CMMC Level 2 Roadmap

    CMMC Level 2 Assessment Roadmap:
    From Gap Analysis to Certification

    Every DIB contractor pursuing CMMC Level 2 follows the same eight stages — scope, gap analysis, POA&M, SSP, mock assessment, SAR, SPRS, and continuous monitoring. This is the roadmap, the artifacts each stage produces, and how Athena's assessment operating system compresses months of consulting into days of focused work.

    Start with a free SPRS score
    110 controls · 320 NIST 800-171A objectives SSP · SAR · POA&M · SPRS · eMASS · OSCAL DIBCAC-grade defensibility
    STAGE 01

    Define your CMMC scope and CUI boundary

    Before a single control gets assessed, the assessor needs to know what's in-scope. Document the people, processes, and technology that store, process, or transmit CUI — and everything that protects them. A tight, defensible boundary is the single biggest predictor of a clean assessment.

    Artifacts you produce
    CUI asset inventory
    Network + data-flow diagram
    Enclave / SRM model
    Run the Scope Check
    STAGE 02

    Get your free SPRS score and a 5-minute gap baseline

    Primes are asking for a SPRS score now. Start with a 25-question self-assessment to lock in your starting point and a one-page POA&M starter. This is the number you put into SPRS today — and the number Athena helps you improve every week.

    Artifacts you produce
    SPRS-formatted score
    Top-10 prioritized gap list
    Get my free SPRS score
    STAGE 03

    Conduct the full 110-control gap analysis

    Athena ingests your policies, screenshots, ticket exports, and configurations, then maps every artifact to the 320 NIST 800-171A assessment objectives. Each finding ships with citation, extractor version, reviewer attribution, and a self-critique pass — DIBCAC-grade evidence, not a spreadsheet.

    Artifacts you produce
    Per-control evidence binder
    Objective-by-objective coverage map
    Reviewer-attributed gap findings
    Open Athena LLM
    STAGE 04

    Build your POA&M with owners, cost, and milestones

    Every gap becomes a Plan of Action & Milestones row — owner, due date, cost, and 30/60/90-day burn-down. Athena's Lift Plan suggests the next best action per control so remediation actually moves the SPRS number, not just the spreadsheet.

    Artifacts you produce
    POA&M (XLSX + CSV)
    Per-control Lift Plan
    Milestone playbooks
    Open POA&M Manager
    STAGE 05

    Draft your SSP — control-by-control, sourced from live data

    The System Security Plan is the assessor's first read. Athena drafts every control narrative from your scope, enclave, shared-responsibility matrix, and assessment data — so the SSP, RACI, and evidence binder never drift out of sync.

    Artifacts you produce
    SSP (DOCX + PDF)
    Shared Responsibility Matrix
    OSCAL SSP export
    Open SSP Builder
    STAGE 06

    Run a DIBCAC-style mock assessment

    Before a C3PAO walks in, replay your binder through Athena's Mock Assessor. Every objective gets scored MET / NOT MET / NA against the live evidence, with adjudication notes you can hand to your Affirming Official.

    Artifacts you produce
    Mock SAR draft
    Findings briefing deck
    Defensibility score
    Run the DIBCAC Mock Assessor
    STAGE 07

    Generate the SAR and the C3PAO submission pack

    Athena builds the Security Assessment Report, evidence binder index, SHA-256 manifest, eMASS pre-assessment JSON, and branded cover packet — every artifact a C3PAO expects, with full provenance traceable back to the source extraction.

    Artifacts you produce
    SAR (DOCX + PDF + PPTX)
    eMASS pre-assessment JSON
    SHA-256 evidence manifest
    OSCAL SAR + POA&M
    Open Assessment Pack Builder
    STAGE 08

    Submit to SPRS and maintain continuous compliance

    Certification isn't the finish line — it's the start of three years of continuous monitoring. Athena watches evidence freshness, surfaces decay before it becomes a finding, and re-runs the closed-loop assessment whenever your environment changes.

    Artifacts you produce
    SPRS submission package
    Evidence freshness dashboard
    Continuous monitoring alerts
    Open SPRS Booster

    Frequently asked questions

    How long does a CMMC Level 2 assessment take?

    Most organizations spend 6–12 months from scope definition to C3PAO submission. The gap analysis and POA&M closure usually take longer than the assessment itself. Athena compresses gap analysis from weeks to hours by extracting evidence directly from your existing policies and configurations.

    What's the difference between a self-assessment and a C3PAO assessment?

    CMMC Level 2 Self-Assessment is sufficient for some DoD contracts; the C3PAO certification is required when the contract specifies certified assessment. Both rely on the same 110 controls and 320 objectives — the artifacts (SSP, SAR, POA&M, SPRS) are identical, but a C3PAO conducts the certified version under DoD oversight.

    How much does CMMC Level 2 cost?

    Direct C3PAO fees typically run $40K–$120K depending on scope, plus internal remediation costs that can dwarf the assessment fee. Athena's Survival Report ($129), Compliance Pro ($299/mo), and C3PAO Submission Pack ($4,995) cover the artifact generation that historically drove most of the consulting bill.

    What artifacts does a C3PAO actually require?

    At minimum: SSP, SAR, POA&M, SPRS score, evidence binder with SHA-256 manifest, scope diagram, shared responsibility matrix, and an Affirming Official attestation. eMASS pre-assessment JSON and OSCAL exports are increasingly requested for federal integration.

    How is Athena different from a GRC platform?

    GRC platforms manage tickets and store evidence. Athena conducts the assessment — extracting findings from documents, mapping them to 800-171A objectives, drafting the SSP/SAR/POA&M, scoring against DIBCAC criteria, and producing defensible artifacts a C3PAO can sign off on.

    Stop running CMMC on spreadsheets. Run it on Athena.

    Get a SPRS score in 5 minutes, then walk the full roadmap with the assessment operating system C3PAOs trust.