ComplianceAide sample deliverable
Illustrative CMMC Gap Report
Illustrative redacted sample. Not a certification report. Not a customer testimonial.
This sample shows the kind of readiness score, gap themes, evidence requests, and prioritized remediation plan a buyer can expect from the ComplianceAide CMMC readiness package. Names, systems, dates, and control details are fictional.
Readiness Snapshot
Illustrative readiness score
Enough program structure to start, but several evidence gaps would slow a Level 2 readiness review.
Priority gaps
Policies exist for core topics, but screenshots, access records, vendor evidence, and incident exercises need owners.
Evidence requests
Requests are grouped by owner so the buyer can collect proof without reading every control first.
Top Gap Themes
- Access reviews are informal. The company describes quarterly review meetings, but there is no repeatable export, approval record, or disabled-account evidence.
- Asset inventory is not tied to control ownership. Workstations, cloud services, and shared drives are listed, but owners and CUI handling notes are missing.
- Incident response is documented but untested. The plan names a response lead, yet there is no tabletop record or after-action evidence.
- Vendor proof is scattered. Key vendors have security pages, but contracts, data-processing terms, and shared-responsibility notes are not collected in one packet.
Sample Evidence Requests
Prioritized Remediation Plan
- Week 1: Confirm CMMC level assumptions, identify the CUI boundary, and assign owners for access, asset, vendor, and incident evidence.
- Weeks 2-3: Collect requested evidence, close missing screenshots/exports, and update policy drafts where evidence contradicts the stated process.
- Weeks 4-6: Run a follow-up readiness review, package the remaining POA&M items, and decide whether a Registered Practitioner or C3PAO conversation is needed.
What This Package Does and Does Not Do
Included readiness support
Organize evidence, identify gaps, create draft policies, summarize remediation priorities, and help the buyer prepare for human review.
Still owned by the buyer
Approve evidence, implement remediation, choose official assessment providers, and decide whether outside legal, security, or C3PAO support is required.