Updated September 29, 2026
You checked your company against CMMC's 110 security requirements and came up short on 23. You have one IT person and a spreadsheet sorted by points. Close anything that lets the wrong person reach CUI right now. Then fix what blocks your status. Then fix what other work is waiting on. Sort by points only after that. Sorting by points first is how a team spends a month rewording policies while a former admin still has a working login.
CUI (controlled unclassified information) is the drawings, specs, and technical data your defense customers send you that the government marks as sensitive. Your status is what your customer checks before awarding you work: Final (all 110 met), Conditional (close enough, with 180 days to finish), or none. No status, no award on contracts that require one.
Here is the rule we use: four questions, asked in order. The first yes decides where the gap goes.
- Can someone reach CUI today who shouldn't? A former employee's account that still works, a sharing link anyone can open, an admin who logs in with only a password. Fix these this week, whatever they're worth on paper.
- Does it block Conditional status? That's any requirement worth 5 or 3 points (with one encryption exception), plus six specific requirements the rules never let you leave open: controlling outside connections, checking what goes on your public website, escorting visitors, logging who enters, tracking keys and badges, and having a System Security Plan (SSP) at all (32 CFR 170.21; for your IT lead, those six are 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5, and 3.12.4). One of these open means "No CMMC Status" at any score. Details →
- Is other work waiting on it? Scope questions, meaning which people, systems, and vendors the assessment covers, come first here. If you don't know where the backups land, you can't write the SSP, and you can't collect proof for systems you haven't listed.
- What's it worth? Now sort the rest by weight, 5 before 3 before 1. How weights work →
Run a real backlog through it. A 30-person shop has these four at the top. The last column is written for the person doing the work.
| Gap | Where it lands | First move | Done when |
|---|---|---|---|
| A former admin, j.patel, can still run the company's Microsoft 365 | Question 1 | Remove his admin role and disable the account today | The Entra ID role assignment report no longer lists j.patel as Global Administrator, and a sign-in attempt fails |
| Activity logs cover the firewall but not the file server or Microsoft 365 (5 points) | Question 2 | Send the file server and Microsoft 365 logs to the log server | A test sign-in from each source appears in the log server, and retention matches the period your audit policy names (3.3.1) |
| Nobody knows which cloud the backup vendor uses | Question 3 | Get the vendor's data location and FedRAMP status (the government's cloud security approval) in writing | Scope and SSP name the provider; the decision is recorded |
| The quarterly check of who has access has no record for Q2 | Question 4 (access control depends on it, but it's a records gap) | Run the review now and date it today | Signed review with removals made, dated today (supports 3.1.1) |
The "done when" column is the part teams skip, and it's the part that decides whether you pass. "Enable audit logs" can be marked complete the day someone buys a license. "A test sign-in from each source appears in the log server" can only be marked complete when it's true. Write the finish line before you hand the task to anyone.
Keep two counts separate. Tickets closed tells you how busy the team was. Requirements re-checked as met, with proof, tells you where you stand. One well-built set of laptop security settings can satisfy five requirements at once, and one requirement like limiting access to approved people can take six tickets. Only the second count goes into SPRS, the Defense Department system where your score is posted.
Once a week, write down the next gap, its owner, what it's waiting on, and what would make you reshuffle. Five lines is enough. It keeps the plan honest without turning every new alert into a reset.
If the list is long and the deadline is fixed, the 90-day plan lays these steps out week by week.
