We Need CMMC Level 2. Where Do We Start?
If your organization needs CMMC Level 2, do not start by treating the 110 NIST SP 800-171 requirements as a checklist.
Start by understanding why CMMC applies, what Controlled Unclassified Information (CUI) your organization handles, where that information lives, which people, systems and service providers are actually in scope, and what cybersecurity capabilities already exist.
Those decisions shape almost everything that follows.
Hotman Group helps organizations scope, assess, remediate, implement and operationalize CMMC Level 2 requirements while integrating the work into the cybersecurity program that already exists.
The objective is not simply to get through a CMMC assessment. It is to build an environment that protects CUI, can demonstrate that protection during assessment and can sustain the requirements afterward.
What Is CMMC Level 2?
Cybersecurity Maturity Model Certification (CMMC) Level 2 is the Department of Defense cybersecurity level associated with protecting CUI and is based on the security requirements in NIST SP 800-171.
For organizations subject to Level 2, CMMC is about demonstrating that the required protections are actually implemented within the applicable environment.
That distinction matters.
Having policies, buying security products or completing a gap assessment does not by itself mean the requirements are implemented.
What Should We Do First for CMMC Level 2?
Start with five questions:
- What DoD contracts, subcontracts or opportunities are driving the requirement?
- What CUI does the organization receive, create, process, store or transmit?
- Where does that CUI flow?
- Which systems, people, locations and external providers touch the CUI environment?
- What existing cybersecurity controls can already satisfy CMMC requirements?
Those answers establish the foundation for scoping and gap analysis.
Why Is CMMC Scoping So Important?
Because CMMC does not necessarily apply to every device, system and employee in the organization.
The assessment boundary is driven largely by how CUI is handled and by the assets and services that protect or support that environment.
Poor scoping can create two opposite problems.
An organization can scope too narrowly and leave required assets or dependencies out of the assessment.
Or it can scope too broadly and unnecessarily subject much more of the enterprise to CMMC requirements, increasing cost, complexity and remediation work.
See what is actually in scope for CMMC.
Should We Build a Separate CMMC Enclave?
Maybe.
An enclave can sometimes reduce scope by creating a defined environment for CUI rather than extending CMMC requirements across a much larger enterprise environment.
But an enclave is not automatically the right answer.
The decision should consider:
- How CUI is used by the business.
- Who needs access.
- Existing technology architecture.
- Operational workflows.
- External service providers.
- Cost.
- User experience.
- Long-term sustainment.
A technically isolated environment that employees cannot practically use can create workarounds that undermine the intended protection.
Do We Need to Implement 110 Completely New Security Controls?
Usually not.
Organizations often already have cybersecurity capabilities that satisfy or partially satisfy CMMC requirements.
Existing identity management, multifactor authentication, logging, vulnerability management, incident response, configuration management, security awareness and other controls may provide substantial reuse.
The work is to determine whether those controls meet the specific CMMC requirement and assessment objectives within the CMMC scope.
See whether existing security controls can be reused for CMMC.
Should We Start With a CMMC Gap Assessment?
Usually, but only after establishing a reasonable scope.
A gap assessment should compare the actual environment against applicable CMMC requirements and assessment objectives.
It should tell the organization more than which requirements are "pass" or "fail."
A useful assessment should identify:
- What already exists.
- What partially satisfies the requirement.
- What is missing.
- What evidence exists.
- What evidence is missing.
- Who owns the relevant control.
- What remediation is required.
- What dependencies affect remediation.
The output should become an implementation plan, not a report that sits on a shelf.
What Is the Difference Between a CMMC Gap Assessment and the Certification Assessment?
A gap or readiness assessment is performed to understand whether the organization is ready and what needs to be fixed.
A CMMC certification assessment is the formal assessment used to determine whether the organization satisfies the required CMMC level when third-party certification is required.
Readiness work should occur before the certification assessment.
The formal assessor should not be the first person to discover that a required control is missing or cannot be demonstrated.
What Documentation Do We Need for CMMC Level 2?
Documentation needs depend on how the organization implements the requirements, but organizations should expect to maintain documentation that explains the environment and supports the operation of the security program.
This commonly includes:
- System Security Plan (SSP).
- Policies and procedures.
- Network and data-flow information.
- Asset and system inventories.
- Roles and responsibilities.
- Configuration information.
- Risk and remediation records.
- Evidence showing controls operate as described.
The documentation should describe the real environment.
Writing an impressive policy that does not match actual operations does not solve the requirement.
What Is the CMMC System Security Plan?
The SSP describes the system environment and how the organization implements the applicable NIST SP 800-171 security requirements.
It is a central CMMC artifact, but it should not be treated as a document written independently from the implementation.
The SSP should reflect the actual architecture, scope, responsibilities and controls.
If the environment changes, the SSP needs to remain aligned with reality.
How Much Evidence Do We Need?
Enough to demonstrate that the requirements are implemented and operating as represented.
Evidence may include:
- System configurations.
- Screenshots.
- Logs.
- Tickets.
- Reports.
- Policies and procedures.
- Training records.
- Technical settings.
- Interview evidence.
- Process records.
The important question is not how many files can be collected.
It is whether the organization can reliably demonstrate the implementation of each requirement and applicable assessment objective.
See how to centralize cybersecurity and compliance evidence without creating more work.
What If We Have a Lot of CMMC Gaps?
Prioritize remediation rather than attempting to fix everything simultaneously.
Consider:
- Requirements that materially affect CUI protection.
- Items that cannot be deferred.
- Technical dependencies.
- Long implementation lead times.
- Policy and process dependencies.
- Technology purchases.
- External provider changes.
- Evidence that must accumulate over time.
A realistic remediation roadmap should assign owners, dependencies, priorities and target dates.
See who can help remediate cybersecurity findings.
Can We Use POA&Ms for CMMC Level 2?
CMMC permits limited use of Plans of Action and Milestones under defined conditions, but organizations should not build their readiness strategy around the assumption that every unmet requirement can simply be placed on a POA&M.
Some requirements cannot be deferred, and conditional status has specific scoring, timing and closeout requirements.
The safer readiness objective is to implement the required controls before the certification assessment wherever possible.
What Is the SPRS Score and Why Does It Matter?
The Supplier Performance Risk System (SPRS) is used for reporting assessment information associated with NIST SP 800-171 and DoD cybersecurity requirements.
Your SPRS information should reflect the organization's actual implementation status.
A score is not a substitute for understanding the environment, and organizations should not represent controls as implemented when they are not.
Who Should Own CMMC Inside the Organization?
CMMC should not belong entirely to one compliance employee.
Different requirements depend on different functions.
For example:
- IT may operate technical controls.
- Security may operate monitoring and incident-response capabilities.
- HR may support personnel and training requirements.
- Facilities may support physical controls.
- Business leaders may own operational decisions.
- Cyber GRC may coordinate requirements, evidence and assessment readiness.
Clear ownership matters because controls must continue operating after the assessment.
See how to create clear ownership for cybersecurity controls.
Do We Need a Full-Time CMMC Person?
Not necessarily.
The right resource model depends on the organization's size, environment, internal expertise and amount of ongoing work.
Some organizations can operate CMMC using existing security and IT teams with Cyber GRC coordination.
Others need outside expertise or ongoing support.
See how to decide between a vCISO, vGRC, Cyber GRC consultant or full-time hire.
Do We Need a GRC Platform for CMMC?
No.
A GRC platform can help organize requirements, controls, evidence, ownership, findings and ongoing monitoring, but the platform does not make the organization compliant.
For some organizations, a platform provides substantial operational value.
For others, especially smaller or narrowly scoped environments, simpler processes may be sufficient.
See whether the organization actually needs a GRC platform.
What About Cloud Providers and Other External Service Providers?
External providers can materially affect CMMC scope and compliance.
If a provider stores, processes, transmits, protects or otherwise supports CUI or the CMMC environment, its role needs to be understood during scoping.
Do not assume that outsourcing a function removes the associated CMMC responsibility.
Vendor architecture, contractual responsibilities, security capabilities and applicable CMMC or FedRAMP requirements may need to be evaluated depending on the service.
Does Microsoft 365 Automatically Make Us CMMC Compliant?
No.
Technology can provide capabilities needed to satisfy requirements, but compliance depends on how the environment is scoped, configured, operated and governed.
Buying a particular Microsoft license or moving users into a particular cloud environment does not by itself implement all CMMC Level 2 requirements.
Do We Need GCC High for CMMC?
Not universally.
The appropriate Microsoft environment depends on the organization's contractual obligations, the type of information involved, applicable export-control considerations, architecture and other requirements.
The decision should be based on the actual requirements rather than the assumption that every CMMC Level 2 organization must use the same Microsoft environment.
What About Our MSP or MSSP?
Managed service providers and managed security service providers can be important parts of the CMMC environment because they may administer systems, provide security functions or have privileged access.
Their role should be evaluated during scoping and architecture decisions.
The organization should understand:
- What the provider can access.
- What security functions it performs.
- What evidence it can provide.
- What contractual responsibilities exist.
- How its services affect the assessment boundary.
How Long Does CMMC Level 2 Readiness Take?
There is no universal timeline.
An organization with a well-managed security program and narrowly defined CUI environment may have substantially less work than an organization with broad CUI flows, weak documentation and significant technical gaps.
Factors affecting the timeline include:
- Scope.
- Current security maturity.
- Technical remediation.
- Technology procurement.
- Architecture changes.
- Policy and process development.
- External service providers.
- Internal resource availability.
Starting early matters because some remediation cannot be completed meaningfully at the last minute.
When Should We Engage a C3PAO?
Do not wait until every readiness activity is complete before thinking about the certification assessment.
Organizations that require a C3PAO assessment should understand assessment timing and availability early enough to incorporate it into the project plan.
But engaging an assessor does not replace readiness work.
The C3PAO evaluates the environment. It is not there to build the program for you.
Can the Same Firm Prepare Us for CMMC and Perform Our Certification Assessment?
Organizations should preserve the independence required for the formal assessment.
The consulting team helping design, implement or remediate the CMMC environment serves a different role from the independent assessor determining whether the requirements have been satisfied.
That separation is useful beyond formal independence requirements. The organization needs implementation help focused on getting the environment right, not merely predicting what an assessor might accept.
What If We Already Have SOC 2 or ISO 27001?
Use what you already have.
Existing cybersecurity controls, policies, risk processes, evidence and governance may provide a significant head start.
But SOC 2 or ISO 27001 does not automatically equal CMMC Level 2.
The organization still needs to map existing capabilities to the specific CMMC requirements, validate the CUI scope and address the gaps.
See how to reuse existing security controls for CMMC.
Should CMMC Become a Separate Cybersecurity Program?
Usually not.
CMMC introduces specific requirements for protecting CUI, but many of the underlying controls should connect to the broader cybersecurity program.
If the organization also maintains SOC 2, ISO 27001, NIST CSF or other frameworks, common controls should be reused wherever requirements genuinely overlap.
See how to build one cybersecurity program across multiple frameworks.
What Happens After We Achieve CMMC Level 2?
The work does not stop.
Controls need to continue operating. Evidence needs to remain available. Changes to systems and vendors need to be evaluated. Documentation needs to stay accurate. Findings need to be addressed. Required affirmations and reassessments need to occur.
A program built only to survive assessment can begin drifting almost immediately afterward.
See how to maintain cybersecurity compliance after certification.
What Are the Biggest CMMC Mistakes to Avoid?
- Starting remediation before understanding scope.
- Assuming the entire enterprise must be in scope.
- Assuming existing certifications automatically satisfy CMMC.
- Treating every existing control as reusable without validating it.
- Writing documentation that does not match reality.
- Collecting evidence only immediately before assessment.
- Making Cyber GRC responsible for controls it does not operate.
- Assuming technology purchases create compliance.
- Ignoring external service providers.
- Waiting until the assessment is imminent to address difficult technical gaps.
- Building a CMMC program that cannot be sustained after certification.
What Is a Practical CMMC Level 2 Roadmap?
A practical sequence is:
- Understand the contractual driver and CUI.
- Define and validate scope.
- Inventory relevant systems, people and service providers.
- Assess existing controls against CMMC requirements and assessment objectives.
- Reuse existing capabilities where they genuinely satisfy requirements.
- Identify and prioritize gaps.
- Assign control and remediation ownership.
- Implement technical, procedural and governance changes.
- Build documentation that reflects the real environment.
- Collect and validate evidence.
- Perform readiness validation.
- Complete the required CMMC assessment.
- Operate and sustain the program afterward.
How Does Hotman Group Help With CMMC Level 2?
Hotman Group helps organizations move from CMMC uncertainty to an implemented and sustainable program.
HG can support CMMC scoping, readiness and gap assessments, control mapping, remediation planning, technical and procedural implementation, policy and procedure development, SSP development, evidence readiness, control ownership, GRC technology, assessment preparation and ongoing sustainment.
Hotman Group also helps organizations reuse existing cybersecurity investments rather than automatically creating a completely separate CMMC program.
The goal is not to manufacture documentation for an assessment.
The goal is to implement the required protections, demonstrate them accurately and make them part of an operating cybersecurity program.
Where Should We Start If We Need CMMC Level 2?
Start with scope.
Understand the CUI, the contractual requirement and the environment that needs to protect it before making major technology or remediation decisions.
Then assess what already exists, identify what is missing and build a prioritized implementation plan.
If you are not yet sure whether the larger problem is CMMC, cybersecurity architecture, Cyber GRC capacity or something else, see what to do when you know you have cybersecurity and GRC problems but do not know what kind of help you need.
About Hotman Group
Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems. Hotman Group designs, builds, implements, remediates, operates and matures cybersecurity and GRC programs.
Learn more about Hotman Group's approach to solving complex cybersecurity and Cyber GRC problems.

