CMMC Level 2 compliance gap assessment: what C3PAO assessors actually verify

Key takeaways
CMMC Level 2 requires 110 security practices mapped to NIST SP 800-171 r2 -- contractors who self-assess tend to score 20 to 40 points higher on SPRS than C3PAO assessors find when they verify the same environment.
The three control families that produce the most findings in C3PAO assessments are Audit and Accountability (AU), Configuration Management (CM), and Identification and Authentication (IA) -- not the ones contractors spend the most time preparing.
Evidence gaps kill assessments more reliably than missing controls: a control that is deployed but undocumented scores the same as one that was never implemented.
Contractors that scope their CUI environment too narrowly before assessment -- excluding dev environments, collaboration tools, and cloud storage -- create audit findings for assets they assumed were out of scope.
A Plan of Action and Milestones (POA&M) that lists gaps without assigned owners, realistic timelines, and remediation evidence will not satisfy a C3PAO assessor -- it will generate additional findings.
CMMC Level 2 is a point-in-time certification with a 3-year renewal cycle, but configuration drift in the first 12 months post-assessment is common enough that it should be treated as a continuous operational requirement, not a project.
TL;DR
CMMC Level 2 gap assessments consistently reveal the same structural problem: contractors understand what the 110 controls require in theory and underestimate what demonstrating them under audit conditions actually takes. The SPRS score gap between self-assessment and C3PAO verification is not a documentation problem -- it is a pipeline problem. If evidence collection is not automated and continuous, the assessment will find gaps that the internal team genuinely did not know existed.
What the SPRS score gap looks like in practice
A 90-person defense contractor has been self-assessing for two years. Their SPRS score sits at -47, which they consider acceptable given their remediation roadmap. They engage a C3PAO eight months before a contract renewal that requires CMMC Level 2 certification. The initial C3PAO gap assessment comes back at -112. The delta is not because the contractor was dishonest in their self-assessment. It is because the self-assessment counted controls as implemented when someone on the team believed they were implemented. The C3PAO asked for evidence.
Three of the largest point deductions came from audit log configurations that had been partially deployed two years earlier and never fully validated, MFA enforcement that applied to most systems but had a documented exception for a legacy application still in production, and a system security plan that described controls accurately but had not been updated in 14 months. None of these were unknown risks. They were tracked in internal documents. They just had not been connected to the evidence pipeline that an assessor would pull.
How the 110 controls actually get evaluated
CMMC Level 2 maps directly to NIST SP 800-171 r2 -- 110 practices across 14 control families. The assessment is not a questionnaire. A C3PAO assessor evaluates three things for each practice: the existence of a documented policy or procedure, evidence of technical implementation, and evidence of operational consistency over time. All three need to be present. A policy without technical implementation fails. A technical control without documentation of consistent operation fails. The scoring model assigns each practice a point value, and deficiencies reduce the SPRS score from a theoretical maximum of 110.
Example
Practice 3.3.1 (AU) requires that organizations create and retain system audit logs to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. Assessors do not accept a SIEM license as evidence. They ask to see the audit log configuration for systems in scope, the retention settings, evidence that logs are being reviewed, and records of any alerts generated. A contractor running a SIEM that ingests 30% of in-scope systems with a 60-day retention window will receive a finding on this practice even if the technology investment was real.
The control families with the highest aggregate point values in NIST SP 800-171 r2 are Access Control (AC) at 22 practices and Audit and Accountability (AU) at 9 practices. These two families account for roughly 28% of total SPRS point exposure. Contractors who focus remediation effort on Identification and Authentication (IA) because MFA is visible and auditable often underinvest in AU, which produces findings that are harder to remediate quickly because they require log architecture changes.
What Vulnox sees in Level 2 readiness assessments
Assessment base: Vulnox assessment data, 2024-2025, defense contractor environments preparing for CMMC Level 2 C3PAO assessments
Self-assessed SPRS scores overstate posture by a consistent margin
In CMMC Level 2 readiness assessments conducted for defense contractors, the gap between client self-assessed SPRS scores and Vulnox-evaluated scores follows a predictable pattern. Contractors who have been self-assessing for more than 12 months show larger deltas than those doing their first structured assessment -- because they have had more time to develop confidence in controls that have not been externally validated. The most common source of inflation is counting partially implemented controls as implemented. A control is either fully implemented with evidence of consistent operation or it is not implemented for scoring purposes.
Contractors using their self-assessed SPRS score to estimate C3PAO readiness are working from optimistic data. The practical implication is that remediation timelines built on self-assessed scores are typically 30 to 50% shorter than the remediation timelines that emerge after an independent gap assessment.
Configuration Management findings cluster around change control, not hardening
The Configuration Management control family generates more findings than contractors expect, and the findings are not usually about baseline hardening. They are about change control: no documented process for approving configuration changes, changes made by administrators that were not recorded, and security configuration baselines that exist as documents but have not been compared to current system states. In several assessments, systems had drifted from their documented baselines within 6 months of the baseline being written, and nobody had run a comparison since.
A hardened baseline that is not maintained and compared to current state on a scheduled basis does not satisfy the CM control family at Level 2. The evidence requirement is not a document -- it is a record of the ongoing process.
CUI scope boundaries are routinely drawn too narrowly
In scoping interviews conducted before Level 2 readiness assessments, contractors consistently exclude assets that are later determined to be in scope. The most common omissions are collaboration platforms where CUI has been shared informally, cloud storage instances provisioned by individual employees rather than IT, and development and test environments built from copies of production data. Assets outside the declared boundary are not covered by the controls inside it, and a C3PAO assessor who finds in-scope CUI on an out-of-scope system will expand the assessment boundary on the spot.
Scope definition should include a digital footprint analysis before the boundary is finalized. The question is not 'what systems are supposed to handle CUI' but 'what systems have actually touched CUI in the last 12 months.'
The control that is easiest to implement is often the one that fails
Common belief
Most contractors treat Identification and Authentication (IA) as a low-risk control family because MFA is widely deployed and the requirement is straightforward: implement multi-factor authentication for privileged accounts and remote access. It is one of the most visible and auditable controls in the framework. Contractors who have MFA in place tend to consider IA a resolved finding before the assessment starts.
What we found
In Level 2 readiness assessments, IA findings that survive into the formal C3PAO assessment almost always involve documented exceptions that were treated as permanently resolved rather than as risks requiring compensating controls and scheduled review. The exception exists, the documentation exists, but the compensating control and the review cadence do not.
The IA findings that emerge in C3PAO assessments are rarely about whether MFA exists. They are about exceptions. A legacy application that cannot support MFA and has a documented exception. A service account with a long-standing password that is not rotated. Remote access that requires MFA for employees but not for contractors using the same VPN infrastructure. These exceptions were created for operational reasons and in many cases are tracked in internal documentation. They do not disappear just because MFA is deployed elsewhere. Assessors specifically look for accounts and access paths that fall outside the standard enforcement perimeter.
Where Level 2 readiness programs consistently fall short
The SSP as a living document requirement
The System Security Plan is treated by most contractors as a compliance artifact -- something to produce before assessment and update when controls change. CMMC Level 2 requires an SSP that accurately reflects the current state of control implementation. In practice, SSPs drift from reality within months of being written. Configuration changes happen, personnel change, systems are added or retired. An SSP that was accurate 14 months ago and has not been reviewed since will generate findings during assessment because the document will contradict what the assessor observes in the environment. The SSP is not a one-time deliverable. It is a document with a maintenance requirement.
POA&M quality as an assessment factor
Contractors who have known gaps going into a C3PAO assessment often believe that a POA&M documenting those gaps demonstrates good faith and will reduce assessment findings. It does not. A POA&M is evaluated on its quality: assigned owners, realistic completion dates, interim compensating controls, and evidence of progress. A POA&M that lists 30 open items with no owners and no completion dates does not demonstrate a remediation program. It demonstrates awareness of gaps without a credible plan to close them. Assessors distinguish between the two.
Incident response plans that have never been tested
Incident Response (IR) control family requirements include not just documenting an IR plan but testing it. The testing requirement is specific: the plan must be exercised through tabletop exercises or simulations, and records of those exercises must exist. Most contractors have an IR plan. Fewer have records of tabletop exercises. Almost none have updated their IR plan based on findings from those exercises. An IR plan with no exercise history and no update record will produce findings in this control family regardless of how detailed the plan document is.
Continuous monitoring treated as a reporting requirement
Continuous monitoring at CMMC Level 2 requires ongoing awareness of security threats and vulnerabilities, not periodic reporting. The distinction matters in assessment. A quarterly vulnerability scan with a report delivered to management satisfies a reporting cadence. It does not satisfy continuous monitoring. Assessors look for evidence of ongoing scanning, alerting, and response activity -- not a schedule of reports. The control requires that the organization knows what is happening in its environment on an ongoing basis, and evidence of that awareness is operational telemetry, not summary documents.
Where Level 2 compliance pressure is heading
The SPRS score will become a procurement signal that primes contractors for failure: buyers will start using SPRS scores in competitive evaluations before C3PAO certification is required, creating incentive to inflate self-assessments, which will produce a wave of CMMC certification failures when C3PAO verification begins at scale.
SPRS scores are visible to contracting officers and are already being referenced in some contract evaluations. The self-assessment mechanism has no external validation at Level 2 except the C3PAO certification itself. If SPRS scores become an informal competitive differentiator before certification is required, the incentive to inflate them increases. When C3PAO certification becomes mandatory and those scores are verified, the gap between stated and actual posture will produce a high failure rate in the first certification cycle.
Confidence: highDoD reporting on first-cycle C3PAO certification failure rates for organizations that had self-assessed SPRS scores above -20 before assessmentThe demand for pre-assessment gap analysis will create a market for low-quality readiness assessors who produce favorable findings to win repeat business, and the damage will not be visible until C3PAO assessment day.
As the CMMC certification deadline pressure increases, contractors will seek gap assessment vendors who tell them they are close to ready rather than vendors who give them accurate findings. The incentive structure rewards optimistic assessors in the short term. The correction arrives only when the C3PAO assessment finds the gaps the readiness assessment missed -- at which point the certification timeline collapses.
Confidence: mediumC3PAO assessors publicly reporting consistent patterns of readiness assessment findings that did not match their own assessment findings for the same client environments
Why most contractors are solving the wrong problem
The dominant focus in CMMC Level 2 preparation is controls -- which controls are implemented, which are partially implemented, which are missing. That framing is correct but incomplete. The assessment is not a control audit. It is an evidence audit. A control that is implemented and undocumented scores zero. A control that is documented and partially implemented scores partial credit. The practical implication is that organizations with 85 fully implemented controls and a strong evidence pipeline will often outperform organizations with 100 implemented controls and informal evidence collection. Investing in evidence infrastructure -- automated log retention, documented review cadences, SSP maintenance workflows -- before finishing control implementation is not backwards. It is often the right sequence.
Counterargument
The counterargument is that evidence without controls is useless, and some organizations genuinely have control gaps that no amount of documentation will resolve. That is true. But in practice, the contractors who fail C3PAO assessments most often are not the ones with structural control gaps -- they are the ones who implemented controls years ago and never built the operational habits to demonstrate continuous operation. The control gap is real but it is a documentation gap masquerading as a technical one.
One thing to do before engaging a C3PAO
Run your SSP against your actual environment before an assessor does. Pick five controls from Audit and Accountability and five from Configuration Management -- the two families that produce the most C3PAO findings -- and verify that the evidence described in your SSP exists, is current, and would be retrievable by someone who does not already know your environment. If it takes more than 30 minutes to pull that evidence for 10 controls, your evidence pipeline is not ready for a C3PAO assessor who will be looking at all 110.
Further Reading
Gap Analysis
framework gap analysisVulnerability Assessment
comprehensive vulnerability assessmentCMMC 2.0 levels explained: which tier applies to your DoD contract and what it actually requires
CMMC Level 2 compliance gap assessment and what C3PAO assessors actually verifyNIST SP 800-30 Risk Assessment Guide
NIST risk assessment guideNIST Vulnerability Assessment Definition
NIST vulnerability assessment definitionUnderstanding Compliance Gap Analysis
compliance gap analysis guide
Frequently Asked Questions
What is the typical gap between self-assessed and C3PAO-verified SPRS scores for CMMC Level 2?
In Vulnox readiness assessments, contractors who have been self-assessing for more than 12 months show the largest deltas between their self-assessed SPRS scores and independently evaluated scores -- often 30 to 60 points -- because partially implemented controls are counted as implemented during self-assessment but scored as deficient when evidence is requested.
Which CMMC Level 2 control families produce the most C3PAO assessment findings?
Audit and Accountability (AU) and Configuration Management (CM) generate more findings than contractors typically prepare for. AU findings cluster around incomplete log coverage and retention. CM findings involve change control records and baseline drift rather than hardening configurations.
What evidence does a C3PAO assessor require for CMMC Level 2 controls?
C3PAO assessors evaluate three things per practice: a documented policy or procedure, evidence of technical implementation, and evidence of consistent operation over time. All three must be present. A deployed control without documentation of consistent operation scores the same as an unimplemented one.
How should contractors define the CUI boundary before a CMMC Level 2 gap assessment?
Scope should reflect where CUI has actually existed in the last 12 months, not where it is supposed to exist. Digital footprint analysis before finalizing scope routinely finds collaboration platforms, cloud storage, and dev environments containing CUI that were excluded from the initial boundary definition.
Does a Plan of Action and Milestones (POA&M) help during a C3PAO assessment?
Only if it meets quality standards. A POA&M with assigned owners, realistic completion dates, interim compensating controls, and evidence of progress demonstrates a credible remediation program. A POA&M that lists open items without owners or timelines generates additional findings rather than mitigating them.
How often does CMMC Level 2 certification need to be renewed?
CMMC Level 2 certification has a 3-year renewal cycle, but configuration drift in the months following certification is common. Controls that were fully implemented at assessment date can degrade through routine IT changes, personnel turnover, and undocumented exceptions -- making continuous monitoring a post-certification requirement, not just a pre-assessment one.
What is the fastest way to identify CMMC Level 2 gaps before a C3PAO assessment?
Pull evidence for 5 Audit and Accountability controls and 5 Configuration Management controls from your current SSP and verify that the evidence exists, is current, and is retrievable without internal guidance. If 10 controls take more than 30 minutes to evidence, the pipeline is not ready for 110.
Related Articles

GovRAMP Moderate authorization: why the Significant Change Request process catches providers off guard
GovRAMP Moderate is the first tier where you need a government sponsor, annual 3PAO reassessment, and a Significant Change Request process that can pause normal product releases for months. Most providers who stall post-authorization were not prepared for what maintaining Moderate status actually costs operationally.

GovRAMP Low+ authorization: the impact level that punishes providers who get the CUI boundary wrong
GovRAMP Low+ is where providers handling limited Controlled Unclassified Information land — or discover they should not be there. The defining failure is not a missing control. It is a CUI boundary that was drawn before anyone asked what data the government actually sends through the system.

GovRAMP High authorization: why FIPS-validated crypto and personnel security controls catch providers off guard
GovRAMP High is where cloud providers discover that having strong encryption is not the same as having FIPS 140-2 validated encryption — and that distinction alone has derailed authorizations from vendors who passed every other control family. The architectural constraints at High are qualitatively different from every lower tier.
Ready to Secure Your Digital Assets?
Get a comprehensive vulnerability assessment for your website today.