The 12 CMMC Level 2 Documentation Gaps That Fail Most C3PAO Assessments
A free guide for defense contractors handling CUI. By Josef Kamara, CPA, CISSP, CISA. Published by Amerifusion GovCon.
Get the 12-gap guide
Sent to your inbox immediately. The 12 documentation gaps that fail most C3PAO Level 2 assessments and how to close each one.
Check your inbox.
The guide is on its way. If it does not arrive in 5 minutes, download it directly below.
Download the PDF →The 12 gaps, grouped by NIST 800-171 domain
Two gaps per domain across the six NIST SP 800-171 Rev 2 families that produce the highest C3PAO finding rates. Each entry inside the PDF includes the control reference, the documentation that fails, why C3PAOs flag it, and exactly how to close it before the formal review.
The account inventory and role/permission matrix
The SSP claims "least privilege." The assessor asks for the current list of every account in the CUI environment, what role each holds, and when each role was last reviewed. Most contractors cannot produce one.
Privileged-account separation evidence
Domain admins, cloud tenant admins, and the EDR console all share the same identity. The control requires separation of privileged duties from non-privileged work, with logged use of admin accounts only for admin tasks.
MFA coverage evidence
The MFA policy is on file. The assessor wants the configuration export from the IdP, an authentication log sample showing MFA enforced for every privileged account, and a coverage matrix proving every CUI-system entry point is in scope.
Password policy implementation proof
The policy document says one thing. The Group Policy or Entra ID export says another. Assessors flag the gap when the in-effect technical control does not match the written policy.
Audit log coverage matrix
"We log everything." The assessor asks which systems generate which event types, where the logs go, how long they are retained, and how they are protected from tampering. There is no documented matrix.
Audit log review evidence
The SIEM exists. The review records do not. C3PAOs sample 90 days of review tickets, alerting rules with thresholds, and escalation runs. A SIEM with no review history is logging in name only.
Baseline configuration documentation
Every system class - workstations, servers, network devices, cloud services - needs a current documented baseline plus drift-detection evidence. The most common finding: a baseline written once and never refreshed against what is actually deployed.
Change control records
Every production change should trace to an approval, a test result, and a post-implementation review. Most contractors have a change ticketing tool and no closed-loop evidence connecting tickets to deployed change.
Network/CUI boundary diagram
The SSP describes the boundary in prose. The assessor wants a current data-flow diagram, ingress/egress controls, and segmentation evidence proving the diagram matches firewall reality. Mismatches between SSP and ACLs are the most common SC finding.
FIPS-validated cryptography evidence
Encryption "in use" is not enough. The control requires a cryptographic inventory, FIPS 140-2 or 140-3 certificate references from the NIST CMVP, and proof that FIPS mode is enabled in production.
Vulnerability management cadence
"Monthly scans" appears in policy. The assessor asks for the last 90 days of scan reports, severity-tiered remediation SLAs, and closeout verification. Most contractors run scans and stop there.
Flaw remediation tracking
Patches go out. The audit trail does not. A defensible record connects each CVE to a specific asset, a patch deployment date, and proof the SLA tier was met. The gap shows up when an assessor samples three CVEs and asks for the deployment evidence.
C3PAOs fail contractors on documentation more often than on technology
The pattern is consistent across DCMA DIBCAC High Assessments and the early CMMC Level 2 C3PAO assessments running under Phase 1 of the rollout. Contractors invest in tooling - EDR, SIEM, MFA, cloud security platforms - and then arrive at the assessment with a SSP that describes an aspirational version of the program rather than the one that is actually running. The technology is rarely the reason a contractor fails. The documentation that proves the technology is doing what the SSP says it does is the reason.
The 12 gaps inside this guide are the specific places that mismatch shows up. Closing them before the formal review is not a heavier lift than the work the contractor has already done. It is a smaller lift. It is the work of writing down, with evidence, what the team is already doing - and then fixing the small set of places where the writing does not match the doing. That is what separates passing contractors from failing ones. This guide is the checklist.
Send it to your inbox.
For deeper editorial coverage of the CMMC Phase 1 rollout, the C3PAO ecosystem, and how the rule fits the broader federal cybersecurity stack, see the CMMC archive on josefkamara.com - the author's personal authority site, no gating.