Home / Service / GAP Assessment

Know Exactly Where You Stand Before a C3PAO Does

Our gap assessment gives you a scored SPRS baseline, a control-by-control gap report, and a remediation roadmap โ€” all before you commit to a full implementation.

What the Assessment Covers

01

SPRS Score Baseline

We calculate your current NIST SP 800-171 score and document the methodology so itโ€™s defensible if questioned.

02

CUI Boundary and Scope Definition

Before any control is reviewed, we define who, what systems, and which locations are actually in scope. In our experience, 95% of organizations skip this step and build on the wrong foundation.

03

CUI Data Flow Mapping

We map how CUI enters your organization, where it lives, how it moves internally, and where it flows out to subcontractors or vendors. This is where most scoping errors surface.

04

Control-by-Control Gap Analysis

All 110 NIST SP 800-171 practices reviewed against your actual environment. No assumptions, no checkbox shorthand.

05

Prioritized Remediation Roadmap

Gaps ranked by risk and implementation effort, with a realistic timeline and cost estimate.

06

Fixed-Scope Implementation Proposal

If you want to move forward, you get a proposal based on what we actually found โ€” not a generic tier.

Why this engagement matters

Enhances Compliance Readiness

Surface and resolve gaps before an external assessor ever opens your environment.

Improves Security Posture

Translate abstract controls into concrete, tested protections across people, process and technology.

Prioritises Remediation Efforts

Rank every finding by risk and effort so your team works on the right things first.

Reduces Audit Risk

Enter your formal CMMC assessment with documented evidence already aligned to the practice requirements.

How the Assessment Runs

01

Scoping Workshop

This is not a kickoff call. Itโ€™s a working session โ€” half a day to a full day depending on your organizationโ€™s size and complexity. We bring together your IT lead, operations, and leadership in the same room. We map your CUI data flow end to end: where it enters, where it lives, how it moves internally, and where it exits to subcontractors or vendors. That data flow document gets built with your team and reviewed for accuracy before anything else moves forward. You approve it. Everything downstream is built on that foundation.

02

Technical Assessment and Walkthrough

Once scope and data flow are confirmed, we conduct the technical review โ€” system configuration review, documentation review, physical walkthrough, and stakeholder interviews. This typically runs 15 to 20 hours and is scheduled around your teamโ€™s availability. We work at your pace, not ours.

03

Gap Report Build

This is the most intensive part of the work on our end. We take everything from the scoping workshop and technical assessment and build a comprehensive, documented gap report โ€” control by control, evidence by evidence. This phase typically runs 25 to 40 hours. We donโ€™t hand you a raw checklist. We hand you a clean, defensible document you could put in front of a C3PAO.

04

Report Delivery and Follow-Up

We present the findings in a structured session โ€” your SPRS score, every gap identified, risk-ranked remediation priorities, and our recommendations. Then we schedule a follow-up call. Thereโ€™s a lot in the report and we want to make sure your team understands what theyโ€™re looking at before they make any decisions about next steps.
Note on Timeline: Total calendar time from scoping workshop to final report delivery varies based on your teamโ€™s availability for the Phase 2 sessions. If you can get the right people in the room, it moves faster.

What you receive

Full GAP Assessment Report (PDF)

Prioritised Remediation Roadmap

Executive Summary for Leadership

90-Minute Findings Walkthrough Call

Proof from a real engagement

Manufacturing ยท Kansas

GAP Assessment Identified 14 Critical Findings โ€” Resolved in 60 Days

A Kansas-based DoD manufacturer engaged AZM for a fixed-scope GAP Assessment. We documented 14 critical findings and a 60-day remediation path. The client returned for a follow-up assessment and passed every closed control on the first review.

Common Questions

Most engagements complete in two to four weeks depending on environment size, scope and how much existing documentation you can provide.
You receive the report, executive summary and roadmap. Many clients then move directly into CMMC Implementation; others execute remediation in-house using the roadmap.
Yes. We scope the assessment to the level required by your contracts โ€” either Level 1 (17 practices) or Level 2 (the full 110 NIST SP 800-171 controls).

Want to Work With a Team You Can Trust? Let's Talk.

Tell us about your contracts and current posture โ€” we’ll show you the fastest path to audit-ready.