Contractors often believe they're ready for a Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment. Assessors regularly find they aren't.
The gap between the two is rarely about effort. It’s almost always about a small, repeatable set of patterns.
Those patterns didn’t disappear when the Department of War paused mandatory third-party (C3PAO) certification assessments on July 13, 2026. They’re just as present in a self-assessment as they were in a C3PAO assessment, and right now, nobody outside your organization is checking for them.
Dig deeper below to learn more.
The patterns below come from what assessors have found across dozens of Level 2 engagements. They hold up regardless of who is reviewing your environment, whether that is a C3PAO or your own team.
Scoping errors
Reducing your Controlled Unclassified Information (CUI) boundary can be an effective way to control cost, but if you scope too narrowly, you could leave systems that touch CUI outside the assessment entirely. The single most common root cause is a CUI boundary that does not match reality.
SPRS scores that do not reflect the environment
A Supplier Performance Risk System (SPRS) score submitted months or years ago rarely matches a live environment. Systems change, staff turnover, and configurations drift. A stale score is one of the fastest ways to turn a routine assessment into a failed one.
SSPs written to the control level, not the objective level
A System Security Plan (SSP) that describes “we use MFA” in general terms is not enough. CMMC Level 2 is assessed against 320 individual assessment objectives underneath the 110 controls, and assessors validate at that level of detail.
Documentation that stops at the control title leaves an assessor guessing on how a requirement is met. That ambiguity gets resolved against the contractor. If it’s not documented, it doesn’t happen.
Policies that do not match actual practice
A written access control policy that says one thing while the environment does another is one of the most common findings in any audit. Assessors check both the document and the configuration, and a mismatch is flagged regardless of intent.
Misunderstanding what a POA&M can cover
Contractors sometimes plan to defer high-value controls (access control, audit logging, multifactor authentication) onto a Plan of Action and Milestones (POA&M), not realizing that a Conditional Level 2 result only allows 1-point requirements on a POA&M, with a short list of items that can never be deferred at all.
External Service Provider gaps in the Shared Responsibility Matrix
When a cloud or managed service provider handles part of the CUI environment, contractors need a documented Shared Responsibility Matrix (SRM) that shows exactly which controls the provider owns and which the contractor owns. Vendor delays in producing this documentation are a recurring bottleneck, and an undocumented gap between provider and contractor responsibility is treated as an unmet control.
Evidence that does not map cleanly to controls
Screenshots, logs, and training records that exist somewhere in the organization are not the same as evidence that is organized, current, and mapped to the specific control and objective it supports. If an assessor has to hunt for proof, or if the evidence is stale, the control is treated as not met.
Avoiding these patterns does more than protect you from a failed assessment. It changes how you look to a prime contractor evaluating subcontractors right now.
“Contractors are responsible for their own security and risk — paused oversight doesn't change that, it raises the burden of proof,” says Ketan Patel, ISI Senior Vice President, Compliance. “The gaps that fail assessments don't disappear when no one's checking. Contractors who act now control the outcome; those who wait let a prime or the government decide it for them.”
Whether you're preparing for a self-assessment or a future C3PAO review, these questions map directly to the patterns above. If you can't answer one confidently, that's the first gap to close.
With third-party certification paused, the attention to detail that used to come from a C3PAO now must come from you. The 110 controls haven’t changed, and neither has the cost of getting them wrong.
Contractors who treat self-assessment with the same rigor as a third-party assessment, scoping honestly, documenting to the objective level, and keeping evidence current, are the ones who will be ready when the CMMC Reform Task Force provides its recommendations, and the ones who look like the lowest-risk option to a prime contractor in the meantime.
Scoping errors. An inaccurate CUI boundary, whether too broad or too narrow, affects every control that follows and is the most common root cause behind other findings.
It can, but only if it is treated with the same rigor as a third-party review. Without an outside check, the discipline must come from the organization itself, including objective-level documentation, honest evaluation of what is implemented versus planned, and a true understanding of what the controls and objectives require.
A mock assessment against the full 320 assessment objectives, combined with an honest review of your CUI scope and your System Security Plan. Most failure patterns surface in one of those two places.
No. Self-assessment still measures your environment against the same 110 controls, and the aforementioned patterns cause self-assessments to be inaccurate just as easily as they cause a C3PAO review to fail.