How can my organization prepare for a CMMC 2.0 assessment?
Preparation starts with identifying where Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) exist in your environment and defining the correct scope. From there, organizations should perform a gap assessment against NIST 800-171, remediate missing controls, document policies and procedures, and conduct a pre-audit assessment to validate readiness before engaging a C3PAO.