ISI Insights

Why Defense Contractors Fail CMMC Level 2 Assessments

Written by Ketan Patel, MBA, CISA | Jul 28, 2026, 4:40:44 PM

Executive Brief

Contractors often believe they're ready for a Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment. Assessors regularly find they aren't.

The gap between the two is rarely about effort. It’s almost always about a small, repeatable set of patterns.

Those patterns didn’t disappear when the Department of War paused mandatory third-party (C3PAO) certification assessments on July 13, 2026. They’re just as present in a self-assessment as they were in a C3PAO assessment, and right now, nobody outside your organization is checking for them.

  • Across dozens of CMMC Level 2 assessments, the same handful of gaps show up time and again, regardless of company size or industry
  • Most failure patterns trace back to a short list of root causes: scoping, documentation depth, and evidence that doesn’t match reality
  • These patterns apply just as much to a self-assessment as they did to a C3PAO review, and self-assessment is what most contractors are relying on right now
  • Understanding these patterns is the fastest way to close gaps before a level 2 assessment, self or C3PAO

Dig deeper below to learn more.

The Most Common Reasons Contractors Fail CMMC Level 2

The patterns below come from what assessors have found across dozens of Level 2 engagements. They hold up regardless of who is reviewing your environment, whether that is a C3PAO or your own team.

Scoping errors

Reducing your Controlled Unclassified Information (CUI) boundary can be an effective way to control cost, but if you scope too narrowly, you could leave systems that touch CUI outside the assessment entirely. The single most common root cause is a CUI boundary that does not match reality.

SPRS scores that do not reflect the environment

A Supplier Performance Risk System (SPRS) score submitted months or years ago rarely matches a live environment. Systems change, staff turnover, and configurations drift. A stale score is one of the fastest ways to turn a routine assessment into a failed one.

SSPs written to the control level, not the objective level

A System Security Plan (SSP) that describes “we use MFA” in general terms is not enough. CMMC Level 2 is assessed against 320 individual assessment objectives underneath the 110 controls, and assessors validate at that level of detail.

Documentation that stops at the control title leaves an assessor guessing on how a requirement is met. That ambiguity gets resolved against the contractor. If it’s not documented, it doesn’t happen.

Policies that do not match actual practice

A written access control policy that says one thing while the environment does another is one of the most common findings in any audit. Assessors check both the document and the configuration, and a mismatch is flagged regardless of intent.

Misunderstanding what a POA&M can cover

Contractors sometimes plan to defer high-value controls (access control, audit logging, multifactor authentication) onto a Plan of Action and Milestones (POA&M), not realizing that a Conditional Level 2 result only allows 1-point requirements on a POA&M, with a short list of items that can never be deferred at all.

External Service Provider gaps in the Shared Responsibility Matrix

When a cloud or managed service provider handles part of the CUI environment, contractors need a documented Shared Responsibility Matrix (SRM) that shows exactly which controls the provider owns and which the contractor owns. Vendor delays in producing this documentation are a recurring bottleneck, and an undocumented gap between provider and contractor responsibility is treated as an unmet control.

Evidence that does not map cleanly to controls

Screenshots, logs, and training records that exist somewhere in the organization are not the same as evidence that is organized, current, and mapped to the specific control and objective it supports. If an assessor has to hunt for proof, or if the evidence is stale, the control is treated as not met. 

How to Catch These Gaps Before They Cost You a Contract

  • Run an internal or third-party mock assessment against the full 320 assessment objectives, not just the 110 control titles
  • Confirm your CUI boundary is accurate before anything else. Every downstream control depends on getting scope right
  • Update your SSP so it reflects your current, implemented environment rather than a template or a future state. What Should Be in Your System Security Plan for CMMC Level 2 covers what a defensible SSP needs to include
  • Get Shared Responsibility Matrixes from every cloud and managed service provider in writing before you need it for an assessment
  • Treat any control that is in progress, planned, or partially configured as not met
  • Understand exactly what can and cannot go on a POA&M before you plan around one 

Closing These Gaps Is a Competitive Advantage, Not Just Risk Avoidance

Avoiding these patterns does more than protect you from a failed assessment. It changes how you look to a prime contractor evaluating subcontractors right now.

  • With third-party verification paused, a self-attestation backed by real evidence, not just intent, is one of the clearest signals of low risk a contractor can offer a prime
  • A completed CMMC Level 2 (C3PAO) certification remains valid for three years and continues to signal low risk even while certification requirements are paused, at a time when many competitors cannot make that same claim
  • Contractors who close these gaps now are the ones positioned to move fastest once formal certification requirements resume
  • Better policies and processes lead to better production — primes want to work with contractors who perform at a high level

“Contractors are responsible for their own security and risk — paused oversight doesn't change that, it raises the burden of proof,” says Ketan Patel, ISI Senior Vice President, Compliance. “The gaps that fail assessments don't disappear when no one's checking. Contractors who act now control the outcome; those who wait let a prime or the government decide it for them.”

Ask Yourself These Questions Before Your Next Assessment

Whether you're preparing for a self-assessment or a future C3PAO review, these questions map directly to the patterns above. If you can't answer one confidently, that's the first gap to close.

  • Can you clearly draw your CUI boundary and explain why each system is in or out of scope?
  • Does your submitted SPRS score reflect your environment today, not the one from your last review?
  • Can you point to evidence for every control at the objective level, not just the control title?
  • Would your written policies match what an assessor would actually see if they looked at your systems today?
  • Do you know which of your gaps are POA&M-eligible, and which items can never be deferred?
  • Do you have a signed Shared Responsibility Matrix from every cloud or managed service provider touching CUI?
  • Could you produce evidence for any control in under 15 minutes, without searching for it?

Where This Leaves You

With third-party certification paused, the attention to detail that used to come from a C3PAO now must come from you. The 110 controls haven’t changed, and neither has the cost of getting them wrong.

Contractors who treat self-assessment with the same rigor as a third-party assessment, scoping honestly, documenting to the objective level, and keeping evidence current, are the ones who will be ready when the CMMC Reform Task Force provides its recommendations, and the ones who look like the lowest-risk option to a prime contractor in the meantime.

 

FAQs

What is the single most common reason contractors fail?

Scoping errors. An inaccurate CUI boundary, whether too broad or too narrow, affects every control that follows and is the most common root cause behind other findings.

Can self-assessment catch these gaps on its own?

It can, but only if it is treated with the same rigor as a third-party review. Without an outside check, the discipline must come from the organization itself, including objective-level documentation, honest evaluation of what is implemented versus planned, and a true understanding of what the controls and objectives require.

What is the fastest way to find these gaps before they become a problem?

A mock assessment against the full 320 assessment objectives, combined with an honest review of your CUI scope and your System Security Plan. Most failure patterns surface in one of those two places.

Do these patterns matter less now that C3PAO certification is paused?

No. Self-assessment still measures your environment against the same 110 controls, and the aforementioned patterns cause self-assessments to be inaccurate just as easily as they cause a C3PAO review to fail.

Helpful ISI Links