CMMC Gap Analysis · Level 2

CMMC gap analysis: find the control gaps before an assessor does

For Defense Industrial Base contractors preparing for CMMC Level 2. Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending.

A CMMC gap analysis answers one question: which of the 110 NIST SP 800-171 controls does your environment not yet meet, and in what order should you fix them? It is the difference between walking into a C3PAO assessment knowing your weak points and discovering them when an assessor writes them up.

What a CMMC gap analysis covers

A proper gap analysis maps your current environment against all 110 controls and 320 assessment objectives, then produces a prioritized remediation roadmap. The output is not just a list of failures. It is an order of operations, because in the DoD Assessment Methodology not every control is worth the same number of points.

The controls that move your score the most

NIST 800-171 controls are weighted on a 5, 3, or 1 point scale. The 5-point controls are where a gap analysis pays for itself, because closing one moves your score five times as far as closing a 1-point item. Four areas that carry 5-point requirements under the DoD Assessment Methodology:

You can run the first pass of a gap analysis right now, free. The gap check asks 10 questions, seven of them on 5-point controls, and shows your estimated point exposure on screen, no account. It scores what you report; it does not read your systems. Find your gaps free →

How to run one

The manual path is a spreadsheet mapped to all 320 objectives, evidence collected control by control. It works, but it is slow and it goes stale the moment your environment changes. The faster path is agents that read your environment's configuration metadata on a schedule, score the controls they can measure against the baseline, and rebuild the analysis each cycle, while your team records what no connector can see and your Affirming Official decides what to affirm. That is what Enclave AI™ does, and the free 10-question gap check is the front door to it.

Run your gap analysis free

The free gap check asks 10 questions on high-weight controls, scored from your answers. When you are ready for more, the CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-control baseline; it measures only the controls a connected source can show, and ranks your top gaps by point recovery, $999 one time, PDF within minutes of intake. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot

Common questions

Which NIST 800-171 controls carry the most points?

Controls are weighted 5, 3, or 1 under the DoD Assessment Methodology. The 5-point controls include MFA (3.5.3), limiting access to authorized users (3.1.1), enforced secure baselines (3.4.1, 3.4.2), FIPS-validated cryptography protecting CUI (3.13.11), and creating audit logs and correlating their review (3.3.1, 3.3.5). Encryption of CUI in transit (3.13.8) is a 3-point control.

How often should a gap analysis be redone?

Every time your environment materially changes: staff turnover on key controls, new cloud tools entering scope, configuration drift. A point-in-time analysis ages fast, which is why re-measuring on a schedule beats an annual spreadsheet exercise.

Is a gap analysis the same as a C3PAO assessment?

No. A gap analysis is preparation you run on your own side. A Level 2 certification assessment is conducted by a C3PAO authorized or accredited by the CMMC Accreditation Body (32 CFR 170.17); a Level 2 self-assessment is your own (32 CFR 170.16). Enclave AI™ is a readiness AaaS provider, not a C3PAO, and that separation is permanent.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas.