This guide includes insights from a webinar hosted by GraVoc’s Director of Information Security, Brian Brunelle, alongside Joe Kurlanski of Monarch, a certified C3PAO.
If you have started looking into CMMC, you have probably run into two terms used almost interchangeably: gap assessment and mock assessment. They are, however, not the same thing.
A gap assessment belongs at the beginning of your certification journey, when you're still figuring out where you stand and what compliance is going to cost. A mock assessment belongs closer to the end, when you think you're ready and want to verify whether you actually are. Neither is required under CMMC; both are preparation steps, not certification milestones.
Below, we break down what each assessment involves, who conducts it, what you walk away with, and how to tell which one your business needs right now. This blog post focuses on CMMC Level 2, which applies to the majority of defense contractors and subcontractors handling CUI.
Prefer to watch?
Brian Brunelle and Joe Kurlanski break down the difference between gap and mock assessments in this clip from our CMMC Level 2 webinar.
What is a CMMC gap assessment?
A gap assessment, sometimes called a readiness assessment, is a point-in-time review of your current security program against CMMC Level 2 requirements. Although a gap assessment is not formally required for CMMC certification, it’s a great place to start to understand where you stand today, identify what’s missing, and build a realistic roadmap toward compliance.
As Brian Brunelle, who leads CMMC readiness engagements at GraVoc, explained during our webinar, a gap assessment helps answer some of the biggest questions organizations have before they begin investing significant time and resources into CMMC:
- How far off are we from meeting CMMC requirements?
- Are our biggest gaps technical, procedural, or documentation-related?
- What will our compliance roadmap look like?
- How much effort, time, and budget should we expect to invest?
For organizations with a mature security program and dedicated internal compliance resources, it may be possible to conduct this evaluation internally. However, many defense contractors and subcontractors don’t have a large cybersecurity team that’s been focused on CMMC for years. They simply need a clear understanding of where they stand and what comes next. A gap assessment provides that foundation.
What is a CMMC mock assessment?
A CMMC mock assessment is designed to simulate the certification process and validate whether your business is ready for an actual CMMC assessment. Like the CMMC gap assessment, a mock assessment is not officially required for CMMC certification, but it is testing that more and more businesses are requesting. CMMC certification can be a tedious and often expensive process, so businesses see the value of mock assessments to ensure their documentation, security controls, and staff are completely ready to pass an assessment.
During a mock assessment, assessors review practices in detail, verify evidence, and evaluate whether personnel know how to demonstrate compliance when asked.
Joe Kurlanski, an assessor with Monarch ISC, an authorized C3PAO, shared an example that many organizations can relate to, “People think they’re ready, they're fired up, but they have staff who have maybe never been through something like this before.” The goal is to help your team become comfortable with the assessment process, understand what evidence will be requested, and uncover issues before they become findings during certification.
Ultimately, a mock assessment is about reducing surprises and building confidence before certification day arrives. As Joe summarized, “We want you to pass the first time and we want you to get through this.”
CMMC gap assessment vs mock assessment: Key differences
Simply put, a gap assessment helps identify missing controls and build a remediation plan, while a mock assessment verifies that your CMMC program will hold up under assessor scrutiny.
Here are the key differences across purpose, timeline, and outcome.
Purpose
A gap assessment establishes where your program stands today, what controls and documentation are missing, and whether your gaps are technical, procedural, or policy-based. You can come out of it knowing what the compliance roadmap looks like and roughly what it's going to cost.
A mock assessment is about verification. By this point, you have done the work, and the question shifts from "what do we need?" to "can we prove it?"
Who conducts it
A gap assessment can technically be done internally. The DoD publishes its assessment materials, and if you have the in-house expertise, you can walk through them yourself. Most organizations bring in a security consultant or advisory firm like GraVoc to get more actionable results.
A mock assessment can be run by either a consultant or a C3PAO. A consultant can tell you how to fix what they find. A C3PAO can’t tell you how to remediate gaps, but they can show you what will be tested and why you failed certain requirements.
The upside of going with your C3PAO, as Joe described it, is that they turn the assessment “as much as we can into an open book test.” Mocks are also typically staffed with a single assessor rather than a full certification team, which keeps the cost below a real assessment.
Outcome
A gap assessment leaves you with an assessment of your current control maturity; a gap register identifying areas that need improvement; prioritized remediation recommendations; guidance around scope, boundaries, and documentation; and input for refining your System Security Plan (SSP) and overall compliance strategy.
A mock assessment gives you practice-by-practice, objective-by-objective results that mirror what a real assessment would produce.
Timing
A gap assessment is conducted before major remediation begins. For most organizations it takes somewhere around six weeks depending on the complexity of their environment.
A mock assessment comes in later, after remediation is largely done. Joe advises, “We usually encourage people if they’re going to do a mock to do it at least eight weeks before their assessment schedule just to make sure they have enough time to wrap it up.”
Gap assessment vs mock assessment: How do you know which one you need?
The answer depends on how far along you are in your CMMC compliance journey.
Start with a gap assessment if you're still asking "where do we begin?"
If you haven’t scoped your environment, your System Security Plan is outdated or nonexistent, or you genuinely don’t know how many of the 110 CMMC Level 2 controls you meet today, start with a gap assessment.
If you're at this stage, our CMMC Level 2 readiness and assessment roadmap walks through what the preparation timeline looks like, from scope definition through certification.
Move to a mock assessment when you think you're ready for certification.
If remediation is largely complete, your documentation is finalized, and your instinct is that you would pass an assessment, that's when a mock is worth it. It’s also the right call if your team has never been through an audit before. Technical readiness and interview readiness are two different things, and it’s best to train your team to answer assessor questions the right way.
Gap & mock assessments FAQ
How does a CMMC gap analysis help organizations improve their cybersecurity posture?
It forces an honest look at what's actually implemented versus what's simply documented. Because CMMC Level 2 is built on NIST SP 800-171, closing those gaps with tighter access control, log retention, and an accurate asset inventory improves your security posture.
What are the key steps to prepare for a CMMC audit?
Start with a gap assessment to establish where you stand against the 110 Level 2 controls and what remediation is going to take. Work through what it uncovers, then conduct a mock assessment once you think you're ready, ideally at least eight weeks out, so there is time to fix anything it surfaces.
For a full roadmap of what to do between these two assessments to prepare for a CMMC audit, read our CMMC Level 2 readiness roadmap.
Is a gap assessment required for CMMC certification?
No, a gap assessment is a preparation step, not a formal CMMC certification requirement.
What's the difference between a CMMC readiness assessment and a gap assessment?
No difference; the terms are used interchangeably. The real distinction is between either of those and a mock assessment.
Should I do a mock assessment with a consultant or with my C3PAO?
Both have their pros and cons. A consultant can help you fix the gaps they find in a mock assessment.
Assessors are permitted to conduct mock assessments, but your C3PAO can't advise on remediation. However the upside here is that you will know what assessors are looking for and why you fell short. Joe advises that if you are close to being ready for CMMC certification, it's best to do the mock assessment with your C3PAO to avoid any surprises.