Common failure modes assessors push back on
Some gaps show up often enough across readiness reviews and assessments that they are worth naming. This is an opinionated shortlist — not a taxonomy of all 320 objectives.
For each failure mode: what it looks like, why it draws pushback, and the minimal change that usually moves the needle. Cross-check with How assessors use ControlVerdict when you want pattern examples rather than anti-patterns.
1. Incomplete MFA coverage (especially local privileged)
- Looks like: “We have MFA” — Conditional Access on Microsoft 365, maybe VPN. Screenshots of Authenticator enrollment.
- Why pushback: IA.L2-3.5.3 asks about privileged local access and privileged network access, plus network access for non-privileged accounts. VPN MFA does not cover an admin at the server console.
- Minimal fix: Privileged account inventory; enforce MFA at each required point; live demo path for local privileged; document break-glass. See Smart card at the rack… and Just-in-time admin roles….
2. Logs that exist but are not reviewed (or have no history)
- Looks like: SIEM connected last month; raw exports nobody reads; “logging is enabled” in the SSP.
- Why pushback: AU objectives care about creating and reviewing / retaining usable records. Two weeks of history and zero review tickets read as aspirational.
- Minimal fix: Event catalog, review cadence with dated tickets (even “no anomalies”), retention that matches your claim. See AU create/retain example and Quarterly logged-event review….
3. Incident response plan without testing evidence
- Looks like: Polished IR plan PDF dated this quarter; no tabletop, no after-action, no closed findings.
- Why pushback: Having a plan and testing the capability are different objectives. Assessors ask for exercise records.
- Minimal fix: Schedule tabletops; produce after-actions with owners and due dates. See Two tabletops and one live containment drill….
4. SSP that does not match the environment
- Looks like: Templated or AI-generated SSP; CUI flow diagram disagrees with how email and file shares actually work; procedures name roles that left last year.
- Why pushback: Phase 1 is a readiness check, not a coaching session. Divergence between the story and the demo is the loudest signal.
- Minimal fix: Rewrite implementation statements to name systems, owners, cadence, evidence, and exceptions. Make SSP, SOPs, and config tell the same story.
5. Security Protection Assets left out of scope
- Looks like: Scope = “where CUI lives.” Entra ID, SIEM, RMM, VPN, ticketing “aren’t in scope because they don’t store CUI.”
- Why pushback: Assets that protect CUI confidentiality are in scope even when they do not store CUI. Identity and logging platforms are the usual misses.
- Minimal fix: Re-run scoping with SPA categories; document inheritance vs customer config for each.
6. “Our MSP / cloud is certified, so we inherit it”
- Looks like: Shared responsibility matrix that copies marketing; OSC staff cannot explain controls the MSP performs in their tenant.
- Why pushback: Inheritance and shared responsibility are different. The assessor still validates what happens in your house. An MSP’s own certification does not auto-MET your objectives.
- Minimal fix: Per-objective SRM; customer-config evidence; authorizing official who can speak without the MSP on speakerphone. See the M365 starter kit.
7. Policy-only “implementation” statements
- Looks like: “We restrict access to authorized users.” No groups, no provisioning path, no review cadence.
- Why pushback: Restating the requirement is not an implementation. Assessors need configured mechanism + evidence of operation.
- Minimal fix: Name the control (e.g. Entra groups + Conditional Access), the operator, the review ticket trail. Pattern reference: Enclave allow-list….
Fatal vs easily fixable
On ControlVerdict’s seven-level scale, some gaps are “finish-line” (add review tickets, extend retention) and some are start-over (no MFA on privileged local, CUI outside the claimed enclave). Do not burn calendar on polish while a structural hole remains.
Disclaimer
These are recurring community and public assessor themes, not a prediction of your assessment. Your C3PAO’s determination is authoritative for your engagement.
Discussion(0)
No discussion on this article yet
Ask clarifying questions or share related assessment scenarios.
Sign in to start a thread.