CMMC Level 2 Audit: What It Is, What It Costs, and How to Pass
If a contract just landed on your desk with a “CMMC Level 2 audit” requirement, here’s the short version before you scroll. What people call a CMMC Level 2 audit is, in the rule, a Level 2 assessment— and it comes in two forms. If your solicitation says Level 2 (Self), you assess your own systems against the 110 security requirements in NIST SP 800-171 Revision 2 and post the result yourself. If it says Level 2 (C3PAO), an authorized or accredited outside assessor evaluates the systems in your scope, and — if you clear the bar — you get a certificate. Which one applies isn’t your choice; it’s stated in the contract. A perfect score of 110 earns Final Level 2. A score of 88 or higher can earn a temporary Conditional status with a 180-day clock, but only under narrow rules that trip up more companies than the technology does.
Here’s the part nobody quotes you up front, and the reason this page exists: the C3PAO’s fee is only one line item — and often not the biggest. The money, and the risk, live in getting ready. We’ll show you the government’s own numbers, the six requirements you can never defer to a later date, exactly what an assessor examines, and how to tell whether you should be booking an assessor at all right now or fixing your house first.
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor’s level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
Not sure which path applies to you, or whether you’re ready?
The right CMMC provider category — C3PAO, RPO, MSSP, GRC platform, or CUI enclave — depends on your required status, CUI scope, environment, and timeline. The contract clause sets your level, not a checklist.
Find My CMMC Path →The two paths, side by side
Read the status printed in your solicitation, then read across:
| Your required status | Who performs it | Formal process | Where results go | Correct next move |
|---|---|---|---|---|
| Level 2 (Self) | Your own organization | NIST SP 800-171A methods + CMMC scoring and scoping rules; not the CAP | Posted by you to SPRS | Complete the self-assessment and affirmation. Don’t buy a third-party assessment just because someone called it an “audit.” |
| Level 2 (C3PAO) | An authorized or accredited C3PAO (CMMC Third-Party Assessment Organization) | The CMMC Assessment Process (CAP) + NIST SP 800-171A + the 32 CFR scoring and scoping rules | Uploaded by the C3PAO to CMMC eMASS, which transmits to SPRS; the C3PAO issues a Certificate of CMMC Status | Get your readiness work done first. Engage a C3PAO only when your evidence is genuinely ready. |
Current as of : Phase 1 of the CMMC rollout began November 10, 2025 and is active, with Level 1 and Level 2 self-assessments as the default for applicable solicitations and contracts. The July 13, 2026 implementation suspension left Phase 1 active, limited new procurement designations to Level 1 (Self) and Level 2 (Self), and suspended new Level 2 (C3PAO), Level 3, and later-phase designations with no replacement Phase II date announced. Your actual obligation comes from the solicitation or contract in front of you — confirm whether a C3PAO requirement survived the required amendment or modification before engaging an assessor. (32 CFR §170.3(e); July 13, 2026 suspension.)
Which category fits — and which doesn’t
Before the details, the honest filter most vendors skip:
- You handle only FCI but the solicitation states Level 2 (Self): you don’t need a C3PAO for that requirement — but confirm the stated level with the contracting officer rather than assuming that handling only FCI automatically drops you to Level 1. The provision lets the contracting officer set the required status, and you can’t override it with your own read of your data.
- You handle CUI and your contract says Level 2 (C3PAO):you need readiness help now and an independent C3PAO later — two different parties. We’ll explain why below.
- You’re not sure which status your contract requires:stop and resolve that first. Everything downstream depends on it, and a checklist can’t answer it for you.
The right CMMC provider isn’t the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can’t resolve those for you, use The Defense Compliance Report’s Find My CMMC Path toolto map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
Find My CMMC Path → Category guidance only. No CUI, drawings, contract files, or system details.
What a “CMMC Level 2 audit” really is
A CMMC Level 2 audit is formally a Level 2 assessment: a structured check that your company has implemented all 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 control families and expanded into 320 assessment objectives. Depending on your contract, it’s either a self-assessment you perform and post to SPRS, or a certification assessment performed by an authorized or accredited C3PAO. “Audit” is the word contractors use; “assessment” is the word in the rule.
The vocabulary matters more than it looks. This isn’t a financial audit, and the government doesn’t call it one. NIST titled the governing procedure document “Assessing Security Requirements for Controlled Unclassified Information” — NIST SP 800-171A — and 32 CFR Part 170 refers throughout to a “Level 2 assessment.” When you see “audit” in a vendor pitch, translate it to “assessment,” because the word tells you which rules apply.
Level 2 means Revision 2 — not Revision 3
We’ll be blunt, because we’ve watched this cost people credibility in front of their own leadership: CMMC Level 2 is assessed against NIST SP 800-171 Revision 2, the 110 requirements published in February 2020 and updated January 28, 2021. Not Revision 3. The Program Rule incorporates Rev. 2 by reference at 32 CFR §170.14, and the DoD has said Rev. 3 will require future rulemaking before it becomes the CMMC baseline. You’re allowed to implementRevision 3 if you want — but if a consultant maps your evidence only to Rev. 3 and can’t also demonstrate every applicable Rev. 2 assessment objective, that’s a red flag, because Rev. 2 is what you’ll be scored against.
The shape of it: 110 requirements, 14 families, 320 objectives
Here’s what the assessor is actually measuring. The 110 requirements are grouped into 14 control families, and each requirement breaks down into one or more determination statements — 320 in total across Level 2. An assessor doesn’t just confirm that 110 policies exist; they confirm each applicable objective is satisfied by real, operating evidence.
| Control family | Requirements |
|---|---|
| Access Control (AC) | 22 |
| Awareness & Training (AT) | 3 |
| Audit & Accountability (AU) | 9 |
| Configuration Management (CM) | 9 |
| Identification & Authentication (IA) | 11 |
| Incident Response (IR) | 3 |
| Maintenance (MA) | 6 |
| Media Protection (MP) | 9 |
| Personnel Security (PS) | 2 |
| Physical Protection (PE) | 6 |
| Risk Assessment (RA) | 3 |
| Security Assessment (CA) | 4 |
| System & Communications Protection (SC) | 16 |
| System & Information Integrity (SI) | 7 |
| Total | 110 |
One consequence of the 320-objective structure is unforgiving and worth memorizing: if one applicable objective under a requirement is NOT MET, the whole requirement is NOT MET.The scoring methodology allows partial credit in only two narrow cases (multi-factor authentication and CUI encryption, both explained below). Everything else is all-or-nothing at the requirement level — which drives more of the pass/fail outcome than any single piece of hardware you’ll buy. (32 CFR §170.24.)
Self-assessment or C3PAO? Your contract decides
Level 2 is not automatically a third-party audit. The rule recognizes both Level 2 (Self) and Level 2 (C3PAO), and the required status is identified in your solicitation and resulting contract — and may reach a subcontractor through the applicable flow-down. The CMMC Assessment Process applies only when you’re undergoing a C3PAO certification assessment. Assuming “Level 2 means C3PAO” is one of the most common and expensive mistakes we see.
The mechanism is simple once you know where to look. Solicitations that include the CMMC clause at DFARS 252.204-7021 also include the notice provision at DFARS 252.204-7025, “Notice of Cybersecurity Maturity Model Certification Level Requirements.” In that provision, the contracting officer fills in one of four options: CMMC Level 1 (Self), CMMC Level 2 (Self), CMMC Level 2 (C3PAO), or CMMC Level 3 (DIBCAC). That fill-in — not your gut, not a checklist — sets your obligation.
A note for anyone comparing clause numbers across documents, because it causes real confusion: effective February 1, 2026, DoD Class Deviation 2026-O0025 directs contracting officers to use revised FAR Part 40 and DFARS Part 240 coverage for applicable new actions, including DFARS 252.240-7997 for NIST SP 800-171 DoD assessment requirements. The codified DFARS still contains 252.204-7019 and 252.204-7020, and existing contracts may continue to cite them — so follow the clauses in your actual solicitation or contract. The two CMMC clauses that matter here, 252.204-7021 and 252.204-7025, did not change.
Handling CUI generally points you toward Level 2 requirements. But whether that Level 2 is self-assessed or C3PAO-assessedis a separate line in the contract, and the two are not interchangeable. A self-assessment is your team evaluating your systems against the same criteria a third party would use, then posting the result and an affirmation of continuous compliance by your Affirming Official in SPRS (the Supplier Performance Risk System, the DoD’s system of record for these results). A C3PAO assessment is an independent, accredited firm assessing you, with results uploaded to the CMMC instance of eMASS and transmitted to SPRS, plus a Certificate of CMMC Status.
When you should not hire a C3PAO yet
We’d rather lose the click than send you to an assessor you’re not ready for. Don’t book a C3PAO if any of these are true:
- Your clause says Level 2 (Self).
- The solicitation is silent or ambiguous about the required status.
- Your CUI boundary isn’t documented.
- Your System Security Plan (SSP) doesn’t match how your environment actually runs.
- You haven’t tested your evidence against the assessment objectives.
- You’re still deciding on your cloud or enclave architecture.
- You only want a gap assessment or a practice run.
If two or more of those describe you, you need readiness work — not a certification assessment. Our guides on Level 2 self-assessment vs. C3PAO and on scoping go deeper than we will here.
Confirm your path before you request a single quote.
Answer a short set of non-sensitive questions about your required status, CUI scope, environment, and timeline, and we’ll map you to a provider category— not a named vendor.
Find My CMMC Path → — Do not submit CUI, drawings, contract files, or sensitive system details.
The one hard truth before you hire anyone
The team that prepares you cannot be the team that certifies you. Under 32 CFR §170.8, a CMMC ecosystem member who served as your consultant to get ready for a CMMC assessment is barred from participating in that certification assessment for three years. And if your C3PAO begins an assessment and finds you aren’t ready, the CMMC Assessment Process bars that same team from turning around and advising you how to fix the gaps when it intends to resume. So no honest vendor can promise that one team will both prepare you and certify you.
This is the admission that costs us the “one-stop shop” pitch — and it’s one of the most important paragraphs on this page. But read it carefully, because the rule is more precise than the slogans you’ll hear. The bar is on the same ecosystem member participatingin the assessment after consulting for you, and on the assessing team switching into remediation mid-engagement. A firm can offer readiness services and then hand you off to a genuinely independent C3PAO — that’s allowed, as long as it’s a clean handoff and disclosed. What no one can honestly sell is the same people doing both jobs on the same engagement.
Here’s why that’s good news, not bad. Independence is the whole point of a third-party assessment. A C3PAO that can’t also bill you for the fix has no incentive to look the other way — which is exactly the credibility your Certificate of CMMC Status is supposed to carry to your prime and your contracting officer.
The practical takeaway: build your bench in the right order. Get readiness help now — from a Registered Provider Organization (RPO) or Registered Practitioner (RP), a CMMC-focused managed security service provider (MSSP), a GRC platform, or a CUI-enclave provider — and bring in an independent C3PAO only when you’re ready to be assessed. The CMMC Path Framework— our logic for mapping your level, FCI/CUI handling, assessment type, environment, and timeline to the right provider category — routes to a category, never a named provider, and is not a score, ranking, or compliance advice.
What a CMMC Level 2 audit actually costs
There is no regulated price and no verified market average for a CMMC Level 2 audit. The DoD’s own cost model, published with the Final Rule, estimates about $101,752 for a small entity’s Level 2 (C3PAO) assessment plus its initial affirmation, and about $104,670 over three years once two more annual affirmations are added. But that model explicitly assumes you already implemented NIST SP 800-171 — so it excludes the remediation and engineering that is usually the largest expense. The assessment fee is only one line item; readiness is where the budget goes.
This is where competitor pages mislead people, and it’s worth slowing down. There are really two very different numbers, and pages that blend them into one scary figure do you a disservice.
The official cost-number decoder
Use this to translate any headline number you see:
| The number | What it actually is | What it is not | How to read it |
|---|---|---|---|
| ~$31,234 | The DoD’s modeled C3PAO engagement line item for one small-entity scenario (outsourced assessor labor) | A rate card, a market average, or your quote | “DoD modeled roughly a $31,234 C3PAO line for one small-entity scenario.” |
| $101,752 | The DoD’s modeled small-entity cost to support the certification assessment plus the initial affirmation | The C3PAO’s fee by itself | “The official model estimated $101,752 for assessment support and the first affirmation.” |
| $104,670 | The same scenario over three years, including two more annual affirmations | A universal three-year total, or an implementation budget | “The modeled three-year burden was $104,670 under the rule’s assumptions.” |
| $0 modeled remediation | The rule assumed NIST SP 800-171 was to be implemented by December 31, 2017, so it attributed no engineering cost to this rule | Evidence that getting ready is free | “The estimate excluded implementation because it assumed the controls were already in place.” |
That last row is the whole game. The model doesn’t price the engineering a contractor needs if it hasn’t already implemented Rev. 2 — so it can’t be read as a full implementation budget. The good news is that readiness cost is the most controllable part of the entire program.
What the market reports
Published industry cost analyses in 2026 — which we cite as third-party estimates, not figures DCR has independently collected — put the C3PAO assessment fee alone at roughly $30,000 to $150,000, driven by your size, scope, environment, and timeline. Once you add readiness, remediation, documentation, and technology, those same analyses commonly report a first full Level 2 cycle between $100,000 and $300,000 or more. The biggest swing factor is your starting maturity: a company already living ISO 27001, SOC 2, or genuine 800-171 discipline may spend a fraction of what a company starting from scratch does. Treat these as directional ranges to plan against, not quotes.
Three cost levers you actually control:
- Scope.Every asset that processes, stores, or transmits CUI is assessed against all applicable Level 2 requirements. Consolidating CUI into a well-designed enclave can reduce scope — but only when the remaining assets genuinely meet the out-of-scope or other asset-category criteria. Branding something an “enclave” doesn’t automatically remove your enterprise network, endpoints, or identity systems from scope.
- Documentation.A clean, accurate SSP and evidence package shorten the assessment and reduce findings. An inaccurate SSP, or evidence that conflicts with how you actually operate, can delay the assessment, widen the assessor’s inquiry, or create findings.
- Timing. Published analyses report consultant rates rising as demand climbs toward Phase 2. Locking in help earlier, on your schedule, is easier than scrambling in the final months before a deadline.
Before you budget a dollar, size your real gap.
Download the CMMC Readiness Checklist, mapped to all 14 control families, so you can see how far you actually are from 110 before you talk price with anyone. Or map your path first — provider category guidance based on your required status, scope, and timeline.
Will you pass? Scoring and the “88 trap”
A Level 2 assessment starts at a maximum score equal to the number of requirements — 110 — and subtracts the assigned value of each requirement found NOT MET; a score can even go negative. A score of 110 earns Final Level 2. A score of 88 or higher can earn a temporary Conditional status — but only if every unmet item is eligible for a Plan of Action and Milestones (POA&M), and six specific requirements can never be on one. 88 does not mean you passed. It means you might qualify for a 180-day runway.
This is the section that saves contracts. Let’s take it in order.
The math
Each of the 110 requirements is scored MET, NOT MET, or NOT APPLICABLE — and each NOT MET requirement costs you 1, 3, or 5 points depending on its security weight (multi-factor authentication and the like carry the heavy deductions). N/A counts as MET for scoring, but only when a requirement genuinely doesn’t apply within your documented scope; it is not an escape hatch. Two derived requirements — MFA (IA.L2-3.5.3) and CUI encryption (SC.L2-3.13.11) — allow a partial deduction rather than the full hit. Everything else is scored at its full value. This weighting is why “we meet 80% of the controls” tells you almost nothing about your score: missing a handful of 5-point requirements can drop you below the threshold even if your raw count looks fine. (32 CFR §170.24.)
The 88 threshold — and why it isn’t a “pass”
To reach Conditional Level 2, your score divided by the number of requirements must be at least 0.8 — which, out of 110, means 88 points. Conditional status is real and useful: it can keep you eligible while you finish the job. But it is a temporary bridge, not a finish line. Final Level 2 requires the full 110, achieved either at the initial assessment or at a POA&M closeout assessment. (32 CFR §§170.21 and 170.24.)
The six requirements you can never put on a POA&M
Here’s the trap card competitors get wrong. A POA&M can only carry 1-point requirements. Every 3- and 5-point requirement must be fully MET at the time of assessment. There is exactly one narrow exception: SC.L2-3.13.11 (CUI encryption)may go on a POA&M if you’re encrypting but haven’t yet moved to FIPS-validated cryptography (it’s then scored as a 3-point gap rather than 5).
And six requirements are prohibited from a POA&M entirely — they must be fully implemented when the assessor arrives:
- AC.L2-3.1.20External Connections (control connections to external systems)
- AC.L2-3.1.22Control Public Information (control CUI posted to public systems)
- CA.L2-3.12.4System Security Plan
- PE.L2-3.10.3Escort Visitors and monitor visitor activity
- PE.L2-3.10.4Physical Access Logs
- PE.L2-3.10.5Manage Physical Access (control and manage physical access devices)
Note the System Security Plan. Under 32 CFR §170.24, the absence of a current, adequate SSP means the assessment can’t be completed— the rule treats it as incomplete information and noncompliance with the safeguarding clause, not simply a zero score. It’s a hard stop, and it can’t be papered over with a plan to write one later.
The 180-day clock, and POA&M vs. OPA
Conditional status starts a hard 180-day clock from your Conditional CMMC Status Date. For a certification assessment, a C3PAO must perform the closeout; for a self-assessment, you perform it. If you miss the window, your Conditional status expires— standard contractual remedies may apply, and the scoped information system is ineligible for additional awards requiring that status until a new CMMC Status is achieved. (32 CFR §§170.17 and 170.21.)
One terminology fix worth making, because it confuses people: a POA&M records eligible NOT MET findings from an assessment and drives Conditional status and the 180-day clock. An Operational Plan of Action (OPA) is different — it documents temporary deficiencies or vulnerabilities after a requirement has otherwise been implemented, and, when it includes deficiency reviews and shows progress toward correction, the underlying requirement can still be scored MET. An OPA is not a backlog of unimplemented requirements. Don’t let a vendor conflate them. (32 CFR §170.24.)
Would you even qualify for Conditional status today?
Map your required status, CUI scope, and readiness in a few non-sensitive questions, and see the provider category that fits before you spend on an assessment.
Find My CMMC Path → — No CUI, drawings, or contract details.
What actually happens during the assessment
A Level 2 C3PAO assessment follows the CMMC Assessment Process (CAP): planning and preparation, conducting the assessment, reporting and quality review, and — if needed — closing out a POA&M. Throughout, assessors use three methods — examine, interview, and test — against the 320 objectives, using focused, nonstatistical sampling. A self-assessment covers the same technical ground but does not run under the CAP.
Here is the sequence, translated from the process document into what will actually happen in your building or on your screen.
The CMMC Level 2 Audit Decision & Evidence Matrix
| Stage | What the process requires | Evidence or decision that must exist | What can stop or change the outcome | Official record or deadline | Right provider category now |
|---|---|---|---|---|---|
| Contract path | Confirm the inserted status: Level 2 (Self) or (C3PAO) | Solicitation, contract, flow-down; written clarification if unclear | Buying a C3PAO assessment when only Self is required | Required status must exist before award | RPO/RP; a federal-contracts attorney if the clause is ambiguous |
| C3PAO & conflict check | A certification assessment uses an authorized or accredited C3PAO with no disqualifying conflict | Current Cyber AB Marketplace status; assessor qualifications; conflict disclosures | An ecosystem member that consulted to prepare you within the prior 3 years may not participate | Verify status the day you sign | Independent C3PAO for the assessment; separate readiness provider beforehand |
| Scope & SSP | Assessment follows your defined CMMC Assessment Scope and Level 2 scoping rules | Final SSP, CUI boundary, asset inventory, data-flow diagram, locations, CAGE codes | Incomplete scope; an SSP that doesn’t match reality (a hard stop under §170.24) | SSP name, version, date feed the record | RPO/RP, scoping specialist, or CUI-enclave architect |
| CSP (cloud handling CUI) | A CSP that processes, stores, or transmits CUI must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency | FedRAMP authorization/equivalency evidence, service description, Customer Responsibility Matrix (CRM) | Assuming the CSP’s compliance covers your own obligations | Evidence available during the assessment | Enclave/cloud provider, MSSP |
| Other external providers (ESPs) | Non-CSP ESP responsibilities are documented and assessed where their services meet a requirement | Service description, responsibilities in the SSP and CRM, ESP staff available for interview | Treating an MSP’s own status as your certification | Evidence available during the assessment | MSSP, RPO/RP |
| CAP — plan & prepare | The C3PAO plans the assessment and confirms you’re ready to proceed | Final documentation, agreed scope, evidence access, personnel availability, secure evidence handling | An adverse readiness determination can stop you here | Assessment plan and schedule | Readiness provider — not another sales push |
| CAP — conduct (examine) | Assessors review specifications and mechanisms | Final policies, SSP, procedures, diagrams, logs, tickets, configurations, training/incident records | Drafts, stale screenshots, documents that don’t match operations | Evidence tied to each objective | GRC platform; RPO/RP for evidence mapping |
| CAP — conduct (interview) | Assessors question the people who own and run the controls | Control owners who can explain what they actually do | Answers that contradict the documents or each other | Interview evidence supports findings | Internal owners; ESP staff; coaching that doesn’t fabricate answers |
| CAP — conduct (test) | Assessors exercise mechanisms under real conditions | Working MFA, logging, access controls, incident response, media handling | A control that exists on paper but doesn’t operate | Test result → MET or NOT MET | MSSP or internal technical owner |
| Sampling & daily checkpoints | Focused, nonstatistical sampling; weak evidence can broaden inquiry | Representative users, devices, sites, records | A narrow sample exposes inconsistency → wider look | Tracked in the active assessment | Remediation should already be done |
| Scoring & re-evaluation | Objectives → MET / NOT MET / N/A; one unmet objective fails the requirement | Additional final evidence to fix a NOT MET finding, before the report | New evidence can’t weaken another MET result; window closes when the report is delivered | Re-evaluation allowed during the assessment and for 10 business days after (§170.17) | C3PAO scores; separate provider remediates |
| Outcome | Final Level 2, Conditional Level 2, or no required status | A passing score or a qualifying POA&M | A sub-88 score, a prohibited gap, or a missing SSP blocks it | Findings report, QA review | C3PAO issues the result; readiness provider for fixes |
| POA&M closeout | Conditional requires ≥88 and strict POA&M eligibility | Eligible remaining items closed and verified | Prohibited items, expired status, unclosed items | 180 days from Conditional status date | Independent remediation; assessing C3PAO verifies |
| Reporting & retention | C3PAO uploads to eMASS → transmits to SPRS; artifacts named and hashed | Assessment metadata, objective-level results, artifact list and hashes | Incomplete records; inability to support the result later | Artifacts retained 6 years from the CMMC Status Date | Internal compliance owner, GRC platform |
| Sustainment | Three-year cycle; affirmation at assessment and annually | Affirming Official; controlled scope; current controls | A previously N/A requirement becoming applicable requires reassessment | Annual SPRS affirmation; triennial reassessment | Internal owner, MSSP, GRC, vCISO |
The four-phase structure, the examine/interview/test methods, the eMASS-to-SPRS transmission, the 10-business-day re-evaluation window, the 180-day conditional limit, the six-year retention, and the annual affirmation all come directly from 32 CFR Part 170 and the CAP.
A word on readiness, said plainly:paying a C3PAO does not buy readiness. If your scope, SSP, people, or evidence aren’t ready when the assessment begins, the process can stop before you ever reach the evidence-testing phase — and the assessor can explain the problem but cannot turn that same engagement into fixing it for you.
What a C3PAO examines, asks, and tests
Assessors don’t verify that 110 documents exist. Using the examine, interview, and test methods in NIST SP 800-171A, they confirm that each applicable objective is satisfied by final, operating evidence that matches your scope and your SSP. Draft policies, stale screenshots, and controls that work only on paper don’t count — the rule requires evidence in final form.
Examine — the paper and the pixels
| The assessor may examine | What it helps prove | The common weakness |
|---|---|---|
| SSP and scope diagrams | Your defined boundary and how it’s implemented | A generic or stale SSP that doesn’t match reality |
| Policies and procedures | Documented governance and ownership | The policy exists, but nothing shows it’s followed |
| Configurations and screenshots | Technical implementation | The screenshot is old, cropped, or not tied to an in-scope asset |
| Logs and alerts | The control actually runs | Logging is on, but nobody reviews or retains it as described |
| Tickets and change records | A repeatable process | Work happened informally, with no evidence |
| Training and personnel records | Awareness and personnel controls | Completion records don’t match the actual workforce |
| Visitor, badge, and media records | Physical and media protection | Cloud-first shops forget they still have a physical scope |
| CRM and provider documents | Shared responsibility with a CSP/ESP | You assumed the provider owned a control it doesn’t |
Interview — the people, not a script
Assessors talk to the people who own and operate the controls: your Affirming Official and senior leadership, system and security administrators, help-desk and HR staff, facilities, incident responders, and — where their services satisfy a requirement — your managed provider’s people. The point isn’t to recite a memorized answer. It’s to confirm that the humans understand and actually perform what the evidence claims. Prepare your people by having them explain their real process in their own words, and reconcile any contradictions before assessment day. Coaching someone to hide an exception is how a good posture becomes a failed assessment.
Test — show it working
Expect to demonstrate live: multi-factor authentication, account disablement, log retrieval, access restrictions, configuration enforcement, incident reporting, media handling and encryption, vulnerability remediation. Demonstrate the current system, not a special assessment-day configuration.
One caution on sampling
The CAP uses focused, nonstatistical sampling. The team may not inspect every user, device, or ticket — but “they only asked for three examples” is a dangerous preparation strategy. Inconsistent evidence in the sample is exactly what prompts the team to widen the net.
Not sure your evidence would survive that?
Map your situation and reach the right readiness category — RPO, MSSP, GRC platform, or CUI enclave — before you commit assessment money.
Find My CMMC Path → — No uploads, no CUI, no system details.
How do scope, cloud services, MSPs, and CAGE codes change the audit?
A Level 2 assessment evaluates your defined CMMC Assessment Scope, so scope decides which systems, people, locations, and provider responsibilities need evidence. Assets are sorted into categories — CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets — each with different assessment treatment. Cloud and outsourced services don’t automatically leave scope; their roles and responsibilities must be documented and, where relevant, assessed.
A few practical points that decide how big — and how expensive — your assessment becomes:
- Asset categories matter. An asset that processes, stores, or transmits CUI is a CUI Asset and is assessed against the Level 2 requirements. Security Protection Assets (the tools that protect CUI), Contractor Risk Managed Assets, and Specialized Assets(like OT or IoT) are handled under their own rules. Getting these categories right is how you legitimately keep systems out of scope — and getting them wrong is how a “small” assessment balloons. (32 CFR §170.19.)
- Cloud handling CUI. If a Cloud Service Provider processes, stores, or transmits your CUI, the offering must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency, with a Customer Responsibility Matrix showing who owns what. That FedRAMP requirement applies to the qualifying CSP offering — it is not a blanket credential every MSP or consultant must hold. (32 CFR §170.17(c)(5).)
- Other external providers.A non-CSP external service provider’s responsibilities must be documented in your SSP and CRM, and its people and evidence may be part of the assessment where their services meet a requirement. An MSP’s own CMMC status does not certify you.
- Multiple CAGE codes and locations.Every CAGE code tied to the assessed information system, and every site that shares the scope, is fair game. Corporate-wide policies don’t prove location-level implementation, and sampling can expose the difference.
This is a section unto itself for a reason — our full CMMC Scoping Guide walks the asset categories and the enclave decision in detail.
Can a C3PAO re-evaluate a NOT MET finding?
Yes, but narrowly. Under 32 CFR §170.17, an assessor may re-evaluate a requirement scored NOT MET during the assessment and for up to 10 business days after the active assessment period — but only if new evidence shows the requirement is now MET, the new evidence doesn’t weaken another requirement already scored MET, and the CMMC Assessment Findings Report hasn’t been delivered yet.
In plain terms: there’s a short, real window to close a gap with evidence you can produce quickly — but it slams shut the moment the findings report is issued, and it can’t be used to trade one passing requirement for another. It’s a reason to have your evidence organized before the assessment, not a safety net to lean on. If a finding can’t be cured inside that window, it flows into the outcome — Final, Conditional, or no required status — and, where eligible, onto a POA&M.
What happens after the assessment
After the active assessment, the C3PAO completes a quality review and Findings Report, uploads the detailed results to CMMC eMASS, and — if the results warrant Final or Conditional status — eMASS returns the status confirmation, unique identifier, and status date, after which the C3PAO issues the certificate. You then retain your evidence for six years, submit an annual affirmation, close any permitted POA&M within 180 days, and keep your assessed environment current between the three-year assessments. An annual affirmation is not an annual audit.
- Reporting.An independent quality review precedes the Findings Report and out-brief. Requirements and their applicable objectives are recorded as MET, NOT MET, or N/A. The briefing covers your result and any conditional obligations — but, again, it does not include remedial advice.
- What the C3PAO submits to eMASS — and what SPRS records. For a certification assessment, the C3PAO uploads detailed data to CMMC eMASS: the assessment date and level, the C3PAO name, the assessment identifier, assessor names, your CAGE codes, the SSP name/date/version, the CMMC Status Date, the result for each requirement objective, POA&M usage, and the artifact names and hash values. CMMC eMASS then provides automated transmission to SPRS. Your Affirming Official separately submits the required affirmation in SPRS. (32 CFR §170.17.)
- Six-year retention. The hashed artifacts used as assessment evidence must be retained for six years from your CMMC Status Date. Build an evidence-retention process, not just an assessment-day folder.
- Affirmation ≠ a new audit every year.The C3PAO assessment runs on a three-year cycle. What’s annual is the affirmation by your Affirming Official that you remain compliant. The three-year cycle and the annual affirmation accommodate ordinary change; the Affirming Official is responsible for deciding whether a change is significant enough to require reassessment, and a previously N/A requirement becoming applicable does require reassessment. Remember, too, that CMMC Status applies to the information systems within your defined CMMC Assessment Scope — it doesn’t automatically cover every system your company operates.
- Appeals.Use the C3PAO’s internal appeal process first; the CAP provides an escalation route. No one can promise an appeal changes a result.
If your assessment doesn’t produce the status your contract requires, that’s a remediation problem, not the end of the road — resolve the gaps with an independent readiness provider and reassess.
If you’re not assessment-ready, fix the right problem — don’t lose the contract.
Who performs the assessment — and how to choose a C3PAO
Only a C3PAO listed on the Cyber AB Marketplace can perform a Level 2 certification assessment. As of the Cyber AB’s May 2026 Town Hall, roughly 104 C3PAOs were authorized and about 988 assessors were credentialed — a small pool against the 76,000–80,000 organizations the DoD estimates will need Level 2. Verify a firm’s current authorization on the Marketplace the day you sign, because authorization can lapse.
A few facts that should shape your shortlist:
The pool is real but tight — and readiness is often the bigger constraint.The Cyber AB reports its numbers monthly, so treat any count as a snapshot and check the Marketplace for the current figure. The DoD estimated that 76,000–80,000 organizations will need Level 2 overall, with about 8,350 medium and large entities needing the C3PAO path specifically. The gap between demand and assessor supply is real, and it points to the same conclusion from two directions: don’t panic-buy a slot, but don’t wait, either — get ready, then confirm your contract's requirement is still in force after the July 13, 2026 suspension before booking.
“Authorized” is not “accredited.”A C3PAO must earn full ISO/IEC 17020 accreditation within 27 months of authorization. Both authorized and accredited C3PAOs can legally assess you during that window — but authorization can be suspended or lapse. One detail that should build your confidence in the pool: to become authorized at all, a C3PAO must itself pass a DCMA DIBCAC-led Level 2 assessment. (That assessment qualifies the firm to operate — it does not give the C3PAO its own CMMC Status or certificate.) These are not self-appointed firms.
Ask these before you sign
- What is your authorization status today — and can I see your current Cyber AB Marketplace listing, dated?
- What specific week can you begin? Give me a date, not a range.
- How many Level 2 assessments have you completed in my industry vertical?
- Will the same Lead Assessor staff the engagement from kickoff through the report?
- How is travel billed, and what travel scope are you assuming?
- What conflicts of interest, if any, apply to my organization?
Get the answers in writing, and put a dated Marketplace screenshot in the engagement letter. A screenshot from six months ago is not evidence of current status.
Ready to line up help — but only in the right category?
Tell us your level, CUI scope, assessment type, environment, and timeline, and we’ll use The CMMC Path Framework to surface source-checked options in the category you actually need: readiness, managed compliance, GRC/evidence workflow, CUI enclave, or formal assessment.
Get matched with source-checked provider options →CMMC Level 2 audit FAQ
These answers cover the shorter questions contractors ask after they understand the main process. Each is written to stand on its own.
- Is “CMMC Level 2 audit” the official name?
- No. The official terms are Level 2 self-assessment and Level 2 certification assessment. “Audit” is common industry and searcher shorthand.
- Does every company handling CUI need a C3PAO audit?
- Not automatically under every current contract. The required status is stated in your solicitation, contract, or subcontract flow-down. Some CUI contracts specify Level 2 (Self); many will specify Level 2 (C3PAO), especially as Phase 2 expands.
- Is CMMC Level 2 based on NIST SP 800-171 Rev. 2 or Rev. 3?
- CMMC Level 2 is currently assessed against Revision 2. You may also implement Revision 3, but you must identify and address any gaps against the Revision 2 assessment baseline until DoD completes future rulemaking.
- How many controls are in a CMMC Level 2 audit?
- 110 security requirements across 14 control families, which expand into 320 assessment objectives.
- Does the assessor test all 320 objectives?
- Every applicable objective must receive a determination, though assessors choose appropriate methods and may use focused sampling. One NOT MET applicable objective makes its associated requirement NOT MET.
- Can draft policies count as evidence?
- No. The rule requires evidence in final form. Drafts and unapproved documents don’t establish implementation, and the evidence must reflect your real, current environment.
- What’s a passing score?
- A score of 110 earns Final Level 2. A score of 88 or higher can earn Conditional Level 2 if every unmet item is POA&M-eligible — but 88 is not a “pass,” it’s a 180-day runway to reach 110.
- Can a C3PAO tell us how to fix a finding?
- The assessment team can explain findings and process requirements, but the certification engagement is not a remediation engagement, and an ecosystem member that consulted to prepare you within the prior three years may not participate in your assessment.
- Can a CMMC Level 2 audit be remote?
- The CAP permits virtual evidence collection, but CUI must not be shared electronically during that process unless both the OSC and the C3PAO are using CMMC Level 2-conforming environments. The final plan depends on your evidence, demonstrations, locations, and the assessor’s judgment.
- What if our MSP or cloud provider implements some of the controls?
- Their responsibilities and evidence must be documented in your SSP and a Customer Responsibility Matrix, and their people may be interviewed. A CSP handling your CUI must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency. You still must prove your own portion and the effectiveness of the combined implementation. A provider’s own status does not certify you.
- Can we put any unfinished control on a POA&M?
- No. Conditional Level 2 requires at least 88 points, only 1-point items are eligible (with a narrow encryption exception for SC.L2-3.13.11), and six requirements — including the System Security Plan (CA.L2-3.12.4) — can never be on a POA&M.
- How long do we have to close a Conditional POA&M?
- 180 days from the Conditional CMMC Status Date, verified by a C3PAO closeout for a certification assessment.
- What are the possible outcomes?
- Final Level 2, Conditional Level 2, or an assessment that does not produce the CMMC Status your contract requires.
- How long must we keep assessment evidence?
- Six years from the CMMC Status Date, for the hashed artifacts used as evidence.
- Is the C3PAO audit annual?
- No. The certification cycle is three years, with an affirmation at assessment and annually thereafter.
- What changes require a new assessment?
- The three-year cycle and annual affirmation accommodate ordinary change. Your Affirming Official decides whether a change is significant enough to require reassessment, and a previously N/A requirement becoming applicable requires reassessment.
- Do small businesses get an exemption?
- Company size alone doesn’t create a general exemption. Applicability follows the solicitation, the contract, the information you handle, and the current phase.
- Does the Cyber AB recommend a specific C3PAO?
- No. Verify authorization in the Cyber AB Marketplace and do your own due diligence.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options.
The CMMC Path Framework routes to a category — C3PAO, RPO/RP, MSSP, GRC platform, or CUI enclave — based on the information you provide. It is not a compliance determination, a provider ranking, or a guarantee of certification.
Find My CMMC Path →What we actually verified
Who wrote this: The Defense Compliance Report Editorial Team.
How:direct review and cross-comparison of the governing regulation, the acquisition rule, the current standards, the assessment process, and DoD assessment guidance — read at the source, not paraphrased from secondary coverage.
Why: to translate the formal Level 2 process into the decisions a DIB contractor has to make before spending money on readiness or an assessment.
| What we verified | Source (version) | Checked |
|---|---|---|
| Levels, scoring, scope, POA&M, affirmation, retention, re-evaluation window | 32 CFR Part 170 (§§170.8, 170.9, 170.14, 170.16, 170.17, 170.19, 170.21, 170.22, 170.24) | July 13, 2026 |
| The six POA&M-prohibited requirements and the encryption exception | 32 CFR §170.21(a)(2)(ii)–(iii) | July 13, 2026 |
| Scoring, partial-credit cases (MFA, encryption), and the missing-SSP consequence | 32 CFR §170.24 | July 13, 2026 |
| The provision that states your level, and the clause that requires you to hold it | DFARS 252.204-7025 and 252.204-7021 (Acquisition.gov); Class Deviation 2026-O0025 | July 13, 2026 |
| Level 2 control baseline (110 requirements, 14 families) | NIST SP 800-171 Revision 2 (Feb 2020, updated Jan 28, 2021) | July 13, 2026 |
| 320 objectives and examine/interview/test methods | NIST SP 800-171A (June 2018); DoD CMMC Assessment Guide – Level 2 | July 13, 2026 |
| Cost model ($31,234 C3PAO line; $101,752 assessment + initial affirmation; $104,670 three-year; remediation excluded) | Federal Register Regulatory Impact Analysis, 32 CFR Part 170 | July 13, 2026 |
| Phase 1 / Phase 2 timing (Nov 10, 2025 / Nov 10, 2026) | 32 CFR §170.3(e); DoD CMMC FAQ | July 13, 2026 |
| C3PAO / assessor counts (≈104 authorized; ≈988 assessors) | Cyber AB Town Hall, May 2026 (a dated snapshot — check the Marketplace for the current count) | July 13, 2026 |
| Real-world cost and timeline ranges | Published third-party industry analyses (2026), cited as estimates — not DCR-collected data; no market-average is asserted as fact | July 13, 2026 |
| Any individual provider’s status | Not evaluated on this page | Verify in the Cyber AB Marketplace when relevant |
Please read this as research, not advice.Confirm your scope and applicability with a CMMC Registered Practitioner or Registered Provider Organization (RP/RPO), and — where contract interpretation is involved — a qualified federal-contracts attorney. The contract clause and your CUI handling set your required level, not a checklist. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.