Seven-phase readiness lifecycle
The work moves from defining the environment, to closing gaps, to proving and maintaining readiness.
1. Discovery and scoping
Section titled “1. Discovery and scoping”Identify the contract requirements, CUI, assessment boundary, relevant assets and services, and control owners.
Done when: stakeholders can explain what is in scope, why it is in scope, and how CUI moves through it.
2. Gap assessment
Section titled “2. Gap assessment”Compare each applicable requirement with the current implementation and its evidence. Separate working safeguards, missing evidence, partial implementation, and confirmed gaps.
Done when: leadership has a defensible view of the current state and a prioritized backlog.
3. Remediation support
Section titled “3. Remediation support”Order the work by assessment effect and dependency. Changes to identity, access, configuration, logging, incident response, and evidence generation often depend on one another.
Done when: each completed change has an owner, validation evidence, and an operational handoff.
4. SSP development
Section titled “4. SSP development”Document the system boundary, environment, roles, connections, and implementation of each requirement. Use specific, testable statements instead of policy slogans.
Done when: the SSP matches the operating system and links each claim to evidence.
5. Pre-assessment review
Section titled “5. Pre-assessment review”Review the package as an assessor would. Check the scope, SSP, assessment objectives, evidence links, unresolved gaps, and consistency across documents.
Done when: the organization resolves or assigns every material finding before scheduling the assessment.
6. Assessment preparation
Section titled “6. Assessment preparation”Organize the evidence, rehearse interviews with control owners, confirm logistics, and prepare the required submission and affirmation steps.
Done when: control owners can demonstrate the documented practices without improvising.
7. Continuous compliance
Section titled “7. Continuous compliance”Keep the SSP, asset inventory, policies, evidence, and training current. Review them after material changes to systems, personnel, vendors, contracts, or CUI flows.
Done when: the organization maintains readiness through routine operations instead of rebuilding it for each assessment.
Published by Eagle Ridge Advisory. Public guidance only: this site holds no client information, completed security plans, evidence, or legal advice. Current CMMC rules and contract terms control.