Process · CMMC Guide

CMMC Level 2 Assessment Process: A Step-by-Step Walkthrough

Much of what an assessor sees is settled before they arrive: the boundary, the documentation, and the evidence.

ProcessCMMC Level 2

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 19, 2026 · 6 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

When a DoD solicitation requires CMMC Level 2 (C3PAO), the certification assessment stands between your organization and contracts that involve Controlled Unclassified Information (CUI). Since July 13, 2026, with Phase 2 suspended, a DoW CIO memorandum allows requiring activities to designate only Level 1 (Self) or Level 2 (Self), so check which assessment type your solicitation actually states. When a C3PAO assessment does apply, knowing what happens before, during, and after it removes surprises.

This walkthrough covers the full process, from initial preparation through final certification.

Phase 1: Pre-Assessment Preparation

The assessment is the exam. Everything before it is the study period.

Define your CUI boundary

Before anything else, define your CUI boundary precisely: the systems, networks, and physical spaces where CUI is stored, processed, or transmitted. This boundary sets the scope of your assessment (32 CFR 170.19). A smaller, well-defined boundary means fewer assets to assess; all 110 requirements still apply inside it. Two ways to get it wrong: defining the boundary too broadly (assessing the whole network when CUI only touches one enclave) or too narrowly (missing systems that process CUI indirectly through email, shared drives, or backups).

Complete your NIST SP 800-171 self-assessment

DFARS provision 252.204-7019 and clause 252.204-7020 require a current NIST SP 800-171 self-assessment score in the Supplier Performance Risk System (SPRS), as the final CMMC rule describes (89 FR 83092). A C3PAO assessment then evaluates the same 110 requirements independently. For a deeper look at the two paths, see CMMC self-assessment vs C3PAO.

Prepare your documentation package

Assessors review your System Security Plan (SSP), your Plan of Action and Milestones (POA&M), policies and procedures for each control family, evidence of implementation for each control, and incident response plans and test results. Documentation quality matters, because assessors can only credit what they can verify through documented evidence and technical demonstration.

Get a directional read on your Level 2 readiness before you book anything; it is a self-assessment, not an official SPRS score. Start the free 10-question gap check →

Phase 2: Selecting Your C3PAO

CMMC Third-Party Assessment Organizations (C3PAOs) are authorized by the CMMC Accreditation Body, which keeps an up-to-date public list of authorized C3PAOs (32 CFR 170.8(b)(8)). Check a C3PAO's status there before signing. Useful selection criteria include scheduling availability, the assessor team's experience with your industry vertical, transparent pricing with no hidden fees for extra assessor days, and clear communication about what happens if issues arise mid-assessment.

Phase 3: The Assessment Itself

The C3PAO performs the Level 2 certification assessment in accordance with NIST SP 800-171A (32 CFR 170.17(c)(1)), and its length depends on the size and complexity of your CUI environment. The DoD's cost model assumes a 120-hour C3PAO engagement for a small entity and 200 hours for a larger one (CMMC Program Regulatory Impact Analysis, pp. 25-26).

Evidence review

Assessors examine your documentation against each of the 110 NIST SP 800-171 requirements and their NIST SP 800-171A assessment objectives: is the control described in your SSP, is it implemented as described, and is there objective evidence that it works?

Technical verification

Beyond documentation, assessors test. That can include examining system configurations, reviewing access control lists, testing MFA, verifying encryption settings, checking audit log configurations, and validating network segmentation. They confirm that what your documentation says matches what your systems actually do.

Personnel interviews

Interviews are one of the NIST SP 800-171A assessment methods, alongside examining and testing. Assessors interview personnel at various levels to confirm that security practices are understood and followed. If your documentation says employees complete annual security awareness training, expect assessors to ask employees about it.

Phase 4: Assessment Results and Findings

Each requirement is scored MET, NOT MET, or NOT APPLICABLE (N/A) under 32 CFR 170.24(b); an objective assessed N/A counts the same as MET. The C3PAO uploads the results into the CMMC instantiation of eMASS, and you receive the final results in a CMMC Assessment Findings Report (32 CFR 170.17(c)(1)).

Handling NOT MET findings

If the score is at least 80% of the maximum and every NOT MET item is POA&M-eligible, you can receive Conditional Level 2 (C3PAO) status and have 180 days to close the items (32 CFR 170.21). Otherwise the assessment produces no CMMC Status, and you remediate before being assessed again.

Phase 5: POA&M Management

The CMMC program allows limited use of POA&Ms, under 32 CFR 170.21(a)(2): the score must be at least 80% of the maximum, each item must carry a point value of 1 (SC.L2-3.13.11 may be included at 3 points where encryption is employed but not FIPS-validated), and six named requirements, including the System Security Plan (CA.L2-3.12.4), can never be on it. A POA&M is not a free pass: the items must be closed out within 180 days of the Conditional status date, or the Conditional status expires. Knowing which controls are eligible and which are not is essential to your preparation strategy, and it is one of the things our 12-week preparation plan builds around.

Phase 6: Certification

With every requirement MET (Final status) or an allowable POA&M (Conditional status), the C3PAO uploads the results into the CMMC instantiation of eMASS, which transmits them to SPRS (32 CFR 170.17(a)). Your CMMC Status is stored in SPRS and presented on a Certificate of CMMC Status (32 CFR 170.4). The certification assessment is repeated every three years, and your Affirming Official affirms continuing compliance after each assessment and annually after that (32 CFR 170.17, 170.22).

Where AaaS Fits

Enclave AI's Agent-as-a-Service (AaaS) agents prepare the readiness side. On a readiness subscription, read-only connectors re-scan your connected cloud and identity sources about every seven days, and each tier cycle re-issues the SSP, POA&M and evidence index against the 110 requirements: measured where a connected source can observe a requirement, answered from your recorded evidence where not. The assessor still assesses. Your designated executive can approve or disapprove each delivered document before your organization presents it, and your Affirming Official makes the affirmation decision. The routine work is automated; the judgment stays with your people.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot compares your connected cloud and identity configuration against all 110 NIST 800-171 controls, measuring the controls those sources can show (intake-based if you connect none), and returns a PDF within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Each subscription tier also offers a month-to-month option.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures attributed to the DoD are its published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost; $999 is Enclave AI's own price for the CMMC Level 2 Readiness Snapshot.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee any CMMC status or certification. A Level 2 certification assessment is conducted by an authorized or accredited C3PAO (32 CFR 170.17). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.