CMMC ComplianceCyber Grants Alliance Blog

Gap Assessment vs Vulnerability Scan: What Each Tells You

July 27, 2026 Cyber Grants Alliance 6 min read

A vulnerability scan tells you what is broken on the machines it can reach. A gap assessment tells you whether your organization can prove it runs a security program that meets a defined set of controls -- which is a completely different question, and it is the one auditors, primes, insurers, and grantmakers actually ask.

Both are useful. Neither substitutes for the other. The trouble starts when a small team runs a scan, sees a clean report, and assumes the compliance conversation is handled. It is not, and recent developments in CMMC made that clearer than usual.

What does a vulnerability scan actually measure?

A scan looks at assets it can see on the network or on the endpoint and compares what it finds against a database of known weaknesses: unpatched software, expired certificates, exposed services, weak configurations, default credentials. Good scanners are excellent at this. They are fast, repeatable, and they catch real problems that would otherwise sit for months.

But look at what a scan is structurally unable to observe. It does not know who you are. It does not know what data you hold, who is allowed to touch it, whether you wrote down the rules, whether anyone follows them, or whether you could show evidence of any of that to a third party twelve months from now.

A scan answers: is this system vulnerable right now? A gap assessment answers: does this organization have a defensible security program?

What does a gap assessment surface that no scanner can?

Most of the requirements in a framework like NIST SP 800-171 are not things a scanner can even look at. They are organizational. A gap assessment covers each of these areas in a way no automated tool can replicate:

Scope and boundary. Which systems store, process, or transmit the sensitive data in question, and which ones are legitimately out of scope? A scanner reports on whatever you pointed it at. It has no opinion on whether you pointed it at the right things. Getting scope wrong is one of the most common and most damaging errors -- and it is exactly what a clear CUI boundary definition is designed to prevent.

Documented policy and procedure. Many controls require a written policy plus evidence that the practice is performed. A scanner cannot read your access control policy because you may not have one.

People and process controls. Security awareness training, personnel screening, sanctions for policy violations, incident response planning and testing, media sanitization, and physical protection all sit outside the scanner's field of view entirely.

Third-party responsibilities. If a cloud provider or managed service provider handles your sensitive data, the responsibility split between you and them is a contractual and architectural question, not a scan result. Do you know, in writing, which controls your provider covers and which ones remain yours?

Evidence. This is the quiet one. Assessors do not accept assertions. They accept artifacts: screenshots, logs, signed policies, ticket records, training rosters. A gap assessment tells you which artifacts exist, which are stale, and which you would have to invent under pressure. That last category is where organizations get hurt.

Get Your Gap Assessment Funded

The CMMC Gap Assessment Grant provides an in-kind assessment for qualifying small businesses -- we perform the assessment for you rather than handing over cash.

Apply for the Gap Assessment Grant →

Does the CMMC Phase II pause mean I can stop?

No, and this is exactly the wrong time to relax. In July 2026 the Department suspended the Phase II requirements of the CMMC program, which had been scheduled to take effect on November 10, 2026, and opened a reform review running roughly sixty days. The Small Business Administration publicly commended the suspension.

What reporting consistently says next matters more: contractors already subject to Phase 1 requirements must continue performing required self-assessments and complying with applicable cybersecurity clauses. The underlying obligations under DFARS 252.204-7012 and the NIST SP 800-171 control set were not repealed. What paused is the third-party certification step for Level 2 -- not the requirement to actually implement and document controls.

The outcome of the reform review is not settled, and anyone telling you exactly what the program will look like in the fall is guessing. Treat the pause as time, not as relief.

If I only have room for one, which should I do first?

If you have never been assessed against a control set, start with the gap assessment. A scan generates a list of technical findings, and a small team can spend two quarters patching that list and still be nowhere on the requirements that carry the most weight in a self-assessment score -- because those requirements were never technical.

The gap assessment gives you a map. It tells you what is implemented, what is partially implemented, what is missing entirely, and what your realistic remediation sequence should be. Then the scanner becomes a tool inside that plan rather than a substitute for it, feeding the vulnerability management and flaw remediation controls with continuous evidence.

Ask yourself honestly: if a prime contractor, a grantor, or an insurer asked you today to show your system security plan and three pieces of supporting evidence, what would you send in the next hour?

What does this look like for a team without a security person?

Most of the organizations we work with have no CISO, no compliance lead, and one very capable person who already has another full-time job. That is normal, not a failure, and we do not treat it as one.

For a team like that, the gap assessment is doubly valuable because it converts an intimidating framework into a finite, ordered list of tasks owned by named humans with dates. A lot of what comes out of it is writing and decision-making rather than technology purchasing. Policies get drafted. Scope gets narrowed deliberately so there is less to defend. Provider responsibilities get pinned down in writing. A plan of action with milestones gets built so that partial progress is documented rather than hidden.

That is work a small team can genuinely do. What a small team usually cannot do alone is the first honest measurement -- which is precisely why our gap assessment grants are offered in kind: we perform the assessment for the organization rather than handing over money.

Frequently Asked Questions

Is a vulnerability scan enough to satisfy NIST SP 800-171?

No. Vulnerability scanning supports specific controls within the risk assessment and system integrity families, but NIST SP 800-171 contains well over a hundred requirements spanning policy, access control, training, incident response, media protection, physical security, and personnel practices. A scanner cannot observe or evidence most of them. Scanning is one input to compliance, not proof of it.

What is the difference between a gap assessment and an audit?

A gap assessment is an internal readiness exercise. It measures your current state against a control set, identifies what is missing, and produces a prioritized remediation plan -- with no pass or fail outcome and no reporting to an outside authority. An audit or certification assessment is a formal evaluation by an authorized third party that results in a decision. You run gap assessments so that audits are boring.

Did the CMMC Phase II suspension eliminate my cybersecurity obligations?

No. Reporting in July 2026 indicates the Department suspended Phase II third-party assessment requirements and launched a reform review, but contractors under existing Phase 1 requirements must continue self-assessments and comply with applicable clauses, including DFARS 252.204-7012. The final shape of the reformed program is not yet settled, so treat current obligations as live.

How often should a gap assessment be repeated?

Annually is a reasonable baseline for most small organizations, and immediately after any material change: a new cloud platform, a merger, a new contract type, a significant staffing change, or a shift in the data you handle. Scanning should be continuous or at least monthly. The two operate on different clocks because they answer different questions.

Can my managed service provider handle all of this for me?

Partly. A provider can operate technical controls on your behalf, but the responsibility for scoping, policy, evidence retention, and the accuracy of any self-assessment score you submit stays with your organization. Ask your provider for a written responsibility matrix showing which controls they cover and which remain yours. If they cannot produce one, that is a finding in itself.

Does a clean scan improve my SPRS self-assessment score?

Not directly. Self-assessment scoring under NIST SP 800-171 is based on which requirements are implemented, not on how many vulnerabilities are currently open. You could have a spotless scan and a poor score if your documentation, scoping, and organizational controls are incomplete.

Sources: PilieroMazza Weekly Update, July 23, 2026; Parker Poe; Crowell; Morrison Foerster; NIST SP 800-171; DFARS 252.204-7012.

Share this article: LinkedIn X Email