A CMMC readiness assessment is a non-official diagnostic that tests whether your security controls are actually implemented and evidenced, not just written down in a policy binder. It is not a certification event, and it does not create an SPRS record or any official CMMC status. It exists so you find your gaps before a Certified Third-Party Assessor Organization (C3PAO) does.
Three artifacts have to hold up before you schedule anything official:
- An accurate System Security Plan that matches your real network, not last year's diagram.
- Verifiable technical evidence: logs, configuration exports, dated screenshots, tied to specific practices.
- A Plan of Action & Milestones for every gap you cannot close before assessment day.
The immediate move is to finalize your CMMC Assessment Scope under 32 CFR § 170.19, then run the readiness assessment yourself or bring in a managed partner like Marfi to do it with you.
Key Takeaways
A CMMC readiness assessment succeeds when scope is locked first, evidence is mapped to assessment objectives, and every gap carries a named owner and a real deadline.
| Point | Details |
|---|---|
| Scope before spending | Finalize your CMMC Assessment Scope under 32 CFR § 170.19 before starting remediation work. |
| Evidence beats policy | Assessors need observable proof (logs, configs, screenshots), not just written policies. |
| Budget real time | Plan roughly 90 days for internal prep and 6 to 12 months for full remediation. |
| Watch the 180-day clock | Conditional Level 2 status requires POA&M closeout within 180 days, with no extensions. |
| Consider managed support | Marfi runs continuous evidence collection, SOC monitoring, and POA&M management for teams without spare capacity. |
Table of Contents
- Scoping: Map CUI, Classify Assets, and Avoid the Common Mistakes
- Evidence Expectations: Building a Library Assessors Trust
- Readiness Workflow and Realistic Timelines
- Common Failure Points and a 30/60/90 Checklist
- How Marfi Shortens the Path From Readiness to Final Level 2
- Getting Ready for Level 2? Here's Where Marfi Fits
- Sources
Scoping: Map CUI, Classify Assets, and Avoid the Common Mistakes
Scoping decides everything downstream, including cost. Get it wrong and you either overspend hardening systems that never touch Controlled Unclassified Information (CUI), or underspend and fail on assets you forgot to count.
The CMMC Scoping Guide for Level 2 breaks your environment into five categories. CUI Assets process, store, or transmit CUI directly and need the full control set applied. Security Protection Assets, think firewalls, SIEMs, identity providers, don't touch CUI themselves but protect the systems that do, so they get assessed too. Contractor Risk Managed Assets can potentially access CUI but are managed through your risk program rather than full technical controls, and they need documented risk treatment. Specialized Assets, like IoT devices or test equipment, often can't run standard security agents and require compensating controls written into the SSP. Out-of-Scope assets are physically or logically separated from CUI with no path back in, and that separation needs proof, not assumption.
Three rules keep your scope defensible when the assessor starts asking questions:
- Trace every CUI data flow from origin to destination, including backups and third-party integrations.
- Document every exception in writing, especially for legacy systems you're treating as Specialized Assets.
- Never exclude a Security Protection Asset just because it doesn't store CUI. If it protects the boundary, it's in scope.
The output should be an asset inventory and a network diagram specific enough that a stranger could trace CUI through your environment using nothing else.
Pro Tip: Scoping mistakes are the single biggest driver of blown budgets and failed assessments, according to Fortra's analysis of common CMMC scoping errors. Lock scope before you spend a dollar on remediation, or you'll redo work later.
Evidence Expectations: Building a Library Assessors Trust
Assessors under NIST SP 800-171A don't take your word for it. They use three methods: examine (review documents and configurations), interview (talk to the people who run the control), and test (watch the control work in real time). Your evidence library needs to support all three, and each assessment objective must land at MET or NOT APPLICABLE for the parent practice to score as MET.
That means your evidence set should include:
- Logs with visible retention windows, not just a snapshot from last Tuesday.
- Configuration exports showing the control as it stands today, dated and version tagged.
- Screenshots with timestamps, taken from the actual production system.
- Ticket histories showing incident response or access changes actually happened.
- Training completion records and signed policy acknowledgments tied to named employees.
The gap that trips up the most organizations is the difference between "policy exists" and "control is observable." A written access review policy proves nothing if you can't produce the actual review log from last quarter. Assessors will ask for the artifact, not the intention.
Organizing this well isn't a nice-to-have. Evidence that's clearly named, dated, and mapped directly to a specific assessment objective shortens the on-site window because the assessor spends less time hunting and more time confirming. Name files by practice ID and objective, not generic labels like "screenshot1.png," and keep a master index that ties every artifact back to your SSP.

Readiness Workflow and Realistic Timelines
Give yourself 90 days for the pre-assessment phase and don't compress it. Assessment windows themselves typically run two to eight weeks depending on organization size, but the prep work that comes before it is where most teams underestimate.
- Weeks 1 to 4: Run a full internal self-assessment against all 110 practices, and confirm your scope from the earlier phase still holds.
- Weeks 5 to 6: Prioritize gaps by SPRS point value and remediation difficulty. Fix high-point, low-effort items first to raise your score fast.
- Weeks 7 to 12: Assign named owners to every open gap and start the long-lead items, hardware procurement, SIEM tuning, that take months, not weeks.
- Ongoing: Track remediation against a calendar. Full remediation commonly takes six to twelve months depending on your starting posture.
Once you clear the readiness assessment and address the major gaps, Level 2 self-assessments get submitted to SPRS with a senior official's affirmation. That affirmation cycle repeats annually, and the self-assessment itself is valid for a three-year cycle before you resubmit. If you land Conditional Level 2 status with open POA&M items, the clock starts immediately: closeout is required within 180 days, no extensions. With CMMC Phase 1 implementation underway since November 2025, contract language is already shifting toward requiring these self-assessments, so this timeline isn't theoretical anymore.
Common Failure Points and a 30/60/90 Checklist
Most failed readiness assessments trace back to the same handful of problems: undocumented evidence, an SSP that describes a network that no longer exists, missing multi-factor authentication (MFA) enforcement, thin log retention, stale POA&Ms nobody has touched in months, and access lists that were never reviewed after someone left the company.
Fix them in this order:
- Days 1 to 30: Enforce MFA everywhere it's missing and run a full access review, removing every account that shouldn't still have access.
- Days 31 to 60: Confirm log retention meets your policy and that your SIEM or logging tool is actually capturing what the SSP claims it captures.
- Days 61 to 90: Rewrite the SSP to match reality and build a POA&M with real dates and owners for anything still open.
Pro Tip: Treat the 30/60/90 checklist as a living project plan, not a document you write once. Assign a name to every line item, or it quietly becomes nobody's job.
How Marfi Shortens the Path From Readiness to Final Level 2
Most compliance teams don't lack knowledge of the CMMC framework. They lack the hours to collect evidence continuously, tune a SIEM, and manage a POA&M project while also running the rest of IT. That's the actual blocker, and it's an operational one, not a knowledge gap.
Marfi is a US-based, AI-enabled provider built specifically for regulated companies that need one accountable team instead of five disconnected vendors. Its 24/7 security operations center and SOC 2 Type II certification mean the evidence, logs, and monitoring outputs an assessor wants already exist in a usable form, because someone is watching continuously rather than scrambling before assessment day.
For defense contractors specifically, Marfi runs dedicated CMMC, DFARS, and NIST SP 800-171 readiness support, handling scoped evidence collection, POA&M project management, and assessor rehearsals. If your team can maintain daily operations without dropping evidence collection for weeks at a stretch, keep it in-house. If readiness work keeps sliding because nobody has time, that's the signal to bring in support.

Getting Ready for Level 2? Here's Where Marfi Fits
If you're staring down a Level 2 self-assessment with limited internal bandwidth, Marfi replaces the scramble with a standing team that already runs your evidence collection, log retention, and POA&M tracking as day-to-day operations, not a fire drill before assessment week.

Instead of stitching together a SIEM vendor, a compliance consultant, and an internal IT team who each own one piece of the puzzle, you get one accountable group covering managed IT, continuous monitoring, and CMMC-specific readiness work under a single agreement. For companies that also run cloud workloads needing FedRAMP-aligned evidence, the same evidence discipline carries over instead of building two separate compliance programs from scratch.
If your internal team is confident in scope but short on hours to execute, request a readiness consultation with Marfi and get a straight answer on what's missing before you schedule anything with a C3PAO.
Sources
- § 170.16 CMMC Level 2 self-assessment and affirmation requirements.
- CMMC Scoping Guide – Level 2
- Get to know the Cybersecurity Maturity Model Certification
