Get Familiar with Your Controls: Building Sustainable CMMC Compliance
A contractor once slid a binder across the table to me. Three hundred pages, professionally produced, every one of the 110 requirements addressed. He was proud of it, and he had every right to be — someone had done real work. I asked him what 3.1.5 meant in his environment. He looked at his IT lead. His IT lead looked at the binder.
That pause is the thing I want to write about, because it is the single most reliable predictor I know of how an assessment will go. Not the quality of the documentation. Not the maturity of the tooling. Whether the people responsible for a control can describe it without reading.
Documented and implemented are different words
NIST SP 800-171 has 110 requirements. Underneath them sit 320 assessment objectives, and each objective is a separate thing an assessor will test. That structure tells you what the standard actually expects.
A requirement is not satisfied because a policy asserts it. It is satisfied when the practice exists, someone owns it, and evidence exists that it happened. Those are three different tests, and an SSP only speaks to the first.
This is where outsourced documentation quietly fails people. A consultant who writes your SSP without changing anything in your environment has produced a description of a company that does not exist yet. It reads well. It is also a set of claims you will be asked to demonstrate, by people whose job is to check.
I am not against outside help — it is what I do. But the deliverable that matters is not the document. It is whether your organization can operate what the document describes after the consultant leaves.
Whose control is it
Ask a small contractor who owns access control and you will usually be told: the MSP. Sometimes that is right. Often it is a guess, and the guess is the problem. Your provider handles some things, you handle others, and a set of requirements are shared in ways that are easy to misread. If your provider gives you a customer responsibility matrix, read it as a contract document rather than a reassurance. The lines in it are the lines you will be assessed against.
What I look for is the gap between two answers. Ask the contractor what their MSP covers. Then ask the MSP. When those answers differ, you have found an unowned control, and unowned controls are where findings live.
Worth being direct about something else: an MSP being SOC 2 certified, or CMMC certified themselves, does not transfer compliance to you. Their certification covers their environment. Yours covers yours. The obligation under your contract stays with you regardless of how capable your vendor is.
The controls that do not belong to IT
A meaningful share of the 110 are not technical at all, and those are the ones that decay fastest, because everyone assumes they belong to somebody else.
Personnel security is HR. When someone leaves, access has to be terminated on a timeline, and someone has to be able to show it happened. That process starts with an HR trigger, not an IT one.
Physical protection is facilities. Visitor logs, escort procedures, where the server closet key lives, whether the conference room where CUI gets discussed has a door that closes.
Media protection touches whoever handles shipping and disposal. Awareness training belongs to whoever schedules it and keeps the completion records.
Incident response is the one I would look at first in most organizations. Not the written plan — the answer to a simpler question: if an employee suspects something at 6pm on a Friday, who do they call, and do they know that without looking it up? A plan nobody has rehearsed is a document, not a capability.
My own practice is built around this, so I will admit the bias plainly: the parts of compliance that only work when people outside IT own them are the parts I see fail most often. It is not a technical problem and it does not have a technical fix.
Why the annual affirmation changes the stakes
An assessment is a point in time. Your obligation is not. Under the CMMC program, a senior official affirms continuing compliance in SPRS, and that affirmation repeats annually. Read that sentence the way I read it — as a lawyer. A named individual is making a representation to the government about the current state of your environment.
The False Claims Act sits behind that, and the Civil Cyber-Fraud Initiative exists specifically to pursue contractors who misrepresent their cybersecurity posture. There are settled cases. This is not theoretical exposure.
So the practical question is not whether you can pass an assessment. It is whether, twelve months later, the person signing that affirmation has any reasonable basis for doing so. If controls have drifted and nobody was watching, they are affirming something they cannot support.
Sustainable compliance means the affirmation is a routine confirmation of something you already monitor. Not an annual leap of faith.
What drift looks like
Nothing dramatic. That is what makes it hard to catch. A new hire needs access quickly, so somebody grants it outside the normal process, intending to document it later. A vendor ships an update that changes a default. Someone stands up a file share for a project and it never gets added to the inventory. An employee leaves and their account stays active for six weeks because the offboarding checklist lives in an email thread. Each is small. Each is reasonable in the moment. Collectively, over a year, they are the difference between what your SSP says and what is true. The organizations that hold their posture are not the ones with the best tooling. They are the ones where someone looks at a defined set of controls on a defined schedule and writes down what they found. That is the entire mechanism. It is unglamorous and it works.
A test you can run this week
Pick ten requirements at random from your SSP. Not the ones you feel good about — random. For each, ask three questions:
- Who owns this by name, and do they know they own it?
- What evidence would we produce, and could we produce it today rather than reconstruct it?
- When did someone last verify it is still working?
If you can answer all three for eight of the ten, you are in reasonable shape and you know where your gaps are. If you are answering for three or four, you do not have a documentation problem. You have an ownership problem, and adding pages will not fix it.
Do this yourself, before an assessor does it for you. The exercise takes an afternoon and it is the most honest picture of your readiness you will get.
Getting familiar
The contractor with the binder passed, eventually. What changed was not the documentation — it was that his operations lead could tell me, without notes, how account provisioning worked and who approved it.
That is what getting familiar with your controls means. Not memorizing requirement numbers. Knowing how your own organization actually works, well enough to describe it to someone who is going to check.
Compliance that depends on a document is fragile. Compliance that depends on people who understand their part of it holds up — through an assessment, through the year after, and through the affirmation that follows.
Reading about it is slower than measuring it. Take the 25-question self-check · CMMC scope, explained · Book a scope call

