CMMC Gap Assessment · Registered Provider Organization

Know Exactly Where You Stand On All 110 Level 2 Requirements

Petronella Technology Group, Inc. is a Registered Provider Organization. We provide CMMC consulting only. Our CMMC practice reviews every NIST SP 800-171 requirement against your actual environment and hands you a written report you own: current posture, a defensible Supplier Performance Risk System score calculation, a prioritized plan of action and milestones, and the evidence you are missing. We never assess, and we never promise a certification result.

Every member of our CMMC practice holds CMMC-RP · DFARS 252.204-7012 is already binding · A current self-assessment score is still required in SPRS before award

What A CMMC Gap Assessment Actually Is

A gap assessment is a structured, evidence-based comparison between the security requirements your contracts impose and the way your environment actually operates today. It is not a questionnaire, and it is not a certification.

Most defense suppliers discover the gap the hard way. A prime sends a flow-down questionnaire, someone in the office fills it in from memory, a number goes into the Supplier Performance Risk System, and nobody can reconstruct how that number was produced. Two years later a prime asks for the supporting artifacts, or a contracting officer asks how the score was derived, and the honest answer is that no one knows. That is the situation a gap assessment is designed to end.

The work is deliberately unglamorous. We walk all 110 security requirements in NIST Special Publication 800-171 Revision 2, one at a time, against your systems, your policies, your identity provider, your endpoints, your backups, your physical space, and your people. For each requirement we record one of three states: implemented with evidence, not implemented, or implemented in practice but not documented in a way that would survive review. That third category is where most organizations lose the most points, and it is also the cheapest to fix.

The output is a written report. Not a slide, not a verbal debrief, not a portal login that expires. A document with the requirement identifier, the finding, the evidence we saw or did not see, the point value at stake, and what closing it would take. You own that document. If you never speak to us again, it still has value, because it is written against the public standard rather than against a proprietary scoring product.

It is worth saying plainly what this is not. It is not a certification assessment, it is not a pre-assessment that binds a certifying body, and it does not produce a CMMC status of any kind. Under 32 CFR 170, only an authorized CMMC Third Party Assessment Organization can conduct a Level 2 certification assessment, and Level 3 assessments are conducted by the Government. A consultant who blurs that line is telling you something about how they will behave later in the engagement.

Scope Comes First: FCI Versus CUI

Before a single control is reviewed, the question that decides the size, cost, and difficulty of everything downstream is which information you actually handle and which systems touch it.

Federal Contract Information

Federal Contract Information is information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It excludes information the Government makes public, such as on a public website, and it excludes simple transactional information like payment processing data. If your contracts contain FAR 52.204-21 and nothing more, your obligation is the 15 basic safeguarding requirements in that clause, which correspond to CMMC Level 1. That is a real obligation, but it is a much narrower one, and it is self-assessed annually.

Controlled Unclassified Information

Controlled Unclassified Information is information the Government creates or possesses, or that an entity creates or possesses for the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. In the defense context it usually arrives as technical drawings, specifications, export-controlled data, or program information carrying a marking. The moment your contract contains DFARS 252.204-7012 and covered defense information lands in your environment, NIST SP 800-171 applies to every covered contractor information system that processes, stores, or transmits it. That is the Level 2 world, and it is where all 110 requirements live.

Why Scope Decides Everything

The single most expensive mistake we see is an organization that never drew a boundary. Controlled information ends up on a shared file server that the whole company can reach, in a general-purpose email tenant, on laptops that also run the shop floor software, and in a backup that replicates to a consumer cloud account. When that happens, the assessment scope is the entire company, and the cost of compliance is the cost of hardening every system you own.

The alternative is an enclave: a deliberately small, well-defined environment where controlled information is allowed to exist, with everything else designated out of scope because it genuinely cannot touch that data. The CMMC scoping guidance recognizes several asset categories, including assets that process controlled information, security protection assets that provide the safeguards, contractor risk managed assets, specialized assets, and out-of-scope assets. Getting each asset into the right category, and being able to defend that categorization with a network diagram and a data flow, is often worth more points and more dollars than any single technical control.

Our gap assessment starts here. We map where controlled information enters, where it lives, who touches it, and where it leaves. If the boundary is wrong, every finding downstream is measured against the wrong environment. If you want to see how we handle boundary work in a broader engagement, our CMMC readiness assessment page walks through the full preparation arc.

The 110 Requirements, By Control Family

NIST SP 800-171 Revision 2 organizes its 110 security requirements into 14 families. Here is what each family covers and what we are actually looking for when we review it.

FamilyRequirementsWhat we review
Access Control22Account provisioning and deprovisioning, least privilege, separation of duties, session lock and termination, remote access authorization and routing, wireless and mobile device access, control of external systems, and how publicly accessible content is checked before it is posted. This is the largest family and usually the largest source of findings.
Awareness and Training3Whether users, managers, and administrators actually receive role-based security training, whether insider threat awareness reaches the people who need it, and whether you can produce completion records rather than an assertion that training happened.
Audit and Accountability9What events you log, whether logs are sufficient to reconstruct an incident, whether individual users can be uniquely traced to their actions, time synchronization, protection of audit records from modification, and whether anyone reviews the logs on a defined cadence.
Configuration Management9Baseline configurations, change control, security impact analysis, least functionality, restriction of nonessential programs and services, application allowlisting, and control over user-installed software. Weak baselines here quietly undermine half the other families.
Identification and Authentication11Unique identification, multifactor authentication for privileged and network access, replay resistance, identifier reuse, password complexity and storage, and how temporary and emergency credentials are handled.
Incident Response3Whether an operational incident handling capability exists with preparation, detection, analysis, containment, recovery, and user response activities, whether incidents are tracked and reported to the right internal and external parties, and whether the capability has actually been exercised.
Maintenance6Scheduled maintenance, control over maintenance tools and media, sanitization of equipment leaving your control, supervision of maintenance personnel without required access, and how remote maintenance sessions are authorized and terminated.
Media Protection9Protection and control of paper and digital media, sanitization and destruction before disposal or reuse, marking, access limits, transport accountability, encryption of portable storage, and control over removable media use.
Personnel Security2Screening before authorizing access to systems containing controlled information, and protecting that information during and after personnel actions such as termination and transfer. Small family, frequently missed evidence.
Physical Protection6Limiting physical access to systems and operating environments, escorting and monitoring visitors, maintaining physical access audit logs, controlling physical access devices, and safeguarding controlled information at alternate work sites, which now means home offices for most contractors.
Risk Assessment3Periodic risk assessment, vulnerability scanning on a defined cadence, and remediation of discovered vulnerabilities in accordance with the risk assessment. A scanner that runs but produces no closed findings does not satisfy this family.
Security Assessment4Periodic assessment of the controls themselves, a plan of action to correct deficiencies, a system security plan that describes boundaries and relationships, and ongoing monitoring. This family is where the SSP and POA&M obligations formally live.
System and Communications Protection16Boundary monitoring and control, subnetworking of publicly accessible components, denial of split tunneling, cryptographic protection of controlled information in transit, FIPS-validated cryptography, session authenticity, key management, and control of collaborative computing devices and mobile code.
System and Information Integrity7Timely flaw remediation, malicious code protection that is actually updated, system and inbound and outbound communications monitoring, security alert response, and identification of unauthorized use. This is where managed detection capability, meaning XDR, SIEM, and monitored response, does most of its work.

Two requirements deserve special mention because they generate more confusion than any others. The multifactor authentication requirement is frequently claimed as implemented when it covers remote access but not local privileged access. The FIPS-validated cryptography requirement is frequently claimed when a product advertises AES encryption but has no Cryptographic Module Validation Program certificate covering the mode in use. Both carry heavy point values, and both are checked closely in an actual assessment, so we check them closely here.

What You Receive

A fixed, clearly scoped deliverable. Written, versioned, and yours to keep, share with a prime, or hand to another provider.

Requirement-By-Requirement Findings

All 110 NIST SP 800-171 requirements, each with a status, the evidence reviewed, the specific deficiency where one exists, and the point value at stake. Written against the public standard, not a proprietary score.

Scope And Boundary Analysis

Where controlled information enters, resides, and leaves. Asset categorization, a current-state data flow, and a candid view of what could be moved out of scope to shrink the problem.

SPRS Score Calculation

Your current score computed under the DoD Assessment Methodology, with the arithmetic shown, so the number you enter is one you can defend line by line rather than one you have to trust.

System Security Plan Posture

An assessment of your existing SSP against what it needs to describe, or an SSP outline aligned to the standard if you do not yet have one. The SSP is a requirement in its own right, not an optional artifact.

Prioritized POA&M

A plan of action and milestones sequenced by point value, effort, dependency, and cost, so you spend first where the score and the risk actually move. Quick wins are separated from structural projects.

Evidence Gap List

The artifacts an assessor would expect to see and that you cannot currently produce. Logs, screenshots, signed policies, training records, review minutes. Often the fastest points available.

Executive Briefing

A short summary written for a board, an owner, or a prime contractor. Plain language, no jargon, honest about what is not done, suitable to send outside the security team.

A Working Session

A live walkthrough of the findings with the people who will have to act on them, so the report becomes a plan instead of a PDF that sits in a shared drive.

How SPRS Scoring Works, And Why Scores Go Negative

Almost every contractor we meet has a Supplier Performance Risk System score. Very few can explain how it was calculated. Here is the arithmetic.

Under the DoD Assessment Methodology for NIST SP 800-171, a self-assessment starts at a perfect score of 110, one point notionally available per requirement. For each requirement that is not fully implemented, a weighted value is subtracted. The weights are 5, 3, or 1 point, assigned according to how much impact the missing requirement has on the security of the system and the information in it. A missing boundary protection or a missing multifactor authentication implementation is weighted heavily. A missing publicly-accessible-content review is weighted lightly.

Because the weights are not uniform, the total possible deduction across all 110 requirements is considerably larger than 110. That is the reason a score can be negative, which surprises people the first time they see it. An organization that has implemented very little can land far below zero, and the methodology defines a floor of minus 203. A negative score is not a clerical error and it is not unusual for a company that has never done this work. It is simply an accurate statement that the heavily weighted requirements are not in place.

Two requirements allow partial credit rather than an all-or-nothing deduction. Multifactor authentication and FIPS-validated cryptography can each be scored at a reduced deduction when they are partially deployed, for example when multifactor covers remote and privileged access but not all users. Getting the partial-credit treatment right is one of the more common places we find a score has been calculated incorrectly, in both directions.

Three practical consequences follow from the math. First, a plan of action and milestones does not earn points. An item on a POA&M is scored as not implemented until it is actually implemented, so a long POA&M and a high score are not compatible. Second, sequencing matters enormously: closing four heavily weighted requirements can move a score more than closing thirty lightly weighted ones, which is exactly why our POA&M is ordered by point value and not alphabetically. Third, the score is only as good as the evidence behind it. Under DFARS 252.204-7019 and 252.204-7020 the Government may verify a self-assessment, and an inflated score that cannot be substantiated is a materially different problem from a low score that can.

For certification specifically, 32 CFR 170.21 sets the conditions under which a Level 2 organization may achieve a conditional status with open items, including a minimum score threshold and a requirement to close those items within 180 days, with certain higher-weighted requirements not eligible for a POA&M at all. If you want to model the arithmetic yourself before we talk, our SPRS score calculator walks through the same weighting, and the Level 2 certification cost detail covers what closing those gaps typically involves.

How The Engagement Runs

A defined sequence with a defined end. You know at the outset what we will look at, who we need time from, and what lands on your desk.

  1. Scoping callBefore anything is quoted, we talk. What contracts do you hold, which clauses are in them, what information actually arrives, how many people touch it, how many sites and systems are involved, and what already exists in the way of policy and tooling. This call is how the engagement gets sized honestly instead of guessed at.
  2. Document and evidence requestWe send a structured request: network diagrams, asset inventory, existing policies, identity configuration, backup and logging configuration, training records, prior assessments, and contract clause excerpts. What you already have shortens the engagement; what you do not have is itself a finding.
  3. Technical review and interviewsOur Registered Practitioners review the environment and talk to the people who run it: the person who provisions accounts, the person who patches, the person who handles a lost laptop. Requirements are satisfied by operations, not by intentions, and interviews are where the difference shows.
  4. Scoring and draftingEvery requirement is assigned a status and a point value, the score is calculated with the arithmetic shown, and the plan of action is sequenced. Where we are uncertain, we say so in the report rather than rounding in your favor.
  5. Findings walkthroughWe present the report live to your team and to leadership if you want them there. This is a working session. Questions get answered, disputed findings get discussed, and the sequencing gets adjusted to your budget and calendar reality.
  6. Your decisionYou own the report. Remediate internally, hire us for the remediation as a separate engagement, or take it to another provider. There is no lock-in in the deliverable, because a report written against a public standard cannot be locked in.

What A Registered Provider Organization Can And Cannot Do

Petronella Technology Group, Inc. is a Registered Provider Organization. Our CMMC practice is staffed entirely by CMMC Registered Practitioners. We provide consulting. That word is doing real work in this sentence, so here is what it means in practice.

We can advise, assess your readiness against the standard, calculate and explain your score, write and improve your documentation, design and implement controls, and prepare your team for an assessment. We can sit with you through the preparation and tell you honestly when we think you are not ready.

We cannot certify you. We cannot conduct the official assessment. We cannot influence the result of an assessment conducted by a CMMC Third Party Assessment Organization, and we cannot guarantee an outcome that is decided by an independent party applying its own judgment to your environment on a day we are not in control of. Any consultant promising you a certification result is either misunderstanding the program or misrepresenting it.

That separation is not red tape. It exists to protect you. A firm that both prepares you and grades you has an obvious incentive to grade generously, and a certification produced that way is worth exactly nothing to the prime relying on it. Because we stay on the consulting side of the line, our incentive is aligned with yours: we are useful to the degree that our findings are accurate, including the uncomfortable ones.

What we do stand behind is the work itself. A fixed, clearly scoped review of all 110 requirements. A practice in which every member holds CMMC-RP. A written report you own, defensible line by line against the published standard, that keeps its value whether or not you ever hire us again.

Program Status: What The Phase 2 Suspension Changed

On July 13, 2026 the Department of War suspended CMMC Phase 2 by memorandum 26-P-1023 and established a CMMC Reform Task Force with a 60-day review and a public request for information. Here is what that did and did not change.

What changed is the certification timeline. With Phase 2 suspended and the reform review underway, there is presently no set date for third-party certification requirements to gate new solicitations at the pace previously announced. We are not going to tell you a deadline is coming, because we do not know that and neither does anyone else selling you something. Deadline pressure is the oldest trick in compliance sales, and it is not one we use.

What did not change is everything that already binds you. DFARS 252.204-7012 was not suspended. If covered defense information touches your systems, you are contractually obligated to implement NIST SP 800-171, to report cyber incidents to the Department within 72 hours, and to flow the requirement down to subcontractors. DFARS 252.204-7019 and 252.204-7020 were not suspended either, which means a current self-assessment score must be in the Supplier Performance Risk System before award, and the Government retains the right to verify it. Phase 1 self-assessment obligations continue to operate.

What also did not change is the commercial reality. Primes are still sending supplier questionnaires. Sourcing decisions still weight security posture. A supplier who can produce a documented score, a real system security plan, and a dated plan of action is a materially easier award decision than one who cannot, and that was true before CMMC existed as a program.

So the honest framing is this: the pause is a preparation window, not a reprieve. The work required to reach a defensible posture takes months, not weeks, and it takes longer when it is done under bid pressure with a proposal deadline in the way. Organizations that use a quiet period to measure accurately and remediate deliberately end up spending less and sleeping better than organizations that wait for a date to be announced and then buy their way through it. For the broader program picture, see our CMMC compliance hub.

Who This Is For

  • Defense contractors and subcontractors whose contracts contain DFARS 252.204-7012, and, where applicable, 252.204-7019 and 252.204-7020. DFARS 252.204-7021 is the CMMC requirements clause tied to the certification program whose Phase 2 rollout is currently suspended, so we treat it as a planning consideration rather than a live obligation.
  • Suppliers who need to demonstrate readiness to a prime before a flow-down is awarded, and who need something more substantial than a filled-in questionnaire to do it.
  • Small and mid-sized manufacturers who handle controlled unclassified information on Department contracts and have never drawn a formal boundary around it.
  • Organizations with a Supplier Performance Risk System score they cannot reconstruct or defend, including scores entered years ago by someone who has since left.
  • Companies planning an enclave build who want the scope and requirement analysis done before they commit budget to architecture.
  • Firms that already hold a status and want an independent pre-check before a reassessment cycle.

Managed service providers, compliance consultancies, and other CMMC-adjacent vendors are not the audience for this page. If you are one, we work with you through our white-label partner program rather than through this engagement. Call the number below and ask for partner terms.

110Requirements Reviewed
RPOConsulting Only
23+Years In Raleigh
2002Founded

Related Services

Common Questions

Is this the same as a C3PAO assessment?
No. A CMMC Third Party Assessment Organization conducts the official Level 2 certification assessment using its own certified assessors. Petronella Technology Group, Inc. is a Registered Provider Organization providing consulting only. We conduct a readiness gap analysis that prepares you for that assessment. The program deliberately separates the two roles, and we stay firmly on the consulting side of that line.
Do you guarantee that we will pass?
No, and we would be suspicious of anyone who did. The certification decision belongs to an independent assessment organization applying its own judgment to your environment. What we commit to is a fixed, clearly scoped review of all 110 requirements, a practice in which every member holds CMMC-RP, and a written report you own that is defensible line by line against the published standard. We will also tell you plainly when we do not think you are ready, which is the part a promise-based sales pitch cannot do.
What does it cost?
Scope drives the number, so we do not publish one. The size of the environment, the number of sites, how many people touch controlled information, how much documentation already exists, and whether a boundary has ever been drawn all move the effort substantially. We scope it with you on a call first, then quote. Call (919) 348-4912.
How long does it take?
That also depends on scope and, more than anything, on how quickly we can get documentation and interview time. A small single-site environment with reasonable records moves fast. A multi-site environment with no asset inventory and no diagrams takes longer, because building the inventory is part of the work. We commit to a schedule in writing at kickoff rather than to a slogan.
CMMC Phase 2 is suspended. Why do this now?
Because nothing that binds you today was suspended. The Department of War suspended Phase 2 on July 13, 2026 and opened a Reform Task Force review with a public request for information, so no date is currently set for third-party certification to gate new solicitations. DFARS 252.204-7012 was not paused: any system that stores, processes, or transmits covered defense information still has to implement NIST SP 800-171. DFARS 252.204-7019 and 252.204-7020 still require a current self-assessment score in the Supplier Performance Risk System before award. Primes are still running flow-down questionnaires. The review period is a calm window in which to measure and remediate, and the same work done later under bid pressure costs more.
Why is our SPRS score negative?
Because the DoD Assessment Methodology starts at 110 and subtracts 5, 3, or 1 points for each requirement that is not fully implemented, and the weighted deductions across all 110 requirements total considerably more than 110. An organization early in the journey can land well below zero. The defined floor is minus 203. A negative score is a normal starting point, not a scandal, and it is far better to hold an accurate negative score than an unsupportable positive one.
What is the difference between FCI and CUI for us?
Federal Contract Information is non-public information provided by or generated for the Government under a contract, and it triggers the 15 basic safeguarding requirements in FAR 52.204-21, which correspond to CMMC Level 1. Controlled Unclassified Information carries a safeguarding or dissemination control under the CUI program, and under DFARS 252.204-7012 it pulls every system that processes, stores, or transmits it into NIST SP 800-171 and CMMC Level 2. Determining which you actually hold is part of the scoping work, and contractors are wrong about it in both directions more often than you would expect.
Does this cover boundary definition?
Yes. Boundary and asset categorization is the first substantive part of the review, not an afterthought. A misdefined boundary is the most common structural problem we find, and it distorts every other finding, because a requirement can only be assessed against a correctly identified system.
What if we have fifty gaps?
Most organizations do on a first honest assessment, and a report that finds only a handful on a first pass is usually a report that did not look hard. The plan of action is sequenced by point value and effort so you can see which findings move the score meaningfully, which can be batched together with a single tooling or documentation project, and which are genuinely structural and need budget and a calendar.
Who performs the work?
Our CMMC practice: Craig Petronella, Blake Rea, Justin Summers, and Jonathan Wood. Every member of the practice holds the CMMC Registered Practitioner credential. Craig is CMMC-RP, Cisco CCNA, CWNE, and a licensed Digital Forensic Examiner, and has led Petronella Technology Group, Inc. since 2002.
Do you fix what you find?
We can, and many clients ask us to. Remediation is scoped and contracted separately from the assessment so that the findings are not shaped by what we would like to sell next. You are equally free to take the report to your internal team or to another provider. It is written against a public standard, so it works in anyone's hands.
Can you help with Level 1 or Level 3?
Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21 and is self-assessed annually. It is a much lighter engagement and we scope it as one. Level 3 adds 24 selected requirements from NIST SP 800-172 on top of the 110, for a total of 134, is assessed by the Government rather than by a third party, and requires a Final Level 2 status as a prerequisite. If Level 3 is genuinely in your future, we will tell you what that path involves rather than sell you into it early.
Will you sign an NDA before we share anything?
Yes, as a matter of routine, and before any environment detail changes hands. Controlled information itself is handled inside an encrypted enclave and exchanged through an encrypted, access-controlled channel rather than by email attachment. We will walk you through the handling arrangement on the scoping call.

Start With A Conversation, Not A Checkout

Scope decides everything about this engagement, so it starts with a call rather than a cart. Tell us which clauses are in your contracts and what information actually arrives, and we will tell you honestly what a gap assessment would involve, what it would not cover, and whether you need one at all right now.

Petronella Technology Group, Inc. is a Registered Provider Organization. Consulting only. We do not conduct certification assessments and we do not promise certification outcomes.