What does a C3PAO actually ask for on assessment day?

Your SSP, scope, inventory, diagram, provider matrices, and proof for each objective, then a live demonstration. And the usual reasons a requirement fails.

Assessment day, in order. Examine the documents. Interview the people. Test it live. Working guide.
In this guide

A C3PAO asks for your System Security Plan, your scope, and proof for each of the 320 small objectives under the 110 requirements, and then it asks your people to show the controls working on a live screen. Most requirements that fail do so because the proof is missing, still in draft, or contradicted by the system, not because a tool was never bought.

A C3PAO is one of the accredited firms that run the official CMMC Level 2 assessment, the Defense Department's check that a supplier protects CUI (controlled unclassified information, the drawings and technical data the government marks as sensitive). Two documents tell you how the day runs. The Cyber AB, the program's accreditation body, publishes the procedure every C3PAO must follow, the CMMC Assessment Process (CAP), version 2.0, December 2024. DoD publishes what the assessor checks for each requirement, the CMMC Assessment Guide, Level 2, version 2.13, September 2024. Both are current as of this writing. This page walks through them in the order you'll meet them.

A note on timing. DoD suspended the November 2026 phase that would have made C3PAO certificates a routine contract condition (DoW memo, July 13, 2026). C3PAO assessments are still available, and the Cyber AB counts nearly 2,000 contractors already certified at Level 2 Final (Cyber AB statement, July 15, 2026). If a prime wants a certificate from you, this is still the process. What the pause changed

Weeks before: the readiness check

Assessment day starts with a document review. In Phase 1 of the CAP, the assessment team reads your SSP for completeness and consistency, the lead assessor validates your scope against the rule, and the team confirms that evidence and people will be available (activities 1.2 to 1.9). The SSP is the document that describes your system and how each requirement is met. Without a current SSP, the rule says the assessment can't be completed at all (32 CFR 170.24).

Then the lead assessor decides whether you're ready. If you aren't, you get a written explanation and no help. The CAP forbids the C3PAO from offering any advice on how to improve, because doing so would conflict it out of finishing your assessment (activities 1.22 and 1.23). That's the moment a lot of companies discover they paid a deposit to be told "not yet."

What goes in the package

The scoping rule requires every in-scope asset to appear in three places: the asset inventory, the SSP, and a network diagram of the assessment scope (32 CFR 170.19(c), Table 3). The CAP adds the rest. Here's the stack an assessor will expect, roughly in the order they'll touch it.

  1. CAGE codes and company identity. The assessment can't proceed without at least one CAGE code, and the C3PAO confirms the exact legal entity being assessed (CAP P.3 to P.6). If you filed a self-assessment in SPRS, bring its unique identifier.
  2. The SSP, final and signed, describing every system in scope.
  3. The asset inventory, sorted into the rule's categories: CUI assets, security protection assets (the tools and people that protect them), contractor risk managed assets, and specialized assets like test equipment.
  4. The network diagram showing the scope boundary and where CUI moves.
  5. A responsibility matrix from each provider in scope, whether MSP, security firm, or cloud service, listing who does each requirement. The team checks that it's current, names everyone with security duties, and covers every requirement the provider touches (CAP 2.17). The provider's people have to attend (CAP 1.6). How to read one
  6. Cloud authorization proof. For any cloud service holding CUI, the team looks up the exact service offering on the FedRAMP Marketplace or reviews the provider's equivalency package for completeness (CAP 2.20 and 2.21). FedRAMP Moderate equivalency
  7. Policies and procedures, in final form. The Assessment Guide is blunt that drafts are not eligible as evidence (p. 9).
  8. A POA&M, if you have open items. That's a plan of action and milestones, the list of known gaps with dates to close them.
  9. Evidence for each objective, which is the bulk of the work and the rest of this page.

At the end, you'll also hash every artifact used as evidence with a NIST-approved algorithm and hand over the file names and hash values, then keep the files for six years from your certificate date (CAP 3.16). Teams that collected evidence as screenshots pasted into email find this step painful. What evidence counts

Examine, interview, test

Every requirement is checked with some mix of three methods drawn from NIST SP 800-171A, the government's assessment procedures. The CAP requires assessors to use them (activity 2.6), and the Assessment Guide explains how they fit together (pp. 8–9). Examine means reading documents and inspecting configurations. Interview means asking your staff what they do. Test means watching it happen. The guide's own summary is that interviews tell the assessor what staff believe and testing shows what has or has not been done. Then it adds a line every IT lead should tape to the monitor: "Most objectives will require testing."

Take the first access-control requirement, 3.1.1, limiting system access to authorized users and devices. The Assessment Guide lists what the assessor may examine: a list of active accounts with the name of the person behind each, records of recently transferred or terminated employees, a list of recently disabled accounts, and a list of devices authorized to connect (p. 14). It lists who they may interview: whoever manages accounts, system administrators, and security staff. And it lists what they may test: your actual account management process.

So the realistic exchange goes like this. The assessor asks for last quarter's departures from HR. They pick a name. They ask your administrator to open Entra ID or the Google Admin console and show that account's status, group memberships, and sign-in history. If the account is disabled and was disabled on the departure date, that objective holds. If it's enabled, or disabled three weeks late with sign-ins in between, it doesn't, and the policy saying "accounts are disabled on the last day" now works against you. One requirement, worked end to end

Who gets interviewed?

The Assessment Guide names roles, not titles, for each requirement. Translated for a company of 40 people, expect conversations with:

  • your IT administrator or MSP technician, for almost everything technical
  • whoever handles hiring and departures, for personnel screening and termination (3.9.1 and 3.9.2)
  • whoever runs security training, plus a few ordinary users, since the guide lists "the general system user community" for awareness training (3.2.1)
  • whoever would handle an incident, for incident response (3.6.1)
  • facilities or the office manager, for badges, visitors, and locked rooms

Physical security is where on-site visits concentrate. The CAP lists 18 objectives, mostly physical protection and media storage, for the lead assessor to plan in-person checks around, such as escorted visitors and secured paper CUI (activity P.11). If your provider owns a requirement, the provider's person answers for it, and the CAP expects them to show real ownership of it (activity 2.18).

How much do they look at?

They sample. For Level 2, the CAP requires a non-statistical sample at the "focused" value for both depth and coverage, as defined in NIST's assessment method descriptions (activity 2.9). In plain terms: more than a glance, less than every machine. Two rules matter more than the sample size. When the team finds questionable or thin evidence, it should increase the sample (2.10). And when you have several sites or CAGE codes, the sample has to account for all of them (2.11 and 2.12).

Here's the failure scene that follows from that. You have 38 laptops managed in Intune and two that aren't, a loaner and the owner's personal MacBook that he uses for email. The assessor asks for the device list, picks four, and one is the MacBook. Now the sample grows, the device inventory is suspect, and requirements that leaned on "all endpoints are managed" are back on the table.

How a requirement ends up Not Met

The scoring is per objective. Each of the 110 requirements breaks into objectives (3.1.1 has six), and every one must be Met or Not Applicable for the requirement to be Met. "One NOT MET assessment objective results in a failure of the entire security requirement" (Assessment Guide v2.13, p. 10). The assessor documents why the evidence fell short for each one.

The reasons repeat across companies:

  • The evidence is a draft. Unapproved policies and working papers are unacceptable evidence (p. 10).
  • The document and the system disagree. The SSP says screens lock after 15 minutes, and the setting on the sampled laptop says 30.
  • The inheritance claim doesn't hold. The matrix says the MSP owns audit logging, and the MSP's technician can't show the alert for a logging failure.
  • The sample finds an exception nobody listed, like the MacBook above.
  • The control is close but not exact. Encryption is on, but the module isn't FIPS-validated, and the guide says using an approved algorithm "is not sufficient" when the module itself lacks validation (p. 234).

DoD's own assessors published which requirements fail most. In a 2022 briefing, DCMA's DIBCAC listed FIPS-validated encryption (3.13.11), multi-factor authentication (3.5.3), flaw remediation (3.14.1), risk assessment (3.11.1), and vulnerability scanning (3.11.2) as the top five, followed by three audit logging requirements, incident response testing, and baseline configuration (DCMA DIBCAC briefing, Oct. 26, 2022). Most of those are things you do on a schedule, which means proving them takes dated records, not a configuration screenshot.

Two escape valves exist. A Not Met requirement can be re-evaluated during the assessment and for 10 business days after, if you have additional evidence, the fix doesn't weaken anything already scored Met, and the findings report hasn't been delivered (32 CFR 170.17(c)(2)). And some gaps can go on a POA&M for a Conditional status, but only if you score at least 88 of 110, only for 1-point requirements (plus non-FIPS encryption at 3 points), and never for the six requirements the rule excludes, the SSP among them. You then have 180 days to close it out (32 CFR 170.21). How the scores add up

After the last interview

The team holds a checkpoint meeting at the end of each day (CAP 2.23). At the out-brief, you get Met, Not Met, or Not Applicable for every requirement, and whether a certificate will be issued. The briefing may not include any suggested fixes (3.15). If you disagree, you appeal first to the same C3PAO, then to the Cyber AB within 15 business days of its decision (3.23 to 3.28). A certificate is signed by the C3PAO's authorized certifying official, not by the assessor who ran your interviews (4.3).

Questions people ask before booking

Can we fix something mid-assessment? Yes, within the re-evaluation rule above. Bring the new evidence before the findings report goes out.

Will the assessor tell us how to fix a finding? No. The CAP prohibits remedial advice at every stage. That's what the months before the assessment are for.

Do we have to send CUI to the assessor? Not over a virtual session. The CAP says CUI isn't shared electronically during a virtual assessment unless both sides' environments meet Level 2 (activity 2.7). Expect to show it on screen or in person.

Does a passing self-assessment score carry over? No. The C3PAO scores you from scratch, though it will ask for your SPRS identifier. Keeping the SSP and the score on the same scope

How do we know where we'll fail? Run the same check first. Garde1 runs a mock assessment, a practice run that doesn't certify anyone, against all 110 requirements and their 320 objectives. It reads the live settings in tools like Microsoft 365, Entra ID, Intune, and Google Workspace, so the 30-minute screen lock and the unmanaged MacBook show up in your findings before they show up in a sample. What a mock should test

Mock assessment

Hear the Not Met before the assessor says it.

Garde1 runs a mock assessment objective by objective against your real configuration, and every finding names the account, device, or setting to fix.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE