CMMC Level 2 · NIST SP 800-171
Technical foundations are largely in place; documentation and segmentation are the gaps.
Domain scorecard
Gap: MFA not enforced for remote administrative access
ATAwareness & Training
Met
AUAudit & Accountability
Partial
Gap: Logs are collected but never reviewed on a schedule
CMConfiguration Mgmt
Not met
Gap: No documented baseline configurations for servers or endpoints
IAIdentification & Auth
Partial
Gap: Shared service accounts still in use for two applications
IRIncident Response
Not met
Gap: No written incident response plan and no tabletop in the last 24 months
MPMedia Protection
Not met
Gap: No media sanitisation procedure for decommissioned drives
PEPhysical Protection
Met
RARisk Assessment
Partial
Gap: Vulnerability scanning is ad hoc rather than scheduled
CASecurity Assessment
Not met
Gap: No System Security Plan; controls have never been formally assessed
SCSystem & Comms Protection
Partial
Gap: CUI enclave is not segmented from the general corporate network
SISystem & Info Integrity
Met
CMMC Level 2 — Readiness Report
Directional self-assessment aid — NOT an official CMMC assessment, SPRS submission, or C3PAO certification. Prepared by the GrayVolk AI Assessor.
Executive Summary
This is a 40-person defence subcontractor running an AWS-heavy environment with Microsoft 365 for identity and productivity, handling CUI on design files and procurement records. The technical foundations are better than the score suggests: endpoint protection, patching and physical controls are genuinely in place, and staff awareness training runs annually.
The gap is not technology — it is evidence and boundaries. There is no System Security Plan, no documented baseline configurations, and no incident response plan, which means several domains cannot be demonstrated to an assessor even where the underlying practice exists. Separately, CUI is not segmented from the general corporate network, which materially widens the assessment scope and will make certification more expensive than it needs to be.
Top Priorities
- Scope the CUI enclave before anything else. Segmenting CUI into a defined boundary is the single highest-leverage move available: it shrinks the number of systems in assessment scope, which reduces both remediation effort and eventual assessment cost. Doing this after remediation means doing much of the remediation twice.
- Write the System Security Plan. Without an SSP, CA cannot be met and an assessor has nothing to assess against. It also forces the boundary decisions in priority 1 to be made explicitly rather than by accident.
- Enforce MFA on all remote administrative access. A small technical change with outsized weight — among the most commonly cited findings, and it directly affects your SPRS score.
POA&M Skeleton
- CM — no baseline configurations → build documented baselines for the three server roles and the standard laptop image → 30 days, IT lead.
- IR — no incident response plan → adopt a written IR plan and run one tabletop against a ransomware inject → 45 days, IT lead with executive sponsor.
- MP — no sanitisation procedure → document and adopt NIST SP 800-88 media sanitisation for decommissioned drives → 15 days, IT lead.
- CA — no SSP → produce the SSP covering the scoped enclave, then self-assess against all 110 requirements → 60 days, requires external support.
- AU — logs unreviewed → define a weekly review cadence with a named owner, and record that the review happened → 30 days, IT lead.
- IA — shared service accounts → replace with individual or managed identities for the two applications → 45 days, application owners.
Recommended Next Step
The fastest path from here is a scoping and documentation engagement rather than a tooling purchase: define the CUI boundary, produce the SSP, and convert the six POA&M items above into a sequenced plan with owners and dates. That work turns a 54% directional score into an evidenced position an assessor can actually verify — and it is the part that cannot be automated, because someone qualified has to make and stand behind the boundary decisions.
This report reflects self-reported information from a rapid, conversational assessment and has not been independently validated.
Illustrative example. Figures and findings are fictional and shown to demonstrate report structure.