CMMC Implementation: 4 Critical Steps to Getting Started

Just getting started with CMMC preparation?

Before you can implement a single security control, you need a clear understanding of your environment. Most organizations underestimate how much foundational work is required before implementation can even begin, and skipping ahead usually means redoing work later when gaps surface.

In this article, we'll walk you through the essential first steps every organization should take to build a strong foundation for CMMC compliance.

01

Define the Network and Boundary

You can't implement CMMC until you know which areas of your organization are actually subject to its requirements. A network diagram of your architecture, paired with a data flow diagram for CUI, keeps you from pouring resources into the wrong places — or missing the right ones.

Building a Network Diagram

Your network diagram should include, at a minimum:

  • User workstations
  • Servers
  • Virtual machines
  • Networking equipment (switches, routers, wireless access points, and firewalls)
  • Connections to Software as a Service (SaaS) or other external services

When building the network diagram, focus more on the architecture rather than the details. You don't need IP addresses, the port position of cables on switches (Ge 1/0/1), or the exact number of devices represented on the network diagram.

Additionally, you'll need to determine the types of remote and external connections that have access into the boundary. Remote connections include internal users located physically outside the boundary of the system, and external connections include external users or organizations who have access into the boundary of the system. VPNs are commonly found on both remote and external connections.

Building a Data Flow Diagram

When it comes to building your data flow diagram, it should clearly show how Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) move through your environment.

Here's a three-step process to constructing the diagram:

  • Add the elements — represent users who handle CUI/FCI, endpoints, servers, applications, databases, cloud services, and external partners in your drawing program of choice
  • Draw the boundaries — box these devices to represent physical sites, internal zones, enclaves, external networks, and so on
  • Connect the flow — link these boxes with lines to show how and where data is moving
02

Establish an Asset Inventory

It's critical to lay the groundwork before you start implementing controls. Your asset inventory should document every system and network-connected device within scope and categorize each by type.

At a minimum, your asset inventory should contain:

  • System Name
  • Asset Type
  • Description
  • Operating System or Firmware Version
  • Location
  • Model Number
  • Serial Number

You'll also need to conduct a CMMC Asset Categorization. To do so, identify which of the following categories each of your devices fall into:

  • CUI Assets — assets that process, store, or transmit CUI
  • Security Protection Assets (SPA) — assets that provide security functions or capabilities to the OSA's CMMC Assessment Scope
  • Contractor Risk Managed Assets (CRMA) — assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place; these assets are not required to be physically or logically separated from CUI assets
  • Specialized Assets (SA) — assets that can process, store, or transmit CUI but are unable to be fully secured, including IoT, IIoT, Operational Technology (OT), Government Furnished Equipment (GFE), Restricted Information Systems, and Test Equipment
These Are Just 2 of 22 Steps

A 110/110 SPRS score takes 22 steps across all 14 NIST SP 800-171 domains. Speak with a consultant about our CMMC Accelerator Methodology to see where you stand.

Talk to a CMMC Consultant
03

Establish Multi-Factor Authentication (MFA)

MFA is one of the highest-value controls because it significantly reduces risk across users, administrators, remote access, and cloud systems.

Follow these tips for successful MFA implementation:

  • Prioritize privileged accounts first if implementation must be phased
  • Simplify enforcement through centralized identity platforms such as Active Directory, Entra ID, and SSO
  • Cover workstations, servers, SaaS, VPN/remote access, mobile devices, and administrative tools

Most organizations have MFA somewhere, but not everywhere it needs to be. Make sure to avoid these common gaps:

  • Local administrator accounts are forgotten
  • Break-glass accounts are not monitored or secured
  • Service accounts are not reviewed or properly restricted
  • Remote maintenance connections are not protected with MFA
  • SaaS applications exist outside of SSO
  • VPN access has MFA, but admin portals do not
  • Mobile device access is not fully controlled
  • Legacy systems cannot support MFA and need compensating controls
04

Establish Baseline Security Configurations

Baseline security configurations create a consistent standard for securing systems.

To ensure consistent enforcement, we recommend applying settings through centralized tools such as GPO, Intune, MDM, or configuration management platforms. Also be sure to use established standards like CIS Benchmarks or DISA STIGs instead of deciding individually which settings "seem important." These standards provide a tested, repeatable security baseline and reduce the risk of overlooking critical configurations.

When establishing baseline security configurations, avoid these common gaps:

  • Not applying baselines across all Windows, Linux, macOS, servers, and workstations
  • Overlooking critical security or auditing settings when configurations are based on personal preference
Where the Other 18 Steps Come In

These four steps lay the foundation, but a 110/110 SPRS score requires closing out the remaining 18 steps across all 14 NIST SP 800-171 domains, and most organizations get stuck figuring out what comes next.

Our 22-Step CMMC Accelerator Methodology gives you a clear, sequenced path from where you are now to a full 110/110 score. Speak with a consultant to see exactly where your organization stands and what the remaining steps look like for you.

Talk to a CMMC Consultant

The Bottom Line

Scoping, asset inventory, MFA, and baseline configurations build on each other in sequence. You can't secure what you haven't inventoried, and you can't inventory what falls outside a boundary you haven't defined. Skipping straight to controls without this groundwork is one of the most common reasons organizations stall out mid-assessment or discover expensive surprises late in the process.

Want to go deeper on any of these topics? Watch the full webinar recording or join our biweekly Office Hours, where you can bring your specific questions directly to a certified CMMC assessor.