- CMMC Assessment & Audit: Types, Process, and How to Prepare
- CMMC Assessment vs CMMC Audit
- Types of CMMC Assessment
- Self-Assessment, C3PAO Assessment, or DIBCAC: Which Path Applies Now
-
CMMC Assessment Process
- Step 1 — Define the CMMC Assessment Scope
- Step 2 — Run a Gap Assessment
- Step 3 — Build a POA&M and Remediate
- Step 4 — Document the SSP and Collect Evidence
- Step 5 — Run a Readiness Assessment
- Step 6 — Complete the Self-Assessment or C3PAO Assessment
- Step 7 — Close out POA&M Items within 180 Days
- Step 8 — Submit the Annual Affirmation
- Common Challenges with CMMC Assessments
- CMMC Level 2 Assessment
- CMMC Mock Assessments, Pre-Assessments, and the Joint Surveillance Reciprocity Path
- How to Operationalize CMMC Readiness
- Key Takeaways
-
CMMC Assessment & Audit FAQs
- What Is a CMMC Assessment?
- What Is the Difference Between a CMMC Assessment and a CMMC Audit?
- What Are the Steps in the CMMC Assessment Process?
- Who Performs a CMMC Assessment?
- What Is the Difference Between a Self-Assessment and a C3PAO Assessment?
- What Is the Difference Between a Gap Assessment and a Readiness Assessment?
- What Is a CMMC Mock Assessment?
- What Is the CMMC Joint Surveillance Assessment (JSVA)?
- How Much Does a CMMC Audit Cost?
- How Long Is a CMMC Certification Valid?
- Is a CMMC C3PAO Audit Required Right Now?
CMMC Assessment & Audit: Types, Process, and How to Prepare
A CMMC audit is the common name for a CMMC assessment, the formal evaluation that checks whether a defense contractor meets the cybersecurity requirements tied to its Cybersecurity Maturity Model Certification (CMMC) level. Because CMMC has three levels, three assessment paths exist:
- Level 1 and Level 2 can be met through a self-assessment the contractor runs in-house.
- A Level 2 certification is the pass/fail evaluation an authorized third-party organization performs, the step most people mean by “audit.”
- The government assesses Level 3.
On July 13, 2026, the Department of Defense suspended CMMC Phase II. During the interim review, contracting officers may require only self-assessments, which is the path most contractors are already on.
This guide explains what a CMMC assessment and audit are, who performs each, the types of assessment, the step-by-step process, what happens inside a Level 2 assessment, how to prepare, and the mock and Joint Surveillance options that sit around the formal event.
CMMC Assessment vs CMMC Audit
“Assessment” is the CMMC program’s official term, and “audit” is the everyday word for the formal, pass/fail Level 2 evaluation that only a C3PAO performs.
CMMC assessments evaluate how well a defense contractor meets the cybersecurity requirements tied to its CMMC level. Level 1 and Level 2 self-assessments happen in-house, an authorized third-party organization (C3PAO) conducts the pass/fail Level 2 audit, and the government’s DIBCAC assesses Level 3. Each requirement is scored as met, not met, or not applicable.
Ultimately, the two words point to different activities with different stakes.
- CMMC assessment: An internal or consultant-run assessment is diagnostic, focuses on finding gaps, carries no penalty, and typically costs a few thousand dollars.
- CMMC audit: A CMMC audit recurs every three years for Level 2 and Level 3 and commonly runs from $30,000 upward depending on scope.
The people involved differ, too. A CMMC auditor is a Certified CMMC Assessor (CCA) working under an authorized CMMC Third-Party Assessment Organization (C3PAO), and the government’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assesses Level 3. As of May 2026, roughly 104 authorized C3PAOs and 988 CCAs served the entire Defense Industrial Base, according to Secureframe, a small third-party capacity relative to the contractor base.
But the rules that underpin the program still apply in full:
- 32 CFR Part 170 took effect December 16, 2024.
- The 48 CFR/DFARS acquisition rule took effect November 10, 2025.
Likewise, DFARS 252.204-7012 and the underlying NIST SP 800-171 Rev 2 obligations remain in force.
Types of CMMC Assessment
CMMC has three official, level-based assessment paths, plus two diagnostic activities most contractors run before any official event.
The three official paths follow the levels directly:
- Level 1 is an annual self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21.
- Level 2 is a self-assessment or a C3PAO assessment against the 110 requirements of NIST SP 800-171 Rev 2, incorporated by reference in 32 CFR §170.14, which break down into roughly 320 assessment objectives.
- Level 3 is a government-led DIBCAC assessment against a selected subset of 24 NIST SP 800-172 enhanced requirements.
The first step is a gap assessment. It measures current posture against the 110 practices, then produces an estimated Supplier Performance Risk System (SPRS) score and a prioritized Plan of Action and Milestones (POA&M).
Later comes a readiness assessment. It simulates the C3PAO process through a System Security Plan (SSP) completeness review, evidence verification, staff interviews, and mock walkthroughs. Like an internal rehearsal, its findings guide remediation before the official assessment.
Self-Assessment, C3PAO Assessment, or DIBCAC: Which Path Applies Now
Each assessment type maps to CMMC level and assurance.
- Level 1 and self-eligible Level 2 are self-assessed by the contractor.
- Higher-assurance Level 2 is assessed by an accredited C3PAO for CUI that demands third-party assurance.
- Level 3 is assessed by the government’s DCMA DIBCAC.
| Path | Who performs it | Standard assessed | Outcome | Frequency | Required under the July 2026 interim? |
|---|---|---|---|---|---|
| Self-assessment (Level 1, Level 2 Self) | The contractor, in-house | L1: 15 FAR 52.204-21 requirements; L2: 110 NIST SP 800-171 Rev 2 requirements | Self-reported SPRS score plus affirmation | L1 annual; L2 every 3 years, plus annual affirmation | Yes, the only path a contracting officer may require now |
| C3PAO assessment (Level 2 Certification) | An authorized C3PAO, staffed by CCAs | 110 NIST SP 800-171 Rev 2 requirements / 320 objectives | Pass/fail certification | Every 3 years, plus annual affirmation | No, suspended during the interim |
| DIBCAC assessment (Level 3) | The government’s DIBCAC | A subset (24) of NIST SP 800-172 | Government-led determination | Every 3 years | No, suspended during the interim |
However, the regulatory state that governs which path a contract can require changed in mid-2026. Following the July 13, 2026 suspension of CMMC Phase II, contracting officers may include only Level 1 (Self) or Level 2 (Self) requirements. They may not require a Level 2 C3PAO assessment or a Level 3 DIBCAC assessment during the interim. But the requirement could return in a modified form after the review.
The DoD implementation memorandum also directs program managers to strip those designations from active solicitations and issue contract modifications, per Morgan Lewis, and existing solicitations are being amended accordingly. Still, an inaccurate self-assessment carries False Claims Act exposure.
CMMC Assessment Process
The CMMC assessment process runs as an ordered sequence, with each stage feeding the next. Scoping decisions made first constrain everything downstream, which is why early errors cost the most to correct late.
The following steps are designed to move teams from defining the environment to actually filing the annual affirmation.
Step 1 — Define the CMMC Assessment Scope
Identify every asset, user, and system that stores, processes, or transmits FCI or CUI, and categorize assets into the types set out in 32 CFR §170.19(c): CUI Assets, Security Protection Assets, Specialized Assets, and External Service Providers. This boundary shapes every later stage.
Step 2 — Run a Gap Assessment
Measure current posture against the 110 practices and generate an estimated SPRS score plus a prioritized POA&M.
Step 3 — Build a POA&M and Remediate
Prioritize the gaps, assign owners, and fix them.
Step 4 — Document the SSP and Collect Evidence
Capture the System Security Plan and gather retrievable, timestamped, final-form evidence for each objective, since assessors accept only approved, final versions.
Step 5 — Run a Readiness Assessment
Simulate the C3PAO process to confirm the environment would hold up.
Step 6 — Complete the Self-Assessment or C3PAO Assessment
Take the official path the contract requires.
Step 7 — Close out POA&M Items within 180 Days
Remediate any conditional findings inside the allowed window.
Step 8 — Submit the Annual Affirmation
File the affirmation of continuous compliance in SPRS through PIEE and keep evidence current, an obligation set by DFARS 252.204-7021.
Common Challenges with CMMC Assessments
Most failed CMMC assessments share the same bottleneck: preparation. In fact, only about 1% of contractors felt fully prepared for CMMC, with a median self-assessment score of 60 out of 110, according to the State of the DIB 2025 report.
Common challenges with CMMC include:
- Incomplete asset inventory: Systems in scope get missed.
- Overlooked Security Protection Assets: Assets that provide security functions to the environment go uncounted.
- Weak shared-responsibility documentation: The Customer Responsibility Matrix does not spell out who does what with external service providers.
- Scattered or untimestamped evidence: An assessor cannot retrieve it on request.
- “Paper” training and incident-response programs: They exist as policy but were never run.
Scoping is another area where many budgets slip. Often, it’s because a VLAN, a folder permission, or encryption alone falls short of the enclave separation the rule requires. That misunderstanding alone ranks among the most expensive in CMMC scoping, according to The Defense Compliance Report.
CMMC Level 2 Assessment
A Level 2 certification assessment follows the CMMC Assessment Process (CAP) v2.0, the procedural guide the Cyber AB published in December 2024 for C3PAOs. CAP defines Preliminary Proceedings plus four phases:
- Pre-Assessment. The lead assessor reviews the SSP, validates scope, and confirms the readiness of evidence.
- Assess Conformity. The team evaluates every requirement against its objectives.
- Report Assessment Results. Findings and the score are documented and recorded.
- Issue Certificate and Close-Out POA&Ms. The certificate issues and any eligible open items are tracked to closure.
In the Assess Conformity phase, the team evaluates all 110 requirements using the examine, interview, and test methods defined in NIST SP 800-171A, which decompose the 110 Level 2 requirements into 320 assessment objectives. The “assessment questions” contractors ask about are the assessor’s objective-mapped questions in this phase.
Each requirement is scored MET, NOT MET, or NOT APPLICABLE under 32 CFR §170.24, and a MET score requires final-form evidence, so assessors accept only approved, final documents. Because the assessment is binary, every requirement is scored met or not. So, a single unimplemented requirement can stop a certification.
Plus, the scoring gate is strict:
- A Level 2 assessment passes at 80%, or 88 of 110 requirements, per the DoD’s CMMC 101.
- A conditional pass is allowed only when the remaining gaps are POA&M-eligible one-point items, closed within 180 days.
- A three-point or five-point failure fails the assessment outright.
CMMC Mock Assessments, Pre-Assessments, and the Joint Surveillance Reciprocity Path
A mock assessment, also called a pre-assessment or readiness assessment, is a full dry run of the formal C3PAO assessment. It works through the SSP, reviews evidence, interviews staff, and walks the controls to surface gaps before the real assessment.
The Joint Surveillance Voluntary Assessment (JSVA) is a reciprocity path. Here, a C3PAO team paired with a DCMA DIBCAC team conducts a single assessment whose result can support a Level 2 certification. To qualify, a company holds an active DoD contract as a prime or a subcontractor. The C3PAO submits the request to the Cyber AB, and DIBCAC then adds the company to the JSVA queue. The assessment typically runs five business days over a standard artifact set:
- System Security Plan (SSP)
- CUI-boundary data-flow diagram
- Asset categorization
- 14-domain policies
- Customer Responsibility Matrix (CRM)
- Vendor service-level agreements (SLAs)
JSVA and DIBCAC availability during the Phase II suspension is unsettled, so confirm the current DIBCAC posture before relying on an open Joint Surveillance queue.
How to Operationalize CMMC Readiness
Operationalizing CMMC readiness means running structured assessments against the 110 requirements and keeping defensible evidence between events. This is the exact work most contractors try to manage in spreadsheets.
Isora GRC is the collaborative GRC Assessment Platform™ that gives security teams one shared workspace to run assessments, manage vendors and assets, track live risks, and publish audit-ready reports. It supports the gap, readiness, and self-assessment stages, and the same evidence package later supports review by a C3PAO or DIBCAC. However, Isora GRC does not perform the official C3PAO assessment, act as a C3PAO, or issue a CMMC certification.
Questionnaires & Surveys
Run a framework-aligned CMMC self-assessment with prebuilt, customizable questionnaires, and attach evidence directly to each response. Multiple contributors can add answers, upload evidence, and route items for sign-off, which keeps the documentation behind a score in one place and cuts the time spent assembling it later.
Risk Management
Publish each gap directly from an assessment as a tracked risk with full context attached, so the Plan of Action and Milestones builds as the work progresses instead of after it.
Reports & Scorecards
Generate scorecards from live assessment data and drill down from a summary score to individual responses and evidence, so gaps surface before a formal C3PAO or DIBCAC assessment.
See how Isora GRC simplifies CMMC assessments →
Key Takeaways
The most useful next move for most contractors is to run a gap assessment against the 110 NIST SP 800-171 Rev 2 practices, then close the gaps and organize the evidence before any official event. That single step reveals the estimated SPRS score and shows where a team sits on the readiness roadmap.
Because the July 2026 Phase II suspension leaves only the self-assessment paths in play for now, a thorough self-assessment and a defensible evidence trail are exactly what a contract can require today.
The process itself is an ordered path: scope the environment, gap-assess, remediate and build evidence, run a readiness assessment, complete the self- or C3PAO assessment, then submit the SPRS score and affirm. Scoping comes first because everything downstream depends on it, and the underlying NIST SP 800-171 Rev 2 controls stay in force throughout the interim.
See the GRC Assessment Platform in action →
CMMC Assessment & Audit FAQs
What Is a CMMC Assessment?
A CMMC assessment evaluates whether a defense contractor’s system meets the security requirements for its required CMMC level. Level 2 assessments check the 110 requirements of NIST SP 800-171 Rev 2 across 14 families. Each requirement is scored MET, NOT MET, or NOT APPLICABLE.
What Is the Difference Between a CMMC Assessment and a CMMC Audit?
“Assessment” is the program’s official term, and “audit” is the common name for the formal, pass/fail Level 2 evaluation. Internal or consultant-run assessments are diagnostic and carry no penalty. A CMMC audit is conducted by a certified third-party organization (C3PAO), produces a pass/fail result, and determines eligibility to hold Level 2 contracts.
What Are the Steps in the CMMC Assessment Process?
The process runs in order: scope the environment, run a gap assessment, remediate and build evidence, run a readiness assessment, complete the self-assessment or C3PAO assessment, then submit the score in SPRS and file the annual affirmation. Each stage feeds the next, so scoping errors early are the most expensive to fix late.
Who Performs a CMMC Assessment?
It depends on the level. Level 1 and self-eligible Level 2 assessments are conducted by the contractor; higher-assurance Level 2 assessments are conducted by an accredited C3PAO using Certified CMMC Assessors (CCAs); Level 3 is assessed by the government’s DCMA DIBCAC.
What Is the Difference Between a Self-Assessment and a C3PAO Assessment?
In a self-assessment the contractor evaluates its own system and submits an affirmation in SPRS. In a C3PAO assessment, an independent accredited organization examines, interviews, and tests all 110 requirements and records the certification result in CMMC eMASS. A C3PAO cannot assess an organization it also consulted for.
What Is the Difference Between a Gap Assessment and a Readiness Assessment?
A gap assessment is the first diagnostic step: it compares current posture against the 110 NIST SP 800-171 Rev 2 practices and produces an SPRS score estimate and a prioritized POA&M. A readiness assessment comes later and simulates the C3PAO audit itself, reviewing the System Security Plan, verifying evidence, and running mock interviews. The recommended sequence is gap assessment, remediation, readiness assessment, then the formal assessment.
What Is a CMMC Mock Assessment?
A mock assessment, also called a pre-assessment or readiness assessment, is a full dry run of the formal C3PAO assessment. It reviews the SSP and evidence, interviews staff, and walks through the controls to surface gaps before the real assessment. The same C3PAO can run both the mock and the formal assessment without a conflict of interest.
What Is the CMMC Joint Surveillance Assessment (JSVA)?
The Joint Surveillance Voluntary Assessment pairs a C3PAO team with a DCMA DIBCAC team to conduct one assessment whose result can support a Level 2 certification. To qualify, a company must hold an active DoD contract. The assessment typically takes about five business days over the standard artifact set.
How Much Does a CMMC Audit Cost?
The DoD Regulatory Impact Analysis estimates a Level 2 C3PAO assessment at roughly $105,000–$118,000 over three years, versus about $37,000–$49,000 for a Level 2 self-assessment; these figures cover the assessment and reporting only, not the cost of implementing controls. Third-party audits are commonly quoted from $30,000 upward depending on scope.
How Long Is a CMMC Certification Valid?
A Level 2 or Level 3 CMMC assessment result is valid for three years, with an annual affirmation of continuous compliance submitted in SPRS in the intervening years. Level 1 requires an annual self-assessment and affirmation.
Is a CMMC C3PAO Audit Required Right Now?
Not currently. On July 13, 2026, the Department of Defense suspended CMMC Phase II, so contracting officers may include only Level 1 (Self) or Level 2 (Self) requirements and may not require a Level 2 C3PAO audit or a Level 3 DIBCAC assessment during the interim review. The underlying DFARS 252.204-7012 and NIST SP 800-171 Rev 2 obligations remain in force.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.