min read
September 3, 2026
|
Updated: 

How to Prepare for a CMMC Audit

Compliance

A practical guide for scoping CUI, producing assessor-ready evidence, and closing last-mile blind spots

The CMMC standard was developed to govern cybersecurity practices within the defense industry. Businesses that support the Department of Defense, whether directly or indirectly, and that handle controlled unclassified information (CUI) have to be CMMC certified to win defense contracts. 

Navigating the CMMC’s intricate requirements is already a daunting task, but getting ready for an actual assessment multiplies that difficulty tenfold. Teams tasked with verifying that CUI remains within designated perimeters must contend with data scattered across various VPNs, VDI setups, SaaS applications, and unmanaged web browsers.

This article walks through audit preparation for the three progressive levels of CMMC compliance. You'll see how to confirm assessment scope, build an evidence habit, close last-mile blind spots, and run a dress rehearsal before a formal review.

What a CMMC audit really examines

CUI is sensitive data, which could include PII, ePHI, and data elements from more than 20 categories. Due to this broad definition, many industries outside of the DoD also rely on the standard to demonstrate their ability to securely handle sensitive data. The CMMC Program final rule is the baseline teams should plan against as requirements show up in solicitations and contracts.

The CMMC’s three-tier framework measures an organization’s ability to protect sensitive information. Each escalating level corresponds to specific types of data and distinct assessment methods:

  • Level 1 (Foundational) protects Federal Contract Information (FCI) by requiring the 15 basic safeguarding requirements in FAR 52.204-21. Certification is through annual self-assessment.
  • Level 2 (Advanced) protects CUI through the application of 110 security controls aligned with NIST SP 800-171. Assessment is required every three years by certified third-party auditors (C3PAO) for critical systems, or periodic self-assessments depending on contract specifications.
  • Level 3 (Expert) demonstrates effective CUI protection on critical/high-priority defense programs against Advanced Persistent Threats (APTs), measured against 110+ required practices and enhanced controls from NIST SP 800-172. Level 3 assessments are performed by Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a governmental organization specifically created to evaluate defense contractor compliance with cybersecurity standards.
The three CMMC levels, by the data they protect and how each is assessed

Assessors test whether your implemented controls match the CMMC’s System Security Plan (SSP), whether your required Plans of Action and Milestones (POA&Ms) are thorough and accurate, and whether you can document adequate policies and processes around data access, monitoring, media protection, and incident response.

Map CUI before you map controls

The wrong prep path can waste months of team time, so the critical first step is to confirm the exact requirements specified in your prime contract awards and flow-downs to subcontractors. Everything after that amounts to building evidence that your organization meets these requirements. 

Inventory where FCI and CUI enter, where they are stored, which roles touch them, and which subcontractors receive flow-down obligations.

Include paths that security stacks often undercount: personal devices on "bring your own device" (BYOD) programs, partners using third-party contractor access, and web apps where users can export files or paste text into unmanaged tools. Navigating the challenges of contractor and third-party access shows up across DIB supply chains, and assessors know the pattern.

Note: If a system cannot be shown to process, store, or transmit in-scope data, you need to create a clear rationale for keeping it outside the CMMC assessment’s scope. This rationale statement still needs to document owners, authentication, logging, and data-handling rules before you debate control wording.

Trace where FCI and CUI enter, rest, and move, including the BYOD and web paths stacks tend to miss

Enact traceability long before audit week

Successful CMMC certs are built on proactive data governance. Decide early which artifacts prove each control family, who owns them, and how often they are updated.

This evidence usually includes:

  • An SSP that matches your current live environment, not the architecture in place when you first created that security plan.
  • POA&Ms that name owners, dates, and residual risk without hiding open issues
  • Access reviews, authentication logs, and privilege changes tied to CUI systems
  • Monitoring and response records
  • Media and data-handling controls for download, print, copy, and transfer paths

Browser activity deserves special attention. Traditional stacks often cannot see what happens inside a session, which is why using your browser as an auditing support tool has become part of modern audit prep. Policy-focused logging of high-risk events is some of the most solid compliance evidence you can present to auditors.

Close last-mile blind spots

Work with CUI increasingly happens in SaaS and web apps, and assessors will definitely audit the last mile of data access to check that your organization follows Zero Trust Network Access (ZTNA) policies of “never trust, always verify.”

Expect questions like:

  • Can a user copy CUI from a governed app into an unmanaged chat or personal drive?
  • Who can download design files, and is that action logged?
  • How do contractors reach the same apps without full corporate endpoints?
  • What happens when someone pastes sensitive text into a consumer AI tool?

If the current answer depends on a network DLP appliance catching every case, prepare for follow-ups. Network and endpoint controls rarely see the full story once data is rendered in a browser tab. You can get ahead of this audit pitfall by protecting sensitive CUI at its most vulnerable point: the browser.

CMMC Compliance: A Browser-Based Approach lays out why protecting CUI at the point of use reduces the number of systems you must prove for everyday web work. Teams modernizing federal zero trust face the same last-mile problem: users will find ways around overly restrictive controls that block their ability to do their jobs — and these bypasses show up in audits.

Put the work environment on your audit path

By the midpoint of prep, most teams need a concrete way to shrink scope and deepen evidence for web and SaaS work. That is where Island belongs in the plan.

The Island Enterprise Browser gives IT and security a governed environment for enterprise work, with policy, identity, and visibility built into the place users already spend their day. Paired with Island Data Protection, you can set boundaries on copy, paste, download, print, and risky destinations without routing every workflow through a remote desktop.

For CMMC prep, that combination helps in three practical ways:

  1. Clearer scope for web work. When CUI-handling roles work inside Island, you can describe a smaller, more consistent path for access and data handling.
  2. Evidence closer to the action. Session and policy events related to CUI handling are easier to produce when logging is tied to the work environment.
  3. Fewer fragile workarounds. Contractor and partner access can use the same policy model instead of long device provisioning cycles that create shadow paths.

If your team is still defining what an enterprise browser is, treat it as an audit-enabling control plane for the last mile.

Run a dress rehearsal before the formal assessment

Schedule an internal walkthrough that mimics assessor behavior. Pick control families that usually trip teams: access control, audit and accountability, media protection, system and communications protection, and incident response.

For each control family, require the owner to:

  1. Point to the live control, not just a policy document
  2. Produce an artifact within a short timebox
  3. Thoroughly explain exceptions and compensating measures

Give every gap identified its own ticket with an owner and due date, and make sure these tickets are closed well before assessment time.  

Pro tip: Rehearse subcontractor flow-down questions as carefully as internal ones. If a partner company handles CUI and cannot show aligned controls, your own CMMC compliance is incomplete.

Use the rehearsal to decide where Island should be mandatory for CUI roles versus optional for general browsing.

Conclusion

CMMC audit prep succeeds when scope exactly matches contractual requirements, evidence is routine, and last-mile data handling is visible. It helps when you can demonstrate literacy with the CMMC framework itself, but at the end of the day assessors only care about the operational proof you provide.

Start with level and assessment type, map FCI and CUI with subcontractors included, and practice producing artifacts before anyone external asks. Where web and SaaS work dominate, put governance in the environment people use so the story you tell matches the sessions you can show.

See how Island supports CMMC prep

If you're mapping CUI workflows and want a clearer last-mile control story for assessors, we're happy to walk through how Island applies in your environment. Schedule a demo to see access, data protection, and auditability in practice.

FAQs

Do we need a C3PAO assessment, or is self-assessment enough?

It depends on the CMMC level and what your contracts and flow-downs require. Confirm the assessment type in the solicitation language and with contracts counsel before you schedule a third party. The higher the CMMC certification level you aspire to, the earlier you need to build in traceability and visibility for any CUI work performed in your org (or by a subcontracting org).

What should be in the SSP versus day-of evidence?

The SSP should describe the in-scope environment, boundaries, and how controls are implemented. Day-of evidence is the live proof: logs, access reviews, configuration screenshots, tickets, and training records that match the plan. If the SSP and the live system disagree, assessors will notice.

Do contractors and BYOD users affect CMMC scope?

Yes: if they can reach FCI or CUI, they are part of the audit. Device ownership does not remove the obligation to control access and data handling. Plan third-party contractor access and BYOD paths with the same clarity you use for corporate endpoints.

Can we still use POA&Ms during audit prep?

Yes, when they are accurate, time-bound, and allowed for the assessment type you face. A POA&M is not a substitute for required implemented controls. Use it to track residual risk with owners and dates, rather than papering over missing fundamentals.

Does browser-level logging help an assessment?

Yes, because much CUI exposure happens after a user is already authenticated in a web app. Network logs rarely show copy, paste, download, or paste-into-AI events. Policy-focused browser logging produces artifacts closer to those actions, which is the point of using your browser as an auditing support tool.

Where should Island sit in a CMMC prep plan?

Use Island for roles that handle CUI in SaaS and web apps when you want consistent access policy, data protection, and session evidence without expanding VDI. Pair the Island Enterprise Browser with Island Data Protection, then document that path in the SSP so assessors see a coherent control strategy and follow-through.

Scott Montgomery

Scott Montgomery has a tenured career building information security and privacy products, helping organizations increase their defensive posture, evangelizing to technical audiences and the greater public, and driving shareholder value. Scott loves making difficult infosec concepts more accessible to wider audiences. He has presented to numerous audiences as a lecturer and has also testified before Congress. Scott has designed, built, tested, fielded, certified, sold, and supported a wide range of information security and privacy products, notably during a ten year stint with McAfee. He has also held multiple Chief Technology Officer positions, including for private and public organizations. A native Philadelphian, Scott, his wife, two kids, and two standard poodles now live just outside Washington DC in suburban Maryland.