Twelve governance actions that carry contractual or legal consequence today — independent of whether a certification assessment is scheduled. Rate where you honestly stand. Nothing is sent unless you choose to email it.
A01 Freeze the phase calendar — not the security programRemove November 2026/2027/2028 certification assumptions from operating plans until revised guidance is issued, while continuing funded remediation and evidence development.
Not started In progress Done, not documented Done & evidenced
A02 Reconfirm clause and data scopeMap FCI, CUI, CDI and export-controlled information to contracts, systems, users, suppliers and services. Distinguish clause applicability from generalized data sensitivity.
Not started In progress Done, not documented Done & evidenced
A03 Validate every SPRS scoreReconcile the posted score to the current SSP, scoring methodology, objective-level evidence, POA&Ms and system boundary. Correct unsupported claims through the appropriate process.
Not started In progress Done, not documented Done & evidenced
A04 Maintain a CMMC-ready evidence packageKeep the asset inventory, network diagram, SSP, policies, procedures, technical artifacts, interview owners and evidence current even while third-party designations are suspended.
Not started In progress Done, not documented Done & evidenced
A05 Reassess cloud and external service provider dependenciesValidate the exact offering's authorization or equivalency, incident terms, forensic access, shared-responsibility matrix, assessment treatment, source allowability and export-personnel model.
Not started In progress Done, not documented Done & evidenced
A06 Build an AI and ICT dependency registerMaintain an AIBOM/SBOM covering models, APIs, hosting platforms, agents, libraries, data sources, routing services, embedded integrations, subprocessors and downstream consumers.
Not started In progress Done, not documented Done & evidenced
A07 Create a source-allowability gateRequire contract, program, supply-chain and legal review before a new AI or ICT source enters a defense workflow. Do not treat FedRAMP or CMMC eligibility as approval for every contract.
Not started In progress Done, not documented Done & evidenced
A08 Control vendor-removal migrationsConfirm scope with the contracting officer; preserve incident and audit evidence; export only authorized records; revoke keys; validate retention and deletion; reassess the replacement; document cost and schedule effects.
Not started In progress Done, not documented Done & evidenced
A09 Design for portabilityUse modular integrations, controlled prompt and configuration repositories, portable test suites and multi-vendor contingency plans so a source restriction does not become an operational outage.
Not started In progress Done, not documented Done & evidenced
A10 Establish an affirmation governance gateRequire scope confirmation, control-owner attestation, evidence review, legal/compliance review and documented exceptions before an affirming official submits an annual statement.
Not started In progress Done, not documented Done & evidenced
A11 Build the Rev. 3 delta backlogMaintain Rev. 2 compliance as the contractual baseline while mapping Revision 3 families, organization-defined parameters and supply-chain requirements for planned uplift.
Not started In progress Done, not documented Done & evidenced
A12 Monitor the live policy eventsTrack post-review CMMC guidance, the final disposition of the FAR CUI proposal, and any source-restriction direction. Update contract playbooks only when official text or direction changes.
Not started In progress Done, not documented Done & evidenced