What CMMC Controls Should You Address First?
-2.png?width=360&height=180&name=Hero%20-%20Inside%20the%20Audit%20-%20CMMC%20self%20assessment%201%20(1)-2.png)
Many government contractors looking to achieve CMMC compliance would love a list of controls to prioritize. They'll ask which CMMC controls to fix first, or which five to knock out to get moving. And I understand the impulse. When you're looking at 110 controls in NIST 800-171 and a compliance obligation you can't put off, a ranked list feels like a good starting point.
But the truth is, there’s no clean and easy answer.
The reason for that is CMMC doesn't work in isolation. I can’t identify a universal priority list, because that prioritization is going to depend on many factors unique to you and your organization. What I can advocate for is how you should approach your own CMMC compliance journey, based on your specific circumstances. Let’s take a closer look at how you should manage compliance when you’re getting started.
Key Takeaways
- When it comes to CMMC controls, there's no universal priority list. The controls that matter most depend on your environment, your controlled unclassified information (CUI) footprint, and where your real risks are.
- Foundational protections come first: CUI, access, identity, devices, data protection, and visibility. When those are weak, weaknesses in one area create problems in others.
- Prioritize by risk, dependency, and readiness impact. Ask what else breaks if a given control isn't working.
- Some improvements move quickly, like cleaning up stale accounts or tightening existing configurations. But quick to configure isn't the same as quick to run day to day.
- A small team isn't a barrier. Ownership, a clear understanding of your environment, and commitment go a long way, and the right partner helps close what's left.
- Good compliance work starts with understanding your business first, then building the roadmap from there.
Which CMMC Controls Should You Prioritize First?
I start with the foundations. That means:
- Controlled unclassified information (CUI) itself
- Access
- Identity
- Devices
- Data protection
- Visibility into what's happening across your environment.
Everything else you do depends on these. When they're weak, the problem rarely stays contained to one control. Weaknesses feed into each other. That’s much harder to untangle than a single gap.
How Do You Decide Which CMMC Controls Matter Most?
The control you address first depends on your own circumstances. When I'm deciding what rises to the top with an individual control, I’m asking myself the following questions:
- How much risk will there be if there’s a gap here?
- What else depends on this control?
- Will closing this loop improve our readiness?
The question about dependencies above is worth coming back to: if this control isn't working, what else falls apart? Will filling this gap solve one problem, or multiple problems?
Addressing some gaps can help you fulfill multiple requirements, so closing them strengthens your whole security posture instead of just a single line item. That's what I go after first. There might be cheaper or easier items to check off your list, but the ones with the most interdependencies helps make your overall task of meeting all controls much simpler.
Of course, that’s not to say that you shouldn’t look to take care of inexpensive or easy problems to solve when you can.
Which CMMC Controls Can You Address Quickly?
There's progress you can make without a big technology spend. A few examples of actions you can take that are (relatively) inexpensive to achieve include:
- Clean up stale accounts by reviewing who holds privileged access, and putting a formal account review process in place.
- Sharpen your security awareness practices by writing down what people are expected to report and when
- Build the inventories you're required to keep
- Tighten the configurations you already have.
Depending on where you’re at right now, a lot of those fixes can move fairly quickly. But I'm careful, and somewhat hesitant, to describe any of these as examples of a “quick win.” A control being quick to configure isn't the same the control being quick to run day to day. You can stand something up in an afternoon and still be a long way from having it work the way it needs to consistently. It might sound cliché to frame it this way, but remember that CMMC compliance truly is a marathon versus a sprint.
Another factor in how you choose to tackle CMMC controls? The size of your team. But you may not need as many people or resources as you think.
Can a Small Team Meet CMMC Requirements?
Having a small team with limited resources can present its own challenges, but don't confuse having a small team with an incapable one. I've watched small teams make a real dent in their security posture, and fast, once they decide to come together, get their arms around their environment, assign ownership, and commit to the work.
Here’s what small teams need to put a real dent in their security posture:
- Establish a clear understanding of their risk profile and environment with an honest self-assessment
- Assign clear ownership
- Identify a remediation roadmap, with clear milestones, goals, and deliverables
- Commit to the work
- Identify an IT partner with the expertise needed to make the promise of CMMC compliance a reality
That commitment usually goes further than simple headcount. The important thing isn’t having a big team – it’s having the right team, with the right people in the right places ready to execute.
With a dedicated IT partner in place, you can have access to the expertise and the guidance you need to succeed. They can help you find prioritize your most critical gaps and close them without having to guess your way through it.
Of course, your mileage may vary depending on the kind of IT partner you work with.
How Do You Build a CMMC Remediation Roadmap?
When you choose an IT partner, you’ll obviously want an expert in CMMC compliance. But beyond that, you’ll want to look for someone who’s curious about your organization. You’ll want an IT partner who’s going to guide you as you build a long term, sustainable CMMC remediation roadmap.
I’ll give you an example from my perspective assisting government contractors. When we start working with a team, we want to understand before we prescribe anything. We’ll ask the following questions:
- Tell us about your business and why you do what you do. (My mom used to say, “I never met a stranger, just a friend who doesn't know me yet,” and I find it helpful to bring that same philosophy into every client engagement)
- What’s your environment?
- What matters to your business?
Once we’ve established your story, we can do the following:
- Scope the environment properly
- Map your CUI boundary
- Assess where the gaps are
- Build the roadmap for the technical remediation that gets you ready
Is There a Universal CMMC Priority List?
The simple answer to the question of a universal CMMC priority list is that there isn’t one. It would be much easier to have a standard list you could hand any government contractor.
But every contractor is different. To truly know what to prioritize, you need to identify your environment, your CUI footprint, your risk profile, and where you're starting from.
The controls that matter most are the ones you need to get right based on what you're protecting and where your greatest risks are. That list exists, but it’s going to change from team to team. And you find it by understanding your organization first.
Not sure what controls to start with? Talk to us to learn more about how Ntiva supports government contractors with creating a comprehensive plan for CMMC compliance.
Back to blog
About the author
Shon Lyublanovits is a nationally recognized cybersecurity executive with over 28 years of experience who serves as a Virtual Chief Information Security Officer (vCISO) in Ntiva's GovCon practice, advising defense contractors and federal suppliers on CMMC, NIST SP 800-171, and FedRAMP. She previously led Cyber Supply Chain Risk Management at CISA and helped shape FedRAMP during her time at GSA, and she's a Fed100 Award winner recognized by IEEE as a "Rockstar of Cybersecurity."
-2.png?width=420&height=210&name=Hero%20-%20Inside%20the%20Audit%20-%20CMMC%20self%20assessment%201%20(1)-2.png)

-1.png?width=420&height=210&name=Hero%20-%20Inside%20the%20Audit%20-%20CMMC%20self%20assessment%201%20(1)-1.png)

.png?width=420&height=210&name=Hero%20-%20Inside%20the%20Audit%20-%20CMMC%20self%20assessment%201%20(1).png)