
How to Run a CMMC Level 2 Gap Analysis Before You Submit Your SPRS Self-Assessment and Score
Emily Bonnie
Senior Content Marketing Manager
Anna Fitzgerald
Senior Content Marketing Manager
With CMMC self-assessments, SPRS reporting, and DFARS 252.204-7012 requirements already in your contracts, a CMMC gap analysis is the most consequential step in your path to compliance and contract eligibility. It's where you stop estimating your cybersecurity posture and actually measure it.
A CMMC gap analysis, also called a gap assessment, compares your current environment against all 110 requirements in NIST SP 800-171 Rev 2. Done well, it shows you where you stand, how your SPRS score shapes up, and what remediation effort stands between you and certification. Done poorly, or skipped entirely, it means you're making financial and operational decisions based on guesses. That gets expensive fast.
This guide walks through how to conduct a proper gap analysis for CMMC Level 2: the steps involved, how long it realistically takes, what some contractors get wrong, and how to use the results to build a defensible path to certification.
What is a CMMC gap analysis?
A CMMC gap analysis is a structured comparison between your current cybersecurity implementation and the 110 requirements in NIST SP 800-171 Rev 2. For each requirement, you determine whether it is fully implemented, partially implemented, or not implemented at all.
You'll see this work described two ways, as a gap analysis and as a gap assessment. They mean the same thing: measuring your environment against the 110 controls before anyone evaluates you formally.
The output isn’t just a scorecard. It should produce four concrete things:
First, a clear view of your compliance posture across all 110 controls. Second, a preliminary SPRS score calculated using DoD scoring methodology. Third, a documented list of remediation actions that will eventually become your Plan of Action and Milestones (POA&M). And fourth, a realistic timeline to assessment readiness.

CMMC Level 2 Compliance Checklist
Download this checklist for CMMC 2.0 Level 2 listing all requirements and assessment objectives to help guide your compliance efforts and assessment preparations.
When should you conduct a gap analysis?
There are several points in your CMMC timeline where a gap assessment makes sense.
The most important is before you begin remediation. You need to know what you’re fixing before you start spending time and money implementing controls, adding new tools, and investing in training.
It’s also common to run a second gap analysis after initial remediation to validate progress. And if you’re preparing for your self-assessment in SPRS, you should conduct an initial readiness review at least a few months beforehand to allow for remediation work.
For most mid-sized organizations, the timeline from first gap analysis to SPRS-ready ranges from three to nine months. Organizations with unclear CUI boundaries or weak documentation often fall on the longer end of that range.
How long does a CMMC gap analysis take?
In a small, well-documented environment with clear CUI boundaries, a disciplined gap analysis can be completed in two to four weeks. Mid-sized contractors with more complex environments should expect four to eight weeks. Multi-site organizations or those with significant documentation gaps should plan for eight to twelve weeks or more.
The variables that extend the timeline most are documentation maturity, system complexity, and stakeholder availability. If key people are hard to pull into evidence review sessions, the process slows. If policies haven't been updated in several years, reconciling them with current operations takes time.
The more organized your environment is before you start, the faster and cleaner the process runs.
If you haven’t conducted one yet, here's how to get started:
Step 1: Assemble the right people
A meaningful gap analysis requires direct visibility into how your environment operates, not just how it's documented. That means you need someone who understands system configurations, someone who owns your policies and procedures, and someone at a leadership level who can make decisions about remediation priorities and business risk.
In smaller organizations, those roles often overlap. A single IT lead and a compliance coordinator can conduct a solid gap analysis if both have genuine access to the systems and documentation in scope. What matters is that the people involved are looking at real configurations and real operating practices, not summarizing what they think is true.
If you're working with a managed service provider (MSP), they should be part of this process from the beginning, particularly if they manage any systems or services that touch CUI.
Step 2: Define your CUI boundary before you score anything
This is the step that most contractors underestimate, and it's the one that causes the most painful surprises during actual assessments.
Before evaluating a single control, you need to define your CUI boundary clearly and specifically. That means identifying which systems, networks, and users process, store, or transmit Controlled Unclassified Information. It means documenting how CUI enters your environment, how it moves internally, and how it exits. It means listing every in-scope asset and understanding which external service providers have any interaction with CUI.
If you're using an enclave strategy to limit scope, this is where you define that enclave precisely, including what keeps CUI contained and what would cause it to cross the boundary.

A poorly defined boundary creates two distinct risks. You may over-scope your environment and significantly inflate remediation costs. Or you may under-scope and end up identifying systems during a self-assessment that were never evaluated. Most difficult and expensive assessments trace back to scoping errors rather than misunderstood control language.
Everything downstream of this step depends on getting the boundary right.
Step 3: Evaluate all 110 controls methodically
Once your boundary is defined, the evaluation begins. Work through the 110 NIST SP 800-171 Rev 2 requirements systematically, and resist the temptation to score controls based on intuition or general familiarity.
Each control should be validated against real evidence: system configurations, operating procedures, log behavior, policy language. That means reviewing real settings, interviewing the people responsible for specific functions, and confirming that what your documentation describes reflects what your environment does. If your acceptable use policy says users receive security awareness training annually, someone should be able to produce records showing that training happened.
For every requirement, document your finding, the evidence reviewed, and any gaps. If you cannot produce defensible evidence for a control, treat it as not fully implemented regardless of your confidence that it's in place. Assessors evaluate objective evidence, not institutional knowledge.
As you work through controls, calculate your preliminary SPRS score in parallel. This gives you a running view of your posture and helps you identify which gaps are carrying the most scoring weight.
You can see all the requirements for CMMC Level 2 and how they’re calculated in your SPRS score in the Requirement Explorer tool on CMMC.com.
Understanding your SPRS score
The Supplier Performance Risk System scoring model starts at 110 points. For each requirement that is not fully met, you subtract its assigned value. Controls are worth one, three, or five points depending on their criticality to CUI protection.
Five-point controls relate to core protections and carry the highest risk impact. A single unmet five-point control affects your posture significantly more than several unmet one-point controls, so identify those early.
While the standalone DFARS 7019 SPRS self-attestation requirement was eliminated in February 2026, SPRS scoring remains embedded in the CMMC framework. For Level 2 certification, organizations must achieve at least 88 points and close all controls that are ineligible for POA&M status. Your gap analysis should make your position against that threshold immediately visible.

Building a useful POA&M
Every control that isn't fully implemented should generate a Plan of Action and Milestones entry. A useful POA&M goes beyond a task list. For each gap, it should describe the specific finding, its root cause, the planned remediation approach, the owner responsible for completion, and a realistic target date.
Some controls cannot remain open at the time of your self-assessment in SPRS. Multi-factor authentication and FIPS-validated encryption are the most common examples. If these are gaps in your current environment, they should be treated as immediate remediation priorities, not items to carry forward on a timeline.
A well-structured POA&M is what turns your gap analysis findings into an operational roadmap. It also demonstrates to assessors that your organization has a clear-eyed understanding of its gaps and a credible plan to address them.
Recommended reading
Understanding the Plan of Action and Milestones (POA&M): A Practical Guide for CMMC and FedRAMP Compliance
The most common CMMC gap analysis findings
Across readiness reviews and self-assessments, the same gaps tend to show up again and again.
Multi-factor authentication is often deployed inconsistently, covering some systems but leaving other in-scope assets uncovered. Encryption is frequently in place but not validated to FIPS standards, which still falls short of the requirement. CUI boundaries are often poorly documented. Logging is enabled on individual systems but not centrally monitored or reviewed. Incident response plans exist on paper but have never been tested, so no one knows whether they hold up. And policies often describe ideal processes that don't match what people do day to day.
Most of these gaps trace back to misalignment between technology, documentation, and daily practice, and a proper gap analysis is what makes that misalignment visible.
The most expensive mistake contractors can make
The most expensive mistake in a CMMC gap analysis is treating it as a documentation exercise instead of a systems validation exercise. Updating policies without validating configurations creates an artificial sense of compliance that collapses during assessment.
A credible gap analysis aligns three things: configuration, documentation, and evidence. If those three elements don't match, the gap will surface eventually.
Automated solutions for CMMC gap analysis
Automated tooling eliminates the manual work of pulling system configurations, checking settings against exact control requirements, tracking and maintaining evidence, and recalculating your SPRS score as findings change. It removes the effort of maintaining a 110-control spreadsheet and keeps your compliance picture current between assessments.
The parts that still need human judgement are scoping your CUI boundary, interpreting whether a control is sufficiently met, and deciding remediation priorities against business risk. Software supports those decisions, but even the best software for CMMC gap analysis can't replace them.
Secureframe Defense runs the continuous side of this work. It evaluates your environment against all 110 NIST SP 800-171 controls, collects evidence automatically, and keeps your SPRS score and POA&M current as your environment changes, so your CMMC preparation holds up from your first gap analysis through your SPRS score submission.
What to do after your gap analysis
Once the gap assessment is complete, the work shifts to remediation and documentation.
You finalize your preliminary SPRS score and use it to prioritize remediation by both risk and certification impact. You update your System Security Plan to accurately reflect implemented controls, not aspirational ones. You assign POA&M items to owners with clear timelines and begin tracking progress on an ongoing basis.
Most organizations benefit from a readiness review several months before their self-assessment. This reduces the risk of late-stage findings that push timelines.
Keep in mind: self-assessments are required every three years, plus an annual affirmation, but compliance is continuous. The gap analysis marks the beginning of an ongoing program, not the completion of a project.
Turn your CMMC gap analysis into a continuous compliance program
Spreadsheets work for a first gap assessment, but they go stale the moment your environment changes. New users get added, systems get updated, policies evolve, and a static document stops reflecting reality unless someone maintains it by hand.
Secureframe Defense runs your gap assessment continuously, so your CMMC preparation stays current from your first pass through to your self-assessment. You can confidently submit your implementation into SPRS with a defensible, up-to-date posture instead of a snapshot that aged out weeks ago.
Streamline your compliance with CMMC 2.0
FAQs
Is a CMMC gap analysis the same as a gap assessment?
Yes. The terms are used interchangeably to describe the internal exercise of measuring your environment against NIST SP 800-171 Rev 2. Some providers say gap assessment and others say gap analysis. The work is the same: find your gaps, calculate your SPRS score, and build a remediation plan you can defend.
Can I conduct a CMMC gap analysis internally, or do I need outside help?
You can conduct one internally if you have people with direct technical and compliance visibility into your environment. The risk with a purely internal review is that familiarity with your own systems can create blind spots. Many organizations do an internal first pass and then bring in an outside advisor to validate findings before moving to remediation.
Should I run my gap assessment with a consultant, internal staff, or a platform?
A consultant-led gap assessment gives you outside expertise for a fixed engagement, with cost that scales with your environment. Internal staff can run a solid first pass when they have direct visibility into systems and documentation. A compliance platform like Secureframe Defense runs the gap assessment against all 110 controls, collects evidence automatically, and keeps your posture current as your environment changes.
What does a CMMC gap analysis typically cost?
It varies significantly based on scope and whether you're using internal staff, a consultant, or automated tooling. A focused internal effort may cost primarily in staff time. Consultant-led gap assessments for mid-sized contractors typically range from $15,000 to $50,000 or more depending on complexity. Automated platforms can reduce ongoing cost significantly once the initial setup is complete.
What if my preliminary SPRS score is very low?
A low score tells you exactly where the remediation work needs to happen and how much of it there is. Organizations with scores well below the 88 conditional threshold often find that a concentrated remediation effort on high-weight controls moves their posture substantially. See all the requirements for CMMC Level 2 and how they’re calculated in your SPRS score in the Requirement Explorer tool on CMMC.com.
How often should I repeat the gap analysis?
At minimum, you should conduct a formal review annually or whenever significant changes occur in your environment: new systems, new personnel, changes in how CUI is handled, or updates to NIST guidance.

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.

Anna Fitzgerald
Senior Content Marketing Manager
Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.