What Does the CMMC Assessment Process Look Like, From Beginning to End?

What Does the CMMC Assessment Process Look Like, From Beginning to End?

Key Takeaways

  • This article covers the Level 2 assessment process conducted by a Certified Third-Party Assessment Organization (C3PAO), the path most controlled unclassified information (CUI)-handling contractors will follow.
  • The process runs through seven stages: scoping, gap assessment, remediation, mock assessment, C3PAO selection, the formal assessment and certification.
  • A C3PAO evaluates each of the 110 NIST SP 800-171 controls using three methods: examine, interview and test.
  • Organizations that score at least 88 out of 110 and meet every specified must-pass control can receive a Conditional status, with any remaining gaps closed through a Plan of Action and Milestones (POA&M) within 180 days.
  • A CMMC Level 2 certification stays valid for three years, but it requires an annual affirmation of continuous compliance within that timeframe.
  • An outdated System Security Plan (SSP), unresolved POA&M items and confusion over which Microsoft cloud environment is required are among the most common reasons assessments stall.

Note: As of July 13, 2026, the Department of War suspended CMMC Phase 2 pending a 60-day program review. Third-party C3PAO certification isn’t currently mandatory for new contracts, but Level 1 and Level 2 self-assessment requirements are unchanged, so the guidance below still applies to organizations preparing for Level 2 certification today.

Most contractors now know they need Cybersecurity Maturity Model Certification (CMMC) certification. Far fewer have a clear picture of what the assessment itself involves, which stages take the longest or where organizations typically get tripped up.

This article walks through the CMMC Level 2 process from the first scoping conversation to the certificate that lands in your SPRS record, so you know what to expect and how to prepare. Level 1 contractors handling only Federal Contract Information (FCI) complete a simpler annual self-assessment and Level 3 contractors handling the most sensitive CUI go through a government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) instead of a C3PAO.

The CMMC Level 2 Assessment Timeline at a Glance

Stage What Happens Typical Duration
1. Scoping Define the CUI boundary and which systems fall inside it Several weeks
2. Gap assessment Compare current controls against all 110 requirements Four to eight weeks
3. Remediation Close identified gaps and update documentation Two to six months, depending on findings
4. Mock assessment Rehearse the real assessment and surface remaining issues One to two weeks
5. C3PAO selection Choose and contract with an authorized assessor Nine to twelve months in advance (ideally)
6. Formal assessment C3PAO conducts the certification assessment Four to eight weeks, including a multi-day on-site or virtual review
7. Certification Certificate issued, POA&M closeout if needed Certification valid three years, with annual affirmations

The stages below unpack each of these in more detail, along with the specific things that tend to add unplanned time to the schedule.

Stage 1: Scoping the Assessment Boundary

Scoping is the process of identifying every system, network segment and group of people that handle CUI in any capacity, then drawing a clear line around what falls inside that boundary versus what doesn’t. Get this step wrong and everything downstream gets harder: an under-scoped boundary leaves CUI outside the protected environment, while an over-scoped boundary drags unrelated systems into an assessment that did not need to include them.

A thorough scoping exercise produces a data flow diagram showing how CUI enters, moves through and exits the environment, along with a network diagram showing how in-scope systems connect to each other and to anything outside the boundary. Red River’s guide to what CMMC compliance requires walks through how this boundary-setting exercise fits into the broader certification path.

Once scoping is complete, most environments fall into a handful of asset categories:

  • CUI assets handle the sensitive data directly.
  • Security protection assets, like firewalls and logging systems, defend that data without touching it themselves.
  • Contractor risk managed assetsare not intended to store, process or transmit CUI, but they sit close enough to the boundary that the organization should apply documented, risk-based controls to them rather than treating them as full CUI assets.

Getting these categories right early prevents a common and expensive mistake: discovering during the formal assessment that a system everyone assumed was out of scope was in scope all along.

Stage 2: Running the Gap Assessment

With the boundary defined, the next step is comparing your current environment against all 110 security requirements in the National Institute of Standards and Technology (NIST) SP 800-171. This step produces two concrete outputs: a detailed list of which controls are fully implemented, partially implemented or missing, plus an honest NIST SP 800-171 score reflecting where the organization stands today.

Teams should document every unmet or partially met control in a POA&M, along with a target date and an assigned owner for closing it. Organizations sometimes treat the gap assessment as a formality and rush through it, but a shallow gap assessment here simply pushes discovery of the same problems into the formal C3PAO assessment later, at a point where surprises are far more expensive.

Stage 3: Closing Gaps Through Remediation

Remediation is where the real security work happens. Teams implement the missing technical controls, whether that means deploying multi-factor authentication, tightening access management, improving logging or closing configuration gaps, while simultaneously updating the SSP to describe the environment as it will exist going forward.

This stage typically takes the longest of the seven and the timeline depends entirely on how many gaps the assessment surfaced and how deeply existing systems have embedded them. Organizations should prioritize remediation by risk and by how heavily the assessment methodology weights a given control, rather than working through the POA&M in whatever order is administratively convenient.

At this stage, documentation matters just as much as technical work. An SSP that accurately reflects every implemented control, written in language that matches what staff will say in an interview later, is just as important as the control itself. Organizations that treat the SSP as a one-time deliverable rather than a living document tend to find it drifting out of sync with reality within months, which becomes a problem the moment a C3PAO starts asking questions.

Stage 4: The Mock Assessment or Readiness Review

A mock assessment is a rehearsal of the real thing, typically run by an internal team or a Registered Provider Organization (RPO), that simulates how a C3PAO would examine, interview and test the environment. This process is deliberately the last checkpoint before engaging a C3PAO and it is where many organizations discover late-stage surprises they assumed were already resolved.

Running interviews with the same staff who will speak to assessors later, rather than only reviewing documentation, is what separates a useful mock assessment from a paperwork exercise. Staff who have never had to explain a control out loud often struggle the first time, even when the underlying control is correctly implemented. A rehearsal gives them a low-stakes opportunity to build fluency before it really counts.

The most common finding at this stage is a contradiction between what the SSP describes and what staff say or do when interviewed. An on-paper control that looks as if it is correctly implemented can quickly fall apart if the person responsible for it cannot describe how it works in practice.

Stage 5: Selecting and Engaging a C3PAO

Only a Cyber AB-authorized C3PAO can conduct a Level 2 certification assessment and choosing one is a decision worth making early rather than at the last minute. With roughly ~100 authorized C3PAOs serving a Defense Industrial Base (DIB) of more than 100,000 contractors requiring Level 2 certification, scheduling backlogs are real and growing. Starting the selection process 9 to 12 months ahead of a target certification date is a reasonable rule of thumb.

The conflict-of-interest rule matters most at this stage. Federal rules prohibit the same organization from both preparing you for certification and formally assessing you, so the RPO or consultant that ran your gap assessment and remediation cannot also serve as your C3PAO. When evaluating C3PAOs, confirm active authorization on the Cyber AB Marketplace, ask how many Level 2 assessments the firm has completed and request a clear breakdown of pricing and expected timeline before signing anything.

Be skeptical of any C3PAO that promises a specific completion date, guarantees priority scheduling or claims to be “almost authorized.” Legitimate assessors cannot control how quickly the Cyber AB processes results or where your organization falls in the broader scheduling queue. Vague promises along those lines are a warning sign worth taking seriously.

Stage 6: The Formal C3PAO Assessment

The Formal C3PAO Assessment

The formal assessment follows the methodology in NIST SP 800-171A, which defines three methods for evaluating each control:

  • Examine involves reviewing documentation and system configurations.
  • Interview means talking to the personnel responsible for implementing a control to confirm they understand and follow it.
  • Test requires observing a control in operation to confirm it works as described, rather than relying only on what staff said about it during the interview.

The on-site or virtual interview portion typically runs three to five days, though the full engagement, including pre-assessment document review, the interview period and final reporting, commonly spans four to eight weeks from start to finish. Each of the 110 controls is scored as Met, Not Met or Not Applicable and the C3PAO submits results to the CMMC Enterprise Mission Assurance Support Service (eMASS) system.

An organization that meets every specified critical requirement and reaches a minimum score of 88 out of 110 can receive a Conditional Level 2 (C3PAO) status, with any remaining gaps documented in a POA&M for closure. Falling short of that threshold or missing one of the requirements the rule treats as non-negotiable generally means no certificate at all rather than a conditional one.

Assessors also pay close attention to how cloud and managed service providers fit into the picture. Where part of the environment runs on an external cloud platform, the C3PAO verifies that a Customer Responsibility Matrix clearly documents which controls the provider covers and which remain the contractor’s responsibility, along with confirming the provider carries the appropriate Federal Risk and Authorization Management Program (FedRAMP) authorization. A missing or vague responsibility matrix is a common source of findings, since it leaves the assessor unable to confirm who is accountable for a given control.

Stage 7: Certification and Ongoing Compliance

Once the C3PAO issues a Final or Conditional certificate, that status gets uploaded to eMASS and becomes visible to contracting officers evaluating your eligibility for CUI-handling contracts. A Conditional status becomes Final once the organization closes out its POA&M items within 180 days; missing that window can terminate the conditional status entirely and require a fresh assessment.

Certification itself is valid for three years, but that is not the end of the compliance obligation. An affirming official must submit an annual affirmation of continuous compliance in the Supplier Performance Risk System (SPRS) for as long as the certification remains active, confirming the environment still satisfies the requirements of its certified CMMC level. That three-year cycle also runs alongside the CMMC certification timeline’s broader phased rollout, so a certification earned under today’s requirements may need to satisfy a stricter phase by the time it comes up for renewal.

What Commonly Delays or Derails an Assessment?

A handful of recurring issues account for most of the assessments that run long or fail outright.

  • An SSP that does not match real practice. The single fastest way to earn a Not Met on an otherwise solid control is a written SSP describing it one way while interviews or system evidence reveal it works differently on the ground.
  • Unresolved POA&M items with no real closure plan. A POA&M with vague dates and no assigned owner signals to an assessor that gaps are tracked rather than fixed.
  • Scope creep. Systems added to the environment after the scoping was finalized, without updating the boundary documentation, create gaps between what was assessed and what needs protecting.
  • Confusion between Microsoft GCC and GCC High. Standard Microsoft 365 GCC can support many Level 2 environments handling ordinary CUI, but it does not meet the requirements for export-controlled data under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). Organizations that assume GCC covers everything sometimes discover during the assessment that specific data types needed GCC High all along, which can mean a costly late-stage tenant migration.

Getting Ready for Your Assessment

The CMMC Level 2 process rewards organizations that treat the certification as a structured, multi-month project rather than a single event to schedule and pass. Every stage before the formal assessment exists to make sure that when the C3PAO arrives, there are no surprises left to find.

Organizations that compress these stages, skipping the mock assessment or treating scoping as a formality, tend to pay for it later in the form of findings that could have surfaced months earlier at a fraction of the true cost of CMMC compliance done right the first time.

Our team holds dual Cyber AB accreditation as both an RPO and a C3PAO and brings years of hands-on experience guiding contractors of every size through NIST SP 800-171 and CMMC Level 2.

Red River helps defense contractors move through every stage of this process, from initial scoping and gap assessment through remediation and mock assessment. Consistent with the conflict-of-interest rule covered above, we do not serve as the C3PAO for any organization we have guided through preparation, so you always get an independent assessor at the finish line.

Contact Red River to talk through where your organization stands and what a realistic assessment timeline looks like from here.

Frequently Asked Questions

How much does a full CMMC Level 2 assessment cost?

A C3PAO assessment fee alone commonly falls somewhere between $40,000 and $100,000 for small to mid-sized contractors, depending on the number of systems in scope and the complexity of the environment. That figure does not include the cost of the gap assessment, remediation work and mock assessment that come before it, which for many contractors adds up to a comparable amount or more. Organizations with existing compliance programs, such as SOC 2 or ISO 27001, sometimes reduce the assessment timeline and cost somewhat, since some evidence-gathering work overlaps with what they already maintain. Travel expenses, evidence review time and any required POA&M validation work can all add to the base assessment fee, so a detailed quote breakdown before signing is worth requesting from any C3PAO under consideration.

What happens if we fail the formal assessment outright?

Failing to reach the minimum score or missing a required critical control generally results in no certificate rather than a conditional one and the organization must remediate before scheduling a new assessment with a C3PAO. This is a meaningfully worse outcome than receiving a Conditional status with a POA&M, since it usually means paying for a second full assessment rather than a more limited closeout review. This is exactly why the mock assessment stage matters: catching a likely failure point during an internal rehearsal costs far less than discovering it during the real thing.

Can our IT team run the gap assessment and remediation internally or do we need outside help?

Some organizations with mature internal security programs and staff already fluent in NIST SP 800-171 can run scoping, gap assessment and remediation without outside support. Many others find that general IT and cybersecurity skill does not automatically translate into the specific documentation style and evidence an assessor expects to see, which is where a Registered Provider Organization can add real value. Either path is workable, provided whoever runs the pre-assessment work is not the same organization that later serves as your C3PAO.

written by

Corrin Jones

Corrin Jones is the Director of Digital Demand Generation. With over ten years of experience, she specializes in creating content and executing campaigns to drive growth and revenue. Connect with Corrin on LinkedIn.

Go to Top