03

The most common reasons organizations are not ready for a Level 2 assessment

Readiness is rarely a technology problem. Most organizations that turn out not to be ready have bought the right tools and still cannot prove what the tools are doing.

Across 40 Level 2 assessments, the same gaps appear again and again. Every environment is different, so treat these as patterns rather than a checklist, but if any of them describes you, it is worth addressing before an assessment rather than during one.

1. You do not actually know where your CUI goes

This is the most common gap, and it is the one that undermines everything else. Organizations know where CUI is supposed to live. Far fewer can show everywhere it actually enters, travels, is stored, and exits: email, chat and collaboration tools, file shares, endpoints, backups, service provider tooling, printers, and vendors.

If you cannot map your CUI flow, you cannot defend your assessment boundary. And every control decision built on an inaccurate boundary inherits that inaccuracy.

2. Your System Security Plan describes an environment you do not have

The most frequent finding of all is an SSP that says one thing while the environment does another. Sometimes the plan was aspirational when it was written. More often the environment changed and the document did not.

An SSP is not a compliance artifact you produce once. It is a description of your system, and it is wrong the moment it stops matching reality.

3. Multifactor authentication has gaps nobody looked for

Almost every organization has MFA on email. Fewer have it consistently across the environment where CUI is stored, processed, or transmitted: privileged and local administrator accounts, remote access, network devices, service accounts, and legacy authentication paths that quietly still work.

4. You cannot prove your encryption is FIPS validated

Encryption being enabled is not the same as being able to demonstrate that the cryptographic module protecting CUI is FIPS validated and configured appropriately. This distinction surprises people, and it is not something you can resolve during an assessment.

5. Your configuration baselines are not defensible

Configurations exist in every environment. Documented baselines, an accurate inventory of what those baselines apply to, and evidence that they are actually enforced are much rarer. The related requirement to restrict nonessential programs, functions, and services is harder than it sounds, because it requires you to have defined what essential means for your organization.

6. Logging exists but cannot answer the question

The question at assessment time is not whether you have logs. It is whether the required events are logged, whether an individual action can be traced to an individual user, and whether logs are retained, reviewed, and protected. Many organizations have a logging platform deployed and no demonstrable process running on top of it.

7. Your incident response plan has never been run

Well-written incident response plans are common. Evidence that the organization can actually execute one is less common, and testing is usually the weak point. A plan nobody has exercised is a document, not a capability.

8. Scanning happens, remediation does not follow

Vulnerability scanning is widely adopted. What often cannot be shown is that remediation is risk-based, tracked, timely, and actually carried out in the environment where CUI is processed and stored.

9. Monitoring that nobody is watching

Endpoint and security monitoring tools are installed nearly everywhere. Demonstrating that someone is actively monitoring, and that unauthorized use would in fact be identified, is a different matter.

10. Evidence assembled the night before

Evidence that has to be reconstructed under time pressure produces a difficult assessment week for everyone. Evidence organized in advance, in folders by control family, with screenshots and artifacts labeled by control objective, produces a smooth one. This costs nothing except forethought and it changes the entire experience.

The common thread

Every item on this list is about being able to demonstrate something rather than having something. Readiness is not a feeling, and it is not a purchase. It is provable, or it is not.

Our CMMC Level 2 Readiness Checklist walks through what an assessor will ask you to prove. Download it, or book an intro call to talk through where you stand.