5 NIST 800-171 control areas where self-reported and measured SPRS posture often diverge.
⌘P (Mac) or Ctrl+P (Windows), choose “Save as PDF.” Print styles included.Why this exists
The SPRS score posted from a self-attested questionnaire and the score an assessor would compute today against the live environment can differ. The divergence concentrates in a few control areas where the distance between “we have this” and “the assessor will accept this” is widest.
Below: five of those control areas, what your C3PAO will look for in each, and the remediation path. The point-impact figures used in earlier drafts have been removed pending validated baseline data.
Multifactor Authentication on Privileged Accounts
What most DIB shops report
"MFA enforced on all administrators."
What the assessor actually finds
- Microsoft 365 admin accounts: MFA enabled (good)
- On-prem Windows domain admin accounts: MFA not enforced
- Linux jump-server root accounts: MFA not enforced
- Network equipment privileged credentials (Cisco, Fortinet, Palo Alto): TACACS+/RADIUS without MFA
- Service accounts that someone occasionally uses interactively: MFA bypassed
The typical privileged-account inventory contains 12–18 accounts; MFA covers 6–10 of them.
Evidence your C3PAO will look for
- Authoritative inventory of all privileged accounts (with role and last-used date)
- MFA policy configuration screenshots
- MFA enrollment logs for the past 90 days for each privileged account
- Documented procedure for adding/removing privileged accounts (and the MFA enforcement step)
The cleanest fix
Roll Duo, Microsoft Authenticator, or YubiKeys to every privileged account. Use a single MFA platform across cloud + on-prem + network equipment so there's one inventory to maintain. Document in SSP Section 3.5. Ship in 5 business days.
Audit Record Review and Analysis
What most DIB shops report
"Logs are reviewed weekly by our IT lead."
What the assessor actually finds
- Logs are being collected, true. Microsoft 365, on-prem firewall, sometimes endpoint EDR.
- There's a phrase in the IT policy that says "reviewed weekly", true.
- No documented review cadence with sign-off
- No record of past reviews (no signed checklist, no Jira/ticket trail)
- No evidence of action taken on log findings, nothing showing the IT lead investigated an anomaly, escalated, and resolved
The phrase "reviewed weekly" appears in the policy but is not operationalized.
Evidence your C3PAO will look for
- Log review SOP (named procedure, named role, defined cadence)
- Signed weekly log review records for the past 90 days
- At least one log-driven action artifact (an investigation ticket, a Slack thread, an after-action note)
- The list of log sources covered by the review (and acknowledged gaps)
The cleanest fix
SIEM or log-aggregation tool (Wazuh, Microsoft Sentinel, Datadog, or Sumo Logic) with a documented weekly review cadence. Build a one-page review template with sign-off. First compliant review record in ~14 days; full backfill of "we started doing this on day X" reports in 30 days.
Monitor and Control Remote Access
What most DIB shops report
"VPN required for all remote work."
What the assessor actually finds
- VPN is deployed and required, true
- No logging of remote sessions (or logs are being collected but not retained beyond 30 days)
- No session-timeout enforcement, workers can leave a VPN session open overnight
- No MFA on the VPN itself, username/password gets you in
- Remote sessions are not reviewed for anomalies (geo-impossible logins, off-hours access)
Evidence your C3PAO will look for
- Remote-access policy
- VPN session logs for the past 90 days
- MFA enforcement evidence on VPN (configuration + enrollment)
- Session-termination configuration (idle timeout, max session length)
- Documented remote-access review cadence (folds into Killer #2's SIEM)
The cleanest fix
Enable VPN session logging (OpenVPN, Fortinet, Cisco AnyConnect all support this natively). Add MFA to the VPN with the same provider used for Killer #1. Configure 30-minute idle timeout, 12-hour absolute max session. Review cadence folds into the SIEM weekly review from Killer #2. Ship in 10 business days.
Enforce Security Configuration Settings
What most DIB shops report
"Standard build images deployed; group policy enforces baseline."
What the assessor actually finds
- Active Directory group policy is in place, true
- Windows endpoints are running multiple OS builds (often 8–14 distinct builds across Win 10 1909 through Win 11 23H2) due to legacy CAD workstations and machine controllers
- CIS benchmarks are not applied to endpoints
- Linux servers have no equivalent baseline (no CIS, no STIG)
- Deviation from policy is not detected or alerted, drift accumulates silently
Evidence your C3PAO will look for
- Baseline configuration documentation (which CIS benchmark version, scope of systems covered)
- Evidence of regular configuration scanning (CIS-CAT, Nessus, Defender for Endpoint, Tenable)
- Deviation reports for the past 90 days
- Remediation evidence on flagged deviations
The cleanest fix
Adopt CIS Level 1 benchmarks for Windows + Linux. Deploy Microsoft Defender for Endpoint configuration drift detection (or Tenable, or Rapid7, your choice). Document baseline and scan cadence in SSP Section 3.4. Initial scan-pass within 2 weeks; ongoing drift detection thereafter.
FIPS-Validated Cryptography
What most DIB shops report
"AES-256 encryption used throughout."
What the assessor actually finds
- AES-256 is in use, true
- The cryptographic modules implementing AES-256 are not FIPS 140-2 (or 140-3) validated for the on-prem file shares, the OpenVPN deployment, or the database encryption
- Windows endpoints have FIPS mode disabled (required by Microsoft for FIPS-validated crypto)
- The product documentation says "AES-256" but the module's CMVP certificate number is missing or expired
CMMC L2 specifically requires FIPS-validated modules, not merely strong-algorithm use.
Evidence your C3PAO will look for
- Documented inventory of cryptographic modules in your environment
- Each module's FIPS validation certificate number from the NIST Cryptographic Module Validation Program (CMVP)
- Configuration evidence showing FIPS mode enabled where applicable (Windows group policy, OpenSSL provider settings, database FIPS mode)
The cleanest fix
Inventory cryptographic modules. Enable FIPS mode on Windows endpoints (group policy: "System cryptography: Use FIPS compliant algorithms..."). Validate VPN crypto module FIPS certification, OpenVPN with FIPS-validated OpenSSL provider is available; commercial VPNs typically have FIPS mode. Switch file-share encryption to a FIPS-validated implementation. Inventory in 1 week; remediation in 4–6 weeks. This is the longest-running of the five.
Putting it together
The five control areas above are technical, specific, and assessor-verifiable. Closing them is documentation plus configuration work, not a re-architecture. Specific point impact for your environment depends on your starting posture and your full 110-control state, which the CMMC Readiness Snapshot measures.
What to do with this
- Compare it to your current SPRS posture. If you've recently submitted a self-reported score to DoD's SPRS system, work down this list and honestly check each of the five.
- If you want a quick read on where you stand, the free CMMC gap check takes about 2 minutes and shows your likely gaps on screen.
- If you want to know your real number, what your environment actually shows when measured against the 110-control NIST 800-171 baseline, start the CMMC Readiness Snapshot™. $799. PDF in your inbox in minutes.
- If you'd rather start the full readiness work, SSP, POA&M, evidence package, audit-ready bundle, Enclave AI™ Standard at $5,995/month is the shortest path. Month-to-month.
- If you have a question, hello@ai4cmmc.ai. Replies are triaged by an Enclave AI™ agent; if a question needs a human, it's escalated.
Want help applying these five to your environment? Leave your email and we'll follow up directly.
What this doesn't include
This is field intel on the five highest-SPRS-impact control areas across the DIB OSA band we work with. It's not:
- A complete CMMC L2 readiness checklist (that's 110 controls, 320 objectives, your real readiness work)
- A substitute for an actual SPRS scoring against your environment
- Legal advice on regulatory exposure or contract-specific obligations
- A replacement for a C3PAO assessment, which only an authorized C3PAO can perform
It's the field intel I'd want before committing to anything. Read it, use what's useful, ignore what isn't, and reach out if you want help with the rest.
About ElasticD3M, LLC
We build AI-driven CMMC Level 1 and Level 2 readiness software. Patent Pending. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We make life easier for the OSAs preparing for assessment, the C3PAOs assessing them, and the RPOs guiding them.
When you are ready to move from this five-control-area read into the full Level 2 readiness work, the free gap check at ai4cmmc.ai/gap-check is the 2-minute first step. The CMMC Readiness Snapshot at ai4cmmc.ai/cmmc-readiness-snapshot is the measured one. $799, one-time, PDF delivered to your inbox within minutes of intake.
Patent Pending
ElasticD3M, LLC · Texas
v1 · Last updated 2026-05-07