Why Your CMMC Gap Analysis Might Be Worthless - 110 Practices vs 320 Assessment Objectives

In this article
If your consultant assessed you against 110 practices instead of 320 assessment objectives, you’re preparing for the wrong test
Kieri Solutions has noticed a troubling pattern.
Defense contractors approaching us for CMMC assessments have had gap analyses performed by third-party consultants. When we ask about their readiness, they reference those gap analyses with confidence.
Then we dig deeper.
We ask: did the gap analysis evaluate you against the 110 practice statements or the 320 assessment objectives?
Many folks don’t know the difference. Many have been assessed against only the practices.
Those companies think they’re ready. They’re not.
The Document Most Consultants Use
When defense contractors prepare for CMMC, they typically find NIST SP 800-171. That’s the document referenced in their DFARS contracts. It contains 110 security requirements.
Each requirement is a single sentence, generally open to interpretation.
Here’s an example from the Awareness and Training family.
“Ensure that managers, system administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.”
That’s the entire requirement, one sentence with multiple clauses.
A weak gap analysis reads that, sees the contractor runs awareness training with a presentation on security risks, and marks it compliant.
They check the box. Move to the next requirement. Repeat 109 more times.
At the end, they feel confident. Maybe 90% ready.
The Document Assessors Actually Use
CMMC assessors don’t evaluate you against those general practice statements.
They evaluate you against 320 specific assessment objectives from NIST SP 800-171A.
Most contractors don’t even know this document exists. It’s mentioned in a small footnote on page 3 of 800-171. Four total references in the entire publication.
But 800-171A is what assessors actually use for pass/fail determinations.
That same awareness training requirement has four assessment objectives. [a] Security risks associated with organizational activities involving CUI are identified [b] Personnel are made aware of the security risks associated with their activities [c] Personnel are made aware of the applicable policies, standards, and procedures related to the security of organizational systems [d] Personnel are made aware of their responsibilities related to the security of organizational systems
Looking at the first objective. It specifically mentions CUI. The practice statement doesn’t.
If your training covers generic security risks but doesn’t specifically address CUI-related risks, you fail that objective. The practice statement alone doesn’t tell you that.
Assessment Objectives Carry the Real Detail
This pattern repeats throughout the 320 objectives. The assessment objectives in 800-171A add specificity that isn’t obvious from the practice statements.
When you read assessment objectives word by word (which is how assessors read them), you discover requirements you didn’t know existed.
“Security risks associated with organizational activities involving CUI are identified.”
An assessor looks at every word:
- Security risks – what risks have you identified?
- Organizational activities – what activities involve CUI in your environment?
- Involving CUI – not generic risks, specifically CUI-related
- Are identified – do you have documentation of this identification?
If your training doesn’t specifically identify CUI-related risks, you fail. Even if you have great generic security awareness training.
You Must Pass Every Assessment Objective
To pass a single practice (one of the 110), you must pass every assessment objective underneath it. One hundred percent.
If a practice has four assessment objectives and you pass three, you fail the practice.
Some practices have ten or more assessment objectives. You need all of them.
The math becomes brutal. At the practice level, you might feel 90% ready. At the objective level, those partial implementations become complete failures.
The Score Gap Is Devastating
Based on what we’ve observed, companies that self-assess against practice statements think they’re roughly 90% compliant.
The same companies evaluated against assessment objectives are often 50% compliant or less.
That’s not a small gap. That’s the difference between thinking you’re ready and discovering you have months of work ahead.
It’s the difference between paying for an assessment you’ll pass and paying for an assessment you’ll fail.
What Your Gap Analysis Should Include
Before paying tens of thousands for a gap analysis, ask to see a sample report.
Does it address all 320 assessment objectives individually?
Not grouped by practice. Individual evaluation of each objective with findings specific to that objective.
If the report only addresses 110 practices, shop for a different provider.
What Certified Assessors Look At
Every Certified CMMC Assessor has been trained on the assessment objectives. Not the practice statements.
During assessment, we don’t read that general sentence and make a judgment. We read each assessment objective individually. We look for evidence that specifically addresses what the objective requires.
If the objective mentions CUI specifically, we look for CUI-specific evidence. If the objective requires identification, we look for documentation of identification. If the objective requires a process, we look for evidence that process exists and is followed.
Word by word. Objective by objective. 320 times.
The CMMC Assessment Guide Adds More
Beyond 800-171A, CMMC assessors also reference the CMMC Assessment Guide.
This guide provides additional discussion, further discussion, and examples for each requirement.
The discussion sections help assessors understand intent. But they’re supplemental, not authoritative.
The assessment objectives remain the pass/fail criteria. If discussion says one thing but the objective says another, the objective governs.
Still, the Assessment Guide provides valuable context for understanding what assessors expect. Contractors preparing properly should review it alongside 800-171A.
Preparing Properly
If you’re preparing for CMMC assessment, use the right documents:
NIST SP 800-171 – The 110 requirements. Good for understanding overall scope.
NIST SP 800-171A – The 320 assessment objectives. This is what assessors actually use. Skip it and you’re not preparing for the real assessment.
CMMC Assessment Guide – Additional assessor guidance. Helpful for understanding intent.
Read each assessment objective. Ask yourself: do we have evidence that specifically addresses this? Not the general practice. This specific objective.
If you can’t point to specific evidence for a specific objective, you have a gap.
Gap Assessment Shopping List
Before engaging a gap analysis provider:
- Will your assessment address all 320 assessment objectives or just 110 practices?
- Can I see a sample report showing how you document findings per objective?
- Have you been through actual CMMC assessments as an assessor?
- What documents do you reference during your assessment?
If they only mention NIST 800-171 and not 800-171A, they’re not prepared to give you useful information.
If their sample report groups findings by practice without objective-level detail, you’re not getting what you need.
The Bottom Line
The gap between 110 practices and 320 objectives is the gap between false confidence and actual readiness.
Companies assessed at the practice level think they’re doing great. Companies assessed at the objective level discover significant work remains.
Make sure you know which assessment you’re getting. Make sure you’re preparing for the test you’ll actually take.
The certified assessor who shows up for your CMMC assessment will be reading 320 objectives, not 110 practices. Prepare accordingly.
Kieri Solutions is one of 54 authorized C3PAOs in the United States. The Kieri Compliance Documentation addresses all 320 assessment objectives, not just the 110 practice statements.
Download the KCD brochure: kieri.com/kcd
Schedule a consultation to discuss whether the KCD fits your compliance needs: kieri.com/schedule-consultation
Talk to a CMMC Expert
Tell us where you are with CMMC and we’ll map out the next steps for your team.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.




























































