Skip to main content
CMMC & CUI

What a C3PAO assessment day looks like

People preparing for a certification assessment tend to imagine a technical examination. It is not really that. It is three or four days of a stranger asking your own people to show them things, and the assessments that go badly almost never go badly because a control was missing. They go badly because of the conversation on the first morning, or because nobody could produce a record made at the time.

Engineering perspective, not legal advice This describes how these assessments are structured and how we prepare for them. Procedures vary between assessor organizations and the program's own rules have been revised more than once. Your assessor's assessment plan and the current rule text govern; treat this as orientation rather than as the procedure you will actually follow.

Who is in the room, and what they are allowed to be

A CMMC Third-Party Assessment Organization is an authorized firm listed in the program's marketplace, and it is worth knowing that these organizations are themselves assessed before they are permitted to assess anyone. The team is led by a certified lead assessor, usually with one or more supporting assessors, and larger scopes get larger teams. They arrive with an assessment plan built from the scope you agreed in advance.

One structural point matters before you choose anyone. The program separates advising from assessing: the firm that helps you build and remediate your environment is not the firm that certifies it. That constraint exists for the obvious reason, and it means a consultant who offers to both fix and certify has either misunderstood the ecosystem or is describing two different companies. Ask any prospective assessor directly how they handle conflicts of interest, and ask any prospective consultant whether they are the same organization as the assessor they are recommending.

The assessment runs in three parts: planning and preparation, which is most of the calendar; conducting the assessment, which is the days people worry about; and reporting, which produces the result that reaches the government system. The middle part is short. What determines its outcome happened weeks earlier.

You are probably here because

  • You have a date booked and want to know what the week is actually like
  • You are deciding whether you are ready enough to book one
  • Your prime has asked whether you hold a certification and you are weighing it
  • You want to run a mock assessment and do not know what to model

If you read one section, read the one on scope validation. More assessments are decided on the first morning than by any control.

The first morning is a scope conversation, and it is the whole ballgame

The assessment opens with the team confirming that the boundary you described is the boundary that exists. They will walk your asset inventory, your network diagram and your system security plan, and check them against what they can see. This is not a formality. If the assessor concludes that something you placed outside the boundary belongs inside it, the assessment you planned is not the assessment you are having.

The usual triggers are the same ones that cause trouble everywhere else. A directory that authenticates both the enclave and the corporate estate. A managed provider whose tooling reaches into the environment. A backup destination nobody listed. A ticketing system where engineers paste content. A second facility. An asset classified as risk-managed where the assessor finds evidence that controlled data has actually been on it.

The way to survive that morning is to have already argued with yourself. Before you book anything, have someone who was not involved in the design try to break the boundary: find the path by which controlled data could reach an out-of-scope system, and then either close it or bring the system inside. Every one of those you find yourself is one you are not finding in front of an assessor with a notebook.

If the assessor decides something outside your boundary belongs inside it, the assessment you planned is not the assessment you are having. That determination is made on the first morning.

Examine, interview, test

The methods come from the companion NIST publication that turns each requirement into assessment objectives with determination statements. For each objective, the team does one or more of three things.

MethodWhat it looks likeWhere it goes wrong
ExamineReading documents, policies, configurations, exports, records, tickets, logsArtifacts with no date, no source and no author. A screenshot proves a setting today; it does not prove a practice
InterviewAsking the people who do the work to describe how they do itThe person's description does not match the written procedure, usually because the procedure was written by someone else
TestWatching the control operate — a login challenged, a blocked action refused, a log query run liveNobody in the room has the access or the familiarity to drive the console under observation

Test is the method firms underestimate. It is one thing to hold a policy saying that external sharing is disabled and another to have someone attempt it while an assessor watches. Practise the demonstrations in advance, and make sure the person who will run them has the rights to do it. An assessment stalling for twenty minutes while somebody hunts for a password is a small thing that sets a tone.

Interview is the method that surprises people most, because it is not limited to the IT staff. Assessors talk to whoever performs the activity: the person at the front desk about visitor escorting, a machinist about removable media, an HR administrator about access removal when someone leaves, a project engineer about how controlled files are handled. The single best preparation is to have each of those people read the procedure that describes their own job, in advance, and tell you honestly whether it matches what they actually do. Where it does not, fix the procedure, not the person — a document that describes an imaginary practice is the finding.

How the days run

Duration scales with the size of the scope, the number of locations and how many external providers are involved. A small, well-scoped enclave is a short engagement. A multi-site estate is not. Ask any assessor to base an estimate on your actual asset counts and locations rather than on your headcount, and get more than one estimate.

The rhythm, in most engagements, looks like this. An opening session confirming scope, logistics and the plan. Then blocks of work moving through the objectives family by family, with the team splitting to cover documentation, technical demonstrations and interviews in parallel. A short out-brief at the end of each day, in which the team tells you what they have provisionally marked and what they still need. Then a closing session with preliminary results before anyone leaves.

Those daily out-briefs are the most useful hour of the week and firms sometimes treat them as a formality. They are the mechanism by which you learn that an objective is at risk while there is still time to produce the evidence that exists but was not indexed. Send someone senior, take notes, and turn each item into an overnight task list.

Requirements are marked as met, not met, or not applicable. There is no partial credit inside a requirement and no narrative score; the objective is either satisfied by the evidence or it is not. Assessors do have limited discretion around small, quickly correctable deficiencies during the assessment period — the rules and the assessment guidance define how much and for how long. Ask your assessor how they apply that discretion before you book, because the answer varies and it matters.

The four things that actually sink assessments

Almost every difficult outcome we have seen or heard described traces to one of these, and none of them is a missing security product.

The plan describes a different environment. The system security plan was written during design, the environment changed during build, and nobody went back. An assessor reads the plan first, so every divergence is a question, and enough questions become a conclusion about the plan's reliability.

Evidence exists but was not made at the time. A firm that reviews logs monthly and keeps no record of it cannot demonstrate the review. Screenshots taken the week before the assessment prove the current state and nothing about the practice. What is wanted is the artifact the activity produced when it happened — the ticket, the dated export, the report sent to a distribution list.

Recurring activities have no history. Access reviews, vulnerability remediation, configuration comparisons, incident exercises. All of these pass on the day they are set up. The assessor asks for the last three, and the dates answer the question.

An external provider cannot be evidenced. Your managed provider implements controls on your behalf. If you cannot show what they do, in writing, and produce evidence from their systems, those objectives have nothing behind them. Sort this out months in advance, because it depends on somebody else's cooperation.

Where preparation time is best spent — our read

Making the plan match the environment
94
An evidence index, objective by objective
88
Attacking your own boundary before they do
84
Interview preparation for non-IT staff
70
Rehearsing live demonstrations
62
Buying additional security tooling
20

Our judgement of preparation value in the last ninety days, not a survey. The bottom row is last because tools bought late have no evidence history behind them.

What comes out the other side

The team produces a report, and the result becomes a status recorded in the government's systems. Two outcomes matter to you.

A Final status means the requirements were met. It is valid for three years, with an affirmation by a named official at assessment and annually after. The affirmation is not ceremonial: it is a statement that you continue to meet the requirements, and the environment it describes keeps changing after the assessors leave.

A Conditional status means you scored at or above the threshold with eligible gaps captured on a plan of action, which must be closed within 180 days through a close-out assessment. If it is not closed in that window, the conditional status expires. Plan the close-out at the same time you plan the assessment, because 180 days is not long for anything that requires procurement or a vendor's cooperation, and the items left on a plan of action are usually the ones that were hard for exactly those reasons.

Not every gap is eligible for a plan of action. Six requirements can never appear on one at any score, and the highest-weighted requirements are constrained. Check the current rule text on this before you assume anything can be deferred, and check it before the assessment rather than after.

If you disagree with a finding, there is a process, and it starts with the assessor organization. Read what your agreement with them says about disputes before you sign it, not on the day you need it. In practice most disagreements are about evidence rather than about fact, and most of those are resolved during the assessment week if you raise them at the out-brief rather than at the end.

Run the mock yourself first

The single highest-value preparation is free, and most firms skip it. The assessment objectives are published. Take them, work through the requirements in your scope, and for each objective write down the specific artifact that satisfies it and where it lives. Not “we do that” — the file name, the system, the date range.

  • Build the evidence index objective by objective, with a pointer to a real artifact for each one
  • Mark honestly. Every objective you cannot point at is a finding you have found early and cheaply
  • Have someone outside the project run the interviews with the actual staff, and record where descriptions diverge from procedure
  • Rehearse the demonstrations with the people and accounts that will do them live
  • Check the dates on every recurring-activity record. Three consecutive instances is the bar to aim at
  • Try to break your own boundary and write down what you found
  • Reconcile the plan to the environment last, once everything above has changed both

Firms with a competent internal team can do all of that without hiring anyone, and we would tell you to try before you buy. Where an outside reader earns their money is when nobody internally can be genuinely sceptical about a system they built, or when a previous attempt went badly and you need to know why. If you have someone in-house who is willing to write down that an objective is not met, that person is worth more than any external readiness engagement.

  • Booking an assessment before the plan matches the environment, which turns the first morning into an argument
  • Treating the daily out-brief as a formality instead of as an overnight task list
  • Preparing only the IT staff when assessors interview whoever does the work
  • Producing screenshots taken last week for practices that are supposed to have a history
  • Discovering a provider dependency during the week, when it needed months of somebody else's cooperation
  • Planning a conditional status without planning the close-out, then losing it on day 181
  • Buying tools in the last month, which adds cost and no evidence history

Bottom line

An assessment is a demonstration, not an examination. What is being tested is whether your description of your own environment is true and whether the activities you claim to perform have actually been performed. That means the preparation that pays is not technical: reconcile the plan to reality, index the evidence objective by objective, make sure the recurring activities have three instances of history, prepare the people who will be interviewed, and attack your own boundary before someone else does.

Do that and the week is mostly uneventful, which is exactly what a good assessment feels like from the inside.

Frequently asked questions

How long does an assessment take?

It scales with scope: the number of in-scope assets, the number of physical locations, and how many external providers have to be evidenced. A tightly scoped single-site enclave is a short engagement; a multi-site estate with several providers is not. Ask assessors to base an estimate on your asset inventory and locations rather than your headcount, and get more than one.

Can we fix something during the assessment?

To a limited extent. Assessors have defined discretion around small deficiencies that can be corrected within the assessment period, and the rules and assessment guidance set the boundaries of it. It is not a general remedy and it should never be part of your plan. Ask your assessor how they apply that discretion before you book, because the answer varies between organizations.

Who do they interview?

Whoever performs the activity, which is frequently not the IT team. Expect conversations with front-desk staff about visitors and escorting, production staff about removable media and physical handling, HR about screening and access removal, and engineers about how controlled files move. Have each of those people read the procedure covering their own job in advance and tell you where it does not match what they actually do.

What is the difference between Conditional and Final?

Final means the requirements were met, and the status runs three years with an annual affirmation. Conditional means you reached the threshold with eligible gaps on a plan of action, and it must be closed out within 180 days or it expires. Not all gaps are eligible — six requirements can never appear on a plan of action, and the highest-weighted ones are constrained — so check the current rule before assuming anything can be deferred.

Can our readiness consultant also assess us?

No, and you should be wary of anyone implying otherwise. The program deliberately separates advising from assessing, so the firm that helps build and remediate your environment is not the firm that certifies it. Ask any prospective assessor how they manage conflicts of interest, and confirm that a consultant recommending an assessor is not describing a related company.

1 business day response

Want someone sceptical to read your plan before an assessor does?

Send the system security plan and your asset inventory, and we will tell you where we think the two disagree. Email bo@precisionfederal.com.

Email an engineerCapabilitiesMore insights →
C3PAOAssessment ObjectivesEvidenceConditional Status