
The Defense Industrial Base Sector Coordinating Council built something called CCRA, or Cybersecurity Compliance and Risk Assessment, to reduce that redundancy. According to ND-ISAC's current CCRA guidance, the goal is one supplier assessment that multiple prime contractors can accept, rather than a dozen separate versions.
CCRA is not a government certification, and it isn't a universal U.S. requirement. It's a specific process, and applicability depends on who's asking. This article covers what CCRA measures, how it connects to CMMC and NIST SP 800-171, how to prepare a response, and where to verify current requirements before you submit anything.
Key Takeaways
- CCRA pairs a compliance questionnaire with a cyber risk assessment for supplier and third-party programs.
- Completing a CCRA does not make you CMMC-certified or fully contract-compliant.
- Treat evidence collection as ongoing, not a one-time form you fill out and forget.
- Confirm current forms, instructions, and deadlines with your prime, Exostar, ND-ISAC, or contract authority.
What Is CCRA and Why Does It Matter?
CCRA evaluates two separate things: whether required security controls are actually in place, and how much residual cyber risk remains even after those controls exist. That distinction matters. A company can technically have a firewall and still carry significant risk if it's misconfigured or unmonitored.
Structurally, the current CCRA tool is a macro-enabled Excel workbook with a maximum of 60 questions. Answers to compliance questions dynamically determine which additional questions appear.
The risk portion draws from a subset of NIST SP 800-171 Rev. 2 requirements. ND-ISAC describes the tool as industry-agnostic, so any company sharing sensitive data with a requesting organization could be asked to complete one.
A general cybersecurity risk assessment is broader. It looks at your entire threat landscape, assets, vulnerabilities, likelihood, and business impact across the organization. CCRA is narrower and supply-chain specific: it gives prime contractors one consistent format for comparing supplier posture instead of reinventing the process with every vendor.

CCRA requirements also vary by customer, contract, and the type of data involved. ND-ISAC is explicit that completing a CCRA does not waive or substitute for DoD-required assessments, and it does not approve you to process CUI. Always confirm current applicability with the organization requesting it.
How CCRA Can Affect Suppliers
An incomplete or outdated assessment doesn't just sit quietly in a portal. It creates friction.
- Procurement delays while the requesting organization asks follow-up questions
- Remediation obligations attached as a condition of continuing the relationship
- Elevated third-party risk flags that can affect future contract opportunities
A current, well-supported assessment works in your favor:
- Documents your security posture in a format primes already recognize
- Helps you prioritize limited IT budget against the controls that matter most
- Shows you treat sensitive information as a contract obligation, not an afterthought
Illustrative example (not a customer case study): picture a 40-person parts supplier preparing its assessment. While gathering evidence for the access control questions, the IT lead discovers that three former contractors still have active VPN credentials. Fixing that before submission turns a potential red flag into a documented, closed finding.
How to Perform a Cybersecurity Risk Assessment for CCRA
A rushed risk assessment produces unreliable answers. Work through it in order.
- Define scope. Identify every system, facility, cloud service, application, and third party that touches the information covered by the contract or customer request.
- Identify assets. Include credentials, endpoints, servers, backups, collaboration tools, externally hosted platforms, and the processes that need protection.
- Identify threats. Cover phishing, ransomware, credential theft, unpatched software, excessive access privileges, insecure remote access, and third-party compromise.
- Evaluate existing safeguards. Check each applicable requirement and document whether a control is implemented, partially implemented, planned, or not implemented at all. Don't round up.
- Assess likelihood and impact. Use a consistent method and factor in operational disruption, potential data exposure, contractual consequences, and recovery costs.
- Document findings in a risk register. Capture the risk statement, affected asset, control gap, risk owner, treatment plan, target date, residual risk, and supporting evidence.

How to Turn Assessment Results into an Action Plan
Finding gaps is only half the job. What you do next determines whether the assessment actually reduces risk.
- Prioritize by impact and exploitability first, not by which fix is easiest. Not every finding can be remediated at once, and pretending otherwise just delays the risks that matter most.
- Assign each task an owner and a realistic deadline. Enforcing multifactor authentication, tightening backup protections, and retiring unsupported software are common early wins.
- Reassess residual risk after remediation. Keep an audit trail showing what changed, when, who approved it, and what evidence supports the new status.
- Revisit the assessment after major changes — new technology, new personnel, a new subcontractor, or a shift in the threat landscape all warrant a fresh look, not a copy-paste of last year's answers.
CCRA, CMMC, and NIST SP 800-171: How They Relate
These three terms get mixed up constantly, and mixing them up is where suppliers get into trouble.
NIST SP 800-171 governs how Controlled Unclassified Information (CUI) must be protected on nonfederal systems. NIST published Revision 3 in May 2024, superseding Revision 2, so if you're referencing an older version, double-check which one your contract actually requires.
CMMC is a separate, broader framework. According to the DoD's own program overview, Level 1 covers basic Federal Contract Information (FCI) safeguarding with 15 requirements and an annual self-assessment.
Level 2 covers CUI protection with 110 requirements drawn from NIST SP 800-171 Rev. 2. Assessments generally run on a three-year cycle with annual affirmation, though some contracts require third-party (C3PAO) assessment instead. Applicability hinges on contract language: whether you process, store, or transmit FCI or CUI.

CCRA sits apart from both. It's an information-gathering and risk-evaluation exercise, not a certification pathway. ND-ISAC states plainly that CCRA completion does not substitute for DFARS-required assessments or CMMC obligations.
| Artifact | What It Is | What It Proves |
|---|---|---|
| CCRA | Supplier compliance and risk questionnaire | A snapshot of controls and risk at time of submission |
| Self-assessment | Internal scoring against a standard (e.g., NIST 800-171) | Organization's own claim of conformance |
| POA&M | Plan of Action and Milestones for open gaps | A documented path to closing specific deficiencies |
| CMMC assessment | Formal review at a defined level | Certification or affirmation of maturity level |
What Evidence Should Support a CCRA Response?
Don't answer "yes" without something behind it. Useful evidence categories include:
- Written policies and procedures
- System and asset inventories with access reviews
- Vulnerability scans and remediation closure records
- Security awareness training records
- Backup, recovery, and incident response test results
- Vendor and subcontractor reviews
Evidence should be current, clearly attributable to your organization, tied to the specific control in question, and retained per your contract and internal policy. Recycling last year's answers without confirming the control is still effective is one of the fastest ways to submit an inaccurate assessment.
How to Prepare for CCRA Compliance
Preparation beats scrambling. Before a questionnaire lands on your desk, get ahead of it.
- Build a current inventory of systems, applications, users, data flows, cloud services, and third parties within scope.
- Review foundational safeguards, starting with MFA, least-privilege access, endpoint protection, patch management, encryption, logging, backups, and incident response.
- Create a central evidence repository with version-controlled policies, screenshots, test results, approvals, and remediation records — not scattered across five people's inboxes.
- Assign clear roles—executive or vCIO sponsor, technical owner, compliance coordinator, and business stakeholder—so answers are accurate and approved before submission.
- Run a readiness review before you submit. Look specifically for contradictory answers, missing evidence, and unresolved high-risk findings.
Support for Organizations Without Internal Compliance Staff
Most small and mid-sized suppliers don't have a dedicated compliance department, and that's normal. A managed IT or cybersecurity partner can help with scoping, control reviews, evidence collection, remediation tracking, continuous monitoring, and executive-level reporting — without taking on your contractual responsibility to the requesting organization.
This is where a firm like nDataStor fits in for small and mid-sized businesses across Northern California. We support CCRA readiness with control reviews, evidence collection, remediation tracking, and vCIO guidance so you can prioritize work that actually reduces risk.
nDataStor is a managed IT and cybersecurity partner, not a CMMC certifying body or a government authority. We help you get ready; assessment and certification decisions rest with the appropriate official channels.
Common CCRA Mistakes to Avoid
These mistakes show up repeatedly, and most are avoidable if you treat CCRA as an ongoing control process:
- Treating it as a one-time form instead of maintaining the underlying controls and updating answers as your environment changes.
- Confusing CCRA completion with CMMC certification or proof that every risk has been eliminated. It's neither.
- Using outdated questionnaire versions or unofficial downloads instead of checking the current source and submission workflow.
- Reporting controls as fully implemented when they're only planned or inconsistently applied. Auditors and follow-up reviews catch this.
- Failing to define scope properly, especially around cloud platforms, remote workers, subcontractors, and managed service providers.
- Ignoring residual risk after remediation rather than having leadership formally approve, transfer, reduce, or accept whatever remains. Silence isn't a decision.
Conclusion: Make CCRA Part of an Ongoing Cybersecurity Program
A strong CCRA response comes down to accurate scoping, honest control evaluation, reliable evidence, and a documented remediation trail. None of that happens well under deadline pressure.
Treat CCRA as a recurring control inside your cybersecurity program, not a one-time scramble. Requirements, form versions, and contract language change, so confirm current instructions with your prime contractor, Exostar, ND-ISAC, or the relevant NIST publication before you act on anything in this article.
Your next steps:
- Inventory the systems and information actually in scope
- Identify your most consequential gaps
- Put dates on a remediation plan before you open the assessment form
Frequently Asked Questions
How do you perform a cybersecurity risk assessment?
Define scope, identify assets and threats, evaluate existing controls against requirements, and rate likelihood and impact consistently. Document everything in a risk register, remediate by priority, and revisit the assessment regularly.
What are the 5 C's of cybersecurity?
One commonly cited framework names change, continuity, compliance, cost, and coverage as lenses for evaluating a security program. Terminology varies by source, though, so don't confuse this with a formal CCRA requirement.
What is the 80/20 rule in cybersecurity?
It's a prioritization principle: a small set of weaknesses often drives most of your risk. The Center for Internet Security uses this idea to focus limited resources, but you should still validate priorities with your own evidence.
Is CCRA the same as CMMC?
No. CCRA is generally a compliance and risk assessment process, while CMMC is a formal maturity model with defined requirements and, at certain levels, third-party certification. Completing a CCRA does not satisfy CMMC obligations.
Who needs to complete a CCRA?
It depends on the prime contractor, customer, contract, and data involved. Some primes require it from all suppliers; others don't use it at all. Confirm applicability directly with the organization requesting it.


