CMMC guide
What a CMMC Level 2 assessment looks like, day by day
A Level 2 assessment is an assessor working through all 110 NIST SP 800-171 requirements with three methods: examine the documents and configurations, interview the people who run them, and test that the control actually does what the System Security Plan says. It takes a few days on site or on screen, weeks of preparation before, and a defined window after for closing anything left open. As of October 2026 the Department of War has suspended the requirement for a third party assessor before award, pending a review; the method below is also how a government led assessment runs, and it is what the suspension review may bring back.
Before: the six weeks that decide the result
The assessment is decided before the assessor arrives. Four things have to exist.
The scope, on paper. Every asset sorted into one of five categories, and the four artifacts the assessor asks for first: the CUI flow diagram, the network boundary diagram, the physical site diagram, and the authorized user list. Missing any of the four is the most common finding on day one.
The System Security Plan, current. One document describing the boundary and how each of the 110 requirements is met, naming the people and the systems. It is read before anything else and every later question refers back to it.
The evidence index. For each requirement, where the proof lives: the configuration export, the screenshot with a date, the log extract, the training record, the ticket. Assessors work from 320 assessment objectives underneath the 110 requirements, and each objective needs its own proof, not a shared paragraph.
The people, named. The owner or executive who signs the affirmation, the person who runs the program day to day, whoever does the technical work (often the IT provider), and the department leads for the non technical requirements: HR for screening and departures, operations for physical access and visitors. Each will be interviewed about their own part.
A readiness review a few weeks before, run by someone other than the people who built the controls, finds the gaps while there is still time to close them.
During: what the assessor actually does
Day one is orientation and scope. The assessor confirms the boundary against the diagrams and the asset inventory, walks the facility or the virtual equivalent, and checks that what is in scope on paper matches what is on the network. If the boundary does not hold, the assessment stops here.
Then the requirements, family by family, with three methods for each.
Examine. The assessor reads the policy, the procedure and the configuration. Not the summary of the configuration: the identity provider's actual conditional access rules, the firewall's actual rule set, the backup job's actual history.
Interview. The person responsible explains how it works in practice, in their own words. The point is consistency. If the procedure says the office manager offboards accounts within one day and the office manager says IT does it when they get around to it, the control is not met regardless of the document.
Test. Where a control can be exercised, the assessor exercises it. Log in without the second factor and watch it fail. Plug in a USB drive and watch the block. Pull the log for a named action and see the user, the time and the system.
The pace is set by evidence. A shop with an evidence index covers twenty requirements in a morning. A shop hunting for screenshots covers five.
After: findings, the open items window, and the affirmation
The assessor reports each requirement as met or not met, with the objective that failed. If every requirement is met, the result is final. If a limited set of items remains open, the assessment can conclude with those items on a plan of action, and they have to close within 180 days or the result lapses. Some requirements have to be in place for the assessment to conclude at all, so the plan is for finishing a nearly complete program, not for starting one.
A final Level 2 result is valid for three years, with an annual affirmation by a senior official in between. The affirmation is the part that outlives the assessor: it says the controls still work, and it is signed by a named officer of the company.
The five things that end an assessment early
- No System Security Plan, or one that describes a different company. The SSP is a requirement in its own right (CA.L2-3.12.4).
- A boundary that does not hold. CUI found on a laptop, a personal phone or a file share that the diagrams say is out of scope.
- No multifactor authentication, or MFA on administrators only with everyone else on passwords.
- An IT provider or cloud service that handles CUI with no written split of responsibilities. The assessor expects a responsibility matrix for every external provider in scope.
- Policies written for the assessment. Documents dated last month, training records all completed the same afternoon, a log retention setting changed the week before. Assessors read timestamps.
How long, and how much?
C3PAO lead times and fee ranges change. At the time of writing, assessor availability ran months out and the assessment fee for a small company sat in the tens of thousands, which is why the readiness work is where the money is best spent. Our program leadership service runs the preparation from the first gap assessment through the assessment itself.
Questions contractors ask
FAQDo I still need to prepare if the third party requirement is suspended?
Yes. The self assessment, the SPRS score and the affirmation are still required, government led assessments continue, and the suspension review may restore the requirement. Preparation is the same work either way.
Can my IT provider sit in the assessment?
Yes, and they should, for the requirements they operate. The assessor will interview them about their part and will ask for the written split of responsibilities.
What if we fail one requirement?
A limited set of open items can go on a plan of action with a 180 day window. Some requirements cannot be left open. The assessor tells you which during the assessment.
How long is the result good for?
Three years, with an annual affirmation in between.
Is an assessment the same as an audit?
Close. An audit checks a sample. A CMMC assessment covers all 110 requirements and all of their objectives, every time.
Already know you want to talk?
BOOK A CALLSkip the form. Pick a time and talk to us directly.
What happens in 30 minutes
- We learn about your business and the defense contracts you hold or are bidding on.
- We walk you through a gap assessment, the first step toward CMMC, and what it covers.
- If you qualify, we help you apply for an in-kind grant from Cyber Grants Alliance to cover it. No slides.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the work itself, including CMMC Level 1 and Level 2 gap assessments, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.