CMMC LEVEL 2 — FIND THE GAPS BEFORE ASSESSORS DO
A CMMC gap analysis is a requirement-focused review of where your environment, controls, and documentation fall short of Level 2 expectations — built on the security requirements in NIST SP 800-171 Rev. 2.
The point is not a vague maturity score. It’s gap identification + a prioritized remediation roadmap your team (and MSP) can execute — so weaknesses show up on your calendar, not during certification week.
brs prepares your organization for assessment. Official certification is performed by an Authorized C3PAO.
CMMC Gap Analysis
Primes, contract language, and self-assessment obligations have a way of making “we think we’re fine” expensive. Gap analysis turns uncertainty into a sequenced backlog — what blocks assessment readiness, what can wait, and what documentation or evidence will not hold up under examine / interview / test methods.
Still need orientation before a deep dive? Start with a CMMC Readiness Assessment.
Why Organizations Run This
Deeper than readiness — into requirements, evidence, and remediation order:
• CUI/FCI scoping refinement (systems, assets, users, enclaves)
• Security requirement analysis against CMMC Level 2 / NIST SP 800-171 Rev. 2 expectations
• SSP and POA&M review — completeness and accuracy vs the live environment
• Policy/procedure alignment — documentation that matches operations, not shelfware
• Evidence readiness sampling — what you can produce today vs what assessors typically expect
• SPRS posture and scoring deficiencies that may not survive scrutiny
• Key personnel interviews — how controls work in practice
• Prioritized remediation roadmap — severity, effort, dependency, assessment impact
This is preparatory consulting by brs. It is not an official CMMC certification assessment.
What’s In Scope
1. Kickoff and scope lock — CUI flows, candidate assessment boundary, stakeholders
2. Artifact collection — SSP, policies, diagrams, prior SPRS materials, evidence samples
3. Requirement-focused review
4. Interviews and sampling — documented controls vs operations
5. Gap consolidation — impact and sequencing
6. Roadmap workshop — a plan your team can run
7. Handoff — remediation, SSP/SPRS, evidence, mock, and C3PAO coordination when ready
How It Typically Runs
• A structured gap register (by control family / requirement — not a RAG score alone)
• A prioritized remediation roadmap with sequencing guidance
• Documentation and evidence gap notes
• Scoping risks that inflate or undermine assessment readiness
• A defined path into later stages, including coordination toward formal assessment with an Authorized C3PAO when appropriate
You should leave knowing what is broken, why it matters for assessment, and what to fix first.
Because “we’ll figure it out during the assessment” is not a strategy. It’s a countdown timer.
What You Walk Away With
What is included in a CMMC gap assessment?
A review of systems, controls, documentation, policies, SSPs, and operational processes against CMMC Level 2 requirements — including CUI/FCI scope, evidence readiness, SPRS posture, and a prioritized remediation roadmap.
How does this relate to NIST SP 800-171 Rev. 2?
CMMC Level 2 is built on the same security requirements found in NIST SP 800-171 Rev. 2. Organizations that implement NIST correctly are typically much better prepared for CMMC assessment. See /nist.
Will this certify us?
No. brs is not a C3PAO. Gap analysis prepares you. Official Level 2 certification assessments are performed by an Authorized C3PAO.
Can we go straight from gap analysis to a C3PAO assessment?
Sometimes — if gaps are limited and evidence is strong. Many organizations need remediation, SSP updates, and a mock assessment first. We’ll tell you which camp you’re in.
Can every gap stay open on a POA&M?
Not every gap can stay open on a POA&M through certification.
Does the program timeline decide assessment path?
CMMC program timelines can change. Your contract still decides whether you self-assess or need a C3PAO.
How do CCPs help?
Certified CMMC Professionals (CCPs) on the brs team help translate assessment expectations into practical prep.
Does this apply to Canadian companies?
Yes, when a Canadian organization supports the US DoD supply chain and handles CUI under applicable contracts. CMMC is a US program. Canadian defense suppliers may also need CPCSC readiness for Government of Canada work. We can help map which path applies.
FAQs
Review Your Current Compliance Position
Get a requirement-focused view of Level 2 gaps and a prioritized remediation roadmap.
1. Earlier: CMMC Readiness Assessment
2. Next: CMMC Remediation Support · SSP & POA&M Support
3. Hub: /cmmc · Broader: /nist · /cpcsc

