CMMC Gap Assessment & Readiness Advisory

Know Exactly Where You Stand Against CMMC — Before Phase 2 Hits

CPA-licensed advisory, senior-led from day one. A clear gap assessment against NIST 800-171, with a remediation roadmap you can actually execute, not just a list of problems.

✓ Senior-only delivery, same practitioners from gap assessment to readiness review
✓ Advisory only — we don't conduct C3PAO certifications, preserving independence for your formal assessment
✓ Multi-framework mapping if you also need HIPAA or SOC 2

Where CMMC Enforcement Actually Stands

This isn't a future concern, it's a rolling deadline, and Phase 2 changes the rules for most CUI-handling contractors. Most organizations need 6–12 months between a gap assessment and being genuinely ready for a C3PAO assessment.

Starting now is what keeps you ahead of Phase 2, not racing it.

RSAA Team
  • Phase 1 - Nov 10, 2025

    Level 1 mandatory self-assessments for new solicitations. SPRS scores required. DoD may require Level 2 (C3PAO) early for select contracts.

  • Phase 2 - Nov 10, 2026

    Third-party C3PAO certification becomes mandatory for most CUI-handling contracts. Self-attestation alone is no longer sufficient.

  • Phase 3 - Nov 10, 2027

    CMMC Level 3 requirements and government-led DIBCAC assessments introduced for the most critical programs.

  • Phase 4 - Nov 10, 2028

    CMMC requirements become universally mandatory across all applicable DoD contracts, solicitations, and renewals.

What Makes RSAA Different

Senior Only Delivery


No bait-and-switch to junior staff after the sales conversation. The same senior practitioners stay on your engagement start to finish.

Independence By Design


RSAA provides readiness advisory. We don't issue attestation reports for clients we advise, preserving the credibility of the report you're paying for.

Multi-framework Ready


If you also need CMMC, HIPAA, or HITRUST, we map controls once across every framework instead of starting from zero each time.

Common Questions

  • What is a CMMC gap assessment?

    A CMMC gap assessment is an advisory review of your security controls against the 110 requirements in NIST 800-171. It identifies what's already in place, what's missing, and produces a remediation roadmap. It does not itself grant any certification.

     
  • Is a CMMC gap assessment the same as certification?

    No. A gap assessment is advisory and produces no certification. Certification at Level 2 requires a formal assessment by a Certified Third-Party Assessor Organization (C3PAO), a separate, independent process. RSAA provides gap assessment and remediation advisory only.

  • When does CMMC Phase 2 take effect?

    CMMC Phase 2 begins November 10, 2026, when third-party C3PAO certification becomes mandatory for most contracts involving Controlled Unclassified Information (CUI). Self-attestation alone will no longer be sufficient for most CUI-handling contractors after this date.

     
  • Does CMMC apply to subcontractors, not just prime contractors?

    Yes. If a prime contractor flows CUI to a subcontractor, the CMMC compliance obligation flows with it, regardless of whether the subcontractor has had an explicit conversation with the prime about CMMC requirements.

Clarify Your CMMC Path

RS Assurance & Advisory is a CPA-licensed compliance advisory firm. Advisory services only — RSAA does not conduct CMMC third-party (C3PAO) certifications.

Scroll to Top