So, you’ve figured out that you need CMMC certification, and you’re ready to start preparing. But where do you begin? How do you know what needs fixing?
That’s where a gap analysis comes in.
A gap analysis is the first step toward getting CMMC-ready. It’s like bringing in a home inspector before selling your house – you want to know what needs fixing before the real assessment. An RPO (Registered Provider Organization) or cybersecurity consultant will examine your current security posture, identify gaps between what you have and what CMMC requires, and help you create a roadmap to compliance.
Let’s break down what happens during a gap analysis, what the process looks like, and what you can do with the results.
What Happens During a Gap Analysis?
A gap analysis is a detailed review of your security policies, technical controls, and overall cybersecurity practices. The goal is to:
- Identify missing technical and policy requirements
- Highlight areas that need improvement
- Provide a clear roadmap to CMMC compliance
What Does an RPO Look At?
An RPO will go through your security setup and compare it to the specific CMMC level you’re aiming for. Here’s what they typically focus on:
For CMMC Level 1 (Foundational)
- Do you use strong passwords?
- Is multi-factor authentication (MFA) enabled?
- Are software updates and patching done regularly?
- Do employees know basic cybersecurity hygiene?
For CMMC Level 2 (Advanced)
- Do you have proper access controls and role-based permissions?
- Is data encryption in place for sensitive information?
- Are there policies for incident response and security monitoring?
- Do you log, track, and audit user activity?
This isn’t an exhaustive list, but these are the types of things an RPO will examine to see where you stand.
How Long Does a Gap Analysis Take?
The time required for a gap analysis depends on:
- The size and complexity of your business
- The CMMC level you’re aiming for
- How organized your security documentation is
For a small business seeking Level 1 compliance, a gap analysis might take a few days to a week.
For a mid-sized company aiming for Level 2, it could take a few weeks to a month – especially if there’s a lot of missing documentation or security gaps.
How Much Access Do You Have to Give?
To conduct a thorough assessment, an RPO needs insider-level access to your systems, policies, and operations. Think of it like hiring an accountant to audit your finances – you can’t just hand them a few receipts and expect them to give a full report.
What They Need Access To:
- Network configurations and IT infrastructure
- Security policies and procedures
- Employee security training records
- System logs and audit trails
How Much Trust is Required?
A gap analysis requires trust—you’re giving an outside party a deep look into your cybersecurity setup. It’s important to work with a reputable RPO that has strong security controls of their own.
On-Site vs. Remote Assessments
A gap analysis can be done remotely, on-site, or a mix of both.
What Can Be Done Remotely?
- Reviewing policies and security documents
- Examining firewall and network configurations
- Checking user access logs and permissions
- Interviewing staff about security practices
What Requires On-Site Work?
- Physical security checks (e.g., badge access, locked server rooms)
- Testing Wi-Fi security and access controls
- Observing day-to-day cybersecurity habits of employees
For smaller businesses, a remote assessment might be enough. Larger organizations or companies handling Controlled Unclassified Information (CUI) often require on-site visits to verify security measures.
The Gap Analysis Report: Your Roadmap to Compliance
Once the gap analysis is complete, the RPO will provide a detailed report. This report is your playbook for getting CMMC-ready.
What’s in the Report?
- A list of security gaps (what’s missing or non-compliant)
- Severity levels for each issue (high-risk vs. minor issues)
- Recommendations for fixes (technical upgrades, policy changes, or training needs)
- A step-by-step action plan to close the gaps
What Do You Do With It?
After receiving the report, your organization has two main tasks:
Fix Policy Gaps
- If the report says you don’t have an incident response plan, write one.
- If there’s no access control policy, create and enforce one.
Fix Technical Gaps
- If your passwords are weak, enforce strong password policies.
- If your backups aren’t encrypted, implement data encryption.
- If logs aren’t being recorded, set up audit logging.
Some businesses handle these fixes in-house, while others hire an RPO or Managed Security Services Provider (MSSP) to help implement changes.
Final Thoughts: Why Do a Gap Analysis?
A gap analysis is not required, but skipping it is risky.
Without a gap analysis, you’re going into your official C3PAO audit blind—and if you fail, it means delays, extra costs, and possibly losing contracts.
- A gap analysis helps you avoid surprises
- It provides a clear path to compliance
- It saves time and money by fixing issues early
If you’re serious about CMMC, doing a gap analysis first is the smart move.
Next up in CMMC for Noobs: How Do I Implement the Recommendations of the Gap Analysis?



