Many government contractors looking to achieve CMMC compliance would love a list of controls to prioritize. They'll ask which CMMC controls to fix first, or which five to knock out to get moving. And I understand the impulse. When you're looking at 110 controls in NIST 800-171 and a compliance obligation you can't put off, a ranked list feels like a good starting point.
But the truth is, there’s no clean and easy answer.
The reason for that is CMMC doesn't work in isolation. I can’t identify a universal priority list, because that prioritization is going to depend on many factors unique to you and your organization. What I can advocate for is how you should approach your own CMMC compliance journey, based on your specific circumstances. Let’s take a closer look at how you should manage compliance when you’re getting started.
I start with the foundations. That means:
Everything else you do depends on these. When they're weak, the problem rarely stays contained to one control. Weaknesses feed into each other. That’s much harder to untangle than a single gap.
The control you address first depends on your own circumstances. When I'm deciding what rises to the top with an individual control, I’m asking myself the following questions:
The question about dependencies above is worth coming back to: if this control isn't working, what else falls apart? Will filling this gap solve one problem, or multiple problems?
Addressing some gaps can help you fulfill multiple requirements, so closing them strengthens your whole security posture instead of just a single line item. That's what I go after first. There might be cheaper or easier items to check off your list, but the ones with the most interdependencies helps make your overall task of meeting all controls much simpler.
Of course, that’s not to say that you shouldn’t look to take care of inexpensive or easy problems to solve when you can.
There's progress you can make without a big technology spend. A few examples of actions you can take that are (relatively) inexpensive to achieve include:
Depending on where you’re at right now, a lot of those fixes can move fairly quickly. But I'm careful, and somewhat hesitant, to describe any of these as examples of a “quick win.” A control being quick to configure isn't the same the control being quick to run day to day. You can stand something up in an afternoon and still be a long way from having it work the way it needs to consistently. It might sound cliché to frame it this way, but remember that CMMC compliance truly is a marathon versus a sprint.
Another factor in how you choose to tackle CMMC controls? The size of your team. But you may not need as many people or resources as you think.
Having a small team with limited resources can present its own challenges, but don't confuse having a small team with an incapable one. I've watched small teams make a real dent in their security posture, and fast, once they decide to come together, get their arms around their environment, assign ownership, and commit to the work.
Here’s what small teams need to put a real dent in their security posture:
That commitment usually goes further than simple headcount. The important thing isn’t having a big team – it’s having the right team, with the right people in the right places ready to execute.
With a dedicated IT partner in place, you can have access to the expertise and the guidance you need to succeed. They can help you find prioritize your most critical gaps and close them without having to guess your way through it.
Of course, your mileage may vary depending on the kind of IT partner you work with.
When you choose an IT partner, you’ll obviously want an expert in CMMC compliance. But beyond that, you’ll want to look for someone who’s curious about your organization. You’ll want an IT partner who’s going to guide you as you build a long term, sustainable CMMC remediation roadmap.
I’ll give you an example from my perspective assisting government contractors. When we start working with a team, we want to understand before we prescribe anything. We’ll ask the following questions:
Once we’ve established your story, we can do the following:
The simple answer to the question of a universal CMMC priority list is that there isn’t one. It would be much easier to have a standard list you could hand any government contractor.
But every contractor is different. To truly know what to prioritize, you need to identify your environment, your CUI footprint, your risk profile, and where you're starting from.
The controls that matter most are the ones you need to get right based on what you're protecting and where your greatest risks are. That list exists, but it’s going to change from team to team. And you find it by understanding your organization first.
Not sure what controls to start with? Talk to us to learn more about how Ntiva supports government contractors with creating a comprehensive plan for CMMC compliance.