If you are a defense supplier preparing for a CMMC 2.0 Level 2 assessment, you probably have one question on your mind:
What will the assessor find?
The fear is understandable. A failed assessment can delay contract work, create expensive remediation obligations, and put your DoD relationships at risk. The problem is that many companies do not fail because they lack security tools. They fail because their controls are incomplete, inconsistently managed, or impossible to prove with objective evidence.
The CMMC Assessment Guide – Level 2 makes the process clear: assessors examine documentation, interview personnel, and test whether controls are implemented correctly and operating as intended.
That is where CPE Level 2 changes the game. It combines infrastructure, security configuration, policies, procedures, managed operations, monitoring, and evidence collection into one integrated environment designed around all 110 CMMC requirements and 320 assessment objectives.
The Six Findings That Put Defense Suppliers at Risk
1. Access control weaknesses
Access control problems are among the most common findings because organizations often have more access than they realize.
Typical issues include:
- Former employees still having active accounts
- Shared or generic accounts that destroy accountability
- Users receiving local administrator privileges unnecessarily
- Remote access that bypasses approved security controls
- Incomplete access reviews
- CUI moving through unauthorized systems or applications
- Devices connecting to the network without formal authorization
CMMC 2.0 Level 2 expects organizations to limit system access to authorized users, processes, and devices. It also requires least privilege, controlled CUI flows, protected remote access, and restrictions on privileged functions.
With CPE Level 2, access control is not left to informal IT habits. The enclave is built around a defined boundary, role-based access, security-centric segmentation, controlled remote access, and managed administrative functions.
The practical benefit: your team is not trying to reconstruct who had access, why they had it, and when it should have been removed after the assessor arrives. The environment is designed to make authorized access visible, restricted, and defensible.

2. Missing or incomplete MFA
Multifactor authentication is a major assessment pressure point.
Many companies believe they have MFA because it is enabled for a VPN or one cloud application. That is not enough. Assessors may look at the entire access path to systems handling CUI, including:
- Remote user access
- Administrative access
- Local interactive logons
- Privileged remote maintenance
- Accounts connected to security-relevant information
- Cloud services or external systems within scope
A password plus a security policy is not MFA. A partial MFA rollout is not complete MFA coverage.
CPE Level 2 addresses identity and authentication as part of the enclave’s integrated architecture. Access pathways are identified, authentication requirements are incorporated into the design, and the associated configurations and records can be organized as assessment evidence.
This matters because assessors do not grade intentions. They test the actual configuration.
3. Unpatched systems and unresolved vulnerabilities
An unpatched system is not only a security risk. It is an assessment problem when you cannot show that vulnerabilities are identified, prioritized, remediated, and tracked.
Common findings include:
- Unsupported operating systems
- Missing security updates
- Firmware that has not been reviewed
- Vulnerability scans performed only once
- High-risk findings with no remediation tickets
- Exceptions that are not documented or approved
- No evidence showing when a patch was installed and verified
CMMC requirements address vulnerability scanning, vulnerability remediation, system flaw correction, configuration management, and ongoing monitoring. A spreadsheet saying “patched” is not strong evidence by itself.
CPE Level 2 includes security patching and maintenance, system hardening, vulnerability monitoring, managed operations, and configuration control. Changes are handled as part of an operational process rather than as isolated acts of memory by an overworked administrator.
The result is a controlled environment with a history: what changed, why it changed, who performed it, and how the result was verified.
4. Poor audit logging and weak monitoring
“We have logs” is not the same as having an effective audit and accountability program.
Assessors may find that:
- Critical events are not being logged
- Privileged functions are not captured
- User actions cannot be traced to unique identities
- Logs are stored locally and can be deleted
- Log retention is too short
- No one reviews the logs consistently
- There is no alert when logging fails
- Logs from different systems cannot be correlated
- Management of audit logging is not restricted
CMMC 2.0 Level 2 requires organizations to create and retain audit records sufficient to support monitoring, analysis, investigation, and reporting of unauthorized activity. The organization must also review logged events and protect audit information from unauthorized modification or deletion.
CPE Level 2 uses integrated monitoring, protected logging, ongoing security operations, and evidence collection to support these requirements. Planet Security’s current approach also includes AI-obfuscated data for AI-enabled workflows.
Generic AI tools cannot be trusted with client data. Defense suppliers should not paste CUI, client records, security logs, or sensitive contract information into ordinary public AI platforms. AI-obfuscated data helps support analysis and automation without exposing the original client or government data to Big-Tech systems.

5. An incomplete or outdated System Security Plan
The System Security Plan is not a formality. It is the authoritative explanation of how your environment protects CUI.
Frequent SSP findings include:
- The SSP is missing
- The SSP is built from a generic template
- The system boundary is unclear
- Connected systems are not identified
- The documented environment does not match the actual environment
- Security requirements are described without explaining implementation
- The SSP has not been reviewed or approved
- The update frequency is undefined
- Recent infrastructure changes are absent from the document
The CMMC Assessment Guide identifies the SSP as a required assessment object under CA.L2-3.12.4. It should describe the assessment scope, operating environment, implementation methods, system boundaries, and relationships with other systems.
CPE Level 2 includes a purpose-built SSP supported by the actual enclave architecture, technical controls, policies, and procedures. This is a major difference from buying a template and hoping someone can fill in the blanks later.

6. Insufficient objective evidence
This is where many otherwise capable organizations get into trouble.
Your team may genuinely perform access reviews, patch systems, review logs, and train employees. But if you cannot produce final, approved evidence, the assessor may not be able to mark the requirement as met.
Typical evidence gaps include:
- Draft policies instead of approved policies
- Screenshots with no date, system name, or context
- Missing access review records
- No training completion records
- No vulnerability remediation history
- No log review reports
- No change management tickets
- No incident response exercise results
- No evidence connecting a control to a specific system or user
CMMC assessments use examine, interview, and test methods. A verbal explanation is not a substitute for technical proof.
CPE Level 2 is designed to make evidence collection part of normal operations. Monitoring records, configuration data, access information, patching activity, system documentation, and security reports are generated and maintained as the environment operates.
Audit readiness should not begin 30 days before the assessment. It should be built into every day of the program.
What Is Included in CPE Level 2?
For current planning, a CPE Level 2 package is $1,299/month for up to 20 users. This includes the protected enclave infrastructure, server licensing, managed service operations, managed security operations, security patching, backups, monitoring, required security policies and procedures, training support, vCISO guidance, evidence support, and assessment representation.
Deployment options may be available based on your situation. Choosing an 8-week deployment instead of a 4-week deployment reduces pricing by $100/month. The right decision depends on your contract timeline, environment, personnel, and readiness requirements: not simply on speed.
The larger point is simple: you are not buying another cybersecurity tool. You are establishing a controlled, documented, continuously monitored environment for protecting CUI.
FAQ: CMMC Assessment Findings
Can an assessor fail us because of one missing piece of evidence?
Yes. If an applicable assessment objective is not satisfied, the related security requirement may be marked NOT MET. One missing artifact can expose a deeper process problem, especially when it shows the organization cannot prove that a control operates consistently.
Does an SSP by itself satisfy CMMC requirements?
No. An SSP explains how requirements are implemented, but the assessor still needs to examine configurations, interview responsible personnel, and test controls. The SSP must match the real environment.
Is MFA for our VPN enough?
Not necessarily. MFA coverage must align with the applicable access paths and systems within the CMMC assessment scope. Remote, administrative, local, and security-relevant access should be evaluated carefully.
Can we use a POA&M for missing MFA or an incomplete SSP?
Organizations should not assume every gap can be deferred. Certain requirements and assessment conditions have specific limitations. Your CMMC strategy must distinguish between an operational plan of action, permitted assessment conditions, and requirements that need to be fully implemented before assessment.
How quickly can CPE Level 2 be deployed?
Full implementation is commonly targeted within about 8 weeks, with expedited 4-week deployment available in qualified situations. The timeline depends on scope, user count, site readiness, logistics, and the organization’s ability to participate in implementation activities.
Stop Guessing. Start Preparing.
The most common CMMC findings are predictable: weak access control, incomplete MFA, unpatched systems, poor logging, inaccurate SSPs, and missing evidence.
The answer is not more disconnected tools. The answer is an integrated operating model that addresses the technical, procedural, documentation, and evidence requirements together.
Explore the CPE Level 2 technical details, review the enclave security reference architecture, and start closing the gaps before they become assessment findings.
We welcome a discussion on how we may assist in your CMMC success story!
| planetsecurity.net | 702.634.7233 | ![]() |
|---|
References: DoD CMMC Assessment Guide – Level 2 · NIST SP 800-171 Rev. 2 · Planet Security CPE Level 2 Technical Details

