CMMC Compliance

What a C3PAO Actually Checks in a CMMC Level 2 Assessment

By Christina Sentry · 2026-07-02

The assessment process is not a mystery. A Certified CMMC Assessor walks through what the team reads first, what they ask your staff, and where contractors lose points.

The assessment process is not a mystery. Contractors who treat it as one arrive underprepared. Those who understand what a C3PAO assessment team actually does — what they read, who they talk to, and what evidence they're looking for — show up with the right materials, answer questions clearly, and finish faster.

This is a practical walkthrough of a Level 2 assessment from the assessor's perspective. The goal is to remove the uncertainty so you can prepare for the process that actually happens, not the one you imagine.

Before the On-Site Visit: Document Review

Every CMMC Level 2 assessment begins with a document review, typically conducted remotely in the weeks before the on-site visit. The assessment team requests a set of core documents. What they're looking for at this stage:

The System Security Plan (SSP) is read first and in full. The team uses it to understand your scope, your architecture, and your claimed implementation for all 110 NIST SP 800-171 practices. They're not checking whether you have an SSP — they're reading it critically. Assessors mark practices where the description is vague, inconsistent with other documents, or claims implementation that seems unlikely given the size or nature of your organization.

Network and data flow diagrams are cross-referenced against the SSP scope section. If your SSP says CUI lives in three systems and your diagrams show those three systems plus a cloud storage service you didn't mention, the assessor notes the discrepancy. Scope boundary questions raised in document review become interview questions on-site.

Policies and procedures are reviewed for the practices that require them. The CMMC Assessment Guide (CAG) specifies which practices have a policy requirement. Assessors confirm the policies exist, are approved by management, and address the required elements. A policy dated five years ago that hasn't been reviewed raises a flag; policies that don't include required content (like a configuration management policy missing the baseline configuration requirement) are marked as partially implemented.

The Plan of Action and Milestones (POA&M) is reviewed for credibility. Are the open items realistic? Are the milestone dates in the past with no update? Does the scope of open items suggest the organization hasn't fully engaged with the requirements? A well-maintained POA&M with realistic near-term closure dates is evidence of a functioning compliance program.

On-Site Day 1: Briefing and Initial Interviews

The first on-site day typically opens with a briefing. You present your environment, your scope, and your organization structure. The assessment team lead will use this session to validate their document-review impressions and clarify any open questions about your architecture.

After the briefing, the team splits across interview tracks. CMMC Level 2 assessments use three types of examination: examine (review of documents and system configurations), interview (discussions with personnel), and test (direct technical testing of controls). Most assessors run all three in parallel throughout the engagement.

Who gets interviewed and what they're asked

Assessors don't only talk to IT staff. They interview whoever is responsible for implementing each control domain — which at many small and mid-size contractors means talking to the system administrator, the HR coordinator (for AT practices), the finance or operations lead (for physical security practices at non-IT staff), and at least one end user.

Common interview questions by domain:

Access Control (AC): "Walk me through how a new employee gets access to systems that contain CUI." "Who approves access requests?" "When was the last time you reviewed user access to confirm terminated employees are removed?" "Can you show me where you configure role-based access?"

Awareness and Training (AT): "When did your last security awareness training occur?" "How do you track who has completed it?" "What does your training cover regarding CUI handling?"

Configuration Management (CM): "What is your baseline configuration for a standard workstation?" "How do you manage software installations — can users install software themselves?" "Walk me through what happens when someone requests a change to a production system."

Incident Response (IR): "If an employee reported a suspected phishing email that may have exposed CUI, what would happen next?" "Who is your incident response coordinator?" "Have you had any incidents in the past year, and can you show me how they were documented?"

The goal of these interviews is not to trick you. Assessors are looking for evidence that the controls described in your SSP are actually operating — that real people are executing real processes, not that a document exists saying they should.

On-Site Technical Testing

Technical testing covers the practices where documentation and interview are insufficient to confirm implementation. Common areas:

Access control configurations are verified directly. An assessor may request access to your identity provider (Active Directory, Azure AD, Okta) to review user accounts, group memberships, and disabled account status for terminated employees. They'll look for accounts with excessive privilege, shared accounts, or accounts for personnel whose employment ended without access being revoked.

System hardening and configuration baselines are spot-checked against your documented baseline. An assessor may pull configuration settings from a sample of workstations or servers to verify that CIS benchmark settings or your custom baseline are actually applied. They're looking for consistency — a policy that says all systems are hardened but a sample that shows default configurations is a problem.

Audit log configuration is examined to confirm that log collection is active, covers the required event types (logon/logoff, privilege use, configuration changes), and that logs are being retained for the required period and protected from modification.

Boundary protection is verified through firewall rule review or network scan. Assessors are looking to confirm that your network perimeter is configured as documented — that CUI systems aren't exposed to systems outside your assessment boundary in ways your SSP doesn't account for.

Where Contractors Lose Points Most Often

Based on patterns across assessments, these are the domains where findings are most frequent:

Configuration Management — specifically CM.2.062 (establish and maintain baseline configurations) and CM.2.064 (define, document, and enforce security configuration settings). Most contractors have policies but lack a maintained, documented baseline that maps to actual system configurations.

Risk Assessment — RA.2.141 through RA.2.143. Contractors often don't have a documented risk assessment process or can't demonstrate they've conducted one within a reasonable timeframe. Risk assessments exist as a one-time deliverable but aren't treated as a recurring practice.

System and Communications Protection — SC.3.177 (employ FIPS-validated cryptography) frequently surfaces gaps. Contractors using older VPN configurations, self-signed certificates, or non-FIPS validated encryption for CUI in transit lose points here.

Incident Response testing — IR.2.093 requires that you test your incident response capability. Many contractors have an IR plan but have never run a tabletop exercise or simulated scenario. "We have a plan" is partial implementation; "we test the plan" is full implementation.

What Makes an Assessment Go Smoothly

Assessors are not adversaries. They are following the CMMC Assessment Guide, evaluating evidence against defined criteria, and scoring what they find. The contractors who complete assessments most efficiently have a few things in common:

They have a dedicated point of contact who knows the SSP, can locate any policy or evidence file quickly, and can connect assessors with the right personnel for interviews without delays.

They organize their evidence before the assessment begins — by practice or control domain — so that when an assessor asks for evidence of AC.2.006 implementation, it can be produced in minutes, not hours.

They brief their staff before the assessment. Employees who know that an assessment is occurring and understand that it's not a disciplinary review answer questions directly and without anxiety. Employees caught off-guard by an assessor's question tend to over-explain or give inconsistent answers.

They treat gaps as gaps. If a control isn't fully implemented, they say so, show the POA&M entry, and explain the remediation timeline. Assessors notice when an organization tries to oversell partial implementation — and it creates more scrutiny, not less.

A CMMC Level 2 assessment takes between two and five days on-site for most contractors, followed by a reporting period. The organizations that clear it in two to three days are those who prepared the way their assessors are trained to assess — by practice, by evidence type, and by domain.

If you're preparing for an upcoming assessment and want an independent readiness review conducted by a Certified CMMC Assessor, contact Cipher Sentinel.