Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
READINESS SELF-CHECK

CMMC Readiness Self-Check: The Questions to Answer Before You Call Anyone

A CMMC readiness self-check should confirm contract obligations, FCI/CUI, scope, assets, SSP accuracy, SPRS status, control ownership, and evidence gaps.

Papercraft checklist clipboard covered in question marks beside a telephone still on the hook, illustrating a readiness self-check to complete before calling a consultant or C3PAO.

Before paying anyone, a small contractor should answer a short set of factual questions: which contracts drive the requirement, whether it handles FCI or CUI, where the data lives, which systems protect it, who owns each control, what its current assessment status is, and where the evidence sits.

A small defense contractor gets more value from asking a narrower question: where inside the FCI/CUI boundary does this requirement apply, who owns it day to day, and what evidence currently backs it up?

The rule in plain English

Start with the contract and data, not with a shopping list. CMMC level and scope follow information handled and solicitation/contract terms.

If the company cannot identify CUI flows or produce a current asset inventory, readiness work should solve those basics before optimizing policies.

How to implement it without overbuilding

Collect clauses, current SPRS information, SSP, asset inventory, network/data-flow diagrams, provider list, and evidence index.

Then sample representative controls across identity, configuration, logging, patching, training, physical security, backups, incident response, remote access, and assessment. Verify each against the live environment.

What evidence to keep

Keep the completed self-check with links to supporting records and unanswered questions. This becomes a better input to an advisor than a generic yes/no questionnaire.

Mark assumptions explicitly so outside help can validate them rather than silently inheriting them.

Where teams get into trouble

The usual mistake is asking 'which tool should we buy?' before confirming scope. Another is reporting a high self-assessment score without objective evidence behind the answers.

Small-contractor walkthrough

Before hiring outside help, the owner discovers that nobody can say which cloud folders contain CUI or whether the SPRS assessment reflects the current enclave. The self-check should surface those foundational uncertainties first because they drive almost every downstream estimate.

For readiness, choose a normal business example rather than a perfect demonstration environment.

  • Collect contract clauses.
  • Identify FCI/CUI.
  • Draw the CUI flow.
  • Reconcile asset inventory.

Decisions to document before assessment

Before marking this topic ready, make four decisions explicit: collect contract clauses; identify fci/cui; draw the cui flow; and reconcile asset inventory. Assign an owner and an evidence location to each decision.

Manual deep review

Before grading 110 requirements, identify which active or target contracts contain DFARS/CMMC language, what FCI or CUI the organization handles, which information systems will perform the work, where CUI enters and moves, and which MSPs, cloud services, collaboration tools, backups, and security providers touch or protect those systems. If those facts are unclear, a completion percentage is not meaningful.

Collect the solicitation or contract clauses, current SPRS information, SSP, asset inventory, data-flow/network diagrams, external-provider list, current NIST assessment record, and evidence index. Mark missing or stale material rather than rebuilding everything before scope is understood. The self-check should expose uncertainty instead of hiding it behind a score.

Sample ten domains before performing a full objective review: identity/access, configuration/change, logging/monitoring, vulnerability/patching, training, physical security, backup/recovery, incident response, remote access, and security assessment. For each ask whether implementation exists, documentation matches, current evidence is retrievable, and a named owner can explain or demonstrate it.

Use at least three readiness states: evidence-supported implemented, known gap, and unknown/not yet validated. Unknown is better than an unsupported yes. For a known gap, record the requirement/objective, affected system, owner, dependency, target evidence, and scope effect. For an unknown, assign a short validation task before buying a product or reporting confidence.

Repeat the self-check with contracts, IT, and operations. Any answer that changes materially by respondent becomes an explicit uncertainty to resolve with evidence. Give a consultant the resulting fact package. A C3PAO is not the remediation consultant; during the current Phase II suspension, confirm the contract or business reason for any formal assessment.

Run a short cross-functional readiness workshop before buying help

Put contracts, IT, operations, and the business owner in one session with the contract, current system diagram, asset inventory, and provider list. Ask each function to identify the FCI/CUI received or generated, system used for performance, external services involved, current assessment/status information, and largest known gap. Differences in answers are themselves findings because they show the organization does not share one scope model.

Record unresolved questions as unknowns with an owner and due date. Examples include whether a SaaS service stores CUI, whether a legacy machine retains a local copy, whether a prime will send CUI, or whether an existing assessed enclave can be reused. Resolving those questions before consulting work starts reduces paid discovery and prevents premature product purchases.

Validate evidence on a small sample of high-value controls

Choose controls that touch different operating teams: account provisioning, MFA/remote access, configuration change, vulnerability remediation, logging/alert review, backup recovery, incident response, physical access, training, and provider evidence. For each, retrieve the current artifact and ask the owner to demonstrate the live process.

Grade the sample by failure type: implementation gap, documentation gap, evidence gap, ownership gap, or scope uncertainty. That classification tells management what kind of remediation is needed. A missing screenshot does not justify replacing a working security architecture, while a policy cannot fix an absent technical control.

Decide when outside help is actually needed

Use the self-check to scope advisory work narrowly. A contractor may need a scoping specialist, cloud architect, policy writer, MSP change, or independent readiness reviewer rather than a single broad 'CMMC package.' Define the desired deliverable and source-backed question for each engagement.

Do not book a formal C3PAO assessment until the organization can retrieve representative evidence, explain its boundary, and demonstrate major controls consistently. During the current suspension, assessment timing should follow a real contract or business decision, not fear of the old phase date.

WORKING CHECKLIST

A short working check

  • Collect contract clauses.
  • Identify FCI/CUI.
  • Draw the CUI flow.
  • Reconcile asset inventory.
  • Review SSP/SPRS status.
  • Sample evidence for representative controls.

Common questions

Should we call a C3PAO first?

Not necessarily. A C3PAO is an assessment organization, not a substitute for basic scoping and readiness.

What is the most important readiness question?

Where does CUI actually enter, move, live, and leave? That drives scope and much of the evidence.

Do we need every policy finished first?

No. The self-check is meant to identify what is implemented, missing, or inaccurately documented.

Can an MSP complete it?

An MSP can support it, but the contractor should understand and own the answers.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.