Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

CMMC Documentation Mistakes That Derail Certification

Technical controls get most of the attention in CMMC preparation, but documentation problems cause more assessment failures than missing firewalls or inadequate encryption. Assessors verify compliance through documentation—if your paperwork is wrong, incomplete, or contradicts reality, you will fail even with solid technical implementation.

CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.

This guide identifies the documentation mistakes that derail certification and shows you how to avoid them.

Why Documentation Matters So Much

CMMC assessors cannot observe your security operations 24/7. They spend limited time evaluating your compliance and rely heavily on documentation to understand:

  • What controls you claim to have implemented
  • How those controls are supposed to work
  • Evidence that controls actually operate
  • Your organizational commitment to security

Poor documentation creates doubt. When assessors cannot verify claims through documentation, they must mark controls as NOT MET.

Mistake 1: No System Security Plan or Inadequate SSP

The System Security Plan is your foundational document. Every other piece of documentation connects to it.

SSP stands for System Security Plan—the comprehensive document describing your security program.

Common SSP Mistakes:

No SSP exists

Some contractors have never created an SSP, assuming technical implementation is sufficient. It is not. No SSP typically means automatic assessment failure.

Generic boilerplate SSP

Contractors download templates and submit them unchanged. Assessors recognize boilerplate immediately. Generic statements like “access is controlled through authentication mechanisms” tell assessors nothing about your actual implementation.

SSP does not match reality

The SSP describes one thing; your environment does another. This is worse than no SSP because it demonstrates either dishonesty or complete disconnect between documentation and operations.

Outdated SSP

Your SSP describes systems you replaced two years ago. It references personnel who left the company. It does not include the cloud migration you completed last quarter.

How to Fix SSP Problems:

  • Create a real SSP customized to your environment
  • Describe actual implementation, not aspirational goals
  • Include specific technologies, configurations, and processes
  • Update SSP whenever significant changes occur
  • Review SSP at least annually

Mistake 2: Policies That Do Not Exist or Do Not Apply

Policies establish organizational requirements. Without policies, controls lack authority and consistency.

Common Policy Mistakes:

No written policies

“Everyone knows how we do things” is not a policy. Verbal expectations and tribal knowledge do not satisfy CMMC requirements.

Policies copied from other organizations

Policies referencing “ACME Corporation” when your company is “Smith Manufacturing” show you did not even read what you submitted. Assessors notice.

Policies that do not cover requirements

Your access control policy discusses passwords but never mentions remote access, wireless, or mobile devices—all of which CMMC requires you to address.

Policies nobody follows

Your policy requires 14-character passwords. Your systems enforce 8 characters. This discrepancy is worse than having no policy because it shows policy violations are tolerated.

Policies never reviewed or updated

Your policies are dated 2019 and reference Windows 7 security settings. Technology and threats have evolved; your policies have not.

How to Fix Policy Problems:

  • Create policies for all 14 control families
  • Customize policies to your organization
  • Ensure policies match actual implementation
  • Communicate policies to all personnel
  • Review and update policies at least annually
  • Date and version-control all policies

Mistake 3: Missing or Unusable Procedures

Procedures ensure consistent implementation. Without them, each person does things differently.

Common Procedure Mistakes:

Procedures not documented

Your IT person knows how to provision accounts, but it is all in their head. When they are sick or leave, that knowledge is gone—and assessors cannot verify a process that exists only in someone’s memory.

Procedures too vague

“Create user account following security requirements” is not a procedure. It provides no actionable guidance.

Procedures too complex

A 47-step procedure for password resets that nobody follows defeats the purpose. Procedures must be practical.

Procedures that do not match practice

Your procedure says accounts are disabled within 24 hours of termination. Your last three terminations took two weeks. Assessors will find this discrepancy.

How to Fix Procedure Problems:

  • Document procedures for all key security activities
  • Write procedures that people can actually follow
  • Include specific steps, not vague guidance
  • Verify procedures match actual practice
  • Test procedures periodically
  • Update procedures when processes change

Mistake 4: Evidence That Does Not Exist or Does Not Support Claims

Evidence proves controls are implemented. Missing or inadequate evidence results in NOT MET findings.

Common Evidence Mistakes:

No evidence collected

You implemented MFA but never took screenshots showing the configuration. You conduct log reviews but keep no records. Assessors need proof, not promises.

Evidence does not show what you claim

Your screenshot shows a password policy, but it is from a test system, not production. Your log review records are blank templates. Your training completion report is from 2022.

Evidence is outdated

Configurations can change. Evidence from two years ago does not prove the current implementation. Assessors expect recent evidence—typically within 90 days for technical configurations.

Evidence contradicts other documentation

Your SSP says you use Microsoft Defender. Your evidence shows CrowdStrike. Your policy requires 14-character passwords. Your screenshot shows a 12-character minimum. Contradictions raise red flags.

Evidence cannot be located

“I know we have that somewhere,” during assessment is effectively “we don’t have it.” If you cannot produce evidence when asked, it does not help you.

How to Fix Evidence Problems:

  • Collect evidence for every control
  • Ensure evidence actually demonstrates implementation
  • Date all evidence and refresh regularly
  • Organize evidence logically with an index
  • Verify evidence aligns with documentation
  • Practice locating evidence before assessment

Mistake 5: POA&M Problems

The Plan of Action and Milestones documents gaps and remediation plans. POA&M problems can disqualify you from even conditional certification.

POA&M stands for Plan of Action and Milestones—tracking security gaps and remediation.

Common POA&M Mistakes:

No POA&M when gaps exist

You know you have gaps, but have not documented them. Without a POA&M, gaps are undocumented failures rather than acknowledged items with remediation plans.

Unrealistic remediation timelines

Your POA&M shows 47 items all completing in 30 days. Assessors know this is impossible and may deny conditional certification.

POA&M items never closed

Items have been open for two years with no progress. This shows your POA&M is paperwork, not an actual remediation tool.

Too many POA&M items

CMMC Level 2 requires 80% of controls implemented for conditional certification. If your POA&M has 50 items, you do not qualify.

Critical controls on POA&M

Some controls cannot be on POA&M for conditional certification. Certain fundamental security controls must be implemented before assessment.

How to Fix POA&M Problems:

  • Document all known gaps in POA&M
  • Create realistic remediation timelines
  • Close POA&M items before assessment when possible
  • Prioritize closing high-point-value items
  • Show progress on remaining items
  • Understand which controls cannot remain open

Mistake 6: Inconsistency Across Documents

Your documentation should tell a consistent story. Contradictions destroy credibility.

Common Inconsistency Mistakes:

SSP says one thing, policies say another

Your SSP describes MFA for all users. Your policy requires MFA only for administrators.

Procedures contradict policies

Your policy requires access reviews quarterly. Your procedure describes annual reviews.

Evidence contradicts everything

Your documentation describes elaborate controls. Your evidence shows basic implementation—or nothing at all.

Different people tell different stories

During interviews, your IT manager describes one process while your security officer describes another. Assessors note these discrepancies.

How to Fix Inconsistency:

  • Review all documents together for alignment
  • Use consistent terminology throughout
  • Update all related documents when changes occur
  • Brief all personnel on documented processes
  • Conduct internal consistency reviews before assessment

Mistake 7: Documentation That Assessors Cannot Navigate

Assessors have limited time. If they cannot find information, they may conclude it does not exist.

Common Organization Mistakes:

Documentation scattered everywhere

Policies in SharePoint, evidence on a shared drive, SSP in someone’s email, procedures in a Wiki nobody uses.

No logical structure

Evidence files named “doc1.pdf,” “screenshot.png,” “final_v2_revised_FINAL.docx.” No mapping to requirements.

Broken links and missing files

Your evidence index references files that do not exist or moved. Links to policies return 404 errors.

Multiple versions are causing confusion

Three different SSP versions with no clear indication which is current.

How to Fix Organization Problems:

  • Consolidate documentation in one location
  • Create a logical folder structure
  • Name files descriptively
  • Maintain an evidence index mapping to requirements
  • Use version control with a clear current version
  • Test all links and references before assessment

Key Takeaways

Documentation problems cause more CMMC failures than technical gaps. Your SSP, policies, procedures, evidence, and POA&M must all exist, reflect reality, align with each other, and be organized for assessor review.

Generic boilerplate fails. Documentation that contradicts implementation fails. Missing evidence fails. Scattered, unorganized documentation fails.

Invest time in documentation before assessment. Review everything for accuracy, consistency, and completeness. The documentation effort is substantial but far less costly than assessment failure.

Related Articles:

Official Sources: This article is based on NIST SP 800-171 Revision 2, NIST SP 800-171A assessment procedures, and the DoD CMMC Assessment Guides.

Documentation is where most contractors stumble. Contact Greypike for expert help building documentation that passes the assessment the first time. For Level 1, skip the documentation headaches—Obolix provides templates, guides your documentation, and gets you compliant in a week or less.

Table of Contents