Skip to content
Cyber Defense Technologies

Compliance

Preparing for a CORA Inspection

Cyber Operational Readiness Assessments look at whether a network is actually defensible, not only whether it is documented. How to prepare, what inspectors focus on, and how to avoid the most common failures.

By Cyber Defense Technologies May 12, 2026 5 min read

For organizations that operate Department of War (DoW) networks, the Cyber Operational Readiness Assessment (CORA) is one of the most consequential evaluations they face. Conducted under Joint Force Headquarters–Department of Defense Information Network (JFHQ-DODIN), CORA replaced the older Command Cyber Readiness Inspection (CCRI). The shift was deliberate: rather than a largely checklist-driven inspection, CORA emphasizes mission risk, threat-informed focus areas and the organization's actual ability to defend its networks.

The result is an assessment that is harder to prepare for at the last minute. It rewards organizations that operate securely every day.

What CORA looks at

While the specific criteria evolve, CORA assessments consistently examine three broad areas:

  • Technical implementation: vulnerability management, configuration compliance with DISA Security Technical Implementation Guides (STIGs), patching, and asset management, verified with scans and hands-on review.
  • Threat-focused areas: controls tied to how adversaries actually attack DoW networks, such as account security, boundary defense, remote access and detection.
  • Mission risk: how cyber weaknesses would affect the missions the network supports, and how well leadership understands that risk.

The common thread is verification. Inspectors compare what the organization says with what the network shows.

Preparation that works

CORA preparation checklist

  • Current, credentialed vulnerability scans across the whole boundary
  • STIG checklists complete and reconciled with actual settings
  • Hardware and software inventories that match what is on the network
  • Open findings tracked in POA&Ms with realistic dates
  • Current incident response and continuity plans, rehearsed
  • Account management evidence: privileged users, reviews, removals
  • Logging and monitoring that can show detection, not only collection
  • Cross-domain, boundary and remote access documentation
  • A mock assessment with findings closed before the visit
  • Named points of contact who can answer for each area

Know what you own

Build and reconcile hardware and software inventories against what is actually on the network. Discovery scans, network access control data and endpoint management tools should agree with the inventory. Unknown devices are among the fastest ways to lose credibility.

Scan everything, with credentials

Run credentialed vulnerability scans across the entire boundary, including network devices, virtualization hosts and systems that are hard to reach. Resolve failed authentications; a scan that could not log in is not a clean scan.

Make STIGs real

Complete STIG checklists for every applicable technology, and make sure they reflect actual settings. Where a setting cannot be applied because it would break the mission, document the deviation, the risk and the mitigation, and track it in a Plan of Action and Milestones (POA&M).

Clean up accounts

Review privileged and service accounts, remove stale accounts, and make sure privileged access requires strong authentication. Account management is consistently a focus area.

Show you can detect

Collecting logs is not enough. Be ready to show how alerts are generated, who reviews them, and how incidents are escalated, ideally with real examples.

Tell the risk story

Leaders should be able to explain the organization's top cyber risks, how they affect the mission, and what is being done about them. POA&Ms should be current, realistic and owned.

Run a mock assessment

The most effective preparation is an honest internal assessment several months before the visit, performed by people who did not build the systems. Treat its findings as if they were the real inspection: fix what you can, document what you cannot, and verify the fixes. Then scan again close to the visit to confirm nothing has regressed.

Common failure points

  • Inventories that do not match the network
  • Stale or unauthenticated scans
  • STIG checklists completed on paper but not applied
  • Unpatched high-risk vulnerabilities, especially known exploited ones
  • Unmanaged or shared privileged accounts
  • Undocumented connections and remote access paths
  • POA&Ms with passed dates and no explanation

After the assessment

Treat the results as a roadmap. Assign owners and dates to every finding, fold them into your POA&M, and use continuous monitoring to prevent the same issues from returning before the next assessment.

A 120-day preparation timeline

Organizations that perform well usually start early. A practical sequence:

  • 120 days out: Assign an overall lead and a lead for each technical area. Pull current inventories, scan results, STIG checklists and POA&Ms. Identify obvious gaps, such as missing scan coverage or outdated checklists.
  • 90 days out: Run a full mock assessment with people independent of the system's administrators. Score the results honestly and brief leadership on the top risks.
  • 60 days out: Remediate the highest-risk findings: critical vulnerabilities, CAT I STIG findings, privileged account issues and unknown devices. Document deviations that cannot be fixed.
  • 30 days out: Rescan everything with credentials. Reconcile inventories again. Confirm that POA&Ms are current and every open item has an owner and a realistic date.
  • Final week: Freeze non-essential changes. Prepare the evidence package, accounts and escorts for inspectors, and brief everyone who may be interviewed.

What leaders should ask their teams

  • Do we know every device and application on our network, and can we prove it?
  • What are our open CAT I findings and known exploited vulnerabilities, and when will each be fixed?
  • Which privileged accounts exist, who reviews them, and when was the last review?
  • If an adversary used a stolen administrator account tonight, how would we know?
  • What are our three biggest cyber risks to the mission, and are they in our POA&M?

Leadership engagement shows. Inspectors notice when commanders and directors understand their cyber risk, and when they do not.

How CDT can help

CDT prepares organizations for CORA through mock assessments, STIG implementation, vulnerability remediation and POA&M development, delivered by our inspection and audit readiness and system hardening teams.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.