“Readiness assessment” is used for three different engagements. A questionnaire, a gap analysis, or a full mock assessment. They differ by an order of magnitude in effort and cost, and buyers frequently pay for the third expecting the first, or the reverse.
The three things people mean
| Engagement | What happens | What it tells you |
|---|---|---|
| Questionnaire | You self-report against the controls, someone reviews it | A rough score. Useful for budgeting, not for assurance |
| Gap analysis | An assessor examines your environment and documentation | Where you actually stand, with a remediation list |
| Mock assessment | A rehearsal of the real thing, evidence tested as an assessor would | Whether you would pass, and what would be challenged |
Ask which one a proposal describes. If it does not say, that is your first question.
What a proper readiness assessment covers
- Scope validation. Confirming the boundary — every system, service and person handling CUI. Over-scoping is the most expensive error in CMMC, and this is where it gets caught.
- Control-by-control review. All 110 controls at Level 2, assessed against evidence rather than assertion.
- Evidence testing. Not “is there a policy” but “show me the configuration export, the log, the dated artefact.”
- Documentation review. Your System Security Plan and POA&M, examined for the gaps an assessor would find.
- SPRS validation. Whether your submitted score is defensible. An inflated score carries real exposure.
- Remediation roadmap. Ranked, costed, sequenced by dependency.
What you should receive
- A control-level findings register — met, partially met, or not met, with the evidence reviewed noted against each.
- A scoped boundary diagram, because most organisations have never had one drawn.
- A remediation plan with effort and cost per item.
- A defensible SPRS score you can actually stand behind.
- A gap list for your documentation, specific enough to act on.
How long it takes, and what it asks of you
For a typical small or midsize contractor, expect two to four weeks from kickoff to findings. The variables are the number of systems in scope, whether documentation exists, and how quickly your people can be made available for interviews.
Your side of the effort is real. Expect to provide network diagrams, asset inventories, existing policies, configuration access, and time from whoever actually knows how things work. Engagements slip on availability far more often than on technical difficulty.
- Ask which of the three engagements a proposal actually describes.
- A readiness assessment cannot certify you. Only a C3PAO or the government can.
- Scope validation is where cost is decided. Insist it comes first.
- Evidence testing, not policy review, is what makes the finding useful.
When to commission one
Three moments justify it. Before you commit budget, so the number is grounded. Before a formal assessment, so there are no surprises. And when a prime asks for evidence and you are not confident what you would show them.
The current pause changes the urgency but not the logic. The Phase 2 third-party mandate is suspended; DFARS 252.204-7012, NIST SP 800-171, SPRS submission and annual affirmation are not. See what still applies.
The organisations that come out of the pause well are the ones who used it to find out where they actually stand, rather than waiting to be told.
Where IP Consulting fits
We are CMMC Registered, and we do both the readiness work and the technical implementation that follows — which is the combination most organisations find they need after the first proposal. Our CMMC compliance services page covers the delivery detail, and choosing a CMMC consultant covers what to verify in anyone you are considering.
Frequently asked questions
What is a CMMC readiness assessment?
A structured review that tells you what a formal CMMC assessment would find. A proper one validates your scope, reviews all 110 controls against evidence rather than assertion, tests your documentation, checks whether your SPRS score is defensible, and produces a ranked remediation roadmap.
Is a readiness assessment the same as a CMMC assessment?
No. A readiness assessment cannot certify you. Only an accredited C3PAO can conduct a formal Level 2 assessment, and Level 3 assessment is government-led. A readiness engagement is a rehearsal that tells you what would be found and challenged.
How long does a CMMC readiness assessment take?
Typically two to four weeks from kickoff to findings for a small or midsize contractor. The variables are how many systems are in scope, whether documentation already exists, and how quickly your people can be made available for interviews. Engagements slip on availability more often than on technical difficulty.
What do we need to provide for a readiness assessment?
Network diagrams, asset inventories, existing policies, configuration access, and time from the people who actually know how the environment works. Expect the internal effort to be real rather than nominal.
Keep exploring
- Is CMMC still required in 2026?
- CMMC levels explained
- How to choose a CMMC consultant
- CMMC compliance services
Ready for a clear path forward?
Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.
Start with a Clarity Conversation