Intake and discovery
Collect basic facts before the first working session. Use working sessions for decisions that require context, and keep sensitive evidence in a controlled environment.
Three layers
Section titled “Three layers”1. Organization facts
Section titled “1. Organization facts”Prepare basic identifiers, applicable contracts and clauses, locations, workforce roles, technology providers, and an initial asset inventory.
2. Guided working sessions
Section titled “2. Guided working sessions”Walk through how CUI is received, accessed, processed, stored, transmitted, backed up, and destroyed. Follow-up questions matter because the boundary depends on how work actually happens.
3. Controlled evidence collection
Section titled “3. Controlled evidence collection”Gather policies, inventories, diagrams, configuration exports, screenshots, logs, training records, and other artifacts that support implementation claims.
Prepare these categories
Section titled “Prepare these categories”- Contract and subcontract flow-down requirements
- CUI categories and representative workflows
- Users, roles, privileged accounts, and non-US-person considerations
- Endpoints, servers, networks, cloud services, and security tools
- External service providers that process, store, transmit, or protect CUI
- Existing SSP, policies, assessments, POA&Ms, and SPRS records
- Available evidence and known implementation gaps
Discovery output
Section titled “Discovery output”A useful discovery package includes a written boundary, a CUI-flow diagram, an asset and service inventory, named control owners, open questions, and an evidence request list.
Published by Eagle Ridge Advisory. Public guidance only: this site holds no client information, completed security plans, evidence, or legal advice. Current CMMC rules and contract terms control.