
Why One CMMC Finding Can Block Certification Entirely
Here is a fact that surprises many contractors the first time they hear it: you can implement 109 out of 110 CMMC Level 2 practices flawlessly, and still walk away without certification. There is no partial credit in the sense that matters most. The certification decision is binary — you either receive it or you don't — and a single unresolved finding in the wrong control can be the difference between winning a DoD contract and losing your eligibility to compete for one.
This is one of the most consequential and least understood aspects of the CMMC assessment process. Contractors often approach preparation the way they might approach a school exam, assuming that a high overall score will carry them across the finish line even if a few items are imperfect. CMMC Level 2 does not work that way, and understanding why is essential to preparing correctly.
The SPRS Score Is Not the Certification Decision
Many contractors track their Supplier Performance Risk System (SPRS) score as their primary readiness indicator, and it's a reasonable thing to monitor — it reflects where your implementation currently stands across the 110 practices derived from NIST SP 800-171. But the SPRS score and the certification decision are not the same thing, and conflating them is a costly mistake.
Your SPRS score is a point-in-time self-assessment snapshot. It can be high, low, or somewhere in between, and it can change based on self-reported progress. The certification decision made by your C3PAO assessor, by contrast, is not a score at all. It is a determination, made practice by practice, of whether each one is "met" or "not met" based on evidence gathered through examine, interview, and test. A contractor with a strong SPRS score can still fail to achieve certification if even one practice in a critical control family cannot be adequately demonstrated during the formal assessment. The score describes your trajectory. The assessment determines your outcome.
How "Not Met" Findings Actually Work
For each of the 110 practices, the assessor determines whether the evidence gathered is sufficient and internally consistent. A practice is met when documentation, personnel interviews, and direct technical testing all align and demonstrate that the requirement is fully and currently implemented. A practice is not met when evidence is missing, contradictory, or fails to demonstrate full implementation — regardless of how close you actually are.
This is a stricter standard than it might first appear. A control can be substantively well implemented from a security perspective and still generate a "not met" finding, simply because the assessor could not confirm it within the assessment's methods and timeframe. A policy that exists but isn't consistently followed is a finding. A configuration that works correctly in production but cannot be demonstrated on demand is a finding. The assessment is a structured verification process, not a security audit in the broadest sense — the question being asked is narrower and more exacting: can this specific practice be proven, right now, using the methods the assessor is required to use?
Not All Findings Are Treated Equally
Once a finding is identified, contractors often assume it can simply be documented in a Plan of Action and Milestones (POA&M) and addressed later. A POA&M does have a legitimate role in the CMMC process — it documents a planned remediation timeline for a finding that has been identified but not yet resolved. However, a POA&M does not eliminate the finding, and critically, not every finding is eligible for POA&M treatment.
Depending on the practice and the current CMMC rulemaking guidance in effect at the time of your assessment, certain findings may require immediate remediation before certification can be granted at all. Contractors sometimes over-rely on the POA&M mechanism as a way to defer difficult or expensive remediation work, only to discover during the assessment that specific findings are not deferable, or that the aggregate weight of multiple deferred findings is itself sufficient to prevent certification. Knowing in advance which controls in your environment carry zero tolerance for open findings is not optional homework — it is one of the most important pieces of information you can have before your assessment begins.
Why This Catches Mature Programs Off Guard
It is tempting to assume that this binary, all-or-nothing risk applies mainly to contractors who are underprepared. In practice, it just as often catches organizations with genuinely mature security programs, because maturity creates a different kind of blind spot: confidence. A contractor who has invested heavily in access control, endpoint protection, and network segmentation can reasonably feel that their program is strong — and it may well be. But a single overlooked practice, in a family the organization considered "already handled," can still produce the finding that blocks certification.
This often happens in the connective tissue between controls rather than in the controls themselves. A well-configured multi-factor authentication rollout can still generate a finding if the audit logs that should confirm its use consistently are incomplete. A carefully documented System Security Plan can still generate a finding if it describes a future state of the environment rather than the one currently deployed. The technical work was done. The evidence trail supporting it was not, and the assessor can only certify what can be demonstrated.
What a Realistic Pre-Assessment Posture Looks Like
Given the binary nature of the certification decision, the right preparation posture is not "get as many practices as close to compliant as possible." It is "identify every practice where a finding is even plausible, and resolve or defensibly document each one before the formal assessment begins."
Start by reviewing your open POA&M items and classifying them by criticality. For each open item, determine whether it falls into a control family or specific practice known to carry limited or no tolerance for deferral under current guidance, and prioritize closing those first — not the ones that are simplest to fix, but the ones that carry the highest risk of blocking certification outright. This requires staying current on CMMC rulemaking guidance, since deferability rules have continued to evolve and a POA&M strategy built on outdated assumptions is a genuine liability.
Next, conduct an honest internal review of practices your team considers "done." The practices most likely to produce a surprise finding are rarely the ones nobody has looked at. They are the ones everyone assumes are fine because the technical control was implemented months ago and hasn't been revisited since. Assign someone to actually pull the evidence — the log sample, the configuration screenshot, the interview responses — for each of these practices as if an assessor were asking for it tomorrow.
Finally, resist the instinct to treat a strong SPRS score as reassurance. Use it as one data point among several, alongside a practice-by-practice evidence review, rather than as a proxy for assessment readiness.
The Cost of Getting This Wrong
The practical consequence of an unresolved finding is significant. Without CMMC Level 2 certification, you cannot perform or compete for contracts that require it under DFARS 252.204-7012. A single blocked certification can mean the loss of existing revenue and the inability to bid on future opportunities, regardless of how much of your program is otherwise sound. This is precisely why the binary nature of the certification decision deserves more attention in pre-assessment planning than it typically receives — the risk is not distributed evenly across 110 practices. It is concentrated in a small number of findings that, left unresolved, can undo the value of everything else you've built.
A Practical Way to Stress-Test Your Readiness
Before your formal assessment is scheduled, it's worth running a deliberate internal exercise that mimics what your C3PAO assessor will actually do, rather than relying on a general sense that "things look good." Pick a handful of practices at random from each of the 14 domains — not just the ones your team feels confident about — and put them through the same examine, interview, and test sequence an assessor would use. Pull the actual document. Ask the actual responsible person to explain the control verbally, without notes. Then observe the control operating in the live environment.
This exercise routinely surfaces the kind of gap that a purely paper-based readiness review misses: a policy that is accurate but was never actually communicated to the person expected to follow it, or a technical control that works as designed but has no one who can explain the exception-handling process on the spot. These are exactly the situations that produce a "not met" finding despite reasonable underlying security, and they are far cheaper to fix in an internal walkthrough than to discover mid-assessment.
It is also worth having a candid conversation with leadership about risk tolerance before the assessment date is locked in. If your internal review turns up two or three practices in a zero-tolerance family that are not yet resolvable, it is almost always better to delay the formal assessment than to proceed and risk an outcome where the certification decision hinges on a small number of findings that could have been closed with a few more weeks of preparation. Certification is not a race against a calendar. It is a determination that either happens correctly or doesn't happen at all, and treating it that way from the outset changes how you sequence your final preparation work.
Know Which Findings Are Deferable Before You're Assessed
Understanding which findings can be documented in a POA&M and which require resolution before certification is one of the most important pieces of preparation you can do. If you want a control-family-by-control-family reference that maps each of the 110 practices to the evidence artifacts assessors commonly request — so you can identify your highest-risk gaps before the formal assessment, not during it — download the CMMC Level 2 Assessment Evidence Guide.
