# CMMC Level 2 - Gap Report (Sample)

**Organization:** Sample Contractor, LLC
**System boundary:** CUI Enclave - Engineering Workstations + M365 GCC High tenant
**Report date:** 2026-01-15
**Prepared by:** Symbiosis Advisory
**Framework:** CMMC Model 2.0 - Level 2 (110 controls, aligned to NIST SP 800-171 Rev 2)

---

## 1. Executive Summary

| Metric                             | Count | %      |
|------------------------------------|-------|--------|
| Controls assessed                  | 110   | 100%   |
| In place                           | 78    | 71%    |
| Partially in place                 | 19    | 17%    |
| Not implemented (gaps)             | 11    | 10%    |
| Not applicable (with justification)| 2     | 2%     |
| **Estimated SPRS score**           | **+82 / 110** | - |

Sample Contractor is materially ready for a C3PAO Level 2 assessment pending closure of 11 open gaps, all of which are tracked in the accompanying POA&M and scheduled to close within 120 days.

## 2. Highest-priority gaps

1. **AC.L2-3.1.1** - MFA not enforced for privileged accounts on legacy jump host. *(High)*
2. **SC.L2-3.13.11** - FIPS 140-3 validated cryptography not confirmed on backup channel. *(High)*
3. **AU.L2-3.3.1** - Windows event forwarding missing on 4 CUI file servers. *(Medium)*
4. **CM.L2-3.4.2** - Baseline configuration undocumented for RHEL 9 enclave. *(Medium)*
5. **IR.L2-3.6.3** - Annual IR tabletop not conducted in last 12 months. *(Low)*

## 3. Results by control family

| Family (17)                              | In place | Partial | Gap | N/A |
|------------------------------------------|:--:|:--:|:--:|:--:|
| Access Control (AC)                       | 17 | 3 | 2 | 0 |
| Awareness and Training (AT)               | 3  | 0 | 0 | 0 |
| Audit and Accountability (AU)             | 6  | 2 | 1 | 0 |
| Configuration Management (CM)             | 6  | 2 | 1 | 0 |
| Identification and Authentication (IA)    | 9  | 1 | 1 | 0 |
| Incident Response (IR)                    | 2  | 0 | 1 | 0 |
| Maintenance (MA)                          | 5  | 1 | 0 | 0 |
| Media Protection (MP)                     | 8  | 1 | 0 | 0 |
| Personnel Security (PS)                   | 2  | 0 | 0 | 0 |
| Physical Protection (PE)                  | 5  | 1 | 0 | 0 |
| Risk Assessment (RA)                      | 3  | 1 | 0 | 0 |
| Security Assessment (CA)                  | 3  | 1 | 0 | 0 |
| System and Communications Protection (SC) | 12 | 3 | 3 | 0 |
| System and Information Integrity (SI)     | 6  | 3 | 2 | 0 |

## 4. Evidence coverage

- **Artifacts collected:** 214
- **Controls with 2+ independent evidence items:** 71 (65%)
- **Controls relying on a single artifact:** 39 (35%) - flagged for reinforcement.
- **NIST 800-53 Rev 5 controls automatically credited via crosswalk:** 612.

## 5. Recommended next 30 days

1. Close the two High-severity gaps (AC.L2-3.1.1 and SC.L2-3.13.11).
2. Reinforce single-artifact controls with a second corroborating evidence item.
3. Schedule and execute IR tabletop; capture minutes and lessons-learned.
4. Freeze SSP v1.0 and package the C3PAO-ready evidence ZIP for pre-assessment review.

---

*This is a sample deliverable produced by the Symbiosis GRC Command Center. Live customer reports are generated automatically from your workspace and refreshed on demand.*
