Which CMMC gaps should I fix first?

Close live exposure first, then anything that blocks your status, then what other work depends on. Points come last.

Fix in this order. 1. Live exposure. 2. Status blockers. 3. Dependencies, then points. Working guide.

Updated September 29, 2026

You checked your company against CMMC's 110 security requirements and came up short on 23. You have one IT person and a spreadsheet sorted by points. Close anything that lets the wrong person reach CUI right now. Then fix what blocks your status. Then fix what other work is waiting on. Sort by points only after that. Sorting by points first is how a team spends a month rewording policies while a former admin still has a working login.

CUI (controlled unclassified information) is the drawings, specs, and technical data your defense customers send you that the government marks as sensitive. Your status is what your customer checks before awarding you work: Final (all 110 met), Conditional (close enough, with 180 days to finish), or none. No status, no award on contracts that require one.

Here is the rule we use: four questions, asked in order. The first yes decides where the gap goes.

  1. Can someone reach CUI today who shouldn't? A former employee's account that still works, a sharing link anyone can open, an admin who logs in with only a password. Fix these this week, whatever they're worth on paper.
  2. Does it block Conditional status? That's any requirement worth 5 or 3 points (with one encryption exception), plus six specific requirements the rules never let you leave open: controlling outside connections, checking what goes on your public website, escorting visitors, logging who enters, tracking keys and badges, and having a System Security Plan (SSP) at all (32 CFR 170.21; for your IT lead, those six are 3.1.20, 3.1.22, 3.10.3, 3.10.4, 3.10.5, and 3.12.4). One of these open means "No CMMC Status" at any score. Details →
  3. Is other work waiting on it? Scope questions, meaning which people, systems, and vendors the assessment covers, come first here. If you don't know where the backups land, you can't write the SSP, and you can't collect proof for systems you haven't listed.
  4. What's it worth? Now sort the rest by weight, 5 before 3 before 1. How weights work →

Run a real backlog through it. A 30-person shop has these four at the top. The last column is written for the person doing the work.

Gap Where it lands First move Done when
A former admin, j.patel, can still run the company's Microsoft 365 Question 1 Remove his admin role and disable the account today The Entra ID role assignment report no longer lists j.patel as Global Administrator, and a sign-in attempt fails
Activity logs cover the firewall but not the file server or Microsoft 365 (5 points) Question 2 Send the file server and Microsoft 365 logs to the log server A test sign-in from each source appears in the log server, and retention matches the period your audit policy names (3.3.1)
Nobody knows which cloud the backup vendor uses Question 3 Get the vendor's data location and FedRAMP status (the government's cloud security approval) in writing Scope and SSP name the provider; the decision is recorded
The quarterly check of who has access has no record for Q2 Question 4 (access control depends on it, but it's a records gap) Run the review now and date it today Signed review with removals made, dated today (supports 3.1.1)

The "done when" column is the part teams skip, and it's the part that decides whether you pass. "Enable audit logs" can be marked complete the day someone buys a license. "A test sign-in from each source appears in the log server" can only be marked complete when it's true. Write the finish line before you hand the task to anyone.

Keep two counts separate. Tickets closed tells you how busy the team was. Requirements re-checked as met, with proof, tells you where you stand. One well-built set of laptop security settings can satisfy five requirements at once, and one requirement like limiting access to approved people can take six tickets. Only the second count goes into SPRS, the Defense Department system where your score is posted.

Once a week, write down the next gap, its owner, what it's waiting on, and what would make you reshuffle. Five lines is enough. It keeps the plan honest without turning every new alert into a reset.

If the list is long and the deadline is fixed, the 90-day plan lays these steps out week by week.

Mock assessment

A fix list already in the right order.

Garde1's mock assessment puts the fixes that block your status first, then what's due, then what clears the most findings, and names the setting and tool for each.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE