News
Tools Don’t Deliver CMMC Compliance – Documentation Does
April 28, 2026
- Hanno Ekdahl
- 1:25 pm
[In many organizations, CMMC readiness is approached like a familiar engineering problem: select the right tools, automate where possible, and assume the compliance outcome will follow.\ \ That assumption is costly.\ \ Tools can strengthen security. They can generate telemetry, enforce configurations, and reduce manual effort. But CMMC is not a product review, and it is not satisfied by the presence of a platform. CMMC assesses whether required practices are defined, implemented, managed, and sustained within the scoped environment. That is fundamentally a governance and execution question, not a purchasing decision.\ \ Why the Tool-First Mindset Fails\ \ A tool is an input. Compliance is an outcome.\ \ Organizations can deploy endpoint protection, enable multi factor authentication, centralize logs, and run vulnerability scans while still failing a CMMC assessment, because the assessment will quickly move beyond “is it turned on” to “how is it operated.”\ \ Assessors tend to ask simple, operational questions that expose gaps immediately:\ \
- Who is responsible for reviewing alerts, how frequently, and what actions are taken when thresholds are met?\
- How is access approved, how is least privilege enforced, and how are approvals recorded?\
- What is the change control process, and how can you demonstrate that it is followed consistently?\
- How are vulnerabilities prioritized, tracked to closure, and validated after remediation?\
- How do you ensure backups are protected, tested, and recoverable?\ \ A tool can produce data points; it cannot, by itself, establish accountability, define decision authority, or demonstrate that an organization follows a repeatable process. Automation does not eliminate the need for process. On the contrary, it increases the need for process, because automated systems still require defined oversight, exception handling, and governance to ensure they remain effective over time.\ \ What Documentation Actually Means in CMMC\ \ When teams hear the term documentation, they often picture static binders or generic templates.\ \ That framing is unhelpful.\ \ In CMMC, documentation is the operational layer that makes security practices consistent and auditable. It is the set of policies, procedures, standards, and defined responsibilities that turns security from a collection of technical features into an organizational capability. Strong documentation is not long – it is precise.\ \ At minimum, it should clearly state:\ \
- What the organization requires and why, through policies and standards;\
- Who is accountable for performing and approving actions;\
- How activities are carried out, through procedures that are specific enough to be followed;\
- How exceptions are handled, including approval and documentation requirements;\
- Where records are maintained, so practices can be demonstrated consistently.\ \ The goal is not to produce “paper;” rather, it is to eliminate ambiguity so that people behave consistently and the organization can show that consistency on demand, both during the assessment and in the three-year interim between recertifications.\ \ Why Documentation Yields Successful Assessments\ \ CMMC assessments validate implementation by tracing requirements to real operational practice. Documentation is what makes that trace possible. When documentation is mature, there is a clear line from a control requirement to a defined process, and from that process to the records that demonstrate it is being followed. In that environment, the assessment becomes confirmation rather than discovery. However, when documentation is weak, technical controls become isolated facts. “MFA is enabled” may be objective true for the environment, but without documentation it is difficult to show scope, exclusions, exception approvals, enforcement mechanisms, or how the organization ensures it remains enabled as systems change.\ \ This is why automation or additional tooling is rarely sufficient in an assessment context. Automation without documented governance is indistinguishable from automation that no one monitors, reviews, or maintains.\ \ The Cost Argument Leadership Should Understand\ \ Tools create immediate spend; lack of documentation creates recurring spend. When policies and procedures are missing or inconsistent, every audit becomes a scramble for answers, every control becomes dependent on specific individuals, and every staff transition introduces risk and rework. Practically, organizations pay for this in labor hours, delayed delivery, repeated meetings, emergency remediation, and program uncertainty. Documentation reduces those costs, which in turn standardizes decision making, reduces rework, and makes evidence easier to produce because records become a natural byproduct of routine operations rather than a last minute reconstruction exercise.\ \ If leadership is focused on immediate cost, documentation should be positioned as the most cost effective control in the program. It is relatively inexpensive to produce and maintain, and it prevents expensive cycles of confusion and correction.\ \ Visualizing and Optimizing This Reality\ \ A useful rule for aligning technical teams with CMMC expectations is simple: if you cannot describe the control as a procedure, you do not have the control. Start with the workflows that most often drive findings and delays, then align tooling to support those workflows:\ \
- Access control and approvals\
- Configuration baselines and change management\
- Vulnerability management and remediation tracking\
- Incident response and reporting\
- Media handling and data protection\
- Tools can accelerate these activities, but documentation is what makes them repeatable and defensible.\ \ Key Message\ \ The right tools can materially improve security outcomes. Yet CMMC compliance is demonstrated through defined policies and procedures that are implemented consistently and sustained over time. Documentation is not bureaucracy: it is the mechanism that turns “we think we do this” into “we do this every time, and we can prove it.” Tools help you operate, but documentation is what makes you compliant.](/content/tools-dont-deliver-cmmc-compliance-documentation-does/index.html)
More News
What’s the Big Idea: Identity Management Projects that Deliver
The Importance of Multiple IT Environments
Hidden Dangers: Why Your Organization’s Cybersecurity Posture is Delusional
Invisible Walls, Real Evidence: Proving Logical and Physical Separation in CMMC Enclaves, Hybrid IT, and Multi-Site Operations
Mark It Right, Spend Less: Simple, Defensible CUI Handling
GSA’s New CUI Security Requirements: A Turning Point for Federal Contractors
If Hackers Had Yelp Reviews
Teaching Claude to Read Designer Workspaces
Non-Human Identities and AI Agents: The New Blind Spot in Your IAM Program
Why HIPAA Compliance Won’t Get You to CMMC Level 2
Official RPO Status: What It Means for Our CMMC Clients—and What Comes Next
Idenhaus Achieves Official CMMC RPO Status
‘Minerva Meets’ Podcast Interview: Foundations of Identity and Access Management with Idenhaus CEO Hanno Ekdahl
Why Your MSP Choice Matters for CMMC: Trust, Scope, Proof
AI is the New Thing, But Identity Management Still Demands a Focus on Fundamentals
Governing the Vibe: VIBE-SEC for better IAM
The Rise of the Machine Employee
CMMC Asset Scoping: How to Categorize Your IT Environment for Level 2 Compliance
Gartner IAM Summit 2025: Key Themes and Takeaways
CMMC by the Numbers: Where Things Stand and How to Get Ahead
EDUCAUSE 2025: Key Takeaways
CMMC Level 2 Is Already Here: Why Defense Subcontractors Can’t Afford to Wait
Laying the Identity Foundation: Building Your Digital House
CMMC Certification Is Now the Ultimate Game Changer for Defense Contractors
5 CMMC Compliance Mistakes That Cost Small Businesses Time and Money
6 Best Practices for Privileged Access Management: What Experts Agree On
Strategies for RBAC Alignment: Pre-Go-Live Baselining and Automation
Identity Management Transformed: The Power of AI, Guided by Human Expertise
AI Agents Reshaping of Identity Management: Evaluating IT Investments in AI-Driven Identity Management
AI Agents Reshaping of Identity Management and Workflow Automation
Balancing The Tension Between IGA and ITSM
Key Takeaways from Identiverse 2025
Top 10 Reasons To Do End-to-End (E2E) Testing
The Inaugural Level Zero Industrial Control System and Operational Technology Conference
Florida’s HB 473: The Cybersecurity Incident Liability Act (2024)
Recap: Official Cybersecurity Summit Dallas 2025
Artificial Intelligence (AI) Opportunities for Improving an Identity Management Program
Who Are the Key Players in the CMMC 2.0 Ecosystem?
5 Security Policies Every Organization Should Have
Access Certifications & RBAC: Aligning User Access with Role-Based Certification
DevOps or Dev-Oops?
32 CFR Final Rule for CMMC Explained
Communicate to Build Relationships For Identity Success
Essential Guidance for CMMC Level 1 Scoping
Top Ten Reasons to Become CMMC 2.0 Certified
Unlocking Government Contracts: FedRAMP vs. CMMC 2.0
Turning User Password Management On Its Head
Top 10 Cybersecurity Lessons Learned for Remote Work
Compliance With CMMC 2.0: Top 10 Questions Answered
Stay Secure on the Go: Essential Security Tips for Using Public Wi-Fi
Successful Identity Management via Concurrent Engineering: A Unified Strategy for Digital Identity Security
Musings on the User Identity Lifecycle
Top 10 IDM Security Risks
Staying Mindful of Your Cybersecurity Practices
Florida’s H.B. 473 Cybersecurity Incident Liability Act
Navigating the Changes in NIST SP 800-171 Rev. 3 – What You Need to Know
How Not to Get Quished When Hungry!
Zero Trust – Avoiding the Paranoid Posture of “Trust No One”
The Good, The Bad, The Agile
FedRAMP vs. CMMC Compliance Questions
Unprepared and Vulnerable: Understanding Disaster Recovery Planning, Risks, DRaaS, and the Benefits of In-House Solutions
Cybersecurity Strategy and Roadmaps: Creating a Secure Foundation for the Future
Building a Culture of Cybersecurity with Strategies for Training and Awareness
Are You Maximizing Your IAM Investment?
Building Cyber Resilience: Part II
Building Cyber Resilience
What’s the Big Idea: Identity Management Projects that Deliver
The Importance of Multiple IT Environments
Mark It Right, Spend Less: Simple, Defensible CUI Handling
Case Studies
From Complexity to Clarity: Spang’s CMMC Level 2 Readiness Journey
Confidence Through Compliance: The Harris Technologies CMMC Journey
Mission Ready: Frontline’s March to CMMC Compliance
Resolute Solutions: A Successful Journey to CMMC Compliance
GARealtors Enhances Security Posture with Cybersecurity Assessment
Institute of Technology Operationalizing Okta
FPS Forges New Defenses with Cybersecurity Assessment
Project N95 Achieves NIST SP 800-171 Compliance
Newsletter Signup
Why You Need An IAM Roadmap
Why you need an IAM Roadmap with Hanno Ekdahl - YouTube
Tap to unmute
Why you need an IAM Roadmap with Hanno Ekdahl Idenhaus Consulting
Idenhaus Consulting60 subscribers