StealthTech365

Receiving a Not Met determination on a CMMC practice isn’t the end of the certification process. For most organizations, it’s a detour — one that adds time and cost to the path to certification but doesn’t permanently block it. What happens after a finding, how quickly the organization responds, and how well the remediation is documented are what determine whether that detour is a brief one or a prolonged and expensive one.

The anxiety that surrounds CMMC audit findings is understandable. Contractors who have invested months and significant budget in compliance preparation don’t want to hear that something didn’t pass. But the more productive response to a finding — whether discovered during a readiness assessment, an internal audit, or the formal C3PAO assessment itself — is to understand exactly what it means, what options exist for addressing it, and what the path from finding to certification actually looks like.

This guide covers all of it: what CMMC audit findings mean structurally, which ones can be addressed through a Plan of Action and Milestones and which ones can’t, how to build a remediation response that satisfies assessors, and how to manage the post-finding certification path efficiently.

What a CMMC Audit Finding Actually Means

A finding in CMMC terminology is a formal determination by a C3PAO assessor that a specific practice is Not Met — meaning the evidence gathered through document review, personnel interviews, and technical testing does not demonstrate that the practice is fully implemented and operating as required. The finding is specific to one of the 110 CMMC Level 2 practices, documented in the assessor’s findings report with a description of what was evaluated and why the determination was Not Met rather than Met.

Findings are not judgments about the overall quality of an organization’s security program. A single finding on one of 110 practices means one thing didn’t meet the standard. It doesn’t mean the other 109 are suspect, it doesn’t mean the organization is fundamentally non-compliant, and it doesn’t mean certification is off the table. What it does mean is that something specific needs to be addressed before the organization can hold a clean or conditional CMMC Level 2 certification.

diverse team collaborates in an office space, discussing cybersecurity strategies

The distinction between a finding discovered during a readiness assessment or internal audit versus one discovered during a formal C3PAO assessment matters significantly in terms of what it costs and how it affects the certification timeline. A finding discovered six months before the formal assessment costs remediation effort.

A finding discovered during the formal assessment costs remediation effort plus potentially a follow-on assessment, plus the delay between the initial assessment and re-certification, plus any contract implications from the gap in certified status. This cost differential is the primary reason that readiness assessments — structured pre-certification evaluations that apply assessor standards before the formal engagement — return more value than almost any other pre-assessment investment. Our guide on CMMC audit preparation covers how readiness assessments fit into the preparation timeline.

The Three Outcomes of a CMMC Level 2 Assessment

Understanding what happens after a formal C3PAO assessment requires understanding the three possible outcomes and what each one means for the certification path.

The first outcome is full certification. All 110 practices are scored as Met. The organization receives a CMMC Level 2 certification valid for three years, recorded in eMASS and reflected in SPRS. No remediation is required, no follow-on assessment is needed, and the organization can immediately satisfy CMMC requirements in covered contracts. This is the outcome that thorough, well-documented preparation produces — and it’s achievable for organizations that have built genuine compliance programs rather than documentation packages.

The second outcome is conditional certification. Some practices are scored as Not Met, but those findings meet the criteria for POA&M-eligible treatment under the DoD’s conditional certification framework. The organization receives a conditional CMMC Level 2 certification — which can satisfy CMMC contract requirements — while completing defined remediation within a specified timeframe. The conditional certification is real and usable, but it comes with a compliance obligation that must be fulfilled within the DoD-specified window.

The third outcome is no certification. The findings are either too numerous, involve practices that aren’t eligible for POA&M treatment, or are significant enough that conditional certification isn’t appropriate under the framework’s criteria. The organization must remediate and undergo a follow-on assessment before any form of certification is granted.

Understanding which outcome a specific set of findings produces requires knowing how the DoD’s POA&M eligibility criteria work — because the distinction between findings that produce conditional certification and findings that prevent any certification is not intuitive and not always communicated clearly in how CMMC compliance is described to contractors.

POA&M-Eligible Findings vs. Immediate Disqualifiers

The Plan of Action and Milestones mechanism allows organizations with specific categories of Not Met findings to receive conditional certification while completing remediation. Not all findings are POA&M-eligible. The DoD has defined criteria that determine whether a finding can be addressed through a POA&M for conditional certification or whether it represents a gap too fundamental to allow any certification to proceed.

The DoD’s CMMC program establishes that certain practices have such direct and immediate impact on CUI protection that a Not Met determination cannot be remediated through a POA&M — these practices must be fully Met at the time of assessment for any certification to be granted. While the definitive list is maintained in the DoD’s CMMC program documentation and is subject to update, the practices that have been identified as carrying this immediate disqualifier status are concentrated in the foundational security domains.

Multi-factor authentication — specifically practice 3.5.3 — is the most commonly cited example of a practice where a Not Met determination cannot be remediated through a POA&M. The logic is straightforward: an environment without MFA enforcement has a fundamental authentication weakness that represents unacceptable risk to CUI regardless of how well other controls are implemented. Other practices in the Access Control and Identification and Authentication domains carry similar weight.

Beyond these specific immediate disqualifiers, POA&M eligibility is also governed by the aggregate number of Not Met findings. The DoD has established limits on how many practices can be addressed through a POA&M while still qualifying for conditional certification. An organization with a single Not Met finding in a POA&M-eligible practice is in a very different position than one with 20 Not Met findings — even if each individual finding would be POA&M-eligible on its own.

For POA&M-eligible findings, the conditional certification that results carries a specific remediation deadline — typically 180 days from the date of the assessment — within which the POA&M items must be fully remediated and verified. Missing that deadline has consequences for the conditional certification status that affect contract eligibility.

Building a Remediation Response That Satisfies Assessors

Whether a finding is discovered during internal audit, readiness assessment, or formal C3PAO assessment, the remediation response needs to meet a specific standard — not just fixing the underlying gap, but fixing it in a way that produces the evidence an assessor would accept as demonstrating the practice is now fully Met.

This distinction — between fixing something and fixing it demonstrably — is where remediation responses most often fall short. An organization that discovers an MFA gap, enforces MFA across the affected accounts, and considers the finding closed has done the technical work. But if the remediation evidence consists only of a screenshot taken the day the fix was applied, the assessor who verifies the remediation sees a single point-in-time artifact rather than evidence of implemented and operating control. Evidence of operating continuously — even a short operating history in a follow-on assessment context — is stronger than evidence of a recent fix.

A remediation response that produces assessor-grade evidence addresses several elements:

The root cause analysis explains why the finding existed, not just what the finding was. An MFA finding that occurred because service accounts were excluded from the conditional access policy scope is remediated differently than one that occurred because MFA wasn’t deployed at all. Understanding the root cause ensures the fix addresses the actual gap rather than a surface manifestation of it, and the root cause analysis becomes part of the remediation documentation that demonstrates to assessors that the fix was deliberate rather than reactive.

The technical remediation record documents exactly what was changed, when, by whom, and what the resulting configuration is. For a configuration finding, this means the before and after configuration states, the change management record governing the modification, and a post-remediation configuration export confirming the fix is in place. For a process finding, this means the updated procedure, the personnel who were notified of the change, and records of the first execution of the updated process.

The evidence of operation demonstrates that the remediated control is functioning, not just that it was implemented. For time-sensitive follow-on assessments, even a few weeks of operational evidence — log entries showing MFA enforcement in practice, access review records reflecting the updated process, vulnerability scan results showing remediated vulnerabilities closed — is more compelling than configuration evidence alone. Starting evidence accumulation immediately after remediation, rather than waiting until the follow-on assessment window approaches, produces a more robust evidence package.

The SSP update reflects the remediation in the control implementation description. If the finding existed because the SSP described a control incorrectly or incompletely, the remediation needs to include an SSP revision that accurately describes the now-implemented control. An assessor verifying remediation at a follow-on assessment will reference the SSP — if the SSP still reflects the state that produced the original finding, the follow-on assessment starts from the wrong baseline.

How to Write a POA&M That Assessors Accept

The POA&M isn’t just a remediation tracking document — it’s a commitment to the DoD that specific gaps will be addressed within a specific timeframe, with specific owners and specific milestones. The quality of the POA&M matters because assessors evaluate it both during the initial assessment and during the follow-on assessment that closes POA&M items.

A POA&M that signals a mature, credible remediation commitment has several characteristics that distinguish it from one assembled hastily to satisfy a documentation requirement.

man is exploring the security system on blurred background

Each item is specific about what’s not met. “MFA not fully implemented” is less useful than “Conditional Access Policy CA-001 does not cover service accounts in the following security groups: [specific groups]. MFA is not enforced for these accounts when accessing CUI systems in the following environments: [specific systems].” The specificity of the problem description reflects the depth of understanding that credible remediation requires.

Each item has a named owner — a specific person, not a role or department — who is accountable for the remediation. Assessors who ask during follow-on assessments about a POA&M item expect to be able to speak with the person who owns it and have that person describe the remediation they’ve executed.

Each item has an interim mitigation describing what the organization is doing to reduce risk while the gap exists. For an MFA gap affecting service accounts, an interim mitigation might include compensating access controls, enhanced logging on the affected accounts, and a documented risk acceptance at the appropriate leadership level. The interim mitigation demonstrates that the organization isn’t simply operating with an unmanaged gap during the remediation period.

Each item has a realistic target date based on actual remediation effort assessment, not an optimistic date chosen to appear favorable. A target date that passes without the item being closed undermines the credibility of the entire POA&M. If a target date needs to change, updating it with a documented reason is more credible than leaving an overdue item unchanged.

The remediation milestones within each item describe the intermediate steps between current state and fully remediated state — the sequence of work that will be completed, with target dates for each milestone. This structure makes the POA&M a management tool rather than a compliance declaration, and that distinction is visible to assessors who have seen both.

Our guide on creating a System Security Plan covers how the POA&M integrates with the SSP as a complete compliance documentation package — because assessors evaluate both documents in relation to each other, and inconsistencies between what the SSP describes and what the POA&M documents create questions that neither document answers clearly on its own.

Managing the Remediation Timeline Under Conditional Certification

Conditional certification triggers a remediation clock. The DoD’s specified timeframe — typically 180 days — is the window within which all POA&M items must be fully remediated and verified through a follow-on assessment. That window is finite, and it starts running from the assessment date rather than from when the organization feels ready to begin remediation.

Managing remediation against this timeline requires treating the POA&M as a project plan rather than a documentation artifact. Each item needs an owner, a sequence of work, resource allocation, and progress tracking. Items with dependencies — where one remediation step is blocked by the completion of another — need to be sequenced accordingly. Items that require technology procurement, configuration changes, or policy revisions that involve multiple stakeholders need lead time built into their timelines.

The follow-on assessment that closes conditional certification needs to be scheduled before the remediation deadline, not on the deadline. Scheduling a follow-on assessment on the last day of the conditional certification window leaves no room for any issue that arises during the assessment — a finding on the follow-on that requires additional remediation, or an assessor question that surfaces additional context about the original finding that needs to be addressed. Building buffer before the deadline protects against these scenarios.

Engaging the C3PAO who conducted the initial assessment for the follow-on assessment, rather than switching providers, typically produces the most efficient follow-on process. The original assessment team has institutional knowledge of the environment and the original findings that a new C3PAO would need to rebuild. For organizations with straightforward remediation — a small number of focused POA&M items that were clearly addressed — the follow-on assessment with the same C3PAO is often scoped tightly to the specific practices that were Not Met rather than requiring a full reassessment of all 110 practices.

Findings That Reveal Program Gaps vs. Findings That Reveal Evidence Gaps

One of the most useful distinctions to make when analyzing CMMC audit findings is whether a finding reflects an actual security control gap or an evidence gap — a control that is implemented but not documented in a way that satisfies assessor standards. These require different remediation responses and carry different compliance implications.

A genuine control gap means the security control isn’t in place. MFA isn’t enforced. Audit logs aren’t being reviewed. Vulnerability scans aren’t covering the full scope of in-scope assets. The remediation is implementing the control and then building the evidence that demonstrates its implementation and ongoing operation.

An evidence gap means the control is implemented but the documentation doesn’t satisfy assessor standards. MFA is enforced but the conditional access policy documentation doesn’t explicitly describe the coverage. Audit log review is happening but no review records are being maintained. Vulnerability scans are covering all in-scope assets but the scan results aren’t organized in a way that demonstrates scope completeness. The remediation is building the evidence framework around an existing control — typically faster and less expensive than implementing the control itself, but still requiring deliberate effort to produce evidence that meets assessor standards.

Evidence gap findings are particularly frustrating because the security work was done correctly — the finding reflects a documentation deficiency rather than a security failure. But they’re also the most directly actionable findings, because the remediation is primarily about evidence management rather than technical implementation. Organizations that respond to evidence gap findings by building the documentation infrastructure around existing controls — and by committing to maintaining that documentation as an ongoing practice rather than a one-time remediation effort — typically close these items quickly and with lasting compliance value. Our guide on building a continuous compliance program covers the evidence management practices that prevent evidence gap findings from recurring through the three-year certification cycle.

What Findings Tell You About Your Program Beyond the Specific Gap

Beyond the immediate remediation task, CMMC audit findings carry information about the compliance program that’s worth analyzing rather than just responding to. Each finding reflects something about how the program was built — either a control implementation gap, an evidence management gap, or a scope definition gap — and understanding the category of the finding helps identify systematic vulnerabilities in the program that other findings might not have surfaced.

A cluster of evidence gap findings across multiple control families suggests that the program built security controls without building the documentation infrastructure around them — a systematic gap in evidence management discipline rather than individual control failures. The remediation is individual POA&M items; the program improvement is implementing evidence collection as a designed output of each control operation.

A finding in a domain where multiple related controls passed suggests a specific configuration gap rather than a domain-level program weakness. An access control finding on service accounts in an environment where standard user MFA enforcement passed means the MFA implementation was correct but incomplete in scope. The remediation is targeted; the program implication is a review of similar account categories that might have the same incomplete coverage.

A finding that reveals a gap between documented practice and operational reality — the SSP described a control that wasn’t deployed, or personnel described a process during interviews that the technical evidence didn’t support — suggests either SSP maintenance gaps or operational discipline gaps. Both require attention beyond the specific finding, because other controls in the same category may have the same documentation-to-reality gap.

Analyzing findings at this level, rather than treating each one as an isolated remediation task, produces compliance program improvements that make the triennial reassessment a cleaner experience than the initial certification was. Organizations that learn from their findings and adjust their program design accordingly arrive at their next assessment with a fundamentally stronger program. A compliance partner who supports ongoing program operation — not just assessment preparation — helps translate finding analysis into program improvement rather than just POA&M management.

Preventing Findings Through Better Preparation

The most effective finding management strategy is preventing findings before the formal assessment. This sounds obvious, but it requires a specific preparation discipline that many organizations don’t implement: applying assessor standards to their own program evaluation before the assessor does.

The gap assessment and readiness assessment process — when conducted with technical rigor and calibrated against assessor evidence standards rather than general compliance standards — identifies the same gaps that formal assessments find. The difference is timing: findings discovered in a readiness assessment six months before the formal engagement leave time for remediation that doesn’t affect certification outcomes. Findings discovered during the formal assessment leave only the POA&M path and the follow-on assessment process.

The internal audit cadence that mature CMMC programs run throughout the three-year certification cycle serves the same function on an ongoing basis — identifying drift from compliance posture before it accumulates into the kind of finding that affects triennial reassessment outcomes. Our guide on CMMC and NIST 800-171 critical controls covers the control domains where audit scrutiny is most intense and where internal audit focus should be proportionally concentrated.

The managed IT services providers and security services partners operating within the CUI environment also play a role in finding prevention — specifically, by maintaining configurations and processes to the compliance standards the SSP documents, rather than drifting from those standards as operational priorities compete for attention between assessment cycles. Vendor-related findings — where a managed provider’s configuration didn’t match the documented standard — are among the most avoidable categories of CMMC assessment finding, and they’re avoided through ongoing vendor governance rather than assessment preparation.

Conclusion: Findings Are Manageable When Handled Correctly

A CMMC audit finding isn’t a verdict — it’s a specific, addressable gap in a compliance program that can otherwise achieve and maintain certification. Organizations that respond to findings with clarity about what’s required, specificity about the remediation, and discipline about the evidence they build around that remediation consistently convert Not Met determinations into closed POA&M items and, ultimately, into certifications that reflect genuinely compliant environments.

The contractors that handle findings best are the ones who treat each finding — whether discovered internally or by an assessor — as information about their program that they’re better off having than not having. The finding tells them exactly what needs to change. The remediation builds something that wasn’t fully there before. And the certification that follows reflects a more complete compliance program than the one the finding revealed.

If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 or visit the website to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness.

Scroll to Top