Skip to content
A Free Guide for Defense Contractors Handling CUI

The 12 CMMC Level 2 Documentation Gaps That Fail Most C3PAO Assessments


A free guide for defense contractors handling CUI. By Josef Kamara, CPA, CISSP, CISA. Published by Amerifusion GovCon.

Free Download

Get the 12-gap guide

Sent to your inbox immediately. The 12 documentation gaps that fail most C3PAO Level 2 assessments and how to close each one.

Joins the AmerifusionGovCon updates list. Unsubscribe in one click.

Check your inbox.

The guide is on its way. If it does not arrive in 5 minutes, download it directly below.

Download the PDF →
Submission failed. Please try again or email amerifusionconsultants@gmail.com.
Written by

Josef Kamara, CPA, CISSP, CISA. 15+ years in audit and risk across KPMG, BDO, and Stryker. At BDO, led both the third-party attestation practice and the information assurance team, covering SOC 1/2, HIPAA, and HITRUST. At Stryker, managed the IT audit function. Today runs CMMC readiness assessments for a small number of defense contractors per quarter through Amerifusion GovCon.

What's Inside

The 12 gaps, grouped by NIST 800-171 domain


Two gaps per domain across the six NIST SP 800-171 Rev 2 families that produce the highest C3PAO finding rates. Each entry inside the PDF includes the control reference, the documentation that fails, why C3PAOs flag it, and exactly how to close it before the formal review.

AC
Access ControlNIST 800-171 family 3.1 - 22 controls
Gap 01 · AC.L2-3.1.1 / 3.1.2

The account inventory and role/permission matrix

The SSP claims "least privilege." The assessor asks for the current list of every account in the CUI environment, what role each holds, and when each role was last reviewed. Most contractors cannot produce one.

Gap 02 · AC.L2-3.1.5 / 3.1.6 / 3.1.7

Privileged-account separation evidence

Domain admins, cloud tenant admins, and the EDR console all share the same identity. The control requires separation of privileged duties from non-privileged work, with logged use of admin accounts only for admin tasks.

IA
Identification and AuthenticationNIST 800-171 family 3.5 - 11 controls
Gap 03 · IA.L2-3.5.3

MFA coverage evidence

The MFA policy is on file. The assessor wants the configuration export from the IdP, an authentication log sample showing MFA enforced for every privileged account, and a coverage matrix proving every CUI-system entry point is in scope.

Gap 04 · IA.L2-3.5.7 - 3.5.10

Password policy implementation proof

The policy document says one thing. The Group Policy or Entra ID export says another. Assessors flag the gap when the in-effect technical control does not match the written policy.

AU
Audit and AccountabilityNIST 800-171 family 3.3 - 9 controls
Gap 05 · AU.L2-3.3.1 / 3.3.2

Audit log coverage matrix

"We log everything." The assessor asks which systems generate which event types, where the logs go, how long they are retained, and how they are protected from tampering. There is no documented matrix.

Gap 06 · AU.L2-3.3.3 / 3.3.5

Audit log review evidence

The SIEM exists. The review records do not. C3PAOs sample 90 days of review tickets, alerting rules with thresholds, and escalation runs. A SIEM with no review history is logging in name only.

CM
Configuration ManagementNIST 800-171 family 3.4 - 9 controls
Gap 07 · CM.L2-3.4.1 / 3.4.2

Baseline configuration documentation

Every system class - workstations, servers, network devices, cloud services - needs a current documented baseline plus drift-detection evidence. The most common finding: a baseline written once and never refreshed against what is actually deployed.

Gap 08 · CM.L2-3.4.3 / 3.4.5

Change control records

Every production change should trace to an approval, a test result, and a post-implementation review. Most contractors have a change ticketing tool and no closed-loop evidence connecting tickets to deployed change.

SC
System and Communications ProtectionNIST 800-171 family 3.13 - 16 controls
Gap 09 · SC.L2-3.13.1 / 3.13.5

Network/CUI boundary diagram

The SSP describes the boundary in prose. The assessor wants a current data-flow diagram, ingress/egress controls, and segmentation evidence proving the diagram matches firewall reality. Mismatches between SSP and ACLs are the most common SC finding.

Gap 10 · SC.L2-3.13.11

FIPS-validated cryptography evidence

Encryption "in use" is not enough. The control requires a cryptographic inventory, FIPS 140-2 or 140-3 certificate references from the NIST CMVP, and proof that FIPS mode is enabled in production.

SI
System and Information IntegrityNIST 800-171 family 3.14 - 7 controls
Gap 11 · SI.L2-3.14.1 / 3.14.4

Vulnerability management cadence

"Monthly scans" appears in policy. The assessor asks for the last 90 days of scan reports, severity-tiered remediation SLAs, and closeout verification. Most contractors run scans and stop there.

Gap 12 · SI.L2-3.14.2

Flaw remediation tracking

Patches go out. The audit trail does not. A defensible record connects each CVE to a specific asset, a patch deployment date, and proof the SLA tier was met. The gap shows up when an assessor samples three CVEs and asks for the deployment evidence.

Why This Matters

C3PAOs fail contractors on documentation more often than on technology


The pattern is consistent across DCMA DIBCAC High Assessments and the early CMMC Level 2 C3PAO assessments running under Phase 1 of the rollout. Contractors invest in tooling - EDR, SIEM, MFA, cloud security platforms - and then arrive at the assessment with a SSP that describes an aspirational version of the program rather than the one that is actually running. The technology is rarely the reason a contractor fails. The documentation that proves the technology is doing what the SSP says it does is the reason.

The 12 gaps inside this guide are the specific places that mismatch shows up. Closing them before the formal review is not a heavier lift than the work the contractor has already done. It is a smaller lift. It is the work of writing down, with evidence, what the team is already doing - and then fixing the small set of places where the writing does not match the doing. That is what separates passing contractors from failing ones. This guide is the checklist.

Get the Guide

Send it to your inbox.

Joins the AmerifusionGovCon updates list. Unsubscribe in one click.

Check your inbox.

The guide is on its way. Direct download below if needed.

Download the PDF →
Submission failed. Please try again or email amerifusionconsultants@gmail.com.