My role as a software developer at Senserva has been spent most of this summer updating the Siemserva user interface from a terminal interface to a simpler graphical one. Included in that work was bringing in our CMMC readiness feature, which will be available soon. The control mappings already in Siemserva were the easy part. The hard part was understanding how CMMC assessment scoring works, and the process of preparing for an assessment.
Some background on CMMC
The Cybersecurity Maturity Model Certification is the Department of Defense's way of verifying that contractors protect the information the government hands them. The program rule, 32 CFR Part 170, was published on October 15, 2024 and took effect on December 16, 2024. The companion acquisition rule that puts the requirement into contracts, DFARS 252.204-7021, was published on September 10, 2025 and became enforceable on November 10, 2025.
There are three levels. Level 1 covers Federal Contract Information with 15 requirements drawn from FAR 52.204-21, verified by an annual self-assessment with no Plan of Action and Milestones allowed. Level 2 covers Controlled Unclassified Information with the 110 requirements of NIST SP 800-171 Revision 2, assessed against the procedures in NIST SP 800-171A, the June 2018 edition the rule names even though NIST has since published a Revision 3. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by the government.
The DoD's Level 2 Assessment Guide breaks the 110 requirements into 320 assessment objectives, and each one is examined, interviewed about, or tested. When a certified third-party assessment organization (C3PAO) performs the assessment, the result is valid for three years, must be affirmed annually, and flows into the Supplier Performance Risk System (SPRS), where contracting officers see it.
Scoring works by deduction. Under the scoring methodology in 32 CFR 170.24, you start at 110 and lose 5 points for each unmet requirement whose failure could lead to significant exploitation or exfiltration of CUI, 3 points for requirements with a confined effect, and 1 point for the rest. Two requirements give partial credit: multifactor authentication implemented only for remote and privileged users costs 3 instead of 5, and encryption that is present but not FIPS-validated costs 3 instead of 5.
A conditional status is possible when the score is at least 88, and every open item on the Plan of Action and Milestones must be worth 1 point, with the single exception of non-FIPS encryption at 3 (32 CFR 170.21). Six requirements can never be deferred, among them the System Security Plan, external connections, public information control, and three physical access requirements. The plan must be closed out by a follow-up assessment within 180 days or the conditional status expires.
As of this writing, October 2026, the Department has paused the phase that would have required third-party (C3PAO) certification to win contracts, pending a reform review. Level 2 self-assessments, the annual SPRS affirmation, and DFARS 252.204-7012 still apply, so a company official is still signing off on the same 320 objectives a certifier would test.
What we learned building this tool
Not everything in a CMMC assessment can be gathered from an API. About one third of the controls are about policy, procedure, people, and physical space, so your organization needs to attest to those controls manually.
Scoring weight matters. The requirements that cost 3 to 5 points each are the ones that can close the Plan of Action and Milestones path to certification if missed, so we put those at the top of our readiness report.
The rules can change out from under you. CMMC Phase 2 was paused in July while we were working on this feature, so we thought it might have been work for nothing. It turned out not to be, because the self-assessment, the annual affirmation, and DFARS 252.204-7012 are still in force, and the evidence standard for a self-assessment is the same 320 objectives.
Prepare for a defensibility test, not a security review
Most organizations that believed they were ready had prepared for the wrong kind of exam. They expected a security review, and what they got was a defensibility test. The only question that matters is whether you can prove you do the right things, consistently, right now.
The assessor will not help you, and the answer is binary
Unlike a SOC audit, there is no room for interpretation and no roadmap from the assessor, unless you use a C3PAO that explicitly provides consulting services. Each of the 110 controls, and each of the 320 assessment objectives beneath them, is either met or not met. What you cannot show does not exist.
The SPRS Readiness Estimate in Siemserva's CMMC report grades every one of the 110 NIST SP 800-171 controls, not just the ones with findings. A control the audit could not evaluate is marked inconclusive and flagged for manual attestation.
Know your number before they do
You need to score at least 88 of 110, and you can carry the remainder on a Plan of Action and Milestones for six months only if every missing control is a 1-point deduction. Non-FIPS encryption, at 3 points, is the one exception the rule allows. Miss any other 3-point or 5-point control and the Plan of Action and Milestones path closes.
The estimate uses those same 1, 3 and 5 point weights against live tenant configuration, and the Attestation Priorities section lists the controls with the highest score impact first, so the ones that would close the Plan of Action and Milestones option sit at the top of the list. The Next Steps section is ordered the same way, with the fastest path to a passing estimate.
Evidence has to be indexed to the objective and quick to reach
An assessor who has to hunt for the answer is an assessor you have already lost. Tailor evidence to each 800-171A objective, point to the exact page, paragraph or screenshot that proves it, and expect to be asked to log in and demonstrate a control live, objective by objective, for all 320.
Every mapped Siemserva check carries that control's ID, so the CMMC report's Requirement Grades section shows each control with the specific findings, entities and evidence behind its grade. The CMMC by Check companion report turns the same data around: each assessed check, the controls it affects, and what to fix, followed by the checks that passed. Certification also requires ongoing maintenance, and assessors expect to see ongoing management: the Plan of Action and Milestones kept current, procedures reviewed, deficiencies recorded as they appear.
Readiness is cheaper than failure
Assessment costs vary widely, from tens of thousands of dollars at the low end to six figures at the high end, and practitioners consistently report that arriving prepared can cut the bill substantially. The sequence that works is a gap analysis first, then a mock assessment run the way a C3PAO would run it.
Siemserva grades the technical controls of a Level 2 self-assessment from live tenant data, gives you evidence for 76 of the 110 requirements indexed to its requirement, and tells you which requirements still need a human answer. It shortens the work, but the self-assessment is still completed and affirmed by your company official, and the certification assessment is performed by a C3PAO. The portion of the 110 controls covered by Microsoft 365, Intune, Defender, Entra ID, and Purview configuration is graded from the source in minutes rather than from a questionnaire. Run it before you engage in a gap analysis.
What the Senserva audit does not do
Siemserva is not a C3PAO. The SPRS figure is an estimate, and the assessment objectives that are about people and paper are out of its reach: the System Security Plan, written procedures, interview readiness, CUI handling, asset categorization under the Level 2 scoping guide, and physical controls. What the audit gives you is a defensible, repeatable read on the technical controls, so the human effort goes where a tool cannot.
About Senserva: Who We Are and What We Do
Senserva is a Microsoft-focused security posture management company based in St. Paul, Minnesota. Its platform continuously scans an organization's Microsoft 365, Intune, Defender, and Entra ID environment, running several hundred built-in checks across identity, privileged access, applications and service principals, endpoint and device compliance, email, logging, and Azure subscription roles.
For every finding, Senserva provides step-by-step remediation guidance, including validated PowerShell scripts and rollback notes, and maps results to recognized compliance frameworks such as the Microsoft Cloud Security Benchmark, CISA's SCuBA baselines, NIST 800-171, CIS, ISO 27001, SOC 2, HIPAA, and PCI-DSS. Senserva is a member of the Microsoft Intelligent Security Association (MISA) and a Microsoft Security Excellence Awards finalist.
Senserva also offers Three Free Unlimited Audits covering every tenant, user, and patch: one to Find, one to Fix, and one to Prove, using the same 650+ checks described above. Registration takes only a work email, with no cost and no obligation to buy. Request an evaluation key at senserva.com/request-key.html.
Senserva also runs Senserva Watch, a free membership that tracks CVEs and Microsoft patches on an organization's behalf and sends an alert only when something being tracked changes, including a same-day notice when Microsoft's Patch Tuesday updates ship. Signing up needs no tenant connection, agent, or call, just an email address, at senserva.com/senserva-watch.html.
Learn more at senserva.com.
Sources
- Federal Register. "Cybersecurity Maturity Model Certification (CMMC) Program," 32 CFR Part 170 final rule, October 15, 2024. federalregister.gov
- 32 CFR 170.3 (applicability), 170.14 (CMMC model), 170.15 (Level 1 self-assessment), 170.17 (Level 2 certification assessment), 170.21 (Plan of Action and Milestones) and 170.24 (scoring methodology).
- Greenberg Traurig. "DoD Publishes Final CMMC Program Rule," October 2024.
- PreVeil. "CMMC Final Rule Published," on the 48 CFR acquisition rule.
- National Institute of Standards and Technology. SP 800-171A, "Assessing Security Requirements for Controlled Unclassified Information," June 2018. csrc.nist.gov
- Department of Defense Chief Information Officer. "CMMC Assessment Guide, Level 2," version 2. dodcio.defense.gov
- Wiley. "DOD Pauses CMMC 2.0 Implementation: A Big Deal with Little Immediate Impact," 2026.
- Nextgov. "DOD suspends CMMC Phase 2, launches 60-day reform review," July 2026.
- Inside Government Contracts (Covington). "CMMC Reform Task Force Updates," September 2026.