The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC Level 2 Audit: What It Is, What It Costs, and How to Pass

By The Defense Compliance Report Editorial Team— an independent trade publication on CMMC 2.0 and DIB compliance.

Last verified:

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This is educational research, not legal, contractual, or compliance advice.

If a contract just landed on your desk with a “CMMC Level 2 audit” requirement, here’s the short version before you scroll. What people call a CMMC Level 2 audit is, in the rule, a Level 2 assessment— and it comes in two forms. If your solicitation says Level 2 (Self), you assess your own systems against the 110 security requirements in NIST SP 800-171 Revision 2 and post the result yourself. If it says Level 2 (C3PAO), an authorized or accredited outside assessor evaluates the systems in your scope, and — if you clear the bar — you get a certificate. Which one applies isn’t your choice; it’s stated in the contract. A perfect score of 110 earns Final Level 2. A score of 88 or higher can earn a temporary Conditional status with a 180-day clock, but only under narrow rules that trip up more companies than the technology does.

Here’s the part nobody quotes you up front, and the reason this page exists: the C3PAO’s fee is only one line item — and often not the biggest. The money, and the risk, live in getting ready. We’ll show you the government’s own numbers, the six requirements you can never defer to a later date, exactly what an assessor examines, and how to tell whether you should be booking an assessor at all right now or fixing your house first.

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor’s level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

Not sure which path applies to you, or whether you’re ready?

The right CMMC provider category — C3PAO, RPO, MSSP, GRC platform, or CUI enclave — depends on your required status, CUI scope, environment, and timeline. The contract clause sets your level, not a checklist.

Do not submit CUI, drawings, export-controlled technical data, contract files, or sensitive system details. Where DCR may receive compensation from a partner, that compensation does not influence our editorial analysis.

Find My CMMC Path →

The two paths, side by side

Read the status printed in your solicitation, then read across:

Your required statusWho performs itFormal processWhere results goCorrect next move
Level 2 (Self)Your own organizationNIST SP 800-171A methods + CMMC scoring and scoping rules; not the CAPPosted by you to SPRSComplete the self-assessment and affirmation. Don’t buy a third-party assessment just because someone called it an “audit.”
Level 2 (C3PAO)An authorized or accredited C3PAO (CMMC Third-Party Assessment Organization)The CMMC Assessment Process (CAP) + NIST SP 800-171A + the 32 CFR scoring and scoping rulesUploaded by the C3PAO to CMMC eMASS, which transmits to SPRS; the C3PAO issues a Certificate of CMMC StatusGet your readiness work done first. Engage a C3PAO only when your evidence is genuinely ready.

Source: 32 CFR §§170.16 (self-assessment) and 170.17 (certification assessment). The solicitation provision that states which status applies is DFARS 252.204-7025; the contract clause requiring you to hold it is DFARS 252.204-7021.

Current as of : Phase 1 of the CMMC rollout began November 10, 2025 and is active, with Level 1 and Level 2 self-assessments as the default for applicable solicitations and contracts. The July 13, 2026 implementation suspension left Phase 1 active, limited new procurement designations to Level 1 (Self) and Level 2 (Self), and suspended new Level 2 (C3PAO), Level 3, and later-phase designations with no replacement Phase II date announced. Your actual obligation comes from the solicitation or contract in front of you — confirm whether a C3PAO requirement survived the required amendment or modification before engaging an assessor. (32 CFR §170.3(e); July 13, 2026 suspension.)

Which category fits — and which doesn’t

Before the details, the honest filter most vendors skip:

The right CMMC provider isn’t the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can’t resolve those for you, use The Defense Compliance Report’s Find My CMMC Path toolto map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

Find My CMMC Path → Category guidance only. No CUI, drawings, contract files, or system details.

What a “CMMC Level 2 audit” really is

A CMMC Level 2 audit is formally a Level 2 assessment: a structured check that your company has implemented all 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 control families and expanded into 320 assessment objectives. Depending on your contract, it’s either a self-assessment you perform and post to SPRS, or a certification assessment performed by an authorized or accredited C3PAO. “Audit” is the word contractors use; “assessment” is the word in the rule.

The vocabulary matters more than it looks. This isn’t a financial audit, and the government doesn’t call it one. NIST titled the governing procedure document “Assessing Security Requirements for Controlled Unclassified Information” — NIST SP 800-171A — and 32 CFR Part 170 refers throughout to a “Level 2 assessment.” When you see “audit” in a vendor pitch, translate it to “assessment,” because the word tells you which rules apply.

Level 2 means Revision 2 — not Revision 3

We’ll be blunt, because we’ve watched this cost people credibility in front of their own leadership: CMMC Level 2 is assessed against NIST SP 800-171 Revision 2, the 110 requirements published in February 2020 and updated January 28, 2021. Not Revision 3. The Program Rule incorporates Rev. 2 by reference at 32 CFR §170.14, and the DoD has said Rev. 3 will require future rulemaking before it becomes the CMMC baseline. You’re allowed to implementRevision 3 if you want — but if a consultant maps your evidence only to Rev. 3 and can’t also demonstrate every applicable Rev. 2 assessment objective, that’s a red flag, because Rev. 2 is what you’ll be scored against.

The shape of it: 110 requirements, 14 families, 320 objectives

Here’s what the assessor is actually measuring. The 110 requirements are grouped into 14 control families, and each requirement breaks down into one or more determination statements — 320 in total across Level 2. An assessor doesn’t just confirm that 110 policies exist; they confirm each applicable objective is satisfied by real, operating evidence.

Control familyRequirements
Access Control (AC)22
Awareness & Training (AT)3
Audit & Accountability (AU)9
Configuration Management (CM)9
Identification & Authentication (IA)11
Incident Response (IR)3
Maintenance (MA)6
Media Protection (MP)9
Personnel Security (PS)2
Physical Protection (PE)6
Risk Assessment (RA)3
Security Assessment (CA)4
System & Communications Protection (SC)16
System & Information Integrity (SI)7
Total110

Source: NIST SP 800-171 Rev. 2. The 320-objective figure and the assessment methods are set out in the DoD’s CMMC Assessment Guide – Level 2 and NIST SP 800-171A (June 2018).

One consequence of the 320-objective structure is unforgiving and worth memorizing: if one applicable objective under a requirement is NOT MET, the whole requirement is NOT MET.The scoring methodology allows partial credit in only two narrow cases (multi-factor authentication and CUI encryption, both explained below). Everything else is all-or-nothing at the requirement level — which drives more of the pass/fail outcome than any single piece of hardware you’ll buy. (32 CFR §170.24.)

Self-assessment or C3PAO? Your contract decides

Level 2 is not automatically a third-party audit. The rule recognizes both Level 2 (Self) and Level 2 (C3PAO), and the required status is identified in your solicitation and resulting contract — and may reach a subcontractor through the applicable flow-down. The CMMC Assessment Process applies only when you’re undergoing a C3PAO certification assessment. Assuming “Level 2 means C3PAO” is one of the most common and expensive mistakes we see.

The mechanism is simple once you know where to look. Solicitations that include the CMMC clause at DFARS 252.204-7021 also include the notice provision at DFARS 252.204-7025, “Notice of Cybersecurity Maturity Model Certification Level Requirements.” In that provision, the contracting officer fills in one of four options: CMMC Level 1 (Self), CMMC Level 2 (Self), CMMC Level 2 (C3PAO), or CMMC Level 3 (DIBCAC). That fill-in — not your gut, not a checklist — sets your obligation.

A note for anyone comparing clause numbers across documents, because it causes real confusion: effective February 1, 2026, DoD Class Deviation 2026-O0025 directs contracting officers to use revised FAR Part 40 and DFARS Part 240 coverage for applicable new actions, including DFARS 252.240-7997 for NIST SP 800-171 DoD assessment requirements. The codified DFARS still contains 252.204-7019 and 252.204-7020, and existing contracts may continue to cite them — so follow the clauses in your actual solicitation or contract. The two CMMC clauses that matter here, 252.204-7021 and 252.204-7025, did not change.

Handling CUI generally points you toward Level 2 requirements. But whether that Level 2 is self-assessed or C3PAO-assessedis a separate line in the contract, and the two are not interchangeable. A self-assessment is your team evaluating your systems against the same criteria a third party would use, then posting the result and an affirmation of continuous compliance by your Affirming Official in SPRS (the Supplier Performance Risk System, the DoD’s system of record for these results). A C3PAO assessment is an independent, accredited firm assessing you, with results uploaded to the CMMC instance of eMASS and transmitted to SPRS, plus a Certificate of CMMC Status.

When you should not hire a C3PAO yet

We’d rather lose the click than send you to an assessor you’re not ready for. Don’t book a C3PAO if any of these are true:

If two or more of those describe you, you need readiness work — not a certification assessment. Our guides on Level 2 self-assessment vs. C3PAO and on scoping go deeper than we will here.

Confirm your path before you request a single quote.

Answer a short set of non-sensitive questions about your required status, CUI scope, environment, and timeline, and we’ll map you to a provider category— not a named vendor.

Find My CMMC Path → — Do not submit CUI, drawings, contract files, or sensitive system details.

The one hard truth before you hire anyone

The team that prepares you cannot be the team that certifies you. Under 32 CFR §170.8, a CMMC ecosystem member who served as your consultant to get ready for a CMMC assessment is barred from participating in that certification assessment for three years. And if your C3PAO begins an assessment and finds you aren’t ready, the CMMC Assessment Process bars that same team from turning around and advising you how to fix the gaps when it intends to resume. So no honest vendor can promise that one team will both prepare you and certify you.

This is the admission that costs us the “one-stop shop” pitch — and it’s one of the most important paragraphs on this page. But read it carefully, because the rule is more precise than the slogans you’ll hear. The bar is on the same ecosystem member participatingin the assessment after consulting for you, and on the assessing team switching into remediation mid-engagement. A firm can offer readiness services and then hand you off to a genuinely independent C3PAO — that’s allowed, as long as it’s a clean handoff and disclosed. What no one can honestly sell is the same people doing both jobs on the same engagement.

Here’s why that’s good news, not bad. Independence is the whole point of a third-party assessment. A C3PAO that can’t also bill you for the fix has no incentive to look the other way — which is exactly the credibility your Certificate of CMMC Status is supposed to carry to your prime and your contracting officer.

The practical takeaway: build your bench in the right order. Get readiness help now — from a Registered Provider Organization (RPO) or Registered Practitioner (RP), a CMMC-focused managed security service provider (MSSP), a GRC platform, or a CUI-enclave provider — and bring in an independent C3PAO only when you’re ready to be assessed. The CMMC Path Framework— our logic for mapping your level, FCI/CUI handling, assessment type, environment, and timeline to the right provider category — routes to a category, never a named provider, and is not a score, ranking, or compliance advice.

What a CMMC Level 2 audit actually costs

There is no regulated price and no verified market average for a CMMC Level 2 audit. The DoD’s own cost model, published with the Final Rule, estimates about $101,752 for a small entity’s Level 2 (C3PAO) assessment plus its initial affirmation, and about $104,670 over three years once two more annual affirmations are added. But that model explicitly assumes you already implemented NIST SP 800-171 — so it excludes the remediation and engineering that is usually the largest expense. The assessment fee is only one line item; readiness is where the budget goes.

This is where competitor pages mislead people, and it’s worth slowing down. There are really two very different numbers, and pages that blend them into one scary figure do you a disservice.

The official cost-number decoder

Use this to translate any headline number you see:

The numberWhat it actually isWhat it is notHow to read it
~$31,234The DoD’s modeled C3PAO engagement line item for one small-entity scenario (outsourced assessor labor)A rate card, a market average, or your quote“DoD modeled roughly a $31,234 C3PAO line for one small-entity scenario.”
$101,752The DoD’s modeled small-entity cost to support the certification assessment plus the initial affirmationThe C3PAO’s fee by itself“The official model estimated $101,752 for assessment support and the first affirmation.”
$104,670The same scenario over three years, including two more annual affirmationsA universal three-year total, or an implementation budget“The modeled three-year burden was $104,670 under the rule’s assumptions.”
$0 modeled remediationThe rule assumed NIST SP 800-171 was to be implemented by December 31, 2017, so it attributed no engineering cost to this ruleEvidence that getting ready is free“The estimate excluded implementation because it assumed the controls were already in place.”

Source: the DoD Regulatory Impact Analysis and Regulatory Flexibility Analysis published with 32 CFR Part 170. The $101,752 and $104,670 figures appear in the rule’s cost tables; the exclusion of implementation engineering is stated in the same analysis.

That last row is the whole game. The model doesn’t price the engineering a contractor needs if it hasn’t already implemented Rev. 2 — so it can’t be read as a full implementation budget. The good news is that readiness cost is the most controllable part of the entire program.

What the market reports

Published industry cost analyses in 2026 — which we cite as third-party estimates, not figures DCR has independently collected — put the C3PAO assessment fee alone at roughly $30,000 to $150,000, driven by your size, scope, environment, and timeline. Once you add readiness, remediation, documentation, and technology, those same analyses commonly report a first full Level 2 cycle between $100,000 and $300,000 or more. The biggest swing factor is your starting maturity: a company already living ISO 27001, SOC 2, or genuine 800-171 discipline may spend a fraction of what a company starting from scratch does. Treat these as directional ranges to plan against, not quotes.

Three cost levers you actually control:

Before you budget a dollar, size your real gap.

Download the CMMC Readiness Checklist, mapped to all 14 control families, so you can see how far you actually are from 110 before you talk price with anyone. Or map your path first — provider category guidance based on your required status, scope, and timeline.

Do not submit CUI, drawings, or sensitive contract details. Where DCR may receive compensation from a partner, that compensation does not influence our editorial analysis.

Will you pass? Scoring and the “88 trap”

A Level 2 assessment starts at a maximum score equal to the number of requirements — 110 — and subtracts the assigned value of each requirement found NOT MET; a score can even go negative. A score of 110 earns Final Level 2. A score of 88 or higher can earn a temporary Conditional status — but only if every unmet item is eligible for a Plan of Action and Milestones (POA&M), and six specific requirements can never be on one. 88 does not mean you passed. It means you might qualify for a 180-day runway.

This is the section that saves contracts. Let’s take it in order.

The math

Each of the 110 requirements is scored MET, NOT MET, or NOT APPLICABLE — and each NOT MET requirement costs you 1, 3, or 5 points depending on its security weight (multi-factor authentication and the like carry the heavy deductions). N/A counts as MET for scoring, but only when a requirement genuinely doesn’t apply within your documented scope; it is not an escape hatch. Two derived requirements — MFA (IA.L2-3.5.3) and CUI encryption (SC.L2-3.13.11) — allow a partial deduction rather than the full hit. Everything else is scored at its full value. This weighting is why “we meet 80% of the controls” tells you almost nothing about your score: missing a handful of 5-point requirements can drop you below the threshold even if your raw count looks fine. (32 CFR §170.24.)

The 88 threshold — and why it isn’t a “pass”

To reach Conditional Level 2, your score divided by the number of requirements must be at least 0.8 — which, out of 110, means 88 points. Conditional status is real and useful: it can keep you eligible while you finish the job. But it is a temporary bridge, not a finish line. Final Level 2 requires the full 110, achieved either at the initial assessment or at a POA&M closeout assessment. (32 CFR §§170.21 and 170.24.)

The six requirements you can never put on a POA&M

Here’s the trap card competitors get wrong. A POA&M can only carry 1-point requirements. Every 3- and 5-point requirement must be fully MET at the time of assessment. There is exactly one narrow exception: SC.L2-3.13.11 (CUI encryption)may go on a POA&M if you’re encrypting but haven’t yet moved to FIPS-validated cryptography (it’s then scored as a 3-point gap rather than 5).

And six requirements are prohibited from a POA&M entirely — they must be fully implemented when the assessor arrives:

(32 CFR §170.21(a)(2)(iii). If you’ve seen a different list elsewhere — including versions naming CA.L2-3.12.1 or SI.L2-3.14.7 — check it against the rule itself; those are not the six the regulation names.)

Note the System Security Plan. Under 32 CFR §170.24, the absence of a current, adequate SSP means the assessment can’t be completed— the rule treats it as incomplete information and noncompliance with the safeguarding clause, not simply a zero score. It’s a hard stop, and it can’t be papered over with a plan to write one later.

The 180-day clock, and POA&M vs. OPA

Conditional status starts a hard 180-day clock from your Conditional CMMC Status Date. For a certification assessment, a C3PAO must perform the closeout; for a self-assessment, you perform it. If you miss the window, your Conditional status expires— standard contractual remedies may apply, and the scoped information system is ineligible for additional awards requiring that status until a new CMMC Status is achieved. (32 CFR §§170.17 and 170.21.)

One terminology fix worth making, because it confuses people: a POA&M records eligible NOT MET findings from an assessment and drives Conditional status and the 180-day clock. An Operational Plan of Action (OPA) is different — it documents temporary deficiencies or vulnerabilities after a requirement has otherwise been implemented, and, when it includes deficiency reviews and shows progress toward correction, the underlying requirement can still be scored MET. An OPA is not a backlog of unimplemented requirements. Don’t let a vendor conflate them. (32 CFR §170.24.)

Would you even qualify for Conditional status today?

Map your required status, CUI scope, and readiness in a few non-sensitive questions, and see the provider category that fits before you spend on an assessment.

Find My CMMC Path → — No CUI, drawings, or contract details.

What actually happens during the assessment

A Level 2 C3PAO assessment follows the CMMC Assessment Process (CAP): planning and preparation, conducting the assessment, reporting and quality review, and — if needed — closing out a POA&M. Throughout, assessors use three methods — examine, interview, and test — against the 320 objectives, using focused, nonstatistical sampling. A self-assessment covers the same technical ground but does not run under the CAP.

Here is the sequence, translated from the process document into what will actually happen in your building or on your screen.

The CMMC Level 2 Audit Decision & Evidence Matrix

This is our original crosswalk, assembled from 32 CFR Part 170, the current DFARS provisions, NIST SP 800-171 Rev. 2, NIST SP 800-171A, the Cyber AB CAP, and the DoD Level 2 Assessment Guide. The facts are public; the assembly — and the “what should stop you” and “who to engage now” columns — is the value. This is not an official assessment instrument, score, or readiness determination, and the provider-category column is DCR editorial judgment built on the verified facts. Last verified .

StageWhat the process requiresEvidence or decision that must existWhat can stop or change the outcomeOfficial record or deadlineRight provider category now
Contract pathConfirm the inserted status: Level 2 (Self) or (C3PAO)Solicitation, contract, flow-down; written clarification if unclearBuying a C3PAO assessment when only Self is requiredRequired status must exist before awardRPO/RP; a federal-contracts attorney if the clause is ambiguous
C3PAO & conflict checkA certification assessment uses an authorized or accredited C3PAO with no disqualifying conflictCurrent Cyber AB Marketplace status; assessor qualifications; conflict disclosuresAn ecosystem member that consulted to prepare you within the prior 3 years may not participateVerify status the day you signIndependent C3PAO for the assessment; separate readiness provider beforehand
Scope & SSPAssessment follows your defined CMMC Assessment Scope and Level 2 scoping rulesFinal SSP, CUI boundary, asset inventory, data-flow diagram, locations, CAGE codesIncomplete scope; an SSP that doesn’t match reality (a hard stop under §170.24)SSP name, version, date feed the recordRPO/RP, scoping specialist, or CUI-enclave architect
CSP (cloud handling CUI)A CSP that processes, stores, or transmits CUI must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalencyFedRAMP authorization/equivalency evidence, service description, Customer Responsibility Matrix (CRM)Assuming the CSP’s compliance covers your own obligationsEvidence available during the assessmentEnclave/cloud provider, MSSP
Other external providers (ESPs)Non-CSP ESP responsibilities are documented and assessed where their services meet a requirementService description, responsibilities in the SSP and CRM, ESP staff available for interviewTreating an MSP’s own status as your certificationEvidence available during the assessmentMSSP, RPO/RP
CAP — plan & prepareThe C3PAO plans the assessment and confirms you’re ready to proceedFinal documentation, agreed scope, evidence access, personnel availability, secure evidence handlingAn adverse readiness determination can stop you hereAssessment plan and scheduleReadiness provider — not another sales push
CAP — conduct (examine)Assessors review specifications and mechanismsFinal policies, SSP, procedures, diagrams, logs, tickets, configurations, training/incident recordsDrafts, stale screenshots, documents that don’t match operationsEvidence tied to each objectiveGRC platform; RPO/RP for evidence mapping
CAP — conduct (interview)Assessors question the people who own and run the controlsControl owners who can explain what they actually doAnswers that contradict the documents or each otherInterview evidence supports findingsInternal owners; ESP staff; coaching that doesn’t fabricate answers
CAP — conduct (test)Assessors exercise mechanisms under real conditionsWorking MFA, logging, access controls, incident response, media handlingA control that exists on paper but doesn’t operateTest result → MET or NOT METMSSP or internal technical owner
Sampling & daily checkpointsFocused, nonstatistical sampling; weak evidence can broaden inquiryRepresentative users, devices, sites, recordsA narrow sample exposes inconsistency → wider lookTracked in the active assessmentRemediation should already be done
Scoring & re-evaluationObjectives → MET / NOT MET / N/A; one unmet objective fails the requirementAdditional final evidence to fix a NOT MET finding, before the reportNew evidence can’t weaken another MET result; window closes when the report is deliveredRe-evaluation allowed during the assessment and for 10 business days after (§170.17)C3PAO scores; separate provider remediates
OutcomeFinal Level 2, Conditional Level 2, or no required statusA passing score or a qualifying POA&MA sub-88 score, a prohibited gap, or a missing SSP blocks itFindings report, QA reviewC3PAO issues the result; readiness provider for fixes
POA&M closeoutConditional requires ≥88 and strict POA&M eligibilityEligible remaining items closed and verifiedProhibited items, expired status, unclosed items180 days from Conditional status dateIndependent remediation; assessing C3PAO verifies
Reporting & retentionC3PAO uploads to eMASS → transmits to SPRS; artifacts named and hashedAssessment metadata, objective-level results, artifact list and hashesIncomplete records; inability to support the result laterArtifacts retained 6 years from the CMMC Status DateInternal compliance owner, GRC platform
SustainmentThree-year cycle; affirmation at assessment and annuallyAffirming Official; controlled scope; current controlsA previously N/A requirement becoming applicable requires reassessmentAnnual SPRS affirmation; triennial reassessmentInternal owner, MSSP, GRC, vCISO

The four-phase structure, the examine/interview/test methods, the eMASS-to-SPRS transmission, the 10-business-day re-evaluation window, the 180-day conditional limit, the six-year retention, and the annual affirmation all come directly from 32 CFR Part 170 and the CAP.

A word on readiness, said plainly:paying a C3PAO does not buy readiness. If your scope, SSP, people, or evidence aren’t ready when the assessment begins, the process can stop before you ever reach the evidence-testing phase — and the assessor can explain the problem but cannot turn that same engagement into fixing it for you.

What a C3PAO examines, asks, and tests

Assessors don’t verify that 110 documents exist. Using the examine, interview, and test methods in NIST SP 800-171A, they confirm that each applicable objective is satisfied by final, operating evidence that matches your scope and your SSP. Draft policies, stale screenshots, and controls that work only on paper don’t count — the rule requires evidence in final form.

Examine — the paper and the pixels

The assessor may examineWhat it helps proveThe common weakness
SSP and scope diagramsYour defined boundary and how it’s implementedA generic or stale SSP that doesn’t match reality
Policies and proceduresDocumented governance and ownershipThe policy exists, but nothing shows it’s followed
Configurations and screenshotsTechnical implementationThe screenshot is old, cropped, or not tied to an in-scope asset
Logs and alertsThe control actually runsLogging is on, but nobody reviews or retains it as described
Tickets and change recordsA repeatable processWork happened informally, with no evidence
Training and personnel recordsAwareness and personnel controlsCompletion records don’t match the actual workforce
Visitor, badge, and media recordsPhysical and media protectionCloud-first shops forget they still have a physical scope
CRM and provider documentsShared responsibility with a CSP/ESPYou assumed the provider owned a control it doesn’t

Interview — the people, not a script

Assessors talk to the people who own and operate the controls: your Affirming Official and senior leadership, system and security administrators, help-desk and HR staff, facilities, incident responders, and — where their services satisfy a requirement — your managed provider’s people. The point isn’t to recite a memorized answer. It’s to confirm that the humans understand and actually perform what the evidence claims. Prepare your people by having them explain their real process in their own words, and reconcile any contradictions before assessment day. Coaching someone to hide an exception is how a good posture becomes a failed assessment.

Test — show it working

Expect to demonstrate live: multi-factor authentication, account disablement, log retrieval, access restrictions, configuration enforcement, incident reporting, media handling and encryption, vulnerability remediation. Demonstrate the current system, not a special assessment-day configuration.

One caution on sampling

The CAP uses focused, nonstatistical sampling. The team may not inspect every user, device, or ticket — but “they only asked for three examples” is a dangerous preparation strategy. Inconsistent evidence in the sample is exactly what prompts the team to widen the net.

Not sure your evidence would survive that?

Map your situation and reach the right readiness category — RPO, MSSP, GRC platform, or CUI enclave — before you commit assessment money.

Find My CMMC Path → — No uploads, no CUI, no system details.

How do scope, cloud services, MSPs, and CAGE codes change the audit?

A Level 2 assessment evaluates your defined CMMC Assessment Scope, so scope decides which systems, people, locations, and provider responsibilities need evidence. Assets are sorted into categories — CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets — each with different assessment treatment. Cloud and outsourced services don’t automatically leave scope; their roles and responsibilities must be documented and, where relevant, assessed.

A few practical points that decide how big — and how expensive — your assessment becomes:

This is a section unto itself for a reason — our full CMMC Scoping Guide walks the asset categories and the enclave decision in detail.

Can a C3PAO re-evaluate a NOT MET finding?

Yes, but narrowly. Under 32 CFR §170.17, an assessor may re-evaluate a requirement scored NOT MET during the assessment and for up to 10 business days after the active assessment period — but only if new evidence shows the requirement is now MET, the new evidence doesn’t weaken another requirement already scored MET, and the CMMC Assessment Findings Report hasn’t been delivered yet.

In plain terms: there’s a short, real window to close a gap with evidence you can produce quickly — but it slams shut the moment the findings report is issued, and it can’t be used to trade one passing requirement for another. It’s a reason to have your evidence organized before the assessment, not a safety net to lean on. If a finding can’t be cured inside that window, it flows into the outcome — Final, Conditional, or no required status — and, where eligible, onto a POA&M.

What happens after the assessment

After the active assessment, the C3PAO completes a quality review and Findings Report, uploads the detailed results to CMMC eMASS, and — if the results warrant Final or Conditional status — eMASS returns the status confirmation, unique identifier, and status date, after which the C3PAO issues the certificate. You then retain your evidence for six years, submit an annual affirmation, close any permitted POA&M within 180 days, and keep your assessed environment current between the three-year assessments. An annual affirmation is not an annual audit.

If your assessment doesn’t produce the status your contract requires, that’s a remediation problem, not the end of the road — resolve the gaps with an independent readiness provider and reassess.

If you’re not assessment-ready, fix the right problem — don’t lose the contract.

See the recovery path after an unsuccessful assessment →

Who performs the assessment — and how to choose a C3PAO

Only a C3PAO listed on the Cyber AB Marketplace can perform a Level 2 certification assessment. As of the Cyber AB’s May 2026 Town Hall, roughly 104 C3PAOs were authorized and about 988 assessors were credentialed — a small pool against the 76,000–80,000 organizations the DoD estimates will need Level 2. Verify a firm’s current authorization on the Marketplace the day you sign, because authorization can lapse.

A few facts that should shape your shortlist:

The pool is real but tight — and readiness is often the bigger constraint.The Cyber AB reports its numbers monthly, so treat any count as a snapshot and check the Marketplace for the current figure. The DoD estimated that 76,000–80,000 organizations will need Level 2 overall, with about 8,350 medium and large entities needing the C3PAO path specifically. The gap between demand and assessor supply is real, and it points to the same conclusion from two directions: don’t panic-buy a slot, but don’t wait, either — get ready, then confirm your contract's requirement is still in force after the July 13, 2026 suspension before booking.

“Authorized” is not “accredited.”A C3PAO must earn full ISO/IEC 17020 accreditation within 27 months of authorization. Both authorized and accredited C3PAOs can legally assess you during that window — but authorization can be suspended or lapse. One detail that should build your confidence in the pool: to become authorized at all, a C3PAO must itself pass a DCMA DIBCAC-led Level 2 assessment. (That assessment qualifies the firm to operate — it does not give the C3PAO its own CMMC Status or certificate.) These are not self-appointed firms.

Ask these before you sign

This is DCR’s recommended due-diligence list, drawn from the mechanics above:

Get the answers in writing, and put a dated Marketplace screenshot in the engagement letter. A screenshot from six months ago is not evidence of current status.

Ready to line up help — but only in the right category?

Tell us your level, CUI scope, assessment type, environment, and timeline, and we’ll use The CMMC Path Framework to surface source-checked options in the category you actually need: readiness, managed compliance, GRC/evidence workflow, CUI enclave, or formal assessment.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. Do not submit CUI, drawings, export-controlled technical data, system documentation, credentials, or sensitive contract details.

Get matched with source-checked provider options →

CMMC Level 2 audit FAQ

These answers cover the shorter questions contractors ask after they understand the main process. Each is written to stand on its own.

Is “CMMC Level 2 audit” the official name?
No. The official terms are Level 2 self-assessment and Level 2 certification assessment. “Audit” is common industry and searcher shorthand.
Does every company handling CUI need a C3PAO audit?
Not automatically under every current contract. The required status is stated in your solicitation, contract, or subcontract flow-down. Some CUI contracts specify Level 2 (Self); many will specify Level 2 (C3PAO), especially as Phase 2 expands.
Is CMMC Level 2 based on NIST SP 800-171 Rev. 2 or Rev. 3?
CMMC Level 2 is currently assessed against Revision 2. You may also implement Revision 3, but you must identify and address any gaps against the Revision 2 assessment baseline until DoD completes future rulemaking.
How many controls are in a CMMC Level 2 audit?
110 security requirements across 14 control families, which expand into 320 assessment objectives.
Does the assessor test all 320 objectives?
Every applicable objective must receive a determination, though assessors choose appropriate methods and may use focused sampling. One NOT MET applicable objective makes its associated requirement NOT MET.
Can draft policies count as evidence?
No. The rule requires evidence in final form. Drafts and unapproved documents don’t establish implementation, and the evidence must reflect your real, current environment.
What’s a passing score?
A score of 110 earns Final Level 2. A score of 88 or higher can earn Conditional Level 2 if every unmet item is POA&M-eligible — but 88 is not a “pass,” it’s a 180-day runway to reach 110.
Can a C3PAO tell us how to fix a finding?
The assessment team can explain findings and process requirements, but the certification engagement is not a remediation engagement, and an ecosystem member that consulted to prepare you within the prior three years may not participate in your assessment.
Can a CMMC Level 2 audit be remote?
The CAP permits virtual evidence collection, but CUI must not be shared electronically during that process unless both the OSC and the C3PAO are using CMMC Level 2-conforming environments. The final plan depends on your evidence, demonstrations, locations, and the assessor’s judgment.
What if our MSP or cloud provider implements some of the controls?
Their responsibilities and evidence must be documented in your SSP and a Customer Responsibility Matrix, and their people may be interviewed. A CSP handling your CUI must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency. You still must prove your own portion and the effectiveness of the combined implementation. A provider’s own status does not certify you.
Can we put any unfinished control on a POA&M?
No. Conditional Level 2 requires at least 88 points, only 1-point items are eligible (with a narrow encryption exception for SC.L2-3.13.11), and six requirements — including the System Security Plan (CA.L2-3.12.4) — can never be on a POA&M.
How long do we have to close a Conditional POA&M?
180 days from the Conditional CMMC Status Date, verified by a C3PAO closeout for a certification assessment.
What are the possible outcomes?
Final Level 2, Conditional Level 2, or an assessment that does not produce the CMMC Status your contract requires.
How long must we keep assessment evidence?
Six years from the CMMC Status Date, for the hashed artifacts used as evidence.
Is the C3PAO audit annual?
No. The certification cycle is three years, with an affirmation at assessment and annually thereafter.
What changes require a new assessment?
The three-year cycle and annual affirmation accommodate ordinary change. Your Affirming Official decides whether a change is significant enough to require reassessment, and a previously N/A requirement becoming applicable requires reassessment.
Do small businesses get an exemption?
Company size alone doesn’t create a general exemption. Applicability follows the solicitation, the contract, the information you handle, and the current phase.
Does the Cyber AB recommend a specific C3PAO?
No. Verify authorization in the Cyber AB Marketplace and do your own due diligence.

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options.

The CMMC Path Framework routes to a category — C3PAO, RPO/RP, MSSP, GRC platform, or CUI enclave — based on the information you provide. It is not a compliance determination, a provider ranking, or a guarantee of certification.

Do not submit CUI, drawings, export-controlled technical data, contract files, credentials, system diagrams, or sensitive environment details.

Find My CMMC Path →

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.

What we actually verified

Who wrote this: The Defense Compliance Report Editorial Team.

How:direct review and cross-comparison of the governing regulation, the acquisition rule, the current standards, the assessment process, and DoD assessment guidance — read at the source, not paraphrased from secondary coverage.

Why: to translate the formal Level 2 process into the decisions a DIB contractor has to make before spending money on readiness or an assessment.

What we verifiedSource (version)Checked
Levels, scoring, scope, POA&M, affirmation, retention, re-evaluation window32 CFR Part 170 (§§170.8, 170.9, 170.14, 170.16, 170.17, 170.19, 170.21, 170.22, 170.24)July 13, 2026
The six POA&M-prohibited requirements and the encryption exception32 CFR §170.21(a)(2)(ii)–(iii)July 13, 2026
Scoring, partial-credit cases (MFA, encryption), and the missing-SSP consequence32 CFR §170.24July 13, 2026
The provision that states your level, and the clause that requires you to hold itDFARS 252.204-7025 and 252.204-7021 (Acquisition.gov); Class Deviation 2026-O0025July 13, 2026
Level 2 control baseline (110 requirements, 14 families)NIST SP 800-171 Revision 2 (Feb 2020, updated Jan 28, 2021)July 13, 2026
320 objectives and examine/interview/test methodsNIST SP 800-171A (June 2018); DoD CMMC Assessment Guide – Level 2July 13, 2026
Cost model ($31,234 C3PAO line; $101,752 assessment + initial affirmation; $104,670 three-year; remediation excluded)Federal Register Regulatory Impact Analysis, 32 CFR Part 170July 13, 2026
Phase 1 / Phase 2 timing (Nov 10, 2025 / Nov 10, 2026)32 CFR §170.3(e); DoD CMMC FAQJuly 13, 2026
C3PAO / assessor counts (≈104 authorized; ≈988 assessors)Cyber AB Town Hall, May 2026 (a dated snapshot — check the Marketplace for the current count)July 13, 2026
Real-world cost and timeline rangesPublished third-party industry analyses (2026), cited as estimates — not DCR-collected data; no market-average is asserted as factJuly 13, 2026
Any individual provider’s statusNot evaluated on this pageVerify in the Cyber AB Marketplace when relevant

Please read this as research, not advice.Confirm your scope and applicability with a CMMC Registered Practitioner or Registered Provider Organization (RP/RPO), and — where contract interpretation is involved — a qualified federal-contracts attorney. The contract clause and your CUI handling set your required level, not a checklist. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.

Last verified . We update this page when the sources above change — not to make it look fresh.