TL;DR: CMMC audit readiness depends less on policy declarations than on proving where controlled unclassified information enters, moves, and is logged across SaaS, web apps, BYOD, and contractor paths, according to Island. The decisive gap is last-mile visibility: assessors will focus on whether live evidence, scope boundaries, and access controls match the work environment, not the plan on paper.
At a glance
What this is: This is a practical guide to preparing for a CMMC audit, with emphasis on scoping CUI, assembling assessor-ready evidence, and closing blind spots in web and SaaS workflows.
Why it matters: It matters because IAM, PAM, and governance teams often know the control set but cannot easily prove where users, contractors, and devices touch CUI across the full access path.
👉 Read Island's guide to preparing for a CMMC audit
Context
CMMC audit preparation fails most often at the boundary between policy and operational proof. Teams may know which controls should exist, but assessors care whether controlled unclassified information is actually scoped correctly, whether access is traceable, and whether the live environment matches the system security plan. In practice, the hardest part is not writing controls, but proving where CUI enters, moves, and is handled across SaaS, web apps, contractor access, and BYOD paths.
That makes this a governance and identity problem as much as a compliance problem. Audit evidence depends on access review, authentication, privilege change, and session-level visibility, especially when work happens in a browser or other managed workspace. For teams already dealing with identity sprawl and third-party access, the CMMC problem is typical: the control story breaks when the actual data path extends beyond the systems auditors can easily see.
Key questions
Q: What breaks when CUI scope is defined only around managed endpoints?
A: CMMC scope breaks when teams assume managed endpoints equal controlled data handling. CUI often moves through SaaS, browser sessions, partner access, and BYOD paths that the endpoint view does not fully capture. If those paths are omitted, assessors will find gaps between the written boundary and the real one.
Q: Why do assessor-ready CMMC controls depend on browser-level visibility?
A: Because much CUI exposure happens after authentication inside web apps, where network logs do not show copy, paste, download, or transfer actions. Browser-level visibility gives auditors evidence closer to the actual user action, which is what they need to verify that approved handling rules were enforced.
Q: What do teams get wrong about CMMC evidence collection?
A: They treat evidence as a pre-audit deliverable instead of an operating process. That leads to screenshots, spreadsheets, and missing timestamps that are hard to validate under assessment pressure. Strong programmes capture evidence continuously, tie it to control ownership, and keep it traceable back to the environment that produced it.
Q: How should organisations handle subcontractor access in CMMC scope?
A: Treat subcontractor access as part of the audit boundary whenever those partners can reach FCI or CUI. Device ownership does not remove the need for access control, logging, and data-handling rules. The safest approach is to scope by exposure and workflow, then verify controls across every party in that path.
Technical breakdown
How CMMC scoping works for FCI and CUI
CMMC scoping starts by identifying where Federal Contract Information and controlled unclassified information enter, rest, and are transmitted. The audit scope is not just the obvious production system. It also includes the paths people use to access, copy, export, or store data, which may extend into SaaS applications, browser sessions, subcontractor workflows, and unmanaged endpoints. If a system cannot be shown to handle in-scope data, it may be excluded, but only with a defensible rationale and supporting ownership, logging, and access rules. That makes scoping a data-flow exercise, not a checkbox exercise.
Practical implication: map the data path before you map controls, or your CMMC scope will be either too broad to defend or too narrow to survive assessment.
Why assessor-ready evidence has to match the live environment
CMMC evidence is strongest when it reflects the current operating environment rather than a stale architecture diagram. Assessors look for a system security plan that matches reality, plans of action and milestones that name owners and due dates, and operational artifacts such as access reviews, logs, and privilege changes. The key issue is traceability. If the policy says one thing and the live system behaves another way, the assessment becomes a reconciliation exercise. For browser-mediated work, session-level logging and policy events often provide the most credible evidence because they sit closer to the user action than network controls do.
Practical implication: build an evidence habit tied to live controls, session logs, and review records so the audit does not depend on last-minute document cleanup.
Why last-mile browser activity is now part of the compliance surface
A large share of CUI handling now occurs after authentication inside SaaS and web applications, where traditional network controls see very little. Users can copy, paste, download, print, or move data into unmanaged destinations without ever leaving the browser. That creates a last-mile governance problem: the organization may own the identity and the app, but not the actual data handling decision at the point of use. Modern audit prep therefore has to treat the browser as part of the control plane when web work is the primary way people interact with CUI.
Practical implication: treat browser-mediated actions as audit evidence and control points, especially for copy, paste, download, print, and data transfer paths.
NHI Mgmt Group analysis
Browser-mediated CUI handling is now a governance boundary, not a user convenience issue. When sensitive work moves into SaaS and web apps, the organization loses visibility exactly where many of the most audit-relevant actions occur. That changes the compliance question from whether users are authenticated to whether the environment can prove control over copy, export, and transfer. For identity teams, this is where access governance meets data handling governance. The practitioner conclusion is clear: last-mile control has become a core part of CMMC readiness.
Audit readiness depends on evidence lineage, not evidence volume. A stack of screenshots and static documents does not compensate for weak operational traceability. Assessors want to see that the SSP, POA&M, access reviews, and logs all describe the same live environment. That aligns closely with NIST SP 800-53 Rev 5 Security and Privacy Controls, especially control families around access, auditability, and configuration. The practitioner conclusion is to make evidence traceable from control to session to owner.
Third-party and subcontractor access is a scope problem disguised as an access problem. CMMC repeatedly exposes the weak assumption that only corporate endpoints matter. Once a subcontractor, BYOD user, or partner can reach CUI, the control boundary expands whether or not the device is managed. That makes lifecycle clarity and access governance central to compliance. The practitioner conclusion is to define scope around data exposure and privileged reach, not around device ownership alone.
Last-mile blind spot: the specific failure mode is invisible browser actions. The article surfaces a concrete concept that matters across identity and compliance programmes. If teams cannot observe copy, paste, download, and transfer behaviour inside web sessions, they cannot reliably prove that CUI stayed within approved boundaries. The practitioner conclusion is to treat browser telemetry as part of the evidence chain, not an optional enhancement.
CMMC is forcing identity programmes to connect access control with data handling proof. This is not just about authentication or least privilege. It is about showing that identities, roles, and session paths actually constrain what a user can do with sensitive data. The practitioner conclusion is that identity governance, PAM, and audit evidence now need to be built as one operational story.
What this signals
Browser-level governance is becoming a compliance control, not just a productivity choice. As more regulated work moves into web applications, the practical question is whether your programme can prove what happened inside a session. That shifts attention toward visible data handling, identity-aware policy enforcement, and audit evidence that follows the work rather than the network.
CUI scope management is an identity problem once third parties and BYOD are in play. If users, contractors, and partners can reach sensitive data, the programme must track who can do what, where, and under which logged conditions. The result is that identity governance, session governance, and data protection can no longer be run as separate workstreams.
Evidence lineage will matter more in the next assessment cycle. Teams that can tie access, policy, and user action together will spend less time defending assumptions. Those that cannot will keep relying on manual reconciliation, which is expensive and fragile at audit time.
For practitioners
- Map CUI flow before defining scope Inventory where FCI and CUI enter, where they are stored, which roles touch them, and which subcontractors inherit obligations. Include SaaS export paths, BYOD usage, and unmanaged web tools that can receive pasted or downloaded content.
- Tie evidence to live controls Align the system security plan, access reviews, privilege logs, and POA&Ms with the current environment rather than the architecture you originally designed. Require owners and due dates for every exception.
- Treat browser activity as control evidence Capture session events for copy, paste, download, print, and data transfer actions where CUI is handled in web applications. Use policy-focused browser logging to document the last mile of access.
- Rehearse assessor questions with subcontractors Run an internal walkthrough that forces internal teams and partners to prove controls for access control, auditability, media protection, and incident response within a short timebox.
Key takeaways
- CMMC readiness fails when scope is inferred from devices instead of traced through actual CUI workflows.
- Assessor confidence comes from live evidence that matches the SSP, not from documentation volume.
- Browser-level visibility and subcontractor discipline are now central to proving controlled handling of sensitive data.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | CMMC audit prep depends on controlled access to sensitive information across users and partners. Map CUI access paths to PR.AC-4 and verify least privilege across internal and subcontractor workflows. |
| NIST SP 800-53 Rev 5 | AU-2 | The article centres on producing assessor-ready logs and records for evidence. Align audit logging with AU-2 so session events, access reviews, and exceptions are available on demand. |
| CIS Controls v8 | CIS-5 , Account Management | Account and access governance underpin the control story for contractors and CUI handlers. Apply CIS-5 to review account scope, remove stale access, and verify subcontractor identities. |
Align audit logging with AU-2 so session events, access reviews, and exceptions are available on demand.
Key terms
- Controlled Unclassified Information: Controlled Unclassified Information, or CUI, is sensitive federal information that must be protected according to defined handling rules outside federal systems. For practitioners, the key issue is not only storage security but also proving that every system, identity, and data path in scope preserves those rules.
- CMMC Scoping: CMMC scoping is the process of defining which systems, users, and workflows are inside the compliance boundary for handling FCI or CUI. It is based on actual data processing, storage, and transmission paths, not on organisational charts or assumptions about inherited coverage.
- Last-mile visibility: Last-mile visibility is the ability to observe what happens at the point where a user actually interacts with sensitive data. In modern compliance programmes, that often means browser-level telemetry for actions like copy, paste, download, print, and transfer, because upstream network controls may not see those events.
- Assessor-ready evidence: Assessor-ready evidence is operational proof that matches the control statement in the system security plan and can be produced quickly during review. It includes live logs, access records, owner assignments, exception handling, and records that demonstrate the environment works as described.
What's in the full article
Island's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step guidance for scoping CUI across browser sessions, SaaS applications, BYOD, and subcontractor workflows.
- Examples of assessor-ready evidence for SSPs, POA&Ms, access reviews, and policy events tied to CUI handling.
- Practical questions to use in a dress rehearsal for access control, auditability, media protection, and incident response.
- Specific ways Island positions the browser as part of the audit trail for last-mile data handling.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management for practitioners who need stronger access control thinking. It helps security teams translate identity controls into operational evidence across modern environments.
Published by the NHIMG editorial team on September 4, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org