If your organization needs CMMC Level 2, start by understanding the contractual requirement, where Controlled Unclassified Information enters and moves through your environment, what systems and people are actually in scope, what existing cybersecurity controls can be reused, and what gaps must be remediated before assessment.
Do not start by buying a CMMC tool.
Do not start by writing 110 isolated answers.
And do not assume the entire company must automatically be included in the assessment boundary.
CMMC Level 2 is an implementation and operating challenge before it is an assessment challenge.
Hotman Group helps organizations scope, assess, design, implement, remediate, document, prepare and sustain cybersecurity programs that need to meet CMMC Level 2 requirements.
The fastest path to CMMC is not rushing to the assessment. It is accurately defining scope, understanding what already works, fixing what does not, and building evidence that demonstrates the required practices are operating.
Organizations often need more than a CMMC gap assessment.
Depending on the current state, the work may require:
Hotman Group can help across that lifecycle rather than stopping after identifying gaps.
CMMC Level 2 is the level generally associated with organizations that handle Controlled Unclassified Information and must demonstrate implementation of applicable cybersecurity requirements based on NIST SP 800-171.
The practical challenge is not merely understanding the requirements.
The organization must be able to demonstrate that applicable practices are implemented within the defined assessment scope.
Start with five questions:
Those answers shape almost everything that follows.
Review the applicable contractual and information-handling requirements.
Determine whether the organization receives, creates, stores, processes or transmits information that drives the Level 2 requirement and what contractual obligations apply.
Do not rely only on a verbal statement that “you need CMMC.”
Scope determines which parts of the environment must satisfy the applicable requirements and be prepared for assessment.
An unnecessarily broad scope can increase:
An incorrectly narrow scope can leave required systems or information outside the program.
See what is actually in scope for CMMC.
Controlled Unclassified Information, or CUI, is information that requires safeguarding or dissemination controls under applicable federal requirements but is not classified national security information.
For CMMC planning, the organization needs to understand what information it actually receives or creates and where that information goes.
Yes.
A gap assessment performed against an undefined or inaccurate environment can produce an inaccurate implementation plan.
Understand:
Not automatically.
The appropriate boundary depends on how CUI and supporting systems are structured.
Some organizations intentionally design more limited environments to reduce complexity.
The architecture still has to support actual business operations and satisfy the applicable requirements.
An enclave can be useful when the organization can reasonably isolate CUI-related activity into a controlled environment.
But an enclave is not automatically the right answer.
Consider:
The goal is a secure and sustainable operating model, not merely the smallest theoretical boundary.
NIST SP 800-171 provides the underlying security requirements relevant to protecting CUI in nonfederal systems and organizations.
CMMC adds an assessment and assurance structure around implementation of the applicable requirements.
For an organization preparing for CMMC Level 2, NIST SP 800-171 implementation is therefore central to the work.
Once scope is sufficiently understood, a current-state assessment is usually an important next step.
The assessment should determine:
Yes, where those controls genuinely satisfy the applicable requirements within the CMMC scope.
Organizations may already have relevant capabilities through:
See how to reuse existing security controls for CMMC.
No.
Overlap creates an opportunity for reuse.
It does not prove implementation.
An existing control must be evaluated against the specific requirement, scope and assessment expectations.
A useful assessment should produce more than a list of failed practices.
The organization should understand:
Build a remediation plan.
Prioritize work based on:
See what should happen after a cybersecurity assessment.
Remediation may require a combination of:
Hotman Group helps organizations move from assessment findings into implemented and sustainable cybersecurity controls.
See how Hotman Group approaches cybersecurity remediation.
Policies and procedures are important where they define how required cybersecurity activities are governed and performed.
But documents should reflect the program the organization actually operates.
Creating a large policy library without implementing the underlying practices does not create assessment readiness.
The System Security Plan, or SSP, documents the system environment and how applicable security requirements are implemented.
It should reflect the actual architecture, scope, controls and operating practices.
An SSP should not be treated as a document created independently from the implementation work.
Control narratives explain how the organization satisfies specific security requirements.
Strong narratives should accurately describe:
Evidence depends on the requirement and implementation.
It may include:
No.
Evidence should be considered during implementation.
A control that is difficult to prove may indicate that the operating process or evidence model needs improvement.
See how to centralize cybersecurity evidence without creating more work.
The applicable CMMC and contractual requirements determine when and how Plans of Action and Milestones may be used.
From a program perspective, a POA&M should document a real remediation commitment with:
It should not become a permanent substitute for required implementation.
No.
A GRC platform can help manage:
But software does not implement CMMC for the organization.
See how to determine whether you actually need a GRC platform.
Automation can reduce administrative work.
It cannot replace:
See how to automate compliance without automating bad processes.
The GRC team should not automatically own every requirement.
Controls may be operated by:
See how to create clear ownership for cybersecurity controls.
CMMC implementation can create substantial temporary and ongoing workload.
Organizations should distinguish between:
See what an overwhelmed cybersecurity and GRC team should consider outsourcing.
There is no universal timeline.
Timing depends on:
A company with substantial existing capability may have a very different path from one starting with an immature security program.
Cost depends on the current environment and what must change.
Potential costs include:
Scope can materially affect these costs.
Not if the organization can integrate the applicable requirements into its broader cybersecurity program.
CMMC may have specific assessment and documentation needs, but many underlying cybersecurity capabilities can support other frameworks and customer requirements too.
See how to build one cybersecurity program across multiple frameworks.
Use the existing program as a starting point.
Existing controls may provide meaningful reuse.
But do not assume certification against one framework automatically demonstrates satisfaction of CMMC requirements.
Evaluate the actual overlap.
Yes.
Where possible, implementation should create reusable cybersecurity capability that can support:
Then CMMC is no longer only a compliance project.
The organization should understand:
See what to do when customer cybersecurity requirements are driving major cost and product decisions.
Before assessment, the organization should be able to:
Assessment readiness should be the result of implementation, not a last-minute evidence exercise.
A readiness review can be valuable when it validates:
before the formal assessment begins.
The cybersecurity program still has to operate.
Controls can degrade as:
See how to maintain cybersecurity compliance after certification.
Hotman Group helps organizations move through the full CMMC readiness lifecycle.
HG can help with:
Documentation matters.
Evidence matters.
Assessment preparation matters.
But they should describe and prove cybersecurity practices that actually operate.
That is why HG approaches CMMC as a cybersecurity implementation and operating problem rather than only a certification exercise.
CMMC readiness is strongest when the organization can clearly connect requirement, implementation, owner, evidence and ongoing operation.
Start by confirming the requirement and understanding CUI scope. Then assess existing cybersecurity capabilities against the applicable NIST SP 800-171 requirements, identify true gaps, remediate them and build the documentation and evidence needed to demonstrate implementation.
Not automatically. Scope depends on CUI flows, systems, people, security protection assets and other relevant components of the environment. Accurate scoping is an important early step.
Yes. Existing cybersecurity controls may satisfy CMMC requirements when they operate within the applicable scope and genuinely meet the specific requirement.
No. A platform can help manage requirements, evidence and remediation, but it does not replace the implementation of required cybersecurity practices.
No. A gap assessment identifies current-state weaknesses. The organization still needs to remediate gaps, implement controls, document the environment, develop evidence and prepare for assessment.
Yes. Hotman Group can help with scoping, assessment, NIST SP 800-171 implementation, remediation, documentation, evidence, SSP development, assessment readiness and ongoing sustainment.
Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance, compliance and technology problems.
HG helps organizations approach CMMC as part of a functioning cybersecurity program, from accurate scoping and implementation through evidence, assessment readiness and ongoing operation.
Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.
Ask HG
