Skip to main content
Course

CMMC Assessment & Consulting

Guide defense contractors from their first gap assessment to a certificate they earned.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

9 hours

Estimated time

What you will be able to do

  • Plan and set up a CMMC consulting engagement, including your role and its limits as an advisor rather than an independent assessor.
  • Scope a client's environment by finding where CUI and Federal Contract Information (FCI) live and mapping how that data moves.
  • Run a readiness or gap assessment using the examine, interview, and test methods that real assessors rely on.
  • Evaluate evidence and score each requirement as met, not met, or not applicable against the assessment objectives in NIST SP 800-171A.
  • Calculate a client's Supplier Performance Risk System (SPRS) score and explain what it means for their eligibility.
  • Turn findings into a prioritized remediation plan and a realistic Plan of Action and Milestones (POA&M).
  • Write a clear, defensible assessment report that both the client and an assessor can trust.
  • Prepare a client for a third-party certification assessment by a CMMC Third-Party Assessment Organization (C3PAO), including a mock assessment and evidence packaging.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Setting Up the Engagement and Scoping the Environment

    Every good assessment starts before you look at a single control. This module shows how CMMC consulting engagements really work, where you fit as a practitioner, and the firm line between advising a client and independently assessing them. You then learn to scope a client's environment by following the data, sorting assets into the five CMMC categories, and drawing a defensible boundary the rest of the project can rest on.

    2 lessons · 5 quiz questions

  2. 02

    Running the Readiness and Gap Assessment

    This is where you turn a standard into a repeatable assessment you can run for any client. You build an assessment plan, schedule interviews by role, and work through the requirements using the examine, interview, and test methods described in NIST Special Publication (SP) 800-171A. The goal is a calm, organized assessment that leaves nothing out and hands the client a clear gap list.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Evaluating Evidence, Scoring, and Findings

    Assessment is judgment, and judgment can be learned. In this module you weigh evidence the way an assessor does, score each objective as met, not met, or not applicable with reasoning you can defend, calculate the SPRS score, and write findings a client can actually act on.

    2 lessons · 5 quiz questions

  4. 04

    Remediation and the Road to Certification

    A list of gaps helps no one until someone closes them, and closing them well is what clients pay a consultant for. This module turns your gap findings into action: you prioritize remediation, build a realistic Plan of Action and Milestones (POA&M) and roadmap, and cost the work honestly. Then you get the client ready for the Cybersecurity Maturity Model Certification (CMMC) third-party assessment, and you support them through assessment day and whatever follows.

    2 lessons · 5 quiz questions · assignment