What to Expect During a CMMC Assessment
A CMMC Level 2 assessment runs 5 to 10 days depending on scope. Here is what assessors do each day and what your team needs to have ready.
Pre-Assessment: 30 to 90 Days Out
The C3PAO engagement starts well before the on-site week. Pre-assessment activities include:
- Scoping conversation: You walk the lead assessor through the CUI boundary. They challenge gaps and confirm the asset categorization.
- Document submission: Your SSP, POA&M, network diagrams, asset inventory, and policies go to the assessment team for pre-review.
- Logistics: On-site dates, remote access for evidence gathering, interview scheduling.
- Pre-assessment finding: Some C3PAOs flag obvious gaps before showing up so you can either remediate or accept the finding.
Use this phase to find every weak spot in your CMMC documentation before assessors arrive. The cost of fixing a gap during pre-assessment is far lower than fixing it after a finding.
On-Site Days 1-2: Kickoff and Document Review
Day 1 starts with a kickoff meeting. The lead assessor walks through the agenda, confirms scope, and introduces the team. Your team introduces system owners and points of contact.
Days 1-2 focus on document review. The assessment team reads your SSP cover-to-cover, cross-references it against your policies, and starts mapping practices to evidence files. They will flag any practice where the SSP narrative does not match the evidence on file.
What helps:
- A clean SSP with each practice section having a clear narrative and evidence pointer
- An evidence index spreadsheet mapping every artifact to a practice
- A document portal (Egnyte, Box GovCloud, or similar) for assessors to pull from
The assessors will start asking targeted questions by end of Day 2. If your evidence is disorganized, this phase blows out and pushes interviews into the next week.
On-Site Days 3-4: Interviews and Technical Testing
Days 3-4 are the most intensive. Interviews and technical testing happen in parallel. The assessment team will:
- Interview personnel: System administrators, security team, helpdesk, executive sponsor. Questions probe whether the practices documented in the SSP are actually how things work day-to-day.
- Test technical controls: Sample MFA enforcement, audit log retention, privileged account management, FIPS module verification, vulnerability scanning configuration.
- Walk-throughs: Watch a user log in, watch an admin make a configuration change, watch the IR team triage an alert.
Interview prep matters. Personnel should know which practices their role covers and have one or two specific examples ready. "Tell me about how we handle incident response" with a blank stare from your IR lead is an immediate finding.
On-Site Day 5: Out-Brief and Findings
Day 5 wraps with the out-brief. The lead assessor walks the senior accountable official through:
- Practices fully met: Count and any noted strengths
- Practices with findings: Specific items that did not meet the assessment objectives
- Recommended POA&M items: Findings eligible for the conditional certification path
- Critical findings: Anything that blocks certification entirely (typically the four ineligible practices listed earlier)
The out-brief is not the final score. The C3PAO has a quality review process that takes 2-4 weeks before the final report is issued. Findings can change during quality review, but the major categorizations rarely shift.
Take detailed notes during the out-brief. The findings list becomes your immediate POA&M, and the 180-day clock starts ticking on conditional items.
Post-Assessment and Final Report
After the on-site week, the assessment team writes the final report and submits it through the CMMC ecosystem to the Cyber AB and DoD. This typically takes 4-8 weeks. Outcomes:
- Final certification: All practices met. Three-year certificate issued.
- Conditional certification: Practices met for full certification minus POA&M-eligible items. 180 days to close POA&M items, then full certification kicks in.
- Failed assessment: Critical findings or POA&M ineligible practices missed. No certification. Remediation required, then re-assessment.
If you receive conditional certification, immediately:
- Update the POA&M with the assessor findings
- Update the SPRS score using the SPRS calculator
- Set up monthly closure tracking with assessor evidence requirements
- Schedule the closure verification with the C3PAO before the 180-day mark
Frequently Asked Questions
Related Articles
CUI Boundary Scoping for CMMC
Your CUI boundary defines what gets assessed. Get it wrong and you either over-spend on out-of-scope systems or fail because in-scope assets were missed. Here is how to scope correctly.
CMMC Plan of Action and Milestones
A CMMC POA&M is the document that lets you certify with open gaps, but only if those gaps are POA&M-eligible and the milestones are credible. Here is how to build one that holds up.
CMMC Conditional Certification Explained
Conditional certification lets you certify with open POA&M items, but only for 180 days. Here is what is eligible, how the closure process works, and the consequences of missing the deadline.