Skip to main content
Defense Contractors: Your CMMC Readiness TemplateRegulatory Compliance
5 min readFor CISOs & Security Leaders

Defense Contractors: Your CMMC Readiness Template

The Department of Defense's suspension of CMMC Phase II doesn't mean you can pause your compliance efforts. Instead, it offers a chance to strengthen your security posture without the immediate pressure of third-party assessments. Use this time wisely.

This template provides a structured approach to CMMC readiness that withstands regulatory changes. Whether Phase II returns unchanged or evolves, you'll have documented your security controls to align with NIST SP 800-171 and demonstrate a good-faith compliance effort.

Purpose of the Template

This CMMC readiness assessment and gap closure tracker is designed for defense contractors handling controlled unclassified information (CUI). It helps you:

  • Document your current state against all 110 security controls in NIST SP 800-171 Rev 2
  • Identify gaps that pose contractual risks under DFARS 252.204-7012
  • Prioritize remediation based on control families and threat profiles
  • Generate evidence artifacts for both self-reported and third-party assessments

The template assumes you're operating under the interim enforcement model the DoD announced: self-assessments plus select government-led reviews. This requires defensible documentation, not just checkbox compliance.

Prerequisites

Before using this template, ensure you have:

Data classification baseline. Identify systems, repositories, and workflows that handle CUI. Without clear boundaries around CUI data flows, you can't accurately scope your compliance efforts. Start with contract reviews and data mapping.

Executive sponsorship. The DoD cited "prohibitive compliance costs" as a reason for suspension. Your CFO and contracts team must understand that non-compliance risks bid disqualification and potential False Claims Act exposure. Secure budget and priority commitment before starting gap analysis.

Technical inventory. Maintain an accurate asset inventory covering endpoints, servers, network segments, and cloud services that process, store, or transmit CUI. If your CMDB is outdated or incomplete, update it first.

The Template

Copy this structure into a spreadsheet or GRC platform. Each row represents one of the 110 controls in NIST SP 800-171 Rev 2.

Column A: Control ID (e.g., 3.1.1, 3.1.2)
Column B: Control Family (Access Control, Audit and Accountability, Configuration Management, etc.)
Column C: Control Statement (Full text from NIST SP 800-171)
Column D: Current Implementation Status (Not Implemented / Partially Implemented / Fully Implemented)
Column E: Evidence Location (Policy document name, system config screenshot, log query, etc.)
Column F: Gap Description (Specific deficiency if status is Not or Partially Implemented)
Column G: Remediation Owner (Name or role)
Column H: Target Completion Date
Column I: Estimated Cost (Labor hours and tool/service costs)
Column J: Risk if Not Remediated (Contract loss, data exposure, audit finding)
Column K: Remediation Notes (Implementation approach, dependencies, blockers)

Conduct an honest assessment of your current state for each control. Avoid inflating your maturity. Overstatement during self-assessment can lead to False Claims Act risk if the government checks your work.

Focus on these high-impact control families:

Access Control (3.1.x): Seventeen controls covering least privilege, session controls, and remote access. Many contractors have gaps in privilege reviews and session termination.

Identification and Authentication (3.5.x): Thirteen controls, including multi-factor authentication. If you're using SMS-based MFA for CUI access, document it as a gap. NIST deprecated SMS in SP 800-63B.

System and Communications Protection (3.13.x): Twenty controls covering boundary protection, cryptography, and network segmentation. CUI data flows crossing untrusted networks without FIPS 140-2 validated encryption are common gaps.

Customizing the Template

Adapt this template to your contract portfolio and operational reality:

For small contractors with limited IT staff, prioritize the 48 basic security requirements applicable to all CUI handling. The remaining 62 derived requirements mainly affect organizations with more complex environments. Sequence your work based on immediate contractual risks.

For subcontractors, ensure your prime's flow-down requirements match the CMMC level specified in the prime contract. Some primes impose stricter requirements than DoD mandates. Document any gaps between prime requirements and your current state separately.

For cloud services handling CUI, add a column for FedRAMP authorization status and shared responsibility matrix. Your CSP's FedRAMP Moderate authorization doesn't cover all 110 controls. You still own identity management, data classification, and incident response.

For multiple enclaves or business units, create separate tabs for each CUI boundary. Don't assume corporate IT controls apply uniformly to engineering networks or OT environments.

Add a summary dashboard that rolls up:

  • Total controls by implementation status
  • Total estimated remediation cost
  • Controls past target completion date
  • High-risk gaps (those that could trigger contract loss)

Update monthly. Compliance drift is real, especially in organizations without dedicated GRC resources.

Validation Steps

Before completing your assessment:

Run a data flow audit. Trace CUI from ingress (contract award, email attachment, partner portal) through processing, storage, and disposal. Ensure all systems touching CUI are in scope. If you find CUI on systems thought to be out of scope, your boundary definition was incorrect.

Test your evidence artifacts. If Column E references a policy, ensure it's current, approved, and enforced. If it references a system configuration, verify it hasn't drifted. Randomly spot-check five controls to validate that the evidence still exists and demonstrates the control.

Review with your contracts team. They need to understand which gaps create bid risk versus post-award compliance risk. A missing policy is easier to remediate than an architectural deficiency requiring network redesign.

Pressure-test your cost estimates. The DoD suspended Phase II partly because only 1% of contractors felt fully prepared, suggesting most underestimated the effort. If your total estimated cost seems low, you likely missed hidden work like policy development, staff training, or tool integration.

Document your self-assessment formally. Even without third-party assessment, you're still required to attest to NIST SP 800-171 compliance in your System Security Plan. Your template becomes the basis for that SSP and any government-led assessment the DoD conducts during the interim period.

The CMMC Reform Task Force has 60 days to recommend changes. Use this time to close gaps, not to wait for clarity. Regulatory uncertainty doesn't reduce your contractual obligations under DFARS; it just changes the assessment mechanism.

You Might Also Like