CMMC Gap Assessment for Defense Contractors and Manufacturers

Know exactly where you stand — before your SPRS score, your prime, or your assessor tells you.

Schedule Your CMMC Gap Assessment

A CMMC gap assessment measures a defense contractor's current cybersecurity controls against all 110 requirements in NIST SP 800-171 Revision 2, identifying which controls are implemented, which are partially implemented, and which are missing. Consilien conducts CMMC gap assessments for California defense contractors and manufacturers, producing a prioritized remediation roadmap, an accurate SPRS score foundation, and a clear path to C3PAO assessment readiness.

Your SPRS score is already visible to contracting officers. Right now. Since CMMC enforcement began November 10, 2025, the Supplier Performance Risk System score your organization submitted, or failed to submit, factors directly into contract award decisions. Contracting officers review it. Prime contractors check it. Some primes are already requiring subcontractor scores of 88 or higher before considering them for new work, per M2 Technology's April 2026 analysis of prime contractor screening behavior.

SPRS scores range from -203 to +110. Most defense contractors who haven't done a rigorous gap assessment don't actually know where they land on that scale.

That's the problem a gap assessment solves first. Before remediation. Before platform decisions. Before SSP development. Before scheduling a C3PAO. You need an honest, documented read on where your controls actually are, not where you think they are.

And there's a legal dimension here that most CMMC content undersells. The Holland and Knight January 2026 analysis of False Claims Act exposure under CMMC is direct: the DOJ settled seven cybersecurity fraud cases in 2025 alone. In April 2025, a defense contractor paid $4.6 million to resolve allegations of a false SPRS score. A university research institution paid $875,000 in September 2025 over a false SPRS score and failure to implement required controls on systems handling CUI. An inaccurate self-assessment isn't just a compliance problem. It's a personal liability issue for the affirming official who signed it.

A gap assessment done correctly is what makes your SPRS score defensible.

See how gap assessment fits into our full CMMC compliance program for California defense contractors

What a CMMC Gap Assessment Actually Measures

Most contractors who haven't done a formal gap assessment significantly overestimate their score. The controls look familiar on paper. MFA is deployed. There's endpoint protection. Backups run nightly. But familiarity with the categories isn't the same as implementation against the specific requirements NIST SP 800-171A sets.

A CMMC gap assessment is a structured evaluation of an organization's cybersecurity controls against the 110 security requirements in NIST SP 800-171 Revision 2, organized across 14 control families. Each requirement is rated as fully implemented, partially implemented, or not implemented. Partial implementation counts against the SPRS score the same as not implemented. A control that's deployed in one system but not documented, or documented but not enforced, scores as a gap.

The 14 control families the assessment covers:

Access Control, Audit and Accountability, Awareness and Training, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

For manufacturers, Physical Protection is where the most surprises show up. CUI on printed job travelers, customer drawings on shop floors, and access to NADCAP-restricted processing areas all fall under this family. Most IT-led assessments skip it. It shows up in the score anyway.

Three Things Your Gap Assessment Has to Produce

An accurate SPRS score

Not aspirational. Not optimistic. Accurate. The SPRS score your organization submits is a legal representation of your compliance posture. Contracting officers check it. DIBCAC can audit it. And submitting an inflated score while knowingly misrepresenting implemented controls creates treble damages exposure under the False Claims Act. Your gap assessment is the documented foundation that makes your SPRS score defensible.

A prioritized remediation roadmap

Not a list of gaps. A sequence. Some gaps carry more assessment weight than others. Some are quick configuration fixes. Others require months of documentation work or platform migration. A gap assessment without prioritization is a spreadsheet of anxiety. A good one tells you what to fix first, why, and roughly how long it takes. That sequencing drives your POA&M and your timeline to C3PAO readiness.

A realistic CUI scope definition

Scope is where cost lives. An over-scoped assessment forces controls onto systems that don't touch CUI. An under-scoped one leaves real gaps invisible. The gap assessment has to start by mapping where CUI actually flows through the business, which systems handle it, which people access it, and what physical environments it passes through. For manufacturers, that scope is rarely limited to email and a file share.

What Happens During Our Gap Assessment

Step 1: CUI Scoping Interview

Before we touch a single control, we map where CUI actually lives. We interview IT leads, operations managers, quality personnel, and anyone whose daily work involves customer-supplied controlled drawings, technical specifications, or derivative documents. For manufacturers, this includes shop-floor walkthroughs. The output is a documented CUI flow map that defines the assessment boundary — and prevents the over-scoping and under-scoping that inflate cost and create blind spots.

Step 2: Control-by-Control Technical Review

We work through all 110 NIST SP 800-171 Rev 2 requirements against your actual environment. Not a questionnaire you fill out yourself. Working sessions with your IT team, reviewing configurations, documentation, policies, and procedures. Every requirement gets rated: implemented, partially implemented, or not implemented. Partial counts as a gap. An undocumented control counts as a gap. We don't give credit for intent.

Step 3: SPRS Score Calculation

Each gap carries a point value under the NIST 800-171 DoD Assessment Methodology. We calculate the score your environment actually earns, document the basis for each rating, and identify which gaps have the highest impact on your score. This becomes the foundation for your SPRS submission — with the documentation behind it that makes the score auditable and defensible.

Step 4: Specialized Asset Classification

Shop-floor operational technology, older CNC controllers, coordinate measuring machine software, and other legacy systems that can't be fully patched or instrumented under standard IT controls get formally classified using Cyber AB scoping guidance. Specialized Assets that don't require full NIST 800-171 controls can be documented as such, with appropriate compensating procedures. This step frequently removes a significant portion of apparent scope items from the remediation footprint.

Step 5: Prioritized Remediation Roadmap

Every gap gets prioritized by three factors: assessment weight in the SPRS scoring methodology, remediation complexity (quick configuration fix vs. platform change vs. documentation project), and impact on the 320 NIST 800-171A assessment objectives a C3PAO will verify. The roadmap sequences remediation in the order that improves your certification posture most efficiently, with realistic time estimates based on your team's capacity.

Step 6: Gap Assessment Report and Briefing

The deliverable isn't a spreadsheet. It's a structured report covering your current SPRS score, the gap findings organized by control family, the remediation roadmap with sequencing and time estimates, a CUI scope boundary document ready to feed into your SSP, and an executive summary that translates the technical findings into business risk language for your leadership team.

The SPRS Score Reality Check

A lot of contractors are sitting on SPRS scores they submitted without a rigorous assessment behind them. Either the score was estimated without walking each control, or it was submitted years ago and the environment has changed, or the self-assessment was done by the IT team without quality systems, operations, and physical environments in scope.

The DoD Assessment Methodology for NIST SP 800-171 specifies that each unimplemented requirement reduces the score from the maximum of 110 by a defined point value. A single missing MFA implementation costs 5 points. Missing audit logging costs another 5. Configuration management gaps across multiple requirements can take the score well below zero before you've addressed half the control families.

Scores below 88 are increasingly being used by prime contractors as a screening threshold. Below that, some primes won't engage a subcontractor for new work regardless of the contract's formal CMMC requirement. Above it, the signal is competitive.

What's your score right now? Do you know it's accurate?

Who This Is Right For

The gap assessment is the right starting point for:

The right starting point:

  • Defense contractors and subcontractors in Los Angeles, Orange County, the Inland Empire, San Diego, and California who handle CUI on DoD contracts and haven't done a formal NIST SP 800-171 gap assessment in the past 12 months
  • Manufacturers with NADCAP accreditation, AS9100D certification, or active DoD subcontracts whose SPRS score was submitted without a structured methodology behind it
  • Companies preparing for a C3PAO Level 2 assessment in the next 6 to 18 months who need a current, documented gap baseline before SSP development and remediation work begins
  • Organizations whose prime contractor has asked for a compliance status update or certification documentation
  • Contractors who received a low or adverse pre-assessment determination and need to understand the real gap picture before re-engaging a C3PAO

Not the right fit:

You've completed a formal documented gap assessment in the last 12 months and your environment hasn't materially changed. In that case, SSP development, remediation, or evidence program work is likely the right next step. We'll help you figure out which.

By the Numbers

-203 to +110

the full SPRS score range; most unassessed contractors don't know where they actually land (NIST SP 800-171 DoD Assessment Methodology)

$4.6 million

April 2025 FCA settlement paid by a defense contractor over an inaccurate SPRS score (DOJ, April 2025, via Holland and Knight)

88+

the SPRS score threshold prime contractors are increasingly requiring from subcontractors before engaging them for new DoD work (M2 Technology, April 2026)

What Consilien Brings to This Work

We've spent over two decades working with manufacturers, defense subcontractors, and mid-market businesses across California. Our gap assessment work is led by a dedicated CMMC consultant with specific experience in NIST SP 800-171 gap analysis, SPRS score methodology, and the manufacturing-specific complications that generic IT assessments miss.

The shop-floor dimension matters here. Most gap assessments are run by IT consultants who evaluate email, endpoints, and servers. They don't walk the production floor, review how job travelers handle CUI-marked drawings, classify operational technology assets under the Cyber AB scoping framework, or assess physical protection controls in a NADCAP-restricted processing area. We do. For manufacturers, those gaps are real and they show up in the score.

Founded in 2001 and headquartered in Torrance, Consilien works across Los Angeles, Orange County, the Inland Empire, San Diego, and California. The gap assessment is where every CMMC engagement starts.

Common Questions About CMMC Gap Assessments

How long does a gap assessment take?
For a small to mid-sized manufacturer or defense contractor with 50 to 250 employees, two to six weeks from kickoff to final report. The variable is how complex the CUI footprint is and how available the internal team is for working sessions. Environments with multiple external service providers, hybrid digital-physical CUI flows, or significant shop-floor operational technology take longer. We don't rush the scoping work because scoping errors create every other problem downstream.
Can we do the gap assessment ourselves?
You can, and a lot of contractors do. The risk is scoring errors — rating a partially implemented control as fully implemented, or missing a control family entirely because it didn't seem to apply. The NIST SP 800-171 DoD Assessment Methodology is specific about how each requirement is rated, and optimistic self-assessment is exactly what creates SPRS score exposure under the False Claims Act. An independent assessment isn't legally required for self-attestation, but it's what gives your score a defensible audit trail.
Does the gap assessment tell us what platform we need — GCC High, PreVeil, or something else?
Yes, indirectly. The CUI scoping work in the gap assessment identifies who handles CUI, where it lives, and how much of the organization it touches. That footprint analysis is what determines whether a full GCC High migration, a scoped PreVeil enclave, or a different architecture makes sense for your environment. We run that analysis before recommending any platform. The gap assessment is where the data comes from.
What's the difference between a gap assessment and a readiness assessment?
They're often used interchangeably but aren't quite the same thing. A gap assessment measures your current controls against NIST SP 800-171 requirements and produces a score and remediation roadmap. A readiness assessment, typically run by a consultant in the months before a C3PAO assessment, is a mock assessment verifying that your remediated environment, documentation, and evidence are ready for the real thing. You do the gap assessment first. The readiness assessment is the final check before the C3PAO comes in.
How does the gap assessment feed into the SSP?
Directly. The gap assessment produces the CUI scope boundary document, the control-by-control implementation status, and the SPRS score that the SSP will reference and document in detail. The SSP then takes each implemented control and describes how it works in this specific environment. An SSP written without a gap assessment behind it is guessing at scope and implementation status. That's how SSPs end up contradicting what an assessor finds when they examine the real environment.
What if our score comes back very low?
Then you have an accurate picture of your actual risk, which is more valuable than a false sense of readiness. A very low score doesn't mean you're out of the running — it means you have a clear remediation sequence and a realistic timeline. The contractors who have the worst experience with CMMC certification are the ones who discover the gap during a C3PAO assessment instead of during a gap assessment they controlled the timing of. Better to know now.

Start Here. Everything Else Follows.

The gap assessment is the first step in every CMMC program for a simple reason. Every decision that comes after it — platform selection, SSP scope, remediation sequencing, POA&M structure, C3PAO scheduling — depends on knowing your actual current state.

Skip it, and every downstream decision is based on assumptions. Assumptions that show up as findings when an assessor tests them.

If your DoD contracts include CUI, and your SPRS score hasn't been validated by a structured assessment against all 110 controls, you're carrying legal exposure you may not be aware of. The gap assessment closes that gap in the picture before it shows up somewhere harder to fix.

Ready to go further? Our CMMC SSP and POA&M development service takes the gap assessment output and builds the full documentation architecture your C3PAO assessment requires.