An in-kind CMMC gap assessment gives a small contractor an honest, documented picture of where it stands against the CMMC requirements, along with a written plan for closing the gaps. Your prime needs that picture to keep you in its supply chain with confidence, even before you hold a certification.
This week MxD published a look at the cybersecurity reality of the American shop floor, and it named the imbalance plainly. A large prime can hire a whole team of compliance and cybersecurity professionals for its CMMC effort. The small machine shop that makes one of its parts usually cannot. CMMC Phase 2 third-party assessments are suspended for now, but Phase 1 self-assessment and flow-down obligations are still active, and that imbalance still matters today. Below is a plain look at what a gap assessment is, what it is not, and how it changes the conversation with your prime.
What does a CMMC gap assessment actually look at?
A gap assessment is a structured readiness review. It is not an official CMMC assessment, and nobody hands you a certificate at the end. Its job is to answer three questions with evidence.
The first question is scope. Where does Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) actually live in your business? Which laptops, file shares, email accounts and people touch it? Do you know every place a drawing marked CUI has ended up since your current contract started?
The second question is requirements. For CMMC Level 2, the measuring stick is the 110 security requirements in NIST SP 800-171 Revision 2. For Level 1, it is the 15 basic safeguarding requirements drawn from FAR 52.204-21. A good gap assessment goes through each requirement and records whether it is met, partly met or not met, and what evidence supports that call.
The third question is documentation. Level 2 expects a System Security Plan (SSP) that describes your environment and how each requirement is met. A gap assessment shows whether your SSP exists, whether it matches what really happens day to day, and what is missing.
The output is a clear picture of your readiness and a prioritized list of your gaps by severity: the starting point for an honest self-assessment score under the DoD Assessment Methodology (the scoring behind the Supplier Performance Risk System, or SPRS) and a Plan of Action and Milestones (POA&M).
Why would my prime care about a gap assessment if it is not a certification?
Your prime carries obligations that depend on you. Under DFARS clause 252.204-7021, which puts CMMC into contracts, primes must flow CMMC requirements down to subcontractors who will handle FCI or CUI. They must also make sure the subcontractor has a current CMMC status at the required level before awarding that work. In a real sense, your gaps are their exposure.
Then there is the question of what gets signed. CMMC requires a senior official at each contractor to affirm compliance when an assessment happens and every year after that. Through its Civil Cyber-Fraud Initiative, the Justice Department has pursued False Claims Act cases tied to cybersecurity representations made by contractors. A prime has every reason to prefer suppliers whose numbers come from a real review and not from a hopeful guess.
A gap assessment gives your prime three things it can use:
- A score built from evidence, not from memory.
- A clear statement of scope, so the prime knows what information it can safely send you.
- A dated plan, so "we are working on it" becomes "these items close by these dates."
That last point is often what shifts the relationship. To a prime, silence or vagueness looks like risk. A plan with owners and dates looks like a partner.
The limits matter just as much. If a contract calls for a Level 2 certification assessment by a C3PAO (a certified third-party assessment organization), a gap assessment prepares you for it but does not replace it. The rule does not say how much weight a prime should give gap assessment results. That varies from prime to prime, so ask yours directly.
When your prime's supply chain contact last asked about your SPRS score, did you have an answer you would be comfortable putting your name to?
Where does the CMMC timeline actually stand right now, and does it touch my contracts?
CMMC is being phased in. The program rule, 32 CFR Part 170, took effect in December 2024. The DFARS rule that puts CMMC into contracts took effect on November 10, 2025, which started Phase 1. In Phase 1, applicable solicitations began requiring Level 1 and Level 2 self-assessments.
Phase 2 was set to begin one year after Phase 1 started, on November 10, 2026, adding Level 2 certification assessments by a C3PAO for applicable solicitations. In July 2026 the Department of War suspended Phase 2 and launched a reform review of the program; as of this writing no new Phase 2 start date has been announced. Phase 1 self-assessment, SPRS reporting and flow-down obligations were not part of the suspension and remain in force.
What is less settled is when Phase 2 resumes and on what terms. The CMMC level is set solicitation by solicitation, and the review could change parts of the program before it restarts. It is safe to assume your prime will keep asking about your readiness in the meantime, suspension or not. A certification assessment also takes planning, so it is worth treating Phase 1 readiness as the real deadline rather than waiting on a new date.
What does "in-kind" mean here, and why does it matter for my standing?
A Cyber Grants Alliance grant is in-kind. The grant is the work itself: the assessment, the guidance and the expertise delivered to your company. It is expert help brought to you.
This matters for your standing because the small contractors who most need a clear readiness picture are often the ones with nobody in-house to produce it. You may have a capable IT person, or an owner who handles IT between other jobs, but no dedicated security lead. That is not a failing. It is how most small shops work. An in-kind gap assessment fills that particular gap, so your conversation with your prime rests on the same quality of evidence a larger supplier would bring.
The benefit reaches past the prime. The same documented picture helps you answer the security questions other customers send. A small manufacturer that stays qualified also keeps work in its community, along with the machinists, inspectors and office staff whose jobs depend on those contracts.
If your prime asked tomorrow for a one-page summary of where you stand, who in your company would write it, and how sure would they be?
What should I do with the findings once I have them?
A gap assessment is only as useful as what happens next.
- Settle scope first. Narrowing where CUI lives can shrink the work ahead.
- Close the simpler items. Some gaps, such as writing down a practice you already follow, can close sooner than others.
- Turn the rest into a real POA&M with an owner and a target date for each item. Under the CMMC rule, you can hold conditional Level 2 status with open POA&M items only if you meet a minimum score and the open items are ones the rule allows. Those items must be closed within 180 days.
- Bring your SSP in line with how your company actually works, and keep it current.
- Share a summary with your prime contact. You decide what to share. A short status covering scope, score and dates is usually more useful than a thick binder.
- Check which government services you may qualify for. NSA's Cybersecurity Collaboration Center offers services to eligible companies in the defense industrial base, such as protective DNS and vulnerability scanning. These strengthen your protection but do not replace an assessment, and NSA decides who is eligible.
Apply for In-Kind Support
If your prime is asking where you stand and you do not yet have an answer you trust, learn about Cyber Grants Alliance in-kind grants, including how in-kind grant support works and what a CMMC level actually requires.
Frequently asked questions
Is a CMMC gap assessment the same as CMMC certification?
No. A gap assessment is a readiness review that compares your current practices with the CMMC requirements and documents what is missing. Certification comes only from an official assessment, which for Level 2 certification means a C3PAO. A gap assessment prepares you for that step and gives you an honest basis for your self-assessment score.
What does an in-kind CMMC grant from Cyber Grants Alliance provide?
An in-kind grant provides expert work. It is delivered as services, such as a gap assessment and guidance on what to do with the findings. The goal is to give a small contractor the same quality of readiness evidence a larger supplier would bring to its prime.
Will my prime accept a gap assessment in place of a CMMC certification?
Not where a contract requires certification. The CMMC clause requires primes to make sure subcontractors handling FCI or CUI hold the required CMMC status, and a gap assessment is not a status. What it can do is show your prime an evidence-based score, a defined scope and a dated plan, which helps the prime judge whether you will be ready.
When does CMMC Phase 2 begin?
Phase 2 was originally set to begin on November 10, 2026, one year after Phase 1 began on November 10, 2025, adding Level 2 certification assessments by a C3PAO for applicable solicitations. The Department of War suspended Phase 2 in July 2026 pending a reform review, and no new start date has been announced. Phase 1 self-assessment requirements are unaffected and remain active.
How long do I have to close POA&M items under CMMC?
Under 32 CFR Part 170, a contractor can hold conditional Level 2 status with open POA&M items only if it meets a minimum score and the open items are ones the rule allows. Those items must be closed within 180 days. Finding your gaps early is the best way to stay inside that window.
Can the organization that does my gap assessment also certify me?
The CMMC rule includes conflict-of-interest safeguards meant to keep the people who help you prepare from also certifying you. Ask any provider directly how they handle this before you start working with them.
Call to action
If your prime is asking where you stand and you do not yet have an answer you trust, learn about in-kind grant support at cybergrantsalliance.org.
