You did the right thing. You completed a CMMC gap assessment and now you are holding a detailed report telling you exactly where your organization stands against the 110 NIST SP 800-171 controls. You have an SSP draft, a list of gaps, and a remediation roadmap.
Now what? For a lot of small manufacturers, this is the moment the process stalls. The assessment is done, the gaps are identified; but turning that document into an action plan feels overwhelming. This post gives you a clear, practical sequence for what to do next.
Have questions about this topic?
Book a call with us and get your questions answered directly.
Book a Call with Us →Step 1: Understand Your Score
Your gap assessment will typically produce a numerical SPRS score ranging from -203 to 110, with 110 representing full compliance. Most small manufacturers come out of their first gap assessment with a score well below 110. That is not a failure; it is exactly what gap assessments are designed to surface.
A low SPRS score does not mean you are in violation today. It means you have work to do before your certification assessment. The gap assessment is the starting gun, not the finish line.
Step 2: Triage Your Gaps
Not all gaps are equal. Prioritize in this order:
- Essential security controls that directly protect CUI: multi-factor authentication, encryption at rest and in transit, and access control restrictions. Fix these first.
- High-impact, low-effort fixes such as configuration changes, software updates, and policy documentation that close significant gaps with relatively little investment.
- Documentation gaps: many small manufacturers have the right practices but lack written documentation. Your SSP, Incident Response Plan, and Configuration Management Plan all need to be formalized.
- Complex technical remediations such as network segmentation, MFA rollouts, and endpoint detection systems. Schedule these with your full timeline in view.
Step 3: Build Your POA&M
Your Plan of Action and Milestones (POA&M) is a formal document listing every gap, planned remediation, responsible party, and target completion date. You will need it for your C3PAO assessment. Start building it from your gap assessment findings immediately.
Step 4: Fund Your Remediation
Before you pay out of pocket, explore available funding:
- CGA Pen Testing Grant: fund independent validation of your controls after remediation
- CGA Employees Cyber Training Grant: fund mandatory security awareness training for all staff
- CGA CyberCert Grant: pursue recognized cybersecurity certification
- MEP Center programs: cost-share grants of up to $22,500 in some states
- State cybersecurity grants: visit cybergrantsalliance.org/state-grants for state-specific programs
Step 5: Validate with a Penetration Test
After remediation is substantially complete, a penetration test independently validates whether your controls are actually working in your live environment, not just in your documentation. Discovering and fixing issues before your C3PAO assessment is far better than discovering them during it.
Step 6: Schedule Your C3PAO Assessment
With remediation underway and your POA&M in place, book your C3PAO assessment slot. Given current backlogs of six months or more, schedule as early as possible, even before remediation is fully complete.
Fund Your Next Step with a CGA Grant
CGA offers Pen Testing, Employee Training, and CyberCert Grants to support your remediation journey after your gap assessment. Apply now.
View All Grant Programs →Attend the CMMC Grant Summit 2026
Join other DIB manufacturers at CGA’s free virtual summit on August 19, 2026. Hear from MEP Centers on available grant programs and get your compliance questions answered live.
Reserve Your Seat →