1What the Assessment Is, and Is Not
A CMMC assessment is not an informal review, and it is not an audit in the financial sense. It is a structured evaluation, run to a published procedure, of whether the requirements in NIST SP 800-171 are actually implemented within a defined scope. Understanding that procedure from the assessor's side is the best preparation a contractor can have, because the assessment rewards an environment that was built to be read the way an assessor reads it.
The procedure is the CMMC Assessment Process, the CAP, published and maintained by the Cyber AB and approved by the CMMC Program Management Office. The current version, 2.0, was issued in December 2024. The CAP is deliberately narrow in what it governs. It does not define the cybersecurity requirements, which come from NIST SP 800-171 and the Department of Defense rules, and it does not decide what CUI is or where it lives. It defines only how the requirements are evaluated during a certification assessment, so that two assessors looking at the same environment reach the same conclusion. Adherence is mandatory for a certified third-party assessment organization, the C3PAO, and its Certified CMMC Assessors.
Which procedure applies depends on the path, and there are three. A Level 1 assessment, and a Level 2 assessment for the contracts that permit it, is a self-assessment: the organization seeking assessment evaluates itself under the DoD Assessment Methodology and affirms the result. A Level 2 certification assessment is conducted by a C3PAO under the CAP, and it is this path that most CUI work will require as the program phases in. A Level 3 assessment is conducted by the government itself, through the Defense Industrial Base Cybersecurity Assessment Center. The rest of this part follows the certification path, because it is the most involved and because the self-assessment mirrors it without the third party in the chair.
| Stage | What happens | Key output |
|---|---|---|
| Preliminary proceedings | Entity confirmation, conflict-of-interest checks, the assessment contract, and team assignment | A signed engagement and an assigned Lead Assessor |
| Phase 1, Plan and Prepare | Review of the system security plan and scope, an evidence collection plan, and a readiness verification | A decision to proceed, replan, reschedule, or cancel |
| Phase 2, Conduct | Examine, interview, and test against the 110 requirements, with daily checkpoints | Each requirement scored MET, NOT MET, or Not Applicable |
| Phase 3, Report | Independent quality assurance, the results package, and upload to eMASS | A recommended Final or Conditional status and a certificate |
| Plan of action closeout | Remediation of permitted gaps within 180 days, verified by a closeout assessment | Final status, or expiry of the conditional status |
2Preliminary Proceedings
Before Phase 1 begins, a set of administrative and ethical steps sets the foundation. The C3PAO confirms the identity of the organization being assessed, tied to its CAGE code and a valid system security plan. The two parties sign a formal assessment contract that conforms to the CMMC Code of Professional Conduct, and the C3PAO, which must operate under the international inspection-body standard ISO/IEC 17020, names the Lead Certified CMMC Assessor it intends to assign.
Conflict of interest is the gating concern at this stage. Either party can raise a conflict, and the C3PAO has to mitigate any that exists, documenting the measures agreed. A C3PAO cannot proceed with an assessment where conflicts are not sufficiently mitigated, which is why the organization that performed a company's readiness work cannot also assess it. The roles that carry the assessment take shape here as well: the Lead Assessor who directs the team and makes the key determinations, the assessment team members who examine and score, a quality assurance reviewer who stays off the team so the review remains independent, and the authorized certifying official who ultimately signs the Certificate of CMMC Status.
3Phase 1: Plan and Prepare the Assessment
The purpose of Phase 1 is to confirm, before any formal evaluation begins, that the organization is genuinely ready and the assessment can be conducted. A failed assessment is expensive for everyone, and this phase exists to catch the problems that would cause one while they can still be fixed.
The Lead Assessor reviews the system security plan for completeness, accuracy, and consistency. This is not yet a judgment of whether the controls work, only a confirmation that the documentation addresses every applicable requirement and reflects the environment as it actually exists. The scope is validated in parallel, and any disagreement about what is inside or outside the boundary has to be resolved before Phase 2, because the scope determines everything the assessment will examine. Where external service providers or cloud services are in scope, the team confirms the supporting evidence, such as FedRAMP Moderate authorization or a documented equivalency, and the customer responsibility matrices that divide the controls between provider and contractor. The team develops its evidence collection approach, maps the expected evidence to each requirement, and verifies any requirement the organization proposes to mark Not Applicable.
The phase ends with a readiness verification that is easy to misread. The assessment team confirms that the evidence exists and is accessible, and it does no more than that. It does not examine the evidence, does not evaluate it for adequacy or sufficiency, and offers no advice or recommendation on how to improve it, because doing any of those things would turn the assessment into the readiness engagement that a different party has to perform. On the strength of that verification the Lead Assessor decides whether to proceed, replan, reschedule, or cancel.
4Phase 2: Conduct the Assessment
Phase 2 is the evaluation itself. It opens with an in-brief that aligns the parties on scope, procedure, and schedule, and then the team assesses the implementation of the 110 requirements within the defined scope, using the three methods that NIST SP 800-171A prescribes.
| Method | What the assessor does | Typical evidence |
|---|---|---|
| Examine | Reviews documents, records, and configurations | Policies, procedures, the system security plan, logs, and configuration exports |
| Interview | Speaks with the people who operate and own the controls | Operator and administrator accounts of how a control works in daily practice |
| Test | Exercises a mechanism or observes an activity | A demonstrated account lockout, an enforced setting, an actual access attempt |
Evidence carries the phase, and it is judged against two standards. Adequacy asks whether the evidence is the right kind to address the objective, whether it actually speaks to what the requirement demands. Sufficiency asks whether there is enough of it, and whether it covers the full assessment scope rather than a single machine or a single office. Where the evidence falls short of either standard, an evidence gap exists, and a gap points to a deficiency in the underlying implementation. The gaps that surface most often are mundane: a document that is incomplete, such as an access list that never added a new hire, an affirmation from someone not in a position to give it, or a policy that no one with authority ever signed.
Each requirement is scored MET, NOT MET, or Not Applicable, and a requirement is MET only when all of its assessment objectives, the roughly three hundred and twenty determination statements that NIST SP 800-171A derives from the 110 requirements, are satisfied. A requirement marked Not Applicable requires a thorough written justification. The evaluation is not conducted in silence: daily checkpoint meetings surface the gaps as they are found, which gives the organization a chance to locate and present additional evidence that can change a score before the phase closes, and a quality assurance reviewer works alongside the team throughout to keep the conduct consistent. After the active assessment concludes, the team has a short window, up to ten business days, to re-evaluate requirements scored NOT MET, a last opportunity for evidence that existed all along to be brought forward.
5Phase 3: Report the Assessment Results
Phase 3 turns the scored requirements into a result. The team compiles the scores, findings, and comments into a package in the prescribed format, and that package goes through a formal quality assurance review conducted by a reviewer who did not serve on the assessment team. That separation is deliberate, because the independence of the reviewer is what protects the integrity of the outcome against the team's own momentum.
The Lead Assessor determines the recommended outcome. All requirements MET, or MET and Not Applicable across the board, produces a recommended Final status. A passing score with a small set of permitted gaps produces a recommended Conditional status, on the terms this guide describes in Core Concepts. The results are presented to the organization and then uploaded, in every case and regardless of the outcome, into the DoD Enterprise Mission Assurance Support Service, the CMMC instantiation of eMASS. An organization that believes a finding is wrong has a defined route to dispute it through the appeals process, and once the result stands, the authorized certifying official issues the Certificate of CMMC Status.
6The Plan of Action Closeout
A Conditional status is a beginning rather than an end. The organization has 180 days from the Conditional CMMC Status Date, the date the results are posted, to close every item on its plan of action, and a closeout assessment then verifies the work. The closeout assessment is narrower than the original: it evaluates only the requirements that were scored NOT MET and placed on the plan of action, and it is performed by the contractor for a self-assessment and by a C3PAO for a certification.
The outcome of the closeout is binary. If the closeout assessment finds those requirements now MET, the organization achieves Final status. If the plan is not successfully closed within the 180 days, the Conditional status expires, and for a contract already in performance the standard contractual remedies follow. The eligibility rules that decide which gaps could be placed on the plan of action in the first place, the 80 percent threshold and the point-value limits, are set out in Core Concepts, and because assessor scheduling runs long, the closeout assessment is booked at the start of the window rather than chased at its end.
Preparing for the chair on the other side of the table
Building an environment that reads cleanly through plan, conduct, and report, with a system security plan that matches reality and evidence organized the way an assessor will ask for it, is onsite readiness work. That is the practice behind this guide.
Start CMMC Readiness or call 802-335-26627Sources
- CMMC Assessment Process (CAP), version 2.0, published and maintained by the Cyber AB and approved by the CMMC Program Management Office, which governs Level 2 certification assessments. cyberab.org
- NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, for the assessment objectives and the examine, interview, and test methods. csrc.nist.gov
- NIST SP 800-171 Rev 2, the 110 requirements evaluated in a Level 2 assessment. csrc.nist.gov
- 32 CFR Part 170, CMMC Program, for the assessment types, statuses, and the plan of action and closeout requirements at 32 CFR 170.16, 170.17, and 170.21. ecfr.gov