Know Exactly Where You Stand On All 110 Level 2 Requirements
Petronella Technology Group, Inc. is a Registered Provider Organization. We provide CMMC consulting only. Our CMMC practice reviews every NIST SP 800-171 requirement against your actual environment and hands you a written report you own: current posture, a defensible Supplier Performance Risk System score calculation, a prioritized plan of action and milestones, and the evidence you are missing. We never assess, and we never promise a certification result.
Every member of our CMMC practice holds CMMC-RP · DFARS 252.204-7012 is already binding · A current self-assessment score is still required in SPRS before award
What A CMMC Gap Assessment Actually Is
A gap assessment is a structured, evidence-based comparison between the security requirements your contracts impose and the way your environment actually operates today. It is not a questionnaire, and it is not a certification.
Most defense suppliers discover the gap the hard way. A prime sends a flow-down questionnaire, someone in the office fills it in from memory, a number goes into the Supplier Performance Risk System, and nobody can reconstruct how that number was produced. Two years later a prime asks for the supporting artifacts, or a contracting officer asks how the score was derived, and the honest answer is that no one knows. That is the situation a gap assessment is designed to end.
The work is deliberately unglamorous. We walk all 110 security requirements in NIST Special Publication 800-171 Revision 2, one at a time, against your systems, your policies, your identity provider, your endpoints, your backups, your physical space, and your people. For each requirement we record one of three states: implemented with evidence, not implemented, or implemented in practice but not documented in a way that would survive review. That third category is where most organizations lose the most points, and it is also the cheapest to fix.
The output is a written report. Not a slide, not a verbal debrief, not a portal login that expires. A document with the requirement identifier, the finding, the evidence we saw or did not see, the point value at stake, and what closing it would take. You own that document. If you never speak to us again, it still has value, because it is written against the public standard rather than against a proprietary scoring product.
It is worth saying plainly what this is not. It is not a certification assessment, it is not a pre-assessment that binds a certifying body, and it does not produce a CMMC status of any kind. Under 32 CFR 170, only an authorized CMMC Third Party Assessment Organization can conduct a Level 2 certification assessment, and Level 3 assessments are conducted by the Government. A consultant who blurs that line is telling you something about how they will behave later in the engagement.
Scope Comes First: FCI Versus CUI
Before a single control is reviewed, the question that decides the size, cost, and difficulty of everything downstream is which information you actually handle and which systems touch it.
Federal Contract Information
Federal Contract Information is information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It excludes information the Government makes public, such as on a public website, and it excludes simple transactional information like payment processing data. If your contracts contain FAR 52.204-21 and nothing more, your obligation is the 15 basic safeguarding requirements in that clause, which correspond to CMMC Level 1. That is a real obligation, but it is a much narrower one, and it is self-assessed annually.
Controlled Unclassified Information
Controlled Unclassified Information is information the Government creates or possesses, or that an entity creates or possesses for the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. In the defense context it usually arrives as technical drawings, specifications, export-controlled data, or program information carrying a marking. The moment your contract contains DFARS 252.204-7012 and covered defense information lands in your environment, NIST SP 800-171 applies to every covered contractor information system that processes, stores, or transmits it. That is the Level 2 world, and it is where all 110 requirements live.
Why Scope Decides Everything
The single most expensive mistake we see is an organization that never drew a boundary. Controlled information ends up on a shared file server that the whole company can reach, in a general-purpose email tenant, on laptops that also run the shop floor software, and in a backup that replicates to a consumer cloud account. When that happens, the assessment scope is the entire company, and the cost of compliance is the cost of hardening every system you own.
The alternative is an enclave: a deliberately small, well-defined environment where controlled information is allowed to exist, with everything else designated out of scope because it genuinely cannot touch that data. The CMMC scoping guidance recognizes several asset categories, including assets that process controlled information, security protection assets that provide the safeguards, contractor risk managed assets, specialized assets, and out-of-scope assets. Getting each asset into the right category, and being able to defend that categorization with a network diagram and a data flow, is often worth more points and more dollars than any single technical control.
Our gap assessment starts here. We map where controlled information enters, where it lives, who touches it, and where it leaves. If the boundary is wrong, every finding downstream is measured against the wrong environment. If you want to see how we handle boundary work in a broader engagement, our CMMC readiness assessment page walks through the full preparation arc.
The 110 Requirements, By Control Family
NIST SP 800-171 Revision 2 organizes its 110 security requirements into 14 families. Here is what each family covers and what we are actually looking for when we review it.
| Family | Requirements | What we review |
|---|---|---|
| Access Control | 22 | Account provisioning and deprovisioning, least privilege, separation of duties, session lock and termination, remote access authorization and routing, wireless and mobile device access, control of external systems, and how publicly accessible content is checked before it is posted. This is the largest family and usually the largest source of findings. |
| Awareness and Training | 3 | Whether users, managers, and administrators actually receive role-based security training, whether insider threat awareness reaches the people who need it, and whether you can produce completion records rather than an assertion that training happened. |
| Audit and Accountability | 9 | What events you log, whether logs are sufficient to reconstruct an incident, whether individual users can be uniquely traced to their actions, time synchronization, protection of audit records from modification, and whether anyone reviews the logs on a defined cadence. |
| Configuration Management | 9 | Baseline configurations, change control, security impact analysis, least functionality, restriction of nonessential programs and services, application allowlisting, and control over user-installed software. Weak baselines here quietly undermine half the other families. |
| Identification and Authentication | 11 | Unique identification, multifactor authentication for privileged and network access, replay resistance, identifier reuse, password complexity and storage, and how temporary and emergency credentials are handled. |
| Incident Response | 3 | Whether an operational incident handling capability exists with preparation, detection, analysis, containment, recovery, and user response activities, whether incidents are tracked and reported to the right internal and external parties, and whether the capability has actually been exercised. |
| Maintenance | 6 | Scheduled maintenance, control over maintenance tools and media, sanitization of equipment leaving your control, supervision of maintenance personnel without required access, and how remote maintenance sessions are authorized and terminated. |
| Media Protection | 9 | Protection and control of paper and digital media, sanitization and destruction before disposal or reuse, marking, access limits, transport accountability, encryption of portable storage, and control over removable media use. |
| Personnel Security | 2 | Screening before authorizing access to systems containing controlled information, and protecting that information during and after personnel actions such as termination and transfer. Small family, frequently missed evidence. |
| Physical Protection | 6 | Limiting physical access to systems and operating environments, escorting and monitoring visitors, maintaining physical access audit logs, controlling physical access devices, and safeguarding controlled information at alternate work sites, which now means home offices for most contractors. |
| Risk Assessment | 3 | Periodic risk assessment, vulnerability scanning on a defined cadence, and remediation of discovered vulnerabilities in accordance with the risk assessment. A scanner that runs but produces no closed findings does not satisfy this family. |
| Security Assessment | 4 | Periodic assessment of the controls themselves, a plan of action to correct deficiencies, a system security plan that describes boundaries and relationships, and ongoing monitoring. This family is where the SSP and POA&M obligations formally live. |
| System and Communications Protection | 16 | Boundary monitoring and control, subnetworking of publicly accessible components, denial of split tunneling, cryptographic protection of controlled information in transit, FIPS-validated cryptography, session authenticity, key management, and control of collaborative computing devices and mobile code. |
| System and Information Integrity | 7 | Timely flaw remediation, malicious code protection that is actually updated, system and inbound and outbound communications monitoring, security alert response, and identification of unauthorized use. This is where managed detection capability, meaning XDR, SIEM, and monitored response, does most of its work. |
Two requirements deserve special mention because they generate more confusion than any others. The multifactor authentication requirement is frequently claimed as implemented when it covers remote access but not local privileged access. The FIPS-validated cryptography requirement is frequently claimed when a product advertises AES encryption but has no Cryptographic Module Validation Program certificate covering the mode in use. Both carry heavy point values, and both are checked closely in an actual assessment, so we check them closely here.
What You Receive
A fixed, clearly scoped deliverable. Written, versioned, and yours to keep, share with a prime, or hand to another provider.
Requirement-By-Requirement Findings
All 110 NIST SP 800-171 requirements, each with a status, the evidence reviewed, the specific deficiency where one exists, and the point value at stake. Written against the public standard, not a proprietary score.
Scope And Boundary Analysis
Where controlled information enters, resides, and leaves. Asset categorization, a current-state data flow, and a candid view of what could be moved out of scope to shrink the problem.
SPRS Score Calculation
Your current score computed under the DoD Assessment Methodology, with the arithmetic shown, so the number you enter is one you can defend line by line rather than one you have to trust.
System Security Plan Posture
An assessment of your existing SSP against what it needs to describe, or an SSP outline aligned to the standard if you do not yet have one. The SSP is a requirement in its own right, not an optional artifact.
Prioritized POA&M
A plan of action and milestones sequenced by point value, effort, dependency, and cost, so you spend first where the score and the risk actually move. Quick wins are separated from structural projects.
Evidence Gap List
The artifacts an assessor would expect to see and that you cannot currently produce. Logs, screenshots, signed policies, training records, review minutes. Often the fastest points available.
Executive Briefing
A short summary written for a board, an owner, or a prime contractor. Plain language, no jargon, honest about what is not done, suitable to send outside the security team.
A Working Session
A live walkthrough of the findings with the people who will have to act on them, so the report becomes a plan instead of a PDF that sits in a shared drive.
How SPRS Scoring Works, And Why Scores Go Negative
Almost every contractor we meet has a Supplier Performance Risk System score. Very few can explain how it was calculated. Here is the arithmetic.
Under the DoD Assessment Methodology for NIST SP 800-171, a self-assessment starts at a perfect score of 110, one point notionally available per requirement. For each requirement that is not fully implemented, a weighted value is subtracted. The weights are 5, 3, or 1 point, assigned according to how much impact the missing requirement has on the security of the system and the information in it. A missing boundary protection or a missing multifactor authentication implementation is weighted heavily. A missing publicly-accessible-content review is weighted lightly.
Because the weights are not uniform, the total possible deduction across all 110 requirements is considerably larger than 110. That is the reason a score can be negative, which surprises people the first time they see it. An organization that has implemented very little can land far below zero, and the methodology defines a floor of minus 203. A negative score is not a clerical error and it is not unusual for a company that has never done this work. It is simply an accurate statement that the heavily weighted requirements are not in place.
Two requirements allow partial credit rather than an all-or-nothing deduction. Multifactor authentication and FIPS-validated cryptography can each be scored at a reduced deduction when they are partially deployed, for example when multifactor covers remote and privileged access but not all users. Getting the partial-credit treatment right is one of the more common places we find a score has been calculated incorrectly, in both directions.
Three practical consequences follow from the math. First, a plan of action and milestones does not earn points. An item on a POA&M is scored as not implemented until it is actually implemented, so a long POA&M and a high score are not compatible. Second, sequencing matters enormously: closing four heavily weighted requirements can move a score more than closing thirty lightly weighted ones, which is exactly why our POA&M is ordered by point value and not alphabetically. Third, the score is only as good as the evidence behind it. Under DFARS 252.204-7019 and 252.204-7020 the Government may verify a self-assessment, and an inflated score that cannot be substantiated is a materially different problem from a low score that can.
For certification specifically, 32 CFR 170.21 sets the conditions under which a Level 2 organization may achieve a conditional status with open items, including a minimum score threshold and a requirement to close those items within 180 days, with certain higher-weighted requirements not eligible for a POA&M at all. If you want to model the arithmetic yourself before we talk, our SPRS score calculator walks through the same weighting, and the Level 2 certification cost detail covers what closing those gaps typically involves.
How The Engagement Runs
A defined sequence with a defined end. You know at the outset what we will look at, who we need time from, and what lands on your desk.
- Scoping callBefore anything is quoted, we talk. What contracts do you hold, which clauses are in them, what information actually arrives, how many people touch it, how many sites and systems are involved, and what already exists in the way of policy and tooling. This call is how the engagement gets sized honestly instead of guessed at.
- Document and evidence requestWe send a structured request: network diagrams, asset inventory, existing policies, identity configuration, backup and logging configuration, training records, prior assessments, and contract clause excerpts. What you already have shortens the engagement; what you do not have is itself a finding.
- Technical review and interviewsOur Registered Practitioners review the environment and talk to the people who run it: the person who provisions accounts, the person who patches, the person who handles a lost laptop. Requirements are satisfied by operations, not by intentions, and interviews are where the difference shows.
- Scoring and draftingEvery requirement is assigned a status and a point value, the score is calculated with the arithmetic shown, and the plan of action is sequenced. Where we are uncertain, we say so in the report rather than rounding in your favor.
- Findings walkthroughWe present the report live to your team and to leadership if you want them there. This is a working session. Questions get answered, disputed findings get discussed, and the sequencing gets adjusted to your budget and calendar reality.
- Your decisionYou own the report. Remediate internally, hire us for the remediation as a separate engagement, or take it to another provider. There is no lock-in in the deliverable, because a report written against a public standard cannot be locked in.
What A Registered Provider Organization Can And Cannot Do
Petronella Technology Group, Inc. is a Registered Provider Organization. Our CMMC practice is staffed entirely by CMMC Registered Practitioners. We provide consulting. That word is doing real work in this sentence, so here is what it means in practice.
We can advise, assess your readiness against the standard, calculate and explain your score, write and improve your documentation, design and implement controls, and prepare your team for an assessment. We can sit with you through the preparation and tell you honestly when we think you are not ready.
We cannot certify you. We cannot conduct the official assessment. We cannot influence the result of an assessment conducted by a CMMC Third Party Assessment Organization, and we cannot guarantee an outcome that is decided by an independent party applying its own judgment to your environment on a day we are not in control of. Any consultant promising you a certification result is either misunderstanding the program or misrepresenting it.
That separation is not red tape. It exists to protect you. A firm that both prepares you and grades you has an obvious incentive to grade generously, and a certification produced that way is worth exactly nothing to the prime relying on it. Because we stay on the consulting side of the line, our incentive is aligned with yours: we are useful to the degree that our findings are accurate, including the uncomfortable ones.
What we do stand behind is the work itself. A fixed, clearly scoped review of all 110 requirements. A practice in which every member holds CMMC-RP. A written report you own, defensible line by line against the published standard, that keeps its value whether or not you ever hire us again.
Program Status: What The Phase 2 Suspension Changed
On July 13, 2026 the Department of War suspended CMMC Phase 2 by memorandum 26-P-1023 and established a CMMC Reform Task Force with a 60-day review and a public request for information. Here is what that did and did not change.
What changed is the certification timeline. With Phase 2 suspended and the reform review underway, there is presently no set date for third-party certification requirements to gate new solicitations at the pace previously announced. We are not going to tell you a deadline is coming, because we do not know that and neither does anyone else selling you something. Deadline pressure is the oldest trick in compliance sales, and it is not one we use.
What did not change is everything that already binds you. DFARS 252.204-7012 was not suspended. If covered defense information touches your systems, you are contractually obligated to implement NIST SP 800-171, to report cyber incidents to the Department within 72 hours, and to flow the requirement down to subcontractors. DFARS 252.204-7019 and 252.204-7020 were not suspended either, which means a current self-assessment score must be in the Supplier Performance Risk System before award, and the Government retains the right to verify it. Phase 1 self-assessment obligations continue to operate.
What also did not change is the commercial reality. Primes are still sending supplier questionnaires. Sourcing decisions still weight security posture. A supplier who can produce a documented score, a real system security plan, and a dated plan of action is a materially easier award decision than one who cannot, and that was true before CMMC existed as a program.
So the honest framing is this: the pause is a preparation window, not a reprieve. The work required to reach a defensible posture takes months, not weeks, and it takes longer when it is done under bid pressure with a proposal deadline in the way. Organizations that use a quiet period to measure accurately and remediate deliberately end up spending less and sleeping better than organizations that wait for a date to be announced and then buy their way through it. For the broader program picture, see our CMMC compliance hub.
Who This Is For
- Defense contractors and subcontractors whose contracts contain DFARS 252.204-7012, and, where applicable, 252.204-7019 and 252.204-7020. DFARS 252.204-7021 is the CMMC requirements clause tied to the certification program whose Phase 2 rollout is currently suspended, so we treat it as a planning consideration rather than a live obligation.
- Suppliers who need to demonstrate readiness to a prime before a flow-down is awarded, and who need something more substantial than a filled-in questionnaire to do it.
- Small and mid-sized manufacturers who handle controlled unclassified information on Department contracts and have never drawn a formal boundary around it.
- Organizations with a Supplier Performance Risk System score they cannot reconstruct or defend, including scores entered years ago by someone who has since left.
- Companies planning an enclave build who want the scope and requirement analysis done before they commit budget to architecture.
- Firms that already hold a status and want an independent pre-check before a reassessment cycle.
Managed service providers, compliance consultancies, and other CMMC-adjacent vendors are not the audience for this page. If you are one, we work with you through our white-label partner program rather than through this engagement. Call the number below and ask for partner terms.
Related Services
Common Questions
Is this the same as a C3PAO assessment?
Do you guarantee that we will pass?
What does it cost?
How long does it take?
CMMC Phase 2 is suspended. Why do this now?
Why is our SPRS score negative?
What is the difference between FCI and CUI for us?
Does this cover boundary definition?
What if we have fifty gaps?
Who performs the work?
Do you fix what you find?
Can you help with Level 1 or Level 3?
Will you sign an NDA before we share anything?
Start With A Conversation, Not A Checkout
Scope decides everything about this engagement, so it starts with a call rather than a cart. Tell us which clauses are in your contracts and what information actually arrives, and we will tell you honestly what a gap assessment would involve, what it would not cover, and whether you need one at all right now.
Petronella Technology Group, Inc. is a Registered Provider Organization. Consulting only. We do not conduct certification assessments and we do not promise certification outcomes.
For broader cost context before you call, see the full CMMC cost breakdown and the Level 2 certification cost detail.