7 Most Common CMMC Level 2
Assessment Findings
Table of Contents
ToggleRanked Residual Findings from Lazarus Alliance C3PAO Assessments
Based on N = 47 completed formal Level 2 assessments • January 2025 – June 2026 • Updated August 2026
On 13 July 2026 the Department of War suspended CMMC Phase II requirements pending a 60-day reform review. Phase I self-assessment requirements and DFARS 252.204-7012 remain in effect. Voluntary C3PAO assessments and prime-driven requirements continue. Primary sources: DoW Release · Memo 26-P-1023 · DoD CIO CMMC.
These rankings reflect the practices that most frequently generated residual findings (partial implementation or not met) across N = 47 formal CMMC Level 2 assessments conducted by Lazarus Alliance as an authorized C3PAO (CPN 10251). Rankings are based on frequency of residual findings after initial evidence review.
Relative Frequency of Top Residual Findings (N = 47)
IA.L2-3.5.3 — Multifactor Authentication
Primary issue observed: Multifactor authentication incomplete for privileged accounts and/or remote access paths. Application-layer MFA was frequently omitted even when network-level MFA existed.
Why it fails: Organizations often interpret “privileged” too narrowly or assume VPN MFA satisfies every remote path that can reach CUI. Assessors look for coverage across all access vectors that touch the assessment boundary.
Remediation focus: Inventory every privileged and remote access path; enforce MFA consistently; retain configuration evidence and access logs that demonstrate enforcement.
AU.L2-3.3.1 / 3.3.2 — Audit Events & Content of Audit Records
Primary issue observed: Incomplete or non-centralized audit logging; insufficient retention; weak or undocumented review processes.
Why it fails: Many environments log some events but miss required event types, fail to protect log integrity, or cannot demonstrate that logs are actually reviewed on a defined cadence.
Remediation focus: Map required audit events to actual log sources; centralize where practical; define and evidence review procedures; protect and retain logs for the required period.
CM.L2-3.4.1 / 3.4.2 — Baseline Configurations & Configuration Change Control
Primary issue observed: Missing or outdated baselines; configuration change control gaps; generic hardening checklists presented as maintained baselines.
Why it fails: A one-time STIGs or CIS checklist is not the same as a current, version-controlled baseline for the actual in-scope systems, with a controlled process for deviations and changes.
Remediation focus: Establish authoritative baselines per system type; version-control them; document the change process; retain evidence of reviews and approved deviations.
AC.L2-3.1.1 / 3.1.2 — Account Management & Access Enforcement
Primary issue observed: Account management and least-privilege enforcement not fully implemented or not sufficiently evidenced.
Why it fails: Policies exist, but operational evidence (joiner/mover/leaver tickets, periodic access reviews, privileged account inventories) is incomplete or inconsistent.
Remediation focus: Demonstrate the full account lifecycle; show periodic reviews; prove least privilege with concrete role/permission evidence.
SI.L2-3.14.1 / 3.14.2 — Flaw Remediation & Malicious Code Protection
Primary issue observed: Vulnerability scanning cadence or coverage incomplete; flaw remediation timelines not consistently met or evidenced.
Why it fails: Scanning may exist but miss portions of the boundary, lack authenticated scans, or fail to show timely remediation and risk acceptance decisions.
Remediation focus: Ensure full boundary coverage; define and meet remediation SLAs; retain scan results, tickets, and risk acceptance records.
SC.L2-3.13.1 / 3.13.5 — Boundary Protection & External System Connections
Primary issue observed: Boundary protection and control of external system connections insufficiently implemented or documented.
Why it fails: Data-flow diagrams are incomplete, external connections that can reach CUI are under-inventoried, or monitoring/control of those connections is weak.
Remediation focus: Maintain accurate data-flow diagrams; inventory and control every external connection into the boundary; evidence monitoring and restrictions.
MP.L2-3.8.1 / 3.8.3 — Media Protection & Sanitization
Primary issue observed: Media sanitization and CUI media handling procedures lacking sufficient operational evidence.
Why it fails: Policies describe sanitization, but records of actual media destruction, sanitization certificates, or controlled handling of CUI media are missing or incomplete.
Remediation focus: Implement and evidence media handling procedures; retain sanitization/destruction records; control portable media that can store CUI.
Summary Ranking Table
| Rank | Practice | Domain | Core Issue |
|---|---|---|---|
| 1 | IA.L2-3.5.3 | Identification & Authentication | Incomplete MFA coverage |
| 2 | AU.L2-3.3.1 / 3.3.2 | Audit & Accountability | Logging completeness & review |
| 3 | CM.L2-3.4.1 / 3.4.2 | Configuration Management | Baselines & change control |
| 4 | AC.L2-3.1.1 / 3.1.2 | Access Control | Account management / least privilege |
| 5 | SI.L2-3.14.1 / 3.14.2 | System & Information Integrity | Flaw remediation cadence |
| 6 | SC.L2-3.13.1 / 3.13.5 | System & Communications Protection | Boundary & external connections |
| 7 | MP.L2-3.8.1 / 3.8.3 | Media Protection | Sanitization & media handling |
Cross-Cutting Evidence Problems
Across these findings, the same evidence weaknesses appeared repeatedly:
- Screenshots without system identifiers, dates, or configuration context
- Policies that describe intent but lack operational proof
- Incomplete or non-centralized logs
- Missing or generic configuration baselines
- Unsupported inheritance claims without customer responsibility matrices or SSP excerpts
Organizations that pre-mapped every practice to specific, timestamped artifacts and ran internal mock assessments required far fewer clarification rounds (overall, 89% of assessments still needed at least one additional evidence request).
Related Benchmark Data
These findings are drawn from the same dataset used in the 2026 CMMC Assessment Benchmark Report (N = 47). Additional metrics:
- Median formal assessment duration: 17 business days
- Assessments with ≥1 POA&M: 74% (35 of 47)
- Required additional evidence: 89% (42 of 47)
- Enclave vs enterprise: 66% / 34%
Aggregate CSV: 2026_CMMC_Benchmark_Aggregate_Data.csv
Authors & How to Cite
Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
Authorized CMMC C3PAO leadership; A2LA-accredited FedRAMP 3PAO; PCI DSS QSA firm principal.
How to Cite
Peters, M. D. (2026). 7 Most Common CMMC Level 2 Assessment Findings. Lazarus Alliance, Inc. Data drawn from the 2026 CMMC Assessment Benchmark Report (N = 47).
About Lazarus Alliance
Lazarus Alliance is an authorized CMMC Third-Party Assessment Organization (C3PAO, CPN 10251), an A2LA-accredited FedRAMP 3PAO, a PCI DSS Qualified Security Assessor (QSA), and a veteran-owned small business headquartered in Scottsdale, Arizona.
Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580 • [email protected]
https://lazarusalliance.com
© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Findings are observational aggregates from anonymized assessments and do not predict individual outcomes.
Scottsdale, Arizona • 1-888-896-7580 • lazarusalliance.com
Data Source
This analysis is based on the 2026 CMMC Assessment Benchmark Report, Lazarus Alliance's aggregate analysis of 47 completed formal CMMC Level 2 C3PAO assessments conducted between January 2025 and June 2026.
Additional Analysis
- How Long Does a CMMC Level 2 Assessment Take?
- How Much Evidence Does a CMMC Assessment Require?
- How Common Are CMMC POA&Ms?
- CMMC Enclave vs Enterprise: What 47 Assessments Show
Talk with one of our experts
Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.
We're here to answer any questions you may have.
