Get Your Free SPRS Score

Get Your Free SPRS Score

Book a personalized demo to unify tasks, pass audits, and scale.

Failed Your CMMC Assessment? Remediation and Retesting

Failed Your CMMC Assessment Remediation and Retesting
Facebook
Twitter
Pinterest
LinkedIn

BLUF - Bottom Line Up Front

CMMC is a major cost and time commitment, often months long and may cost tens or hundreds of thousands of dollars. A C3PAO checks 320 items tied to 110 NIST SP 800-171 controls. Outcomes: full approval, conditional approval with POA&Ms (usually 180 days), or denial. If denied, fix control gaps, update the SSP and evidence, then reapply. Use proper tools and avoid assessor conflict.

CMMC is unquestionably a huge investment. For many organizations, it represents many months of planning, work, and implementation, with tens or even hundreds of thousands of dollars of improvements, licenses, employees, consultation fees, and more on the line.

Pushing that final button and scheduling your C3PAO assessment, then, is extremely anxiety-inducing. 

What if you fail?

What if all of that time and money goes to waste?

What happens then?

What it Means to Fail a CMMC Assessment

First of all, what does it even mean to fail an assessment?

Well, what is the assessment, for that matter? The assessment, often called an audit even if it's not technically defined as such, is a thorough review of your security controls according to the requirements set out by CMMC.

This assessment looks at 320 specific elements of verification, which reflect the 110 security controls that are described in NIST SP 800-171. These are the controls you've been working on implementing throughout the process. All of the logs, configuration records, test results, and other artifacts of validation you've been generating along the way align with these 320 criteria.

Note: The bulk of this article refers to Level 2 CMMC certification procedures. Level 1 is a self-assessment, so you don't have to worry about a C3PAO failing you, though you do need to make sure you aren't misrepresenting your status. Level 3, meanwhile, has a lot more going on, but at the same time is guided directly by the government, so you won't be going it alone the way you are at Level 2.

What it Means to Fail a CMMC Assessment

When a C3PAO assesses your organization across these criteria, they're checking how well you meet the requirements, if and where you fall short, and what you might need to do to fix the problems they find. Each control is given a MET or NOT MET status, reflecting whether or not you've successfully implemented the control and criteria in question.

This is not, strictly speaking, a pass/fail assessment. Instead, there are three possible outcomes.

Possibility #1: Approval. When your C3PAO goes through all 320 criteria and finds that they are all met, you can then be issued your certification for Level 2 CMMC. Congratulations; you now have your certification and can proceed to work with the Department of Defense or its subcontractors on contracts handling CUI.

Possibility #2: Conditional Approval. When your C3PAO goes through all 320 criteria and finds that most of them are MET, but a few of them are NOT MET, then you reach a crossroads. If those NOT MET criteria are not critical, you are allowed to put them under a Plan of Action & Milestones. POA&Ms are tangible plans with guidelines that state that you know this criteria is not met, you have a plan to make sure it's met, and a timeline to get it done.

If you successfully close out all POA&Ms within the timeline, and none of the NOT MET criteria were critical in nature, then you will be validated and granted approval when the work is finished.

All CMMC controls are assigned a point value and a criticality rating. All controls of 5 points or 3 points are considered critical. A selection of 1-point controls are also considered critical. Failing any of the critical controls pushes you to possibility three.

Possibility #3: No Certificate Issued. If any of the NOT MET criteria are critical in nature; if you have glaring flaws that indicate you didn't even try; if you have no POA&Ms for the NOT MET criteria; or if there is any other reason for the C3PAO to deny you, you will not be granted a certificate. This is your failure condition.

CMMC Approval Denied: What Now?

As you can see, there are two possibilities for denial, and the actions you take will depend on which one you received.

CMMC Approval Denied What Now

While most denials come from NOT MET criteria, sometimes there can be another reason why you fail your assessment. You could have met the criteria but lacked the documentation to prove it, or you could have an incomplete or faulty system security plan

If conditional approval is possible, it means you're most of the way to a secure state, but you didn't quite make it all the way. Your SSP is complete and accurate, your controls are documented, but a few of them aren't fully implemented properly. Maybe you missed some details, maybe one or two slipped through the cracks, or maybe you even thought one of them wasn't applicable when it was.

Sometimes, it's as simple as rushing your timeline, scheduling your assessment too soon, and not having all of the work done by the time the date rolls around. Rescheduling could set you back a long time.

As long as you've done the majority of the work properly and can prove it, and the controls you didn't fully meet are low-weight controls, you can be eligible for a POA&M window. 

A POA&M window is generally 180 days. During this time, you establish a plan for remediating the faulty controls, you put in the work, and you generate whatever new documentation you need to handle it. 

When you've fixed the problem, you'll need to re-test your security. The good news is, this isn't a full-scale assessment; it just checks the POA&Ms and validates the fixes you've implemented. 

On the plus side, POA&Ms with a conditional approval mean the Cyber-AB has not found reason to deny your certification, and you'll be able to receive it once you've finished up the work.

On the downside, this is an unavoidable delay in certification. If you had time-conditional offers for contracts that required CMMC, you'll probably miss those deadlines. It also means you're paying for a (partial) reassessment, which is another added cost.

What if You're Not Granted Approval?

So, what if you aren't granted approval, even conditional?

What If You're Not Granted Approval

This means something is seriously wrong. 

  • You have completely ignored certain controls.
  • You have failed to meet controls that are high-weighted.
  • You have failed to meet too many controls regardless of weight.
  • You have a malformed or incomplete SSP.
  • You were granted a POA&M, but your 180-day window expired.

There's good news and bad news if this is your status.

The good news is, you're not penalized by the Cyber-AB or the DoD. Failing an assessment just means failing an assessment; you aren't fined or penalized or prevented from trying again.

The bad news is, you're back where you started. Your timeline is undefined, your contracts are nebulous, and you have more work and more expense ahead of you to get things right.

Even though you aren't penalized by the government, there are negative repercussions.

  • You lose any pending contracts that were contingent on you achieving CMMC certification.
  • You may lose trust and reputation, particularly with contracts that were burned once before by your failure.
  • You lose any expected revenue streams you may have been counting on.

So, what steps should you take if this is your situation?

What to Do if You Failed Your Assessment

When your C3PAO performs their assessment, they will create a detailed report, which is submitted both to you and to the Cyber-AB. This report will tell you everything that went wrong, which will then allow you to figure out what steps you need to take.

What to do If You Failed Your Assessment

From the bird's-eye view, your task is simple: fix all of the gaps and controls that weren't met, and try again.

At the ground level, it's harder.

We recommend, before looking for technical implementations, figuring out what went wrong. Consider:

  • Was there a lack of top-level buy-in that hindered the implementation process?
  • Was there an external consultant you relied on who, it turns out, was giving bad information?
  • Was there an employee or implementation team that turns out to have been substandard or incapable of doing the work required?
  • Was a tool you're using not actually doing its job properly, reporting false data, or otherwise failing you?

We've seen many organizations over the years fail because of institutional-level problems. The reason we recommend identifying these issues first is to avoid trouble down the line.

To use an easy example, if you hired a consultant to help you with the process and that consultant failed to do the job properly, bringing them back in isn't necessarily going to get you better results. 

Once you address the underlying issue, if there is one, you can then get to work on solving the individual issues described in your assessment report. 

If your SSP needed work, review it and create a new version with an appropriate scope. SSPs, improper scoping, and related issues are some of the most common reasons why organizations fail their assessments. Other common reasons include poor credential management, outdated documentation, bad cryptography, failure to maintain logs, failure to test incident response plans, and poor continuous monitoring.

Otherwise, it's just a matter of identifying the controls that didn't get full implementation, identifying why they didn't get full implementation, and fixing the problem.

Sometimes, this is as easy as toggling a setting in a control panel somewhere. Sometimes it means a deeper level of testing, such as verifying the integrity of backup systems. Sometimes it means running a mock incident and testing your incident response plan. 

Whatever the case, it's a lot of work, but it can be done.

Reapplying for CMMC

Failing a CMMC assessment doesn't mean you're prevented from applying again. In fact, unless you were somehow extremely egregious in wasting the time of everyone in the Cyber-AB or you caused extensive problems for numerous C3PAOs, or something similarly outrageous and unlikely, you're probably in a better position than a newcomer. 

At least you've been through the process once before, right?

Reapplying for CMMC

Go through and validate your controls, verify that you have all of the evidence you need, and make sure any and all documentation, artifacts, and paperwork is up to date. One of the biggest issues we see with re-tests is organizations that didn't keep their documentation straight and end up submitting a mishmash of old and new evidence.

Can you use the same C3PAO for your reassessment? Yes, but there's one hurdle. Your C3PAO is not allowed to give you implementation advice. For example, if you hired us at Ignyte to consult and help you implement your security, we cannot then perform your assessment for you, since it's a conflict of interest. If, however, you hired us to handle your assessment, and you have the goal of passing a second time if you fail the first, we can do that. We just can't give you advice on fixing the issues in between.

Some C3PAOs offer a "mock assessment" conversion process. Basically, if you hire them for your assessment and you fail, they can give you advice on fixing the problems, and then perform an assessment for you with lower stakes and no officiality. This mock assessment can validate your implementation, but does not get submitted to the Cyber-AB; you still need to find a different C3PAO to do the real second assessment.

How can you make sure everything is implemented properly? Use good tools and resources. The Ignyte Assurance Platform is our recommendation, for obvious reasons. We designed this platform from the ground up to be a compliance tool for a wide range of different certifications, including CMMC. Our experience as a C3PAO has given us a great perspective on what helps organizations succeed, and we've worked those features into the platform.

  • Easy, visual widgets that showcase compliance goals and targets, with at-a-glance visualizations to track your progress.
  • Centralized documentation storage, so all of your logs, artifacts, and documents are kept secure in one collaborative location, free from siloed and conflicting storage methods.
  • Simple tracking of individual controls and their status, prioritized by gap from completion.

If this and more sounds helpful to you, reach out and get in touch. We'll book you a free demo and strategy session where we can discuss your needs and how we can help you out. With Ignyte on your side, you're sure to pass your next assessment and get your certification.

Stay up to date with everything Ignyte