) contracts follows by 2028.

The CMMC Readiness Gap by the Numbers

The numbers are sobering. A 2025 survey by CyberSheath found that only 1% of defense contractors report being fully prepared for CMMC assessments.

Worse, 75% believed they were compliant based on self-assessments. Only 4% passed once a third-party assessor looked at their controls.

That gap is the whole problem. It is the space between what firms think they have built and what they can actually show. Pre-assessment security testing exists to close it.

A separate report from Kiteworks and Coalfire confirms the readiness crisis. Only 46% of Defense Industrial Base (DIB) contractors feel prepared for Level 2 certification. A full 57% have not even finished a gap analysis against NIST SP 800-171.

The median SPRS score across the DIB sits at just 60. CMMC Level 2 calls for 110.

Third-party assessors also estimate that 25% of firms seeking certification hit false starts from failed pre-assessments. That means wasted time, real expense, and adverse findings that must be reported in the Enterprise Mission Assurance Support Service.

This is not just a paperwork problem. It is a testing problem. Firms set up controls on paper without proving that those controls work in practice.

A firewall rule can be in place but never tested. It might fail to block traffic it should stop. An access control policy can sit in a binder and still hide gaps that a C3PAO assessor will spot at once.

What This CMMC Pre-Assessment Checklist Covers

So pre-assessment security testing has become one of the highest-value steps a defense contractor can take. You run it before you hire a C3PAO. It lifts your odds of passing on the first try.

This article gives you a domain-by-domain checklist. It walks through each testing task you should finish before you book your official assessment. It applies whether you seek Level 1, Level 2, or Level 3.

Treat security testing as core prep work, not an afterthought. That choice saves you time and money. It also protects your access to more than $849 billion in annual DoD contracts.

Understanding the Pre-Assessment Landscape

Before you work the checklist, it helps to know two things. First, why testing carries so much weight right now. Second, how your testing maps to what a C3PAO will actually judge.

Why Pre-Assessment Testing Matters More Than Ever

The CMMC assessment process is strict, formal, and costly. Hiring a C3PAO usually starts at $50,000. It can run much higher based on your size and complexity.

A failed assessment costs more than money. It costs time.

Rework after a failed assessment can push your timeline back by months. You may miss contract bids that require proven compliance.

Think of pre-assessment security testing as your dress rehearsal. It proves that your written controls are more than words. It shows they are in place, set up right, and working as intended.

The goal is not zero findings. The goal is to find and fix issues before the C3PAO does.

Put it another way. A CMMC readiness assessment reviews your policies, records, and overall compliance posture.

Pre-assessment security testing goes one step further. It proves the controls work under real conditions.

You need both. The testing part is what sets first-time passers apart from the firms that stumble.

The Relationship Between Testing and CMMC Assessment Objectives

CMMC Level 2 assessments cover 110 security practices across 14 control families drawn from NIST SP 800-171. Those break down into 320 separate assessment objectives.

Assessors do not just check that you hold a policy for each control. They check that each objective is met, and they do it three ways:

  • A review of your records.
  • Interviews with your staff.
  • Hands-on technical testing.

Your pre-assessment testing should mirror that. For each control family, prove three things:

  • Your technical setup matches your written steps.
  • Your settings match what policy calls for.
  • Your proof of ongoing compliance exists as logs, scan reports, and system output.

The Pre-Assessment Security Testing Checklist

This checklist follows the NIST SP 800-171 control families. It covers the tests most likely to surface gaps before your official assessment. Each part lists the key checks, the common failure points, and the proof you should have ready.

1. Access Control (AC)

Access control is the largest control family in NIST SP 800-171. It holds 22 requirements. It forms the backbone of how you protect Controlled Unclassified Information (CUI).

It also trips up many firms. Access control is not one tool. It is a web of policies, settings, and technical parts that all have to work as one.

Test multi-factor authentication (MFA). Check that MFA is enforced on each system that handles CUI. That includes cloud services, VPN links, remote access portals, and admin accounts.

Do not just confirm that MFA is on. Try to get in without it. Test bypass paths, such as old protocols or exception accounts that skip MFA.

C3PAO assessors often find MFA gaps in service accounts and admin tools that firms overlook.

Check least privilege and separation of duties. Pull the access lists from each CUI system.

Compare them against your written role-based rules. Flag any account that holds too much power.

Pay close attention to staff who changed roles. They often keep old rights that no one removed. Then test whether a standard user can reach data outside their approved scope.

Test remote access controls. Staff now work from many places, so remote access draws close scrutiny. Check that:

  • Each remote link is encrypted.
  • Session timeouts fire as written.
  • Remote access runs through controlled, monitored entry points.
  • Your VPN split-tunneling setup keeps CUI traffic apart.

Check wireless access limits. Do you run wireless in a site that handles CUI? If so, prove that rogue access points cannot join CUI networks.

Confirm that your wireless encryption meets current standards, and that rogue access point detection works. Then run a wireless survey to spot any device you did not approve.

Look at mobile and external system access. Review and test the rules for mobile devices that touch CUI.

Check that your mobile device management tool enforces the security settings you require. It should also enforce encryption and remote wipe.

2. Awareness and Training (AT)

Training may look like a paper control. C3PAO assessors will still probe whether your program builds real security habits. Testing here proves that training turns into practice.

Run social engineering drills. Send phishing campaigns to your own staff before the assessment. Track click rates, credential entry rates, and report rates.

The results do double duty. They show how well your training works, and they serve as proof of ongoing awareness work. If click rates are high, you still have time to add training and retest.

Check training records. Confirm that each person with CUI access has finished role-based security training on time. Records must be complete and easy to reach.

They should list the content, the dates, and the people who took part. Spot-check that new hires trained before they got CUI access.

Test insider threat awareness. Check that staff can spot and report insider threat signs. Use tabletop scenarios or short interviews with a sample of CUI system users.

3. Audit and Accountability (AU)

Audit logging is the evidence base of your whole security program. Without full, tamper-proof logs, you cannot show that controls work over time. That proof is exactly what CMMC assessors need to see.

Check log coverage. Confirm that each in-scope system writes logs for the required event types:

  • Login attempts, both good and failed.
  • Use of admin rights.
  • File access in CUI stores.
  • Changes to system settings.
  • Account management actions.

Test it by running each event type yourself. Then confirm it lands in the logs with the detail you need: who, what, when, where, and the outcome.

Test log protection. Try to change or delete audit logs, first as a standard user and then as an admin. Confirm that log files resist edits you did not approve.

Confirm that central log collection blocks local tampering. Confirm that log retention meets your written policy.

Do you run a Security Information and Event Management (SIEM) platform? If so, confirm that SIEM ingestion works for each in-scope system.

Check alerts and response. Trigger test events that should raise a security alert. Good examples are failed login thresholds, blocked access attempts, and privilege escalation.

Confirm that alerts fire, reach the right people, and get a response inside your written time limits. That proves your process, not just your tools.

Firms that struggle with audit and accountability often gain from managed cybersecurity services. A managed team watches and reviews logs around the clock, so security events are not just stored but acted on.

4. Configuration Management (CM)

Configuration management is where the tech meets day-to-day discipline. This control family proves that your systems are set up safely.

It also proves that the setup holds steady over time. That last part is known as drift control.

Run baseline scans. Scan each in-scope system against a set security baseline. Use CIS Benchmarks, DISA STIGs, or the vendor hardening guide.

Write down each deviation. Confirm that any exception has a signed risk acceptance on file.

Watch for default settings that no one hardened, such as:

  • Default passwords.
  • Services you do not need.
  • Open ports.
  • Sample apps left in place.

Test change management. Review recent system changes.

Confirm each one followed your written change steps, including impact review, sign-off, and post-change checks. Then test whether someone can change a live system with no alert and no approval.

Check software inventory and whitelisting. Confirm that app whitelisting or software limits block installs you have not approved on CUI systems. Try to install software that is not on the list.

The attempt should fail, and it should be logged. Strong vulnerability management starts with knowing just what software runs in your environment.

5. Identification and Authentication (IA)

These controls make sure that only approved people reach CUI systems. They also make sure the system can confirm who each person is.

Test password rules. Confirm that your rules for length, complexity, history, and max age are enforced by the system, not just written down. Try to set a password that breaks the rules.

It should be rejected. Test lockout limits, and confirm that a locked account needs admin help to unlock.

Check how you manage credentials. Confirm that default passwords are gone from each device. Confirm that shared accounts are removed or tightly held.

Confirm that service account credentials are stored safely. Then test whether an expired or revoked credential still opens a door.

Check identity proofing. Review and test how you issue new credentials.

Look at the ID checks, how you hand the credential over, and how you set the first password. The process must block interception and stop anyone from issuing credentials without approval.

6. Incident Response (IR)

CMMC assessors want more than an incident response plan on paper. They want proof that it works. Testing this area before the assessment shows real operating maturity.

Run a tabletop exercise. Hold at least one tabletop drill for a cyber incident that touches CUI. The scenario should test how you detect, respond, contain, and recover.

It must also test your notice deadlines, including the 72-hour report to the DoD. Write down the drill, the people, the choices made, and the lessons learned.

Test detection and containment. Simulate security events and watch what happens. Useful ones include:

  • Malware run inside a sandbox.
  • Attempts to move data out of your network.
  • Lateral movement between systems.

Judge three things. Do your monitoring tools catch it? Does your team respond well?

Do your containment steps limit the damage? This hands-on work proves your plan is more than theory.

Check forensic readiness. Confirm that your environment can support an investigation. Logs must be kept long enough.

Evidence steps must be written down. Staff must know how to preserve evidence without spoiling it. Test it by collecting evidence for a mock incident, then judge how complete and sound the result is.

7. Maintenance (MA)

Maintenance controls keep upkeep work, both routine and one-off, from opening holes or exposing CUI.

Check patch management. Run vulnerability scans to find missing patches on each in-scope system. Cover operating systems, apps, firmware, and network gear.

Compare the results against your written patch windows. Confirm that critical patches land on time, and track each finding through to a fix.

Test remote maintenance. Do you allow remote upkeep on CUI systems? If so, confirm that sessions are encrypted, backed by MFA, logged, and watched.

Test whether remote tools grant only the access the task needs. Confirm that session recording or oversight works.

Review maintenance staff controls. Confirm that maintenance staff are approved and watched as required. That covers your own team and outside contractors alike.

Their access must stop at the systems they need. Also confirm that tools and media are checked before they touch a CUI system.

8. Media Protection (MP)

Media protection controls govern how you store, move, and destroy CUI on physical and digital media. Testing here proves that your controls block data leaks.

Test media encryption. Try to copy CUI onto an unencrypted USB drive, an external hard drive, and optical media. Confirm that data loss prevention rules or device limits block the copy.

If you do allow encrypted portable media, confirm the encryption meets FIPS 140-2 validated standards.

Check media sanitization. Review and test how you wipe gear that has held CUI.

Confirm that hard drives, solid-state drives, and other media are wiped by NIST SP 800-88 compliant methods before reuse, transfer, or disposal. Ask for proof of recent wipes.

Check CUI marking and handling. Review digital and physical CUI assets. Confirm each one carries the CUI markings it needs.

Test whether your systems enforce those markings on files and email. Then confirm that staff handle marked material the right way.

9. Personnel Security (PS)

Personnel security testing proves that CUI access goes only to screened, approved people. It also proves that access ends the moment it is no longer needed.

Test account termination. Review recent departures. Confirm that each person lost system access inside your written time limit.

Try to log in with the credentials of a person who just left, and confirm the account is dead.

This is a frequent C3PAO finding. Firms often hold a good termination policy but act on it too slowly.

Check personnel screening. Confirm that each person with CUI access has passed the required background screening.

Confirm those records are on file. Contractors, temps, and third-party staff must be screened too.

Test transfer steps. When staff change roles, confirm that someone reviews and adjusts their access to match the new job. Then test whether rights carried over from the old role are gone.

10. Physical Protection (PE)

Physical protection testing proves that CUI stays safe from entry you did not approve. That covers CUI on a disk and CUI on paper.

Test physical access controls. Try to enter areas where CUI is handled or stored without the right approval. Test each control that guards those areas:

  • Badge readers.
  • Door locks.
  • Combination locks.
  • Visitor sign-in steps.

Confirm that access logs capture entry and exit. Keep those logs as long as policy states.

Check environmental protection. Confirm that server rooms and data centers holding CUI systems have the right environmental controls:

  • Fire suppression.
  • Temperature and humidity monitoring.
  • Water detection.
  • Emergency power.

Then test whether environmental alarms reach the right people.

Review visitor management. Test how you escort and admit visitors.

Confirm that visitors are identified, logged, and escorted in CUI areas. Confirm that any temporary badge is returned and switched off when they leave.

11. Risk Assessment (RA)

Risk assessment controls ask you to find, judge, and rank the risks to CUI. Testing here proves that your risk process yields results you can act on. It also proves that those results shape your security choices.

Run full vulnerability scans. Run authenticated scans across each in-scope system. Cover every layer:

  • Network gear.
  • Servers.
  • Workstations.
  • Applications.
  • Cloud services.

Compare the results against your written risk assessments to confirm that known flaws are captured and tracked.

NIST SP 800-171 calls for vulnerability scanning at least every 90 days. Confirm that your scan history proves you meet that pace.

Consider penetration testing. Penetration testing is required outright only at CMMC Level 3.

Even so, it is high value for Level 2 firms as a pre-assessment check. A skilled network penetration test can reveal what scanners miss.

That includes business logic flaws, chained attack paths, and privilege escalation routes. Read more in our guide to penetration testing for CMMC 2.0 compliance.

Check your risk assessment records. Review the assessment itself. It should cover each CUI system, name current threats and flaws, weigh the impact, and set risk levels that drive your control priorities.

It must also be current. Assessors expect a recent risk assessment, not a file that has sat untouched for years.

12. Security Assessment (CA)

This control family is a bit meta. It asks you to assess your own controls and keep a plan for fixing what falls short. Your pre-assessment testing feeds it directly.

Review your System Security Plan (SSP). The SSP is the base document for a CMMC assessment. Confirm that it maps your current environment: each in-scope system, the network design, the data flows, and the controls in place.

Walk through each control write-up and test whether the real world matches it. A recent Greenberg Traurig analysis noted that an incomplete SSP can preclude completion of a third-party assessment entirely.

Review your Plan of Action and Milestones (POA&M). Confirm that each known gap has a fix plan with a realistic date.

Under CMMC 2.0, POA&Ms must be resolved within 180 days of the conditional assessment. Assessors will ask about progress, so keep proof that the work is moving.

Run an internal mock assessment. Walk the 320 assessment objectives as if you were the C3PAO. For each one, try to find and hand over the proof an assessor would ask for.

The drill exposes missing records, messy evidence, and controls that live in policy but not in practice. It is one of the highest-value things you can do before the real assessment.

13. System and Communications Protection (SC)

These controls guard CUI while it moves and while it sits in your systems. This control family is dense, so test it with care.

Test encryption. Confirm that each piece of CUI in transit is encrypted with FIPS-validated crypto modules. Test each path CUI travels:

  • Email.
  • File transfer.
  • VPN tunnels.
  • Web app links.

Use network capture tools to confirm that CUI never crosses the wire in plain text.

Then check data at rest. Encryption must cover each system that stores CUI, including databases, file shares, backup media, and cloud storage.

Check network segmentation. Does your firm use a secure enclave to isolate CUI work?

If so, test the boundary controls hard. Try to reach CUI systems from network segments that hold no CUI.

Confirm that firewall rules, access lists, and network design block lateral movement. Segmentation failures rank among the most common and most costly findings in CMMC assessments.

Test boundary protection. Confirm that each link between your network and an outside system is watched, controlled, and written down.

Test whether data loss prevention rules catch and stop CUI leaks. Confirm that your DNS, web, and email controls block known bad content.

Check cloud settings. Do you use cloud services to handle or store CUI? Then confirm those settings meet FedRAMP requirements and that the shared responsibility model is set up right.

Your cloud engineering team should have identity federation, conditional access policies, and data residency controls in line with CMMC.

14. System and Information Integrity (SI)

These controls guard against malicious code, unwanted changes, and flaws in your systems. This is where your security operations get put to the test.

Check malware defense. Confirm that antivirus and endpoint detection and response tools run on each in-scope system. Signatures must be current and real-time scanning must be on.

Test it with a harmless test file (EICAR) to confirm detection. Then confirm that malware events raise alerts and get looked into as your steps require.

Test security monitoring. Confirm that your tools catch the events CMMC cares about:

  • Blocked access attempts.
  • Malware activity.
  • Odd network traffic.
  • System integrity breaks.

Generate test events and follow them all the way through detection, alerting, and review.

Check file integrity monitoring. Confirm that file integrity monitoring covers critical system files and settings. Test it by changing a watched file.

The change should be caught and flagged. Confirm that integrity checks run as often as your policy states.

Test spam and content filters. Confirm that email controls block phishing, bad attachments, and spam.

Test web filtering to confirm that known bad sites are blocked. Download controls should stop anyone from installing a program you have not approved.

Building Your Pre-Assessment Testing Program

A checklist alone will not get you certified. You also need a schedule, the right partners, and a clear way to rank the fixes that testing turns up.

Establishing the Right Testing Timeline

Pre-assessment security testing is not a one-day event. It is a program, and it should start well before your C3PAO date. The typical CMMC prep window of 6 to 18 months should carry testing milestones all the way through.

Six to twelve months before assessment. Start with full vulnerability scanning and baseline reviews.

These surface the most findings early, which buys your team the most time to fix them. Run your first phishing drill and tabletop exercise in this phase.

Three to six months before assessment. Test specific control families in depth.

Focus where your gap analysis found weak spots. This is the right window for penetration testing, since it leaves time to fix findings and retest.

One to three months before assessment. Run your internal mock assessment. Confirm you can produce proof for all 320 assessment objectives.

Run final vulnerability scans, confirm that earlier findings are fixed, and check that POA&M items are on track for the 180-day window.

Selecting the Right Testing Partners

Not every security testing firm knows CMMC. A generic penetration tester may hand you a list of flaws with no tie to specific NIST SP 800-171 controls. Your team is then left to bridge the gap between test results and compliance.

The right partner brings both technical depth and CMMC know-how. They should know which controls C3PAOs press hardest.

They should know what counts as good proof. They should frame findings so they map straight to your SSP and POA&M.

A virtual CISO, or outsourced chief information security officer, can steer the whole prep effort. That keeps your testing work in line with your wider compliance roadmap.

Some firms need advice and hands-on build work at once. One partner that does both beats juggling many vendors. It cuts complexity and makes sure gaps get fixed, not just logged.

Essendis pairs former Big Four audit methodology with hands-on security engineering. Our cybersecurity advisory services take defense contractors from found gaps to proven compliance.

Prioritizing Remediation After Testing

Pre-assessment testing will turn up findings. The key is a clear way to rank fixes by CMMC impact, not by a generic risk score.

Start with findings that would earn a “Not Met” mark on any of the 320 assessment objectives. Those are your must-fix items.

Next, take on findings that could leave an assessor unsure, where a control is partly in place but the proof falls short. Last, take on findings that improve security beyond the CMMC minimum.

Keep tight records the whole way. Each finding needs a matching fix plan in your POA&M. Each completed fix needs a retest.

That retest proof becomes part of your assessment package. It shows you did not just find issues. It shows you solved them.

Common Pre-Assessment Pitfalls to Avoid

Testing scope that is too narrow. Many firms test only the obvious CUI systems and skip the supporting gear. Your CUI environment is wider than the boxes where CUI lives.

It also holds each system that could open a path to CUI: admin workstations, login servers, backup systems, and network gear. If a system sits in your CMMC assessment scope, it belongs in your testing scope.

Confusing vulnerability scanning with penetration testing. A scanner finds known flaws based on software versions and settings.

Penetration testing puts skilled humans on the job. They chain flaws together, test business logic, and copy real attack methods.

Both belong in pre-assessment testing, but they are not the same thing. Firms that lean on scanning alone often miss the complex flaws that a C3PAO assessor, or a real attacker, would find.

Testing with no written proof. Thorough testing with no records is like studying for an exam without taking notes. Each test should leave a trail:

  • Scan reports.
  • Test logs.
  • Screenshots.
  • Finding summaries.
  • Fix records.

That proof is not just handy for the assessment. You need it to show that you keep checking your controls over time.

Treating pre-assessment testing as a one-time job. CMMC compliance runs all year, not on one day.

Your program should set a steady rhythm for vulnerability scanning (at least every 90 days), access reviews, setting audits, and incident drills. Firms that bake testing into normal operations find ongoing compliance far lighter than firms that scramble before each cycle.

Ignoring third-party and vendor risk. You are only as strong as the weakest link in your supply chain. If a vendor can reach your CUI environment, that vendor belongs in your pre-assessment testing.

A solid vendor risk management program finds, rates, and watches third-party security. It keeps a vendor's weak spot from breaking your CMMC compliance.

From Testing to Certification: Connecting the Dots

Pre-assessment security testing does not stand alone. It is the tissue that links your written program to your real security posture.

Done well, it yields the proof a C3PAO needs to mark each control “Met.” It also lifts your true defense against the threats aimed at the defense industrial base.

The defense contracting landscape is shifting fast. Phase 1 of the CMMC rollout is already live. It makes self-assessments a pre-award condition for new contracts.

Phase 2 arrives in November 2026 and requires third-party Level 2 certification. By November 2028, full enforcement covers each DoD contract that involves Federal Contract Information or CUI.

Firms that start full pre-assessment testing now get ahead of the curve. They find and fix gaps while there is still time.

They build the evidence sets that assessors expect. They also build the security maturity that keeps them compliant long after the assessment ends.

The cost of delay is no longer just lost contracts. It is the exposure of sensitive national security data.

More than $849 billion in annual DoD contracts are at stake, and nation-state actors keep targeting the defense supply chain. So the question is not whether to invest in pre-assessment security testing. It is how fast you can start.

Is your firm preparing for CMMC certification and looking for expert help with pre-assessment security testing? Please contact Essendis to speak with a cybersecurity advisor who knows the defense industrial base well.

Frequently Asked Questions

How far in advance of my C3PAO assessment should I begin pre-assessment security testing?

Start six to twelve months before your assessment date. Begin with broad work like vulnerability scanning and baseline reviews. That gives you the most time to fix what you find.

More targeted work should follow three to six months out. That includes penetration testing and mock assessments.

Save final validation scans and evidence reviews for the last one to three months. Firms that squeeze this timeline tend to rush their fixes, and rushed fixes are the ones assessors catch.

What’s the difference between a CMMC readiness assessment and pre-assessment security testing?

A CMMC readiness assessment is a broad look at your compliance posture. It reviews policies, steps, records, and overall fit with CMMC.

Pre-assessment security testing is one part of that work. It focuses on proving that your controls work as designed.

Think of the readiness assessment as checking that you have the right answers on the test sheet. Pre-assessment security testing confirms you actually did the work behind those answers. Both matter, and most successful firms run them side by side.

Do I need penetration testing for CMMC Level 2?

CMMC Level 2 does not explicitly mandate penetration testing in all cases. It does require vulnerability scanning at least every 90 days, plus extra testing for custom software applications.

Still, penetration testing is strongly advised for Level 2 firms as a pre-assessment check. Many prime contractors now ask their subcontractors for penetration testing whatever their CMMC level.

Level 3 firms must run annual penetration testing as a hard requirement. For more on testing across levels, see our article on penetration testing for CMMC 2.0.

Can my organization conduct pre-assessment security testing internally, or do I need an outside firm?

You can run much of it in house. That covers vulnerability scanning, setting audits, access reviews, and tabletop drills.

Some work still gains from outside help. Penetration testing works best when the testers do not know your environment. They can then act like a true outside threat.

Outside testers also bring CMMC-specific practice. They spot compliance gaps your own team may walk past, simply because your team knows the environment too well.

What happens if my pre-assessment testing reveals significant gaps?

That is the whole point. Finding gaps now beats finding them during the official C3PAO assessment.

When testing shows a gap, log it in your POA&M with clear fix steps and a realistic date. Handle the worst gaps first, meaning the ones that would earn a “Not Met” mark on an assessment objective.

Under CMMC 2.0, firms can earn a conditional certification with up to a set number of open POA&M items. Those items must be resolved within 180 days. Even so, the surest path is to close as many findings as you can before the assessment starts.

How does pre-assessment testing apply to organizations using cloud environments for CUI?

Cloud brings its own testing needs. You must confirm that your cloud service provider meets FedRAMP requirements. You must confirm that your cloud settings line up with CMMC controls.

You must also confirm that the shared responsibility model is set up right. That means you have secured the parts that fall to you as the customer.

Your testing should cover these areas:

  • Cloud identity and access management.
  • Data encryption.
  • Network security group settings.
  • Logging and monitoring.
  • Data residency controls.

Do you run a secure enclave for CUI? Test the enclave itself. Then test the boundary controls that keep it apart from the rest of your environment.

What documentation should I retain from pre-assessment testing?

Keep it all. These records all feed your assessment package:

  • Vulnerability scan reports.
  • Penetration testing findings.
  • Setting audit results.
  • Phishing drill metrics.
  • Tabletop records.
  • Fix evidence.
  • Retest reports.

Sort it by NIST SP 800-171 control family so assessors can find the proof for a given objective fast. Timestamped proof is worth the most. It shows not just that controls exist, but that you keep them running over time.

Talk to a Cloud Cybersecurity Expert

Thank you for contacting Essendis. Our team is reviewing your submission and will be in touch shortly. 
We look forward to assisting with your cybersecurity and cloud computing needs. 

Continue Exploring Essendis’ Offerings

Return to Essendis
Oops! Something went wrong while submitting the form.