Jackie Ramsey July 21, 2026 0

A CMMC assessment day can expose gaps that felt minor during preparation. A missing policy approval, unclear employee answer, or unavailable system owner can turn a solid security program into a difficult review.

I prepare small defense contractors to treat the assessment as an evidence exercise, not a sales presentation. A practical CMMC assessment checklist keeps the right people, records, and systems ready when the assessor asks for proof.

Key Takeaways

  • Assessment scope starts with the contract, the CMMC level, and where FCI or CUI exists.
  • For Level 2, I map each required practice to evidence, an owner, and a demonstration method.
  • Assessors commonly examine records, interview personnel, and test technical safeguards.
  • A clean assessment day depends on controlled access to evidence, systems, and knowledgeable staff.
  • This checklist improves readiness, but it doesn’t guarantee a passing result or certification.

Confirm Scope Before You Prepare Evidence

My first task is to confirm exactly what the assessment covers. Small contractors often waste time gathering records for systems that never handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Worse, they may exclude a cloud tenant, laptop, or subcontractor process that does handle protected data.

The CMMC level and assessment type depend on the solicitation and contract requirements. Level 1 focuses on the 17 safeguarding requirements aligned with FAR 52.204-21. Level 2 aligns with the 110 requirements in NIST SP 800-171 Rev. 2. The Department of Defense provides an overview of the CMMC program and its assessment levels.

Before assessment day, I complete this scope checklist:

  • Read the solicitation, award documents, and applicable DFARS clauses. Record whether the work requires Level 1, Level 2 self-assessment, or a C3PAO certification assessment.
  • Identify every location where FCI or CUI is created, received, stored, processed, or transmitted. Include shared drives, Microsoft 365, endpoints, backups, mobile devices, and paper files.
  • Document authorized users, administrators, remote workers, subcontractors, and managed service providers with access.
  • List in-scope boundaries, including cloud tenants, networks, VLANs, secure enclaves, and approved external connections.
  • Verify that your System Security Plan reflects the current environment, rather than a network diagram from two years ago.

The assessment scope must match how your team works today, not how the environment looked when the policy was first written.

A small firm may keep CUI in a Microsoft 365 GCC High tenant while using a separate commercial tenant for ordinary business. If that separation is real, documented, and technically enforced, it can reduce the in-scope environment. If staff move files between those tenants without controls, the boundary will not hold up.

Build an Evidence Package That Matches Each Practice

An assessor needs more than a statement that a control exists. For each practice, I prepare objective evidence that shows the safeguard operates in the assessed environment. Policies matter, but screenshots, configurations, tickets, logs, training records, and interview responses carry equal weight.

The DoD’s Level 2 assessment guide describes the three common assessment methods: examine, interview, and test. I use those same methods during an internal readiness review.

For every applicable requirement, I organize the following:

  1. The policy or procedure that defines the requirement and assigns responsibility.
  2. Implementation evidence, such as identity settings, encryption settings, endpoint console reports, network diagrams, access-review records, or incident tickets.
  3. Operational records that show the procedure occurred, including patch reports, vulnerability scans, backup test results, and security awareness completions.
  4. A designated interviewee who understands the process and can explain it plainly.
  5. A repeatable demonstration that can be performed without exposing unnecessary CUI.

For Level 2, keep the System Security Plan, Plan of Action and Milestones, inventory, risk assessment, incident response plan, and media-protection records under version control. Your SSP should identify the responsible role, the technology used, and how the practice works in daily operations.

A POA&M is not a substitute for implemented controls. It documents unfinished work and its planned correction. Therefore, I review every open item before the assessment and confirm that its status is accurate.

Run a Focused Readiness Review One Week Before

The final week is for validation, not major redesign. I test the processes most likely to fail under direct observation. Small teams benefit from assigning one assessment coordinator who controls evidence requests and keeps interviews on schedule.

Start with identity and device controls because they touch nearly every user. Confirm that terminated accounts are disabled, privileged accounts are limited, multifactor authentication works, and shared credentials do not exist. Then check whether endpoint management reports actually cover every in-scope device.

My pre-assessment checklist includes:

  • Review user and administrator access. Remove stale accounts and confirm privileged access approvals.
  • Confirm Endpoint Security reports show active protection, current signatures, and reporting from in-scope endpoints.
  • Validate Device Hardening baselines for laptops, workstations, servers, and network equipment.
  • Test backups and document a recent restoration result. A successful backup job alone doesn’t prove recovery.
  • Review patch status, vulnerability findings, exceptions, and remediation tickets.
  • Confirm encryption protects CUI at rest and in transit, including removable media where applicable.
  • Walk through incident reporting. Staff should know who receives a suspected cyber incident and how quickly the team acts.
  • Verify physical security for offices, equipment rooms, printed CUI, visitor access, and media disposal.

This is also the right time to rehearse the interview flow. I ask staff simple, realistic questions: Where do you store CUI? How do you report phishing? What happens when someone leaves? Confident, accurate answers show that the written program operates beyond the compliance folder.

If a practice cannot be demonstrated, document the gap honestly and determine whether the assessment should proceed. A rushed workaround often creates a bigger problem than a disclosed limitation.

Control the Assessment Day, Not the Assessor

Assessment day should feel organized and calm. I designate a conference room or secure virtual meeting, confirm attendance, and set up a protected evidence-sharing process. Random screen-sharing from personal desktops creates avoidable exposure and confusion.

The assessment coordinator should open with the scope statement, participant list, and schedule. Then the team should answer only the question asked. Long explanations can create conflicting statements or invite a review of systems outside the agreed boundary.

Use this assessment-day checklist:

  • Have the SSP, scope diagram, asset inventory, policies, POA&M, and evidence index ready in a controlled folder.
  • Confirm each system owner is available during the assigned time window, including IT, HR, facilities, contracts, and executive leadership.
  • Use a clean demonstration account or pre-approved screens when possible. Protect CUI and credentials while showing configuration evidence.
  • Record every assessor request, the requested evidence, the owner, delivery time, and any follow-up question.
  • Provide original evidence rather than edited screenshots when the assessor needs dates, system names, or configuration details.
  • Pause when a request appears outside the defined scope. The coordinator can clarify it without becoming defensive.
  • Keep a separate internal issue log. Do not debate findings during the session.

I also make sure leadership understands the assessment format. Executives may need to discuss resources, risk decisions, policy approval, and accountability. Their role isn’t technical troubleshooting. It is proof that security responsibilities have ownership and support.

Keep General IT Services Separate From CMMC Evidence

Technology services support compliance only when they are configured, documented, and operated for the CMMC scope. Marketing descriptions do not count as evidence.

For example, Small Business IT, Cloud Infrastructure, and an Office 365 Migration may improve daily operations. However, the assessment requires proof of access controls, secure configuration, audit logging, and CUI boundaries. The same rule applies to Data Center Technology, Restaurant POS Support, and Kitchen Technology Solutions. Those services may be outside scope unless they connect to systems handling FCI or CUI.

I evaluate providers by asking whether their Cybersecurity Services include retained evidence, defined responsibilities, and dependable response procedures. A Business Technology Partner should support accountable control ownership, not replace it with vague assurances.

The right Technology Consulting work can connect Infrastructure Optimization, Digital Transformation, and an IT Strategy for SMBs to actual security requirements. In practice, that may mean a Secure Cloud Architecture, documented Cloud Management, and Managed IT for Small Business services that produce patch, backup, and access-review records.

Terms such as Innovative IT Solutions and Tailored Technology Services sound appealing, yet an assessment needs specific proof. I look for documented Business Continuity & Security testing, named control owners, and repeatable evidence.

Prepare for Findings and Follow-Up

A CMMC assessment may generate requests for clarification, additional artifacts, or findings that need formal response. I keep the same discipline after the meeting that I used during it.

First, review every request against the assessor’s wording and the documented scope. Then provide complete, traceable evidence through the agreed channel. Avoid sending a flood of unrelated files. Extra material can create new questions without resolving the original request.

For contractors seeking a broader orientation before the review, this CMMC 2.0 compliance overview offers useful background on assessment expectations. Still, your contract requirements and the assessor’s scope control the work.

Final Thoughts

A strong CMMC assessment day starts weeks earlier with a current scope, reliable evidence, and people who understand their responsibilities. The best preparation shows that your security controls work during normal business operations.

I treat the CMMC assessment checklist as a working record, not a one-time document. When evidence, systems, and responsibilities stay current, assessment day becomes a verification of disciplined work already in place.


Discover more from Guide to Technology

Subscribe to get the latest posts sent to your email.

Category: 

Leave a Reply