“Readiness assessment” is used for three different engagements. A questionnaire, a gap analysis, or a full mock assessment. They differ by an order of magnitude in effort and cost, and buyers frequently pay for the third expecting the first, or the reverse.

The three things people mean

EngagementWhat happensWhat it tells you
QuestionnaireYou self-report against the controls, someone reviews itA rough score. Useful for budgeting, not for assurance
Gap analysisAn assessor examines your environment and documentationWhere you actually stand, with a remediation list
Mock assessmentA rehearsal of the real thing, evidence tested as an assessor wouldWhether you would pass, and what would be challenged

Ask which one a proposal describes. If it does not say, that is your first question.

Good to know: a readiness assessment is not a formal CMMC assessment and cannot certify you. Only a C3PAO can do that at Level 2, and only the government at Level 3. A readiness engagement tells you what a real assessment would find.

What a proper readiness assessment covers

  1. Scope validation. Confirming the boundary — every system, service and person handling CUI. Over-scoping is the most expensive error in CMMC, and this is where it gets caught.
  2. Control-by-control review. All 110 controls at Level 2, assessed against evidence rather than assertion.
  3. Evidence testing. Not “is there a policy” but “show me the configuration export, the log, the dated artefact.”
  4. Documentation review. Your System Security Plan and POA&M, examined for the gaps an assessor would find.
  5. SPRS validation. Whether your submitted score is defensible. An inflated score carries real exposure.
  6. Remediation roadmap. Ranked, costed, sequenced by dependency.

What you should receive

How long it takes, and what it asks of you

For a typical small or midsize contractor, expect two to four weeks from kickoff to findings. The variables are the number of systems in scope, whether documentation exists, and how quickly your people can be made available for interviews.

Your side of the effort is real. Expect to provide network diagrams, asset inventories, existing policies, configuration access, and time from whoever actually knows how things work. Engagements slip on availability far more often than on technical difficulty.

Key takeaways
  • Ask which of the three engagements a proposal actually describes.
  • A readiness assessment cannot certify you. Only a C3PAO or the government can.
  • Scope validation is where cost is decided. Insist it comes first.
  • Evidence testing, not policy review, is what makes the finding useful.

When to commission one

Three moments justify it. Before you commit budget, so the number is grounded. Before a formal assessment, so there are no surprises. And when a prime asks for evidence and you are not confident what you would show them.

The current pause changes the urgency but not the logic. The Phase 2 third-party mandate is suspended; DFARS 252.204-7012, NIST SP 800-171, SPRS submission and annual affirmation are not. See what still applies.

The organisations that come out of the pause well are the ones who used it to find out where they actually stand, rather than waiting to be told.

Where IP Consulting fits

We are CMMC Registered, and we do both the readiness work and the technical implementation that follows — which is the combination most organisations find they need after the first proposal. Our CMMC compliance services page covers the delivery detail, and choosing a CMMC consultant covers what to verify in anyone you are considering.

Frequently asked questions

What is a CMMC readiness assessment?

A structured review that tells you what a formal CMMC assessment would find. A proper one validates your scope, reviews all 110 controls against evidence rather than assertion, tests your documentation, checks whether your SPRS score is defensible, and produces a ranked remediation roadmap.

Is a readiness assessment the same as a CMMC assessment?

No. A readiness assessment cannot certify you. Only an accredited C3PAO can conduct a formal Level 2 assessment, and Level 3 assessment is government-led. A readiness engagement is a rehearsal that tells you what would be found and challenged.

How long does a CMMC readiness assessment take?

Typically two to four weeks from kickoff to findings for a small or midsize contractor. The variables are how many systems are in scope, whether documentation already exists, and how quickly your people can be made available for interviews. Engagements slip on availability more often than on technical difficulty.

What do we need to provide for a readiness assessment?

Network diagrams, asset inventories, existing policies, configuration access, and time from the people who actually know how the environment works. Expect the internal effort to be real rather than nominal.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation