When a DoD solicitation requires CMMC Level 2 (C3PAO), the certification assessment stands between your organization and contracts that involve Controlled Unclassified Information (CUI). Since July 13, 2026, with Phase 2 suspended, a DoW CIO memorandum allows requiring activities to designate only Level 1 (Self) or Level 2 (Self), so check which assessment type your solicitation actually states. When a C3PAO assessment does apply, knowing what happens before, during, and after it removes surprises.
This walkthrough covers the full process, from initial preparation through final certification.
Phase 1: Pre-Assessment Preparation
The assessment is the exam. Everything before it is the study period.
Define your CUI boundary
Before anything else, define your CUI boundary precisely: the systems, networks, and physical spaces where CUI is stored, processed, or transmitted. This boundary sets the scope of your assessment (32 CFR 170.19). A smaller, well-defined boundary means fewer assets to assess; all 110 requirements still apply inside it. Two ways to get it wrong: defining the boundary too broadly (assessing the whole network when CUI only touches one enclave) or too narrowly (missing systems that process CUI indirectly through email, shared drives, or backups).
Complete your NIST SP 800-171 self-assessment
DFARS provision 252.204-7019 and clause 252.204-7020 require a current NIST SP 800-171 self-assessment score in the Supplier Performance Risk System (SPRS), as the final CMMC rule describes (89 FR 83092). A C3PAO assessment then evaluates the same 110 requirements independently. For a deeper look at the two paths, see CMMC self-assessment vs C3PAO.
Prepare your documentation package
Assessors review your System Security Plan (SSP), your Plan of Action and Milestones (POA&M), policies and procedures for each control family, evidence of implementation for each control, and incident response plans and test results. Documentation quality matters, because assessors can only credit what they can verify through documented evidence and technical demonstration.
Phase 2: Selecting Your C3PAO
CMMC Third-Party Assessment Organizations (C3PAOs) are authorized by the CMMC Accreditation Body, which keeps an up-to-date public list of authorized C3PAOs (32 CFR 170.8(b)(8)). Check a C3PAO's status there before signing. Useful selection criteria include scheduling availability, the assessor team's experience with your industry vertical, transparent pricing with no hidden fees for extra assessor days, and clear communication about what happens if issues arise mid-assessment.
Phase 3: The Assessment Itself
The C3PAO performs the Level 2 certification assessment in accordance with NIST SP 800-171A (32 CFR 170.17(c)(1)), and its length depends on the size and complexity of your CUI environment. The DoD's cost model assumes a 120-hour C3PAO engagement for a small entity and 200 hours for a larger one (CMMC Program Regulatory Impact Analysis, pp. 25-26).
Evidence review
Assessors examine your documentation against each of the 110 NIST SP 800-171 requirements and their NIST SP 800-171A assessment objectives: is the control described in your SSP, is it implemented as described, and is there objective evidence that it works?
Technical verification
Beyond documentation, assessors test. That can include examining system configurations, reviewing access control lists, testing MFA, verifying encryption settings, checking audit log configurations, and validating network segmentation. They confirm that what your documentation says matches what your systems actually do.
Personnel interviews
Interviews are one of the NIST SP 800-171A assessment methods, alongside examining and testing. Assessors interview personnel at various levels to confirm that security practices are understood and followed. If your documentation says employees complete annual security awareness training, expect assessors to ask employees about it.
Phase 4: Assessment Results and Findings
Each requirement is scored MET, NOT MET, or NOT APPLICABLE (N/A) under 32 CFR 170.24(b); an objective assessed N/A counts the same as MET. The C3PAO uploads the results into the CMMC instantiation of eMASS, and you receive the final results in a CMMC Assessment Findings Report (32 CFR 170.17(c)(1)).
Handling NOT MET findings
If the score is at least 80% of the maximum and every NOT MET item is POA&M-eligible, you can receive Conditional Level 2 (C3PAO) status and have 180 days to close the items (32 CFR 170.21). Otherwise the assessment produces no CMMC Status, and you remediate before being assessed again.
Phase 5: POA&M Management
The CMMC program allows limited use of POA&Ms, under 32 CFR 170.21(a)(2): the score must be at least 80% of the maximum, each item must carry a point value of 1 (SC.L2-3.13.11 may be included at 3 points where encryption is employed but not FIPS-validated), and six named requirements, including the System Security Plan (CA.L2-3.12.4), can never be on it. A POA&M is not a free pass: the items must be closed out within 180 days of the Conditional status date, or the Conditional status expires. Knowing which controls are eligible and which are not is essential to your preparation strategy, and it is one of the things our 12-week preparation plan builds around.
Phase 6: Certification
With every requirement MET (Final status) or an allowable POA&M (Conditional status), the C3PAO uploads the results into the CMMC instantiation of eMASS, which transmits them to SPRS (32 CFR 170.17(a)). Your CMMC Status is stored in SPRS and presented on a Certificate of CMMC Status (32 CFR 170.4). The certification assessment is repeated every three years, and your Affirming Official affirms continuing compliance after each assessment and annually after that (32 CFR 170.17, 170.22).
Where AaaS Fits
Enclave AI's Agent-as-a-Service (AaaS) agents prepare the readiness side. On a readiness subscription, read-only connectors re-scan your connected cloud and identity sources about every seven days, and each tier cycle re-issues the SSP, POA&M and evidence index against the 110 requirements: measured where a connected source can observe a requirement, answered from your recorded evidence where not. The assessor still assesses. Your designated executive can approve or disapprove each delivered document before your organization presents it, and your Affirming Official makes the affirmation decision. The routine work is automated; the judgment stays with your people.