Compliance Gap Analyzer
Maps your current controls to framework requirements. Shows exactly what is missing.
Reads your policies, SSP, and evidence directory, then maps each control against the target framework's requirements. Produces a gap register with severity, remediation effort estimate, and sequenced roadmap.
Try a sample prompt:
Gap Register · CMMC L2 · 2026-05-09
Total gaps: 14 (3 Critical · 5 High · 4 Medium · 2 Low)
Conformant practices: 96 / 110 · Projected SPRS: 78 / 110
Certification readiness: NOT READY — 3 critical practices are POA&M-ineligible
AC.L2-3.1.5 · Least Privilege · CRITICAL · POA&M-eligible: NO
Requirement (NIST 800-171 Rev 2 §3.1.5): Employ the principle of least privilege, including for specific security functions and privileged accounts.
Current state: Domain Admin group has 11 members. No just-in-time access. No quarterly access review documented since Q2 2024.
Gap: Three of five AOs not met: [b] privileged accounts not separated from standard accounts for 8 of 11 admins; [d] no documented review process; [e] no enforcement of need-to-know.
Remediation effort: 4–6 weeks
Sequence: Fix BEFORE any AC.L2-3.1.6/7/12 (depends on this baseline)
Evidence needed: PAM tool config showing JIT activation, quarterly review attestation, separation-of-duties matrix.
IA.L2-3.5.3 · MFA Enforcement · CRITICAL · POA&M-eligible: NO
Requirement: Use multifactor authentication for local and network access to privileged accounts and network access to non-privileged accounts.
Current state: MFA enforced for VPN and M365 admin only. Five internal applications (HR, finance, ticketing, monitoring, backup console) have password-only access.
Gap: AOs [b] and [c] not met for non-privileged network access.
Remediation effort: 8–12 weeks (depends on app modernization)
Sequence: Fix in parallel with AC.L2-3.1.5
Evidence needed: SSO config showing MFA enforcement on all five apps, exception register if any cannot be MFA-enabled.
MP.L2-3.8.3 · Sanitize Media · CRITICAL · POA&M-eligible: NO
Requirement: Sanitize or destroy system media containing CUI before disposal or release for reuse.
Current state: No documented sanitization policy. IT team verbally states they wipe drives but no records exist.
Gap: AOs [a], [b], [c] all NOT MET — policy missing, procedure missing, records missing.
Remediation effort: 2 weeks
Sequence: Fix immediately — paper-only fix (write policy, retroactive attestation, start log)
Evidence needed: Approved sanitization policy, NIST SP 800-88 method assignments per media type, disposal log.
High-Severity Gaps (POA&M-eligible if needed)
| Practice | Gap | Effort | SPRS Impact |
| AU.L2-3.3.5 | No correlated log review | 4 wk | −3 |
| CM.L2-3.4.6 | No baseline config | 6 wk | −5 |
| IR.L2-3.6.3 | No IR test in 12 mo | 1 wk | −3 |
| SI.L2-3.14.2 | No malware protection on 4 servers | 2 wk | −3 |
| SC.L2-3.13.11 | FIPS crypto not validated | 4 wk | −5 |
Sequenced Remediation Roadmap
What you can defend at audit today
96 practices fully conformant with assessment-ready evidence. SPRS at 78 is sufficient for DOD contract eligibility under SPRS-only path. Certification requires closing the 3 POA&M-ineligible practices first.