By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and Defense Industrial Base compliance.
Last reviewed: August 14, 2026
Educational research — not legal, contractual, assessment, cybersecurity, or compliance advice.
Regulatory and contractual claims were verified on August 14, 2026 against 32 CFR Part 170; DFARS 252.204-7012, -7019, -7020, -7021, and -7025; the Cyber AB Code of Professional Conduct v2.0; the CMMC Assessment Process v2.0; the current DoD CMMC Assessment Guide — Level 2; NIST SP 800-171 Revision 2; NIST SP 800-171A (June 2018); and the Department of War's July 13, 2026 Phase II suspension materials. The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, or any U.S. government agency.
A CMMC mock assessment is an optional, unofficial dry run of your CMMC Level 2 assessment — run the way a real assessor would run it — so you find out where you'd fall short before the formal Level 2 assessment puts real money and hard deadlines on the line. It creates no CMMC status, and the mock itself is not submitted to the government's CMMC system. If you are already inside the formal process, the urgent version is: can you convert a C3PAO assessment to a mock assessment after the engagement has started?
And here's the part almost every page glosses over: “mock” is a loose label stretched across at least five materially different services, and buying the wrong one can either waste your budget or quietly cost you the C3PAO you were counting on to certify you.
That last risk is the one that catches good teams off guard. And there is a second question we now get more than any other: can you convert a booked or in-progress C3PAO assessment to a mock once the real one is already underway — or already going badly? Contemporaneous published recaps of the Cyber AB's February and May 2026 Town Halls report yes, in one direction only: a formal Level 2 certification assessment may be paused and converted to a non-certification assessment at the organization's request, while a mock cannot be upgraded into a certification assessment mid-process. The regulation, Code of Professional Conduct, and CMMC Assessment Process do not publish a universal conversion cutoff or a standard commercial procedure, so your stage, reporting status, and contract treatment still have to come from your C3PAO in writing.
So instead of paraphrasing another vendor's blog, we read the actual rules — the Cyber AB Code of Professional Conduct, 32 CFR § 170.9, and 32 CFR § 170.17 — and separated what is written, what the Cyber AB has reportedly clarified in Town Halls, and what is our own decision framework. This page gives you the fast verdict up front, then the specific version of a mock you should buy, what it should cost, when to run it, the independence rule that trips people up, and what to do if you are already inside a formal assessment you want out of.
Quick verdict, before you scroll:
| Your question | The bottom line |
|---|---|
| Is a mock required? | No. It is an optional risk-reduction step. Nothing in the CMMC rule mandates it. |
| Who is it for? | Contractors with a stable scope, controls actually implemented, finished documentation, and evidence ready to survive scrutiny. |
| Who is it not for? | Contractors still defining their CUI boundary, writing the SSP, or implementing controls. You need readiness help first, not a dress rehearsal. |
| Does it create CMMC certification? | No — no certificate and no official CMMC status. |
| Is it reported to the government? | The non-certification assessment itself is not submitted to CMMC eMASS. A contractor may separately use qualifying work as the basis for an applicable self-assessment and report that self-assessment in SPRS. |
| Can the same firm do my mock and my real assessment? | Sometimes. A C3PAO can run a strictly no-advice non-certification assessment and remain eligible to assess you later only when the Code of Professional Conduct § 3.4 conditions are met, the results deliverable is retained for three years, and no other conflict exists. If that firm gives preparation or remediation advice, the three-year consultant bar applies. |
| Can I convert a booked or in-progress C3PAO assessment to a mock? | Published recaps of the Cyber AB's February and May 2026 Town Halls report yes, at the organization's request — in one direction only. A mock cannot become a certification assessment mid-process. No controlling written source sets a universal stage cutoff. |
| Does converting erase what already happened? | No published authority says prior formal-stage activity disappears. Ask the C3PAO, in writing, what CAP activity occurred, what was uploaded to CMMC eMASS, and when. |
| Do I get my money back? | No universal rule exists. Fees, credits, rescheduling, travel, data return, and reassessment terms are governed by your agreement with the C3PAO. |
| What does it cost? | No official mock price exists. Public seller examples are not directly comparable, and a mid-engagement conversion price lives in your agreement. Match scope before you compare price. |
If you're assessment-ready, a mock can be the smartest money you'll spend before a formal Level 2 assessment. If you're not, it's money you'll wish you'd spent on remediation. Let's make sure you know which one you are.
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
One honest thing before we go further
A mock assessment may be the wrong use of your budget right now. If your System Security Plan (SSP) is still a draft, your CUI boundary is still moving, or you're hoping someone will tell you how to build the controls, buy readiness and remediation work first — a mock only earns its cost once your environment is stable enough to actually test. Spending on a mock too early just produces an expensive list of things you already know are broken.
That's the bad news, and it's short. The good news: once you are stable, a mock is the highest-leverage thing you can do to de-risk a formal assessment — and everything below shows you how to buy the right one. If you're still in build mode, start with our gap assessment vs. C3PAO assessment guide, use the CMMC readiness checklist, or read who to hire first for NIST SP 800-171 implementation. Come back when your controls are real.
What is a CMMC mock assessment?
Answer capsule: A CMMC mock assessment is an unofficial, full or partial evaluation of a contractor's environment conducted outside the formal CMMC process, designed to simulate a real Level 2 certification assessment. When a C3PAO performs one, the Cyber AB calls it a “non-certification assessment.” It does not issue or deny CMMC status and is not reported to CMMC eMASS. Its job is to test the defined scope and document the results before real money and deadlines are on the line.
CMMC stands for Cybersecurity Maturity Model Certification — the Department of Defense program that verifies whether defense contractors protect two kinds of government information: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). A CMMC Third-Party Assessment Organization (C3PAO) — the term used by the Cyber AB and in 32 CFR Part 170 — is the independent organization authorized or accredited to conduct an official Level 2 certification assessment. A mock assessment is the practice run before that.
Strip away the sales language and a good mock is a controlled attempt to answer five questions honestly:
- Does your documented scope match what your network actually looks like?
- Can your team produce evidence on demand — not next week, on demand?
- Can the people who run each control explain and demonstrate it under questioning?
- Do the controls hold up when someone who isn't on your payroll pokes at them?
- Are there deficiencies worth fixing before real money and real deadlines are on the line?
An advisory version may also hand you a prioritized list of what to fix. A strict, same-C3PAO § 3.4 mock cannot — more on that below.
Why “mock assessment” doesn't name one standard service
Here's the trap. The Cyber AB acknowledges that a non-certification assessment is often referred to as a mock assessment, gap assessment, dry-run assessment, or other names — and sellers add “pre-assessment” and “readiness assessment” to the pile. The title on the proposal tells you almost nothing. It does not tell you whether advice is allowed, whether the work is full or partial, whether a C3PAO is performing it, or whether that C3PAO can still certify you afterward.
We'll untangle all five versions in a minute. For now, hold onto this: the word “mock” is not a specification. The statement of work is.
Why this mostly matters at Level 2
Most people searching for a mock assessment are preparing for CMMC Level 2, and that's where the interesting questions live. Level 1 (FCI only) is an annual self-assessment against 15 basic requirements. A full C3PAO-style rehearsal is usually unnecessary because a contractor can use third-party assistance and the result remains the contractor's self-assessment.
Level 2 (CUI) currently means implementing all 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 requirement families. Depending on the requirement stated in your solicitation and contract, you either complete a triennial Level 2 self-assessment or obtain a Level 2 C3PAO assessment, while maintaining the required annual affirmation of continuous compliance in between. That's the environment a mock is built to pressure-test.
NIST published SP 800-171 Revision 3 in May 2024, but Revision 3 is not the controlling CMMC Level 2 requirements set unless and until DoD changes the rule or otherwise changes the applicable contractual requirement. The current CMMC rule still incorporates Revision 2 for Level 2. A seller can offer separately labeled Revision 3 transition-readiness work; it cannot honestly call Revision 3 the current CMMC Level 2 assessment basis.
Is a CMMC mock assessment required?
Answer capsule: No. The CMMC Program Rule at 32 CFR Part 170 and the DFARS acquisition provisions and clauses establish how the required CMMC level and assessment type are designated, plus status and affirmation duties, but none requires a mock assessment. A mock is an optional business decision to reduce uncertainty before a formal assessment.
We checked the rule text and the current DFARS clauses. There is no “mock assessment” prerequisite in them. What is required is the applicable real assessment or self-assessment: the program manager or requiring activity selects the needed level and assessment type under the governing rules and current policy, and the solicitation and contract state the requirement when it applies. A mock is something you choose to do so you do not discover the truth at the most expensive possible moment.
When a mock is probably worth the money:
- Your environment has never faced outside, assessor-style scrutiny.
- Your CUI scope changed recently — a new cloud service, acquisition, remote-work model, site, or line of business.
- Different people wrote the SSP and built the actual environment, and nobody has checked that they agree.
- Evidence exists, but it has never been mapped to requirement-level determination statements or challenged.
- Key staff have never been interviewed about how their controls work.
- You are staring at a costly, schedule-locked C3PAO assessment and leadership wants an outside go/no-go read.
When it is probably premature:
- Your CUI scope is not final.
- You do not yet know your required level or assessment type.
- Your SSP is missing or materially incomplete.
- Controls are still being implemented, not operating.
- You already know about major deficiencies you have not fixed.
- Evidence has not been collected.
- You want someone to tell you how to fix things — and you are hoping that same firm will certify you later. Hold that thought. It is the most expensive misunderstanding in this whole topic, and we cover it below.
When it may be unnecessary:
- A credible independent readiness provider already tested you at the determination-statement level, and nothing material has changed.
- Your scope is small, stable, and already validated.
- You have real, current assessment expertise in-house and leadership accepts the residual risk.
- You are on a self-assessment path and do not need a full C3PAO-style rehearsal.
- The mock would consume remediation dollars you need for known gaps.
Gap assessment vs. mock assessment vs. the formal pre-assessment: the five things “mock” can mean
Answer capsule: A gap assessment finds weaknesses and tells you how to fix them. An advisory mock simulates a real assessment and then helps you improve. A “true” C3PAO mock — a non-certification assessment under the Cyber AB Code of Professional Conduct § 3.4 — tests you with no remediation advice so the same C3PAO may remain eligible to certify you later. CAP Phase 1 is part of the formal certification engagement, not a separate mock product. Only the formal Level 2 certification assessment can produce Conditional or Final Level 2 (C3PAO) status.
This is the heart of the confusion, and it is why two contractors can both “buy a mock” and end up with completely different results and completely different risks. Below is the distinction no single vendor page draws cleanly. We built it by cross-checking the Cyber AB's Code of Professional Conduct and CMMC Assessment Process against how these services are actually sold.
The CMMC Mock Assessment Independence & Fidelity Matrix
A Defense Compliance Report editorial framework. Last verified August 14, 2026. These labels describe how the services function — they are not official Cyber AB service categories.
| Service | Its real job | Typical provider | Advice or remediation allowed? | Can this firm run your later Level 2 certification assessment? | Official CMMC reporting treatment |
|---|---|---|---|---|---|
| 1. Gap or readiness assessment | Find deficiencies and explain how to close them | RP/RPO, consultant, MSP/MSSP, vCISO, or a C3PAO-affiliated consulting provider | Yes | No, when the same C3PAO organization or proposed assessment-team members performed prohibited preparation or consulting within the three-year window | No official CMMC assessment result; separate self-assessment reporting remains the contractor's responsibility |
| 2. Advisory mock assessment | Simulate assessor scrutiny, then help you fix what it finds | Assessment-experienced readiness provider, consultant, RP/RPO, MSP/MSSP | Yes | No for a provider that also wants to serve as your C3PAO within the prohibited three-year window | No official CMMC assessment result; separate self-assessment reporting remains the contractor's responsibility |
| 3. True C3PAO non-certification mock under CoPC § 3.4 | A formal, high-fidelity dry run with no fixes offered | A C3PAO | No recommendations, advice, or consultative information | Possibly — only when the § 3.4 engagement conditions are met, the results deliverable is retained for three years, and no other conflict exists; the C3PAO makes its own determination | Not reported to CMMC eMASS; may serve as the basis for an applicable self-assessment that the contractor completes and reports separately in SPRS |
| 4. CAP Phase 1 pre-assessment | Confirm scope, documentation, logistics, and readiness to begin the formal assessment | Your contracted C3PAO's assessment team | No remediation advice | It is part of that formal engagement | The Pre-Assessment Form is uploaded to CMMC eMASS |
| 5. Level 2 certification assessment | Determine conformity and produce the official result | Authorized or accredited C3PAO | No | Not applicable | The C3PAO submits assessment data to CMMC eMASS; CMMC status information is transmitted to SPRS |
The controlling distinction is not the word on the invoice. It is how the engagement is conducted. A consultative gap assessment and a no-advice C3PAO mock might look similar on a calendar, but they carry opposite consequences for who can certify you.
Two clarifications the matrix earns. First, number 4: CAP Phase 1 is not another informal review you shop for separately. It is the first phase of the formal certification engagement, it produces specified pre-assessment information that the C3PAO uploads to CMMC eMASS, and it cannot quietly turn into a remediation-consulting session when readiness problems surface. If a vendor is selling you “the pre-assessment” as a standalone readiness product, ask hard questions about what it actually means.
Second, on status: of the five services here, only the formal Level 2 certification assessment can produce Conditional or Final Level 2 (C3PAO) status. Level 1 and Level 2 self-assessments can produce their own applicable Self statuses through SPRS. A mock produces neither.
The right CMMC provider is not the same for every contractor. The category you need — a C3PAO, RPO, MSP/MSSP, GRC platform, or CUI enclave — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, cloud and IT environment, and contract timeline. The requiring activity and your actual solicitation and contract establish the requirement, not an online checklist.
You don't know which of these five you are actually buying.
That is the exact problem the matrix solves, and it is the one to solve before you talk to a vendor. Find My CMMC Path → maps your level, scope, environment, and timeline to the provider category that fits — readiness, enclave, GRC, or assessment. It routes to a category, not a named vendor, and it is not a score, ranking, endorsement, or compliance determination.
Do not submit CUI, drawings, export-controlled technical data, evidence files, credentials, network diagrams, contract files, or sensitive system details. Provider routing is free for readers. Where DCR may receive compensation from a partner, that compensation does not control our editorial analysis.
Can the same C3PAO run your mock and your official CMMC assessment?
Answer capsule: Sometimes — and this is the rule most pages get wrong. Under the Cyber AB Code of Professional Conduct § 3.4, a C3PAO can conduct a non-certification assessment and remain eligible for your later Level 2 certification assessment only when the engagement is formal, provides no remediation advice, produces a documented results deliverable, and the C3PAO retains that deliverable for three years — and only when no other conflict exists. If the firm provides preparation, advisory, or consulting help, the three-year consultant prohibition applies. The C3PAO, not the contractor or Cyber AB, makes and documents the engagement-specific conflict determination.
The baseline rule is blunt: a C3PAO cannot consult for, advise, or prepare an organization it will then assess. 32 CFR § 170.9(b)(2) requires a C3PAO to comply with applicable conflict-of-interest and Code of Professional Conduct policies, and the substantive three-year consultant prohibition appears at 32 CFR § 170.8(b)(17)(ii)(G). That prohibition reaches the C3PAO organization and the individuals on the assessment team.
The separation is baked into the regulation, not just industry etiquette.
But there is a carve-out, and it is real. The Cyber AB's Code of Professional Conduct defines a non-certification assessment and lays out how one may be conducted without creating the prohibited preparation relationship.
The three engagement conditions — plus the retention rule
Under Code of Professional Conduct § 3.4, a C3PAO's non-certification assessment avoids the preparation conflict only when the engagement satisfies these three enumerated conditions:
- It is conducted formally, using the applicable assessment procedures and framework guidance, except for official reporting and other parts that apply only to certification assessments.
- The C3PAO provides no recommendations, advice, or consultative information about how you might fix, configure, document, or improve anything.
- You receive a deliverable documenting the results of the non-certification assessment.
The section then imposes a separate retention requirement: the C3PAO must retain the results deliverable for three years and make it available to the Cyber AB upon request.
Miss one of the three engagement conditions — most commonly the no-advice condition — and the “mock” becomes preparation or consulting for conflict purposes. Breaching the retention obligation is also a Code problem, but retention is not a fourth enumerated engagement condition.
There is a related mechanic in the CAP: if the C3PAO finds during Phase 1 that you are not sufficiently prepared, the Lead CCA may recommend suspension in writing and explain why without giving remedial advice. If the organization postpones or cancels, the parties handle the commercial consequences under their agreement, and the C3PAO still completes, reviews, and uploads the Pre-Assessment Form. What happens next depends on your stage →
In other words, even inside the formal engagement, the assessor's job is to tell you that something is wrong, not how to fix it.
What stays inside the lines vs. what crosses into consulting
A Defense Compliance Report editorial illustration of the boundary — not a substitute for the C3PAO's own conflict-of-interest analysis.
| Fits a no-advice true mock: findings only | Crosses into consulting: disqualifying preparation for a future assessment |
|---|---|
| “This objective was Not Met because the evidence was not demonstrated.” | “Here is the configuration you should deploy.” |
| “We could not verify this process from the evidence you presented.” | “Rewrite your procedure using this language.” |
| “Your SSP and your observed environment were inconsistent.” | “Here is how we would re-architect your network.” |
| “This artifact did not substantiate the objective.” | “Use this template or tool to generate acceptable evidence.” |
| Determination-statement findings, with the basis for each | Product, implementation, documentation, or remediation recommendations |
A tradeoff worth naming
A true, same-C3PAO mock is deliberately less useful for fixing your problems. That is not a flaw — it is the design. Its value is high-fidelity, independent testing plus the possibility of assessor continuity. But if you need someone to explain how to remediate what the mock uncovers, a separate eligible provider has to do that work. You cannot get both “tell me how to fix it” and “also certify me” from the same C3PAO. Decide which you need more.
An affiliate, sister company, subcontractor, investment relationship, or shared personnel arrangement is not automatically safe or automatically disqualifying merely because of its label. The C3PAO has to disclose relevant relationships, analyze the facts, protect impartiality, and avoid or mitigate the conflict as the governing policies require. Put that analysis in writing rather than accepting “different LLC” as the whole answer.
Ask these in writing before you sign
- Are you treating this as a § 3.4 non-certification assessment under the Code of Professional Conduct?
- Do you intend to remain eligible to perform our later certification assessment?
- Will you provide any advice, recommendations, sample configurations, templates, documentation language, or remediation guidance? If yes, you are out as our C3PAO for the prohibited three-year period — and that may be fine, but we need to know.
- Who performs your conflict-of-interest review, and when do we receive it in writing?
- Will the same people who run the mock be assigned to the certification team?
- What deliverable documents the results, and how long do you retain it?
- Are there affiliates, subcontractors, sister companies, financial relationships, or shared personnel that could affect impartiality?
Getting this wrong can make the organization or an assessment-team member ineligible, create Cyber AB enforcement exposure, and disrupt an assessment you have already paid dearly for. It is worth a paragraph in the contract.
Advice from that firm, or certification continuity with that firm: pick one.
If you still need hands-on guidance, route to a readiness provider and keep a separate C3PAO for the formal assessment. If your environment is stable and you want a no-advice dry run, compare current C3PAOs with the § 3.4 boundary documented in writing. Find My CMMC Path → maps your level, scope, environment, and timeline to the right category.
Do not submit CUI, drawings, export-controlled technical data, evidence files, network diagrams, credentials, or sensitive contract details.
Can you convert a C3PAO assessment to a mock assessment?
Answer capsule: Contemporaneous published recaps of the Cyber AB's February 2026 and May 2026 CMMC Town Halls report that a formal Level 2 certification assessment may be paused and converted into a non-certification assessment at the organization's request, while a mock cannot be turned into an official certification assessment mid-process — a certification assessment has to start cleanly. The published Code of Professional Conduct, CMMC Assessment Process, and 32 CFR Part 170 do not define a universal conversion stage cutoff, reporting procedure, or commercial remedy, so get your exact CAP stage, eMASS activity, effective conversion time, deliverable, independence position, and fee treatment from the C3PAO in writing.
Here is the shape of it, because the asymmetry is the whole rule:
Formal Level 2 certification assessment → non-certification assessment: reported as available at the organization's request.
Non-certification assessment → formal Level 2 certification assessment mid-process: reported as not permitted.
The February 2026 Town Hall recap reports that a certification assessment may be paused and converted to a non-certification assessment, while a mock cannot simply become an official certification assessment midstream and the formal assessment must start cleanly. The May 2026 recap reports that the Cyber AB rejected a contrary market rumor that a mock could be upgraded mid-process when things were going well.
We are flagging that provenance on purpose. This operating answer comes from contemporaneous published recaps of Town Hall remarks, not from a conversion section in the regulation. We read 32 CFR Part 170, the Code of Professional Conduct, and the CMMC Assessment Process looking for a written conversion procedure and universal cutoff. They do not provide one. What they do provide is the architecture around the decision: what a non-certification assessment is, what formal C3PAO activity produces and reports, what the CAP requires when readiness fails, what the 10-business-day re-evaluation route does, and where assessor independence is lost.
Where this answer comes from — read the labels
We use three source tiers here. It matters more in this section than anywhere else on the page, because a Town Hall recap is not a regulation and we will not dress one up as the other.
| Source tier | What it establishes here | How to treat it |
|---|---|---|
| Written requirement — 32 CFR Part 170, Code of Professional Conduct v2.0, CAP v2.0, current DFARS clauses | Non-certification conditions, three-year consultant bar, eMASS and SPRS reporting, CAP Phase 1 completion, written suspension mechanics, the 10-business-day re-evaluation route, and the 180-day POA&M clock | Controlling text. Cite the section and apply it to the facts of the engagement. |
| Town Hall clarification, reported in a dated recap | The one-way conversion direction and the reported “existing evidence” interpretation of the 10-day route | Operationally important but not codified in the sources above. Confirm the C3PAO's current written position for your engagement. |
| DCR editorial conclusion | The Off-Ramp Map, decision table, amendment checklist, sequencing, and recommendations | Our synthesis of the written rules and reported clarifications. Not an official Cyber AB framework, CMMC status determination, or compliance advice. |
First, the thing nobody says out loud: you are not the first
If you are reading this because an assessment is going sideways, here is the most useful context we found.
A July 2025 Cyber AB Town Hall recap reported eight Level 2 assessment failures at that point and attributed to Cyber AB CEO Matthew Travis the caveat that the published count might not capture unreported false starts. The recap described false starts as organizations stopping partway through or converting to a mock when significant gaps surfaced.
That does not prove conversion caused the reported failure count to be low, and we are not claiming that it did. It does show that stopping or changing course when the evidence turns bad is not a scenario invented by one nervous contractor. It has been publicly acknowledged as part of the ecosystem's operating reality.
So no: converting is not an admission of disgrace. It is a decision. Make it a documented one.
Why the door only opens one way
The asymmetry looks arbitrary until you see what a formal assessment produces.
Under 32 CFR § 170.17(a)(1), a C3PAO submits Level 2 certification assessment results into CMMC eMASS, which then automatically transmits information to SPRS. Section 170.17(a)(1)(i) lists the minimum contents:
- Date and level of the assessment
- C3PAO name
- Assessment unique identifier
- Each assessor's name and business contact information
- Every industry CAGE code associated with the information systems in the CMMC Assessment Scope
- The SSP name, date, and version
- CMMC Status Date
- The assessment result for each requirement objective
- POA&M usage and compliance information, as applicable
- Artifact names, hash values, and the hashing algorithm used
That is what “official” means here. It is not simply a judgment that the work was good. It is an attributed data package created through the designated formal process and tied to an assessment identifier, assessment team, scope, SSP version, results, and artifact-hash record.
The regulation does not say, “these ten data elements are why conversion only works one way.” That explanation is DCR's operational inference from the formal record architecture plus the reported Town Hall direction. Work performed outside the formal process cannot simply be relabeled after the fact as if it had begun with the formal assessment identifier, team, process, and evidence-chain requirements. Going from a formal process to non-certification steps out of the official process; going from an informal mock into certification would try to retrofit work that did not begin there.
The DCR C3PAO Assessment Off-Ramp Map
A Defense Compliance Report editorial framework assembled from the Code of Professional Conduct, CMMC Assessment Process, 32 CFR Part 170, and dated Town Hall recaps. It is not official Cyber AB terminology, a CMMC status determination, or compliance advice. Last verified August 14, 2026.
Your options narrow as you move through the process. Find your row before you pick up the phone.
| Where you are right now | What the written rules establish | Conversion status | What may already exist | Get this in writing |
|---|---|---|---|---|
| No formal engagement signed | A C3PAO may perform a non-certification assessment. It creates no CMMC status and is not reported as a CMMC certification assessment to eMASS. | Not a conversion — you are choosing the engagement type. | Nothing from a formal C3PAO process. | Which of the five services you are buying; full or partial scope; advice boundary; future assessor role. |
| CAP Phase 1 underway; Pre-Assessment Form not yet uploaded | The Lead CCA evaluates readiness. If the organization is not sufficiently prepared, the Lead CCA may recommend suspension in writing without remedial advice. If the organization postpones or cancels, the C3PAO still completes, reviews, and uploads the Pre-Assessment Form. | Town Hall recaps support formal-to-non-certification conversion at the organization's request, but the written sources do not set conversion mechanics for this stage. | Working papers and CAP records held by the C3PAO; the Pre-Assessment Form may still be due for upload under the CAP. | Exact CAP activity; whether the C3PAO treats the action as conversion, suspension, postponement, cancellation, or a combination; what will be uploaded and when. |
| Pre-Assessment Form uploaded; Phase 2 not started | CAP Phase 1 concludes when the Pre-Assessment Form is successfully uploaded to CMMC eMASS. | No published universal cutoff was found. Do not assume you are eligible — and do not assume you are not. | The Phase 1 upload and the C3PAO's supporting records. | Upload date; current assessment status; effective conversion time; treatment of Phase 1 data; future independence position. |
| Phase 2 conformity assessment active | The formal team is evaluating implementation under the CAP. The CAP does not publish a stage-specific conversion procedure. | Town Hall recaps describe the formal-to-non-certification direction generally; no controlling source reviewed sets a universal cutoff. | Working papers, interviews, tests, artifacts, preliminary observations, and possibly formal system activity. Ask rather than guessing. | Exact stage; activities completed; effective time of any conversion; data already submitted; what the non-certification deliverable will contain. |
| Active assessment period ended; Findings Report not delivered | Section 170.17(c)(2) permits a NOT MET requirement to be re-evaluated during the assessment and for 10 business days after the active assessment period only when all three conditions are met. | This is a formal re-evaluation route, not conversion. | The formal assessment remains active for this narrow purpose. | Exact deadline; qualifying requirement; evidence basis; written confirmation all three conditions are met. |
| CMMC Assessment Findings Report delivered or results submitted | Final results are communicated through the Findings Report; Level 2 certification results are submitted to eMASS and transmitted to SPRS. | No source reviewed supports retroactively reclassifying a completed formal result as a mock. | The formal result and associated record. | Actual options: dispute or appeal rights, POA&M closeout if eligible, or a future assessment — not an assumed rewrite. |
| Conditional Level 2 (C3PAO) with an open POA&M | The POA&M closeout assessment must be completed by a C3PAO within 180 days of the Conditional CMMC Status Date, or the Conditional status expires. | A separate issue: you already hold a CMMC status. | The Conditional status, certificate record, POA&M, and running clock. | Closeout plan, eligible items, deadline, assessor, fees, and evidence. Do not confuse this with conversion. |
Read the map honestly. It does not say conversion is available at every stage. It shows where written sources are explicit, where the Town Hall recaps supply the reported operating answer, and where you must get the C3PAO's written position before relying on anything.
Three things conversion does not do
Say these out loud in your next internal meeting, because at least one person in the room believes the opposite.
It does not erase what already happened. We found no authoritative source stating that prior formal-stage activity disappears when an engagement becomes non-certification. A standalone non-certification assessment is not reported as a certification assessment to CMMC eMASS. That is a different sentence from “nothing from the prior formal engagement exists.” If a Pre-Assessment Form or results-related data were uploaded, ask the C3PAO exactly what was submitted, when, under what status, and what happens next.
It does not refund your money. No regulation or reviewed Cyber AB policy sets a conversion fee, credit, refund, or discounted reassessment. Those issues live in the agreement: work earned, assessor time reserved, travel committed, data held, deliverables scoped, rescheduling rights, and future-assessment terms. A mock and a full certification assessment are not the same product and should not be assumed to carry the same commercial treatment.
It does not unlock advice from a C3PAO that wants to preserve future independence. If the C3PAO intends to remain eligible to certify you later, the no-advice boundary still matters. 32 CFR § 170.8(b)(17)(ii)(G) bars CMMC Ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant to prepare for any CMMC assessment within the preceding three years. You can preserve advice from that firm or future certification continuity with that firm. You do not get both.
You know the possible off-ramps. You do not yet know which one your stage supports.
That is a stage question, a reporting question, and a contract question — and getting it wrong costs more than the conversation. Before you call your C3PAO, map where you sit: required level, CUI scope, environment, CAP stage, reporting status, and timeline. Find My CMMC Path → points you to the provider category that fits what is left to do — readiness, enclave, GRC, or assessment. It routes to a category, not a named vendor, and it is not a score, ranking, endorsement, or compliance determination.
Do not submit CUI, drawings, export-controlled technical data, evidence files, credentials, network diagrams, or contract text.
Is the 10-business-day window the same as converting? No — and the difference is expensive
Answer capsule: No. Under 32 CFR § 170.17(c)(2), a security requirement scored NOT MET may be re-evaluated during the assessment and for 10 business days after the active assessment period only when additional evidence is available to demonstrate the requirement is MET, the re-evaluation does not change or limit the effectiveness of other requirements already scored MET, and the CMMC Assessment Findings Report has not been delivered. It is a narrow evidence mechanism inside a live formal assessment — not a conversion procedure and not a general remediation period.
This is the most misunderstood ten days in CMMC, and the misunderstanding costs contractors their best option.
The rule says “additional evidence,” and contractors hear “time to build something.” A July 2025 Town Hall recap reports the Cyber AB's operational interpretation as evidence that already existed but was not presented — a policy that was not pulled up, a system demonstration that was not shown, or a needed subject-matter expert who was not available — rather than a newly implemented control or newly created evidence package. That reported interpretation is not a fourth condition written into § 170.17(c)(2), so keep the source label attached to it.
Run this test on your own situation:
Use the 10-day route when the evidence already existed, it can demonstrate the requirement is MET, considering it will not undercut other MET findings, and the Findings Report has not been delivered. Move immediately. The clock is short.
Do not reach for it when a control is not implemented, the SSP is materially incomplete, the environment needs re-architecture, the CUI boundary is wrong, or you need weeks of work. Those are suspension, postponement, conversion, or future-assessment conversations. Spending the ten days pretending otherwise means arriving at the deadline with the same gaps and one fewer option.
If there is real time pressure anywhere on this page, it is here. Not on a suspended November date. On this.
Does the same C3PAO survive a conversion?
Answer capsule: Possibly. A converted engagement has to preserve the Code of Professional Conduct § 3.4 boundary if the C3PAO wants to remain eligible for your later Level 2 certification assessment: formal engagement, no recommendations or consultative information, documented results deliverable, three-year retention, and no other conflict. The C3PAO makes and documents that determination; the Cyber AB does not issue an advance opinion for a specific engagement.
Converting mid-engagement adds questions the written sources do not expressly answer. Put these on paper before the change takes effect:
- Does the conversion change the original conflict-of-interest determination, and who re-runs it?
- Will the C3PAO document its impartiality conclusion after the engagement changes character?
- Will the converted engagement be conducted as a § 3.4 non-certification assessment — formal, no advice, documented deliverable, three-year retention?
- Does the C3PAO intend to remain eligible to conduct the later certification assessment?
- Has anyone at the firm, an affiliate, sister company, or subcontractor already given implementation or remediation input?
- Will the same assessment team return, and is that guaranteed, best-effort, or unavailable?
That last question is commercial, not regulatory, and it is worth asking. Team continuity is one of the few real advantages of converting in place instead of walking.
What the July 13, 2026 Phase II suspension does — and does not — do to this decision
Answer capsule: On July 13, 2026, the Department of War immediately suspended the transition to CMMC Phase II, which had been scheduled for November 10, 2026. Official implementing direction says program managers and requiring activities may designate only Level 1 (Self) or Level 2 (Self) during the suspension, may not designate Level 2 (C3PAO) or Level 3 (DIBCAC), must amend active solicitations with those higher designations as soon as practicable, and must remove them from existing contracts at the next option period or scheduled administrative modification. All Phase I self-assessment requirements remain in place. The suspension does not automatically terminate a private C3PAO agreement or erase an unmodified prime or subcontract requirement.
The suspension changed the business case for some assessments overnight. It did not amend 32 CFR Part 170, eliminate the current DFARS clauses, or cancel a private agreement between a contractor and a C3PAO. The official July 13 release also states that contractors and subcontractors remain obligated to protect covered defense information under DFARS 252.204-7012 and that the Department will enforce NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments during the review.
Before you convert because of the suspension, check four things in this order:
- Your actual solicitation or contract. Has it been amended or modified, or are you acting on a headline? The implementing direction tells the acquisition workforce what to remove and when; the document governing your award still needs to reflect the change. Ask the contracting officer in writing.
- Your prime or customer requirement. Government suspension guidance does not, by itself, rewrite a private subcontract, teaming agreement, or customer requirement. Determine what the prime still requires and whether that requirement will be changed.
- Your C3PAO agreement. Termination, deferral, credit, rescheduling, data return, travel, and future-assessment rights are in that document. Read it while you still have leverage.
- Your readiness and economics. If the engagement is going cleanly and certification still has customer or timing value, finishing may make sense. If the procurement requirement was actually removed and no prime or customer still requires it, the reason to spend now may genuinely have changed.
The Department established a 60-day reform task force on July 13, 2026. As of this review, the official sources cited here did not announce a replacement Phase II date. Do not let anyone sell you urgency built on the suspended November 10, 2026 milestone. The real clocks on this page are your assessment date, the 10-business-day re-evaluation period if it applies, the 180-day POA&M clock if you hold Conditional status, and the deadlines in your own agreement.
Convert, postpone, use the evidence window, or finish?
Answer capsule: Choose by the problem, not the label. Use the 10-business-day re-evaluation route when qualifying evidence can resolve a NOT MET result; use suspension, postponement, or reported formal-to-non-certification conversion when broader remediation is needed or the business case has changed; finish when scope, implementation, evidence, customer requirements, and economics still support the formal assessment.
A Defense Compliance Report editorial decision framework. Not a CMMC determination or compliance advice.
| Your situation | Most defensible next move | Why |
|---|---|---|
| Existing evidence could resolve a NOT MET result and the Findings Report has not been delivered | Ask about § 170.17(c)(2) re-evaluation immediately | It may preserve the formal assessment without changing the environment. It is the shortest clock on the page. |
| A control genuinely is not implemented | Stop treating it as an evidence problem | The re-evaluation route will not turn an unimplemented control into existing evidence. You need remediation from an eligible provider. |
| SSP, CUI scope, architecture, or evidence package is materially incomplete | Ask about suspension, postponement, or conversion, then bring in separate readiness help | The problem is broader than one artifact and the C3PAO cannot remediate it while preserving future independence. |
| Your solicitation or contract still expressly requires Level 2 (C3PAO) and has not been changed | Do not abandon the formal path because of a headline | Get the contracting officer's written position and the actual amendment or modification. |
| The higher assessment requirement was removed and no prime or customer still requires it | Reassess timing and economics before continuing | The near-term reason to spend may have changed. |
| The assessment is going well and the objective remains valuable | Finish | Conversion adds little when the formal result is still reachable and useful. |
| The Findings Report has been delivered | Use the actual dispute, POA&M, or future-assessment route available to your facts | No source reviewed supports retroactive reclassification of a completed formal result. |
| You do not know which stage you are in | Get a written stage and reporting statement first | This decision cannot be made from a generic checklist. |
What the conversion amendment has to say
Answer capsule: Document a conversion in a written amendment to the engagement agreement, not a loose email exchange. At minimum, identify the original and new engagement types, effective date and time, CAP activity reached, eMASS submissions already made, no-advice boundary, deliverable, fees, data handling, retention, future assessor eligibility, and resumption or future-assessment terms.
You are changing the contractual character of an engagement in which a third party may hold detailed evidence about your security posture. “We will just treat it as a mock” is not a document.
Make the amendment answer every line:
Engagement and status
- Original engagement type and new engagement type
- Effective date and time of the change
- CAP activity reached when the change took effect
- Whether CAP Phase 1 concluded
- Pre-Assessment Form upload status and date
- Any other CMMC eMASS activity tied to the engagement
- Whether the formal engagement is suspended, terminated, postponed, or replaced
Scope and output
- Full or partial non-certification scope, with exclusions named
- Assessment criteria and versions: NIST SP 800-171 Revision 2, NIST SP 800-171A (June 2018), 32 CFR Part 170, the current DoD Level 2 Assessment Guide, and applicable CAP procedures
- Deliverable: determination-statement-level results, methods, coverage, limitations, date, and version
- Advice boundary, stated explicitly
- No-status and no-guarantee statement
Independence and handoff
- Whether the C3PAO intends to remain eligible for the later certification assessment
- Who documents the conflict-of-interest determination and when you receive it
- Assessment-team continuity: guaranteed, best-effort, or unavailable
- Confirmation that remediation will come from a separate eligible provider if C3PAO continuity is preserved
Money and data
- Fees earned to date
- Credit, refund, or rescheduling treatment of unused assessment days
- Travel already committed, incurred, refundable, or nonrefundable
- Terms for a future formal assessment: separate fee, credit, retainer, or no commitment
- Data return, retention, destruction, subcontractor access, secure-transfer requirements, and any AI use
- Confidentiality, dispute, and termination terms
Keep a one-page internal decision record too: date, attendees, procurement requirement confirmed, CAP stage, eMASS status, re-evaluation-window status, option selected, source relied on, conflict status, remediation-provider category, commercial treatment, and next review date. If the decision is questioned later by a prime, contracting officer, auditor, new CFO, or board, that page is the answer.
You have converted. Now you have findings and an assessor who cannot help you fix them without giving up future assessor independence.
That is by design, and it is the moment most contractors lose weeks. The work ahead is readiness and remediation: scoping, SSP reconciliation, control implementation, evidence rebuilds, enclave decisions, and provider handoffs. It has to come from a provider whose involvement will not disqualify the C3PAO you want back.
Find My CMMC Path → maps your level, scope, environment, and timeline to the right provider category — readiness, MSP/MSSP, CUI enclave, or GRC platform — and keeps the future C3PAO boundary visible. Category routing, not a paid ranking or endorsement.
Do not submit CUI, drawings, export-controlled technical data, evidence files, credentials, network diagrams, or sensitive contract details.
Who should perform your CMMC mock assessment?
Answer capsule: Choose the provider category by what you actually need: remediation advice, a true no-advice C3PAO rehearsal, targeted testing, or the formal assessment itself. A credential or Cyber AB Marketplace listing verifies a role — it does not prove that the proposed team, scope, deliverable, independence position, availability, or price fits your environment. Verify current status directly at the source, then verify fit.
There is not one “mock provider.” There are categories, and the right one falls out of the decision you just made about advice versus continuity.
- If you need implementation or remediation help first, you are buying readiness, not a mock. Look at a Registered Practitioner Organization or Registered Practitioner, CMMC-focused consultant, or CMMC-focused MSP/MSSP. A C3PAO or affiliated provider that prepares you cannot simply assess you later without satisfying the governing independence rules.
- If you want an advisory mock — assessor-style pressure plus a punch list, an assessment-experienced readiness provider fits, and you preserve a separate C3PAO for the formal assessment.
- If you want a true no-advice C3PAO mock, you need a current C3PAO willing to run it under § 3.4: no recommendations, a formal results deliverable, three-year retention, and a documented conflict review — plus an honest answer about whether the same team will return and whether future scheduling is guaranteed.
- If you are already assessment-ready, do not buy more consulting because a provider invented another stage. Move to C3PAO selection and let the assessment organization perform the required CAP Phase 1 work.
Whatever the category, verify the organization and the people separately. Check the firm's current role and authorization in the Cyber AB Marketplace rather than trusting a logo on a slide. Confirm who is assigned to the engagement, the individuals' current credentials where relevant, and the date you checked. A Marketplace listing tells you the organization or individual holds a role. It does not tell you the team is available, experienced in your architecture, independent for your facts, or right for your scope.
For a category-by-category view before you contact anyone, use the CMMC provider categories guide.
How much does a CMMC mock assessment cost?
Answer capsule: There is no official mock-assessment price, and the public seller examples are not comparable enough to support a universal market range. The authoritative numbers are DoD's regulatory cost-model assumptions for the formal assessment a mock is meant to protect. Compare exact scope, advice boundary, testing depth, travel, deliverable, data handling, and future C3PAO role before you compare two prices. A mid-engagement conversion cost is contract-specific.
Start with the authoritative numbers, then read them correctly. In the CMMC Final Rule, DoD modeled these Level 2 certification costs:
| Cost item | Small entity | Other-than-small entity | What the number is |
|---|---|---|---|
| C3PAO assessment engagement | ~$31,234 | ~$52,056 | Regulatory burden-model assumption for the assessment provider engagement |
| Full assessment plus initial affirmation burden | ~$101,752 | ~$112,345 | Modeled contractor labor and support, C3PAO engagement, and initial affirmation burden |
| Three-year cycle including two annual affirmations | ~$104,670 | ~$117,768 | Modeled total over the three-year status cycle |
Those figures are regulatory modeling assumptions, not invoices, and the model assumes the organization has already implemented NIST SP 800-171 Revision 2. They price the assessment burden — not the work of becoming ready. For the full breakdown, see the CMMC Level 2 cost guide.
A mock is separate spend, and no official price exists. One seller-published June 2026 guide from PreVeil lists roughly $3,000 to $20,000 for mock audits or readiness coaching. That is not a verified market average and does not define a full C3PAO-style mock. A facilitated documentation review and a multi-day Examine-Interview-Test rehearsal across the full scope can both be sold as “mock assessments,” and they are not the same product.
| Public cost reference | Amount | Use it for |
|---|---|---|
| Seller-published mock or readiness support example | ~$3,000–$20,000 | A dated seller observation only; verify exactly what is included |
| DoD modeled C3PAO engagement — small entity | ~$31,234 | Understanding the formal assessment spend a mock is intended to protect |
| DoD modeled C3PAO engagement — other-than-small entity | ~$52,056 | Same, for the other-than-small model |
| DoD modeled full initial burden — small entity | ~$101,752 | Budget context, not a vendor quote |
| DoD modeled full initial burden — other-than-small entity | ~$112,345 | Budget context, not a vendor quote |
| DoD modeled three-year burden — small entity | ~$104,670 | Three-year regulatory burden context |
| DoD modeled three-year burden — other-than-small entity | ~$117,768 | Three-year regulatory burden context |
The seller figure is seller-stated data, not an audited invoice. The DoD figures are model assumptions, not quotes. The assembled comparison above was verified August 14, 2026.
A conversion mid-engagement has no universal price. The answer lives in your agreement: fees earned, unused assessment days, travel, rescheduling, data return, converted deliverable, and future formal-assessment terms. Do not infer a refund from the fact that the engagement changed labels. Use the conversion amendment checklist.
What actually drives the cost
Scope, mostly. Then: number and type of sites; number of in-scope systems and enclaves; cloud, hybrid, on-premises, and operational-technology complexity; how many External Service Providers touch the environment; interview count; travel; depth of testing; condition of the evidence; and detail in the final deliverable.
Two 50-person contractors can receive materially different quotes for legitimate reasons because employee count does not define CUI scope, sites, systems, ESP dependencies, interviews, or evidence condition. Ask what assumptions sit behind the quote.
What a cheap quote may quietly leave out
A low price is not automatically low quality — but confirm it is not skipping technical testing, determination-statement-level results, interviews, ESP review, multiple sites, retesting, or a real deliverable. A questionnaire emailed back to you is not the same as an assessor walking your controls.
What an expensive quote may be hiding
Sometimes the premium is readiness or remediation work bundled under a “mock” label, plus project management, travel, documentation development, tool resale, or a deposit toward the formal assessment. That may be exactly what you need. Just make sure you know you are buying it.
The only fair way to line up two quotes is to normalize them: base fee, travel, scope additions, retesting, optional advice or remediation, data handling, and formal-assessment commitments. Compare the normalized total — not the number in the headline.
Ready to get quotes, but you do not want three proposals that all just say “mock”?
Make every vendor answer the same questions. Use the SOW checklist below to force scope, advice rights, reporting, deliverables, data handling, and future C3PAO eligibility onto the page. If you are not sure which category you need, Find My CMMC Path →.
Do not submit CUI, drawings, export-controlled technical data, evidence files, network diagrams, credentials, or contract text in any form.
What should the mock-assessment SOW and final report require?
Answer capsule: The statement of work should remove ambiguity before you share evidence or fees become nonrefundable. It should identify the engagement type, tested scope, authoritative criteria and versions, methods and coverage, advice boundary, future C3PAO role, reporting treatment, data handling, deliverable, retention period, exclusions, change-order triggers, cancellation treatment, and what happens if the environment is not ready.
This is the checklist we would hand any contractor before signing a mock. Make the vendor answer every line in writing.
- Engagement identity. Is this consultative readiness, an advisory mock, a § 3.4 no-advice C3PAO mock, or the formal CAP engagement? Everything else depends on this answer.
- Scope and exclusions. Every CAGE code, system, enclave, asset category, site, ESP, and interview group that is in — and explicitly what is out. If partial, state what remains unvalidated.
- Authoritative criteria and versions. NIST SP 800-171 Revision 2, NIST SP 800-171A (June 2018), 32 CFR Part 170, the current DoD Level 2 Assessment Guide, and applicable CAP procedures when a C3PAO performs the work. Do not allow Revision 3 to be substituted as the current CMMC Level 2 basis.
- Methods and coverage. Which determination statements will be examined, interviewed, tested, or sampled, plus the depth and coverage for each tested area.
- Advice boundary. May the team recommend fixes, configurations, architectures, products, documentation language, or evidence formats? Yes for an advisory engagement; no for a § 3.4 mock intended to preserve C3PAO eligibility.
- Future C3PAO role. Does the provider or any affiliate, subcontractor, sister company, or shared team intend to remain eligible for the later certification assessment? Who documents the conflict determination, and when do you receive it?
- Reporting treatment. A standalone non-certification assessment does not create a CMMC certification result for eMASS. A separate contractor self-assessment may have its own SPRS reporting duty. State whether the provider will assist with a separate self-assessment, what the contractor remains responsible for, and whether any CAP or formal-stage activity already exists.
- Deliverable. Determination-statement-level results: what was tested, what was not, MET or NOT MET findings, evidence relied on, sampling limits, assumptions, date, report version, and whether recommendations were included or intentionally excluded. Add an explicit no-status and no-guarantee statement.
- Data handling. Where evidence is stored; who can access it; whether subcontractors are used; retention and destruction terms; secure transfer; whether AI is used; and whether any customer data would enter an internet-accessible AI application.
- Change orders and retesting. What triggers added cost: sites, scope expansion, ESPs, onsite work, interviews, evidence changes, or retesting.
- Remediation handoff. When advice is prohibited, identify who may help after the mock without disqualifying the intended C3PAO.
- Cancellation and conversion. What happens to fees, travel, data, scheduling, CAP records, deliverables, credits, and future assessment rights if the environment is not ready or a formal engagement converts to non-certification.
Get those answers before evidence changes hands and you remove most of the ways a mock engagement goes sideways.
When should you schedule a mock — and how long does it take?
Answer capsule: Schedule a mock after remediation is complete and controls are operating, with enough runway to fix what it finds and evaluate resulting changes before the formal assessment. Public seller examples run from several working days to a few weeks, but no authoritative universal duration exists. Do not treat a short delivery window as proof your organization will be ready when it ends — the point is to find problems, and problems take time to fix.
A practical sequence looks like this:
- Confirm the required CMMC level and assessment type against the actual solicitation and contract.
- Stabilize the CUI scope.
- Complete known remediation.
- Finalize the SSP and evidence index.
- Choose the mock type: advisory or true no-advice C3PAO mock.
- Run the mock.
- Triage findings.
- Remediate through an eligible provider when C3PAO continuity matters.
- Retest changed areas.
- Begin or resume formal C3PAO planning.
How much buffer to leave depends on what the mock finds. Missing evidence or a documentation mismatch may take days. A cryptography gap, architecture change, new tool, ESP contract problem, or scope redefinition can take weeks or months. Do not book the formal assessment on the assumption that every finding is a quick fix.
The phase clock — real, and worth reading correctly
The original phased schedule in 32 CFR § 170.3, tied to the November 10, 2025 effective date of the acquisition rule, was:
- Phase 1: November 10, 2025 through November 9, 2026
- Phase 2: November 10, 2026 through November 9, 2027
- Phase 3: November 10, 2027 through November 9, 2028
- Phase 4: November 10, 2028 onward
That is the original rule schedule, not the current implementation timetable. On July 13, 2026, the Department suspended the transition to Phase II and pending and future implementation milestones. The official CMMC page states that the program is paused in Phase 1, Phase I self-assessment requirements remain in place, and no replacement Phase II date had been announced as of August 14, 2026.
During the suspension, official implementing direction permits requiring activities to designate Level 1 (Self) or Level 2 (Self), not Level 2 (C3PAO) or Level 3 (DIBCAC), and directs amendments or modifications for higher designations as described above. That does not make your actual documents disappear. Confirm the current requirement in the solicitation, contract, subcontract, and any amendment before changing course.
If you have a booked or active formal assessment whose business case changed after July 13, read the conversion section before you invoke a suspended date as if it cancelled the engagement.
Do not let anyone stampede you into a rushed, over-scoped engagement with “everyone must be certified by November 10, 2026.” Confirm your required level against the actual procurement and, when needed, ask the contracting officer or a qualified federal-contracts attorney.
Does a CMMC mock assessment satisfy DFARS 252.204-7012, -7019, -7020, or -7021?
Answer capsule: No. A mock does not replace any separate DFARS cybersecurity or assessment obligation. DFARS 252.204-7012 safeguarding and 72-hour cyber-incident-reporting duties remain; -7019 requires an offeror to have current applicable NIST SP 800-171 DoD Assessment summary scores in SPRS for award; -7020 governs the DoD assessment clause, access, and SPRS posting; and -7021 governs required CMMC status, annual affirmation, reporting, and flow-down when included and applicable. A mock can inform the work. The mock itself is not the required SPRS score, CMMC status, or affirmation.
These get conflated constantly, so separate them:
- DFARS 252.204-7012 requires adequate safeguarding for covered contractor information systems and rapid cyber-incident reporting within 72 hours, among other duties.
- DFARS 252.204-7019 is the solicitation provision requiring a current NIST SP 800-171 DoD Assessment for covered systems relevant to the offer and verification that the applicable summary scores are posted in SPRS.
- DFARS 252.204-7020 is the contract clause governing NIST SP 800-171 DoD Assessments, contractor access for government assessments, and SPRS score posting.
- DFARS 252.204-7021 requires the contractor to have and maintain the CMMC status inserted in the clause for applicable systems, complete annual affirmations, report changes as required, and flow down requirements to covered subcontractors.
- DFARS 252.204-7025 is the solicitation notice that identifies the required CMMC level and assessment type when used.
A Code of Professional Conduct § 3.4 non-certification assessment may serve as the basis for a separate applicable self-assessment. That does not mean the mock itself becomes the contractor's required SPRS record. The contractor still has to conduct, report, and affirm the applicable self-assessment in the required system and format.
For the practical posting distinction, see the SPRS score guide.
What a CMMC mock assessment cannot prove
Answer capsule: A mock cannot create CMMC status, bind the formal assessment team, guarantee certification, prove the environment will remain compliant after later changes, resolve ambiguous contract applicability, or retroactively remove formal-stage activity already submitted. It is a dated evaluation of a defined scope and evidence set — not government approval and not a transferable promise that every assessor will reach the same result.
- It creates no status. No certificate, no official Conditional or Final Level 2 result, and no Level 2 certification result reported to CMMC eMASS from the mock itself.
- It cannot guarantee the official result. Even a high-fidelity mock can diverge because of environmental changes, new evidence, sampling, different assessors, scope corrections, or time elapsed. The Code of Professional Conduct prohibits guarantees of a particular assessment outcome.
- It may find a scope problem, not a control problem. An inaccurate boundary can force SSP revisions, asset recategorization, new systems into scope, additional ESP scrutiny, or more sites — changing cost and timeline. Better to learn it now.
- It cannot undo a formal assessment already in the record. No source reviewed says conversion retroactively removes a Pre-Assessment Form, formal result, or other activity already submitted. Ask what exists rather than assuming a clean slate.
- It does not move accountability off you. The contractor remains responsible for accurate representations, continuous operation, affirmations, contract applicability, evidence, remediation, and protecting CUI.
A favorable mock result is only as meaningful as what it documents. Before you treat “we would pass” as real, make sure the report captures the metadata that gives the conclusion meaning. Think of it as the receipt:
- Provider and provider category
- Engagement classification: advisory or § 3.4 no-advice
- Date
- Scope, CAGE codes, systems, and sites
- Requirements version and Assessment Guide version
- Full or partial coverage
- Determination statements tested
- Methods, depth, and coverage
- Exclusions and assumptions
- Whether advice was provided or prohibited
- Reporting treatment
- Future C3PAO eligibility position
Without those, a “pass” is a number without a scope — and a number without a scope tells you nothing about the assessment you are about to face.
What should you do after the mock assessment?
Answer capsule: Treat the mock as a decision point, not a finish line. Sort findings by scope, evidence, documentation, interview, technical, and ESP-dependency issues; resolve them through an eligible provider; update the SSP and evidence set; retest changes; and enter the formal assessment only when the resulting environment is ready, not merely when the original mock report is complete.
If you arrived here from a converted certification assessment rather than a standalone mock, the sequence is the same — but first confirm the prior CAP and CMMC eMASS status in writing.
The CMMC Mock-to-Formal Go/No-Go Gate
A Defense Compliance Report editorial decision framework — not a CMMC score, assessment result, status determination, or guarantee.
Proceed toward formal assessment only when:
- Required level and assessment type are confirmed.
- Scope is stable and documented.
- The SSP matches reality.
- Required evidence is available.
- Known deficiencies have been handled.
- Staff can demonstrate the processes they own.
- ESP responsibilities are documented and supportable.
- Material post-mock changes have been evaluated for scope and evidence impact.
- The future C3PAO's conflict review is complete.
- Leadership understands the remaining risk.
If the mock found documentation problems, fix the underlying process — not just the wording. Reconcile conflicting documents, update version history, confirm employees follow the revised process, and generate fresh operational evidence.
If it found technical problems, route remediation to an eligible technical provider, document and test the change, update the SSP and diagrams, and check whether the change altered the CMMC Assessment Scope.
If it found interview problems, do not coach people to recite things that are not true. Determine whether staff are simply unprepared to explain a working process, responsibilities are unclear, evidence is hard to reach, or the process is not actually operating. See the CMMC assessment interview questions guide for a domain-by-domain breakdown.
An eligible remediation provider is one whose work does not create a prohibited conflict for the C3PAO organization or individuals intended to conduct the later Level 2 certification assessment. If you used a no-advice C3PAO mock to preserve continuity, remediation has to come from someone else.
You have findings and need the right hands to fix them without wrecking assessor independence.
Find My CMMC Path → routes you to the readiness, implementation, enclave, or GRC category that fits the problem and keeps the future C3PAO boundary visible.
Do not submit CUI, drawings, export-controlled technical data, evidence files, credentials, network diagrams, vulnerabilities, or sensitive contract details.
What we actually verified for this guide
We use primary sources for regulatory and contractual claims, dated secondary sources only when no official transcript was available for a reported Town Hall clarification, dated seller sources for market observations, and clearly labeled editorial frameworks for decision guidance. Here is the ledger.
Primary regulatory and technical sources — verified August 14, 2026
- 32 CFR § 170.17: Level 2 assessment process; eMASS submission and automated SPRS transmission; minimum data elements; 10-business-day re-evaluation conditions; 180-day POA&M closeout; and artifact retention.
- 32 CFR § 170.8(b)(17)(ii)(G): the three-year consultant prohibition.
- 32 CFR § 170.9: C3PAO duties, conflict policies, eMASS submissions, and record retention.
- Cyber AB Code of Professional Conduct v2.0, § 3.4: non-certification assessment conditions, results deliverable, three-year retention, C3PAO responsibility for conflict determinations, and no Cyber AB advance opinion on a specific engagement.
- CMMC Assessment Process v2.0: Phase 1 readiness determination, successful Pre-Assessment Form upload as the end of Phase 1, written suspension recommendation without remedial advice, and required Pre-Assessment Form handling after postponement or cancellation.
- NIST SP 800-171 Revision 2 and NIST SP 800-171A (June 2018), as incorporated for CMMC Level 2 by 32 CFR Part 170: 110 requirements in 14 families and the assessment procedures used by the current rule.
- NIST SP 800-171 Revision 3, published May 2024: newer NIST publication, but not the CMMC-controlling Level 2 requirements set absent a DoD rule or contractual change.
- NIST SP 800-172 Revision 3, published May 2026: newer NIST publication; the current CMMC Level 3 rule text still incorporates selected requirements from the February 2021 SP 800-172 edition unless DoD changes the rule.
- Current DFARS 252.204-7012, -7019, -7020, and -7021: safeguarding, incident reporting, SPRS score, government-assessment access, CMMC status, affirmation, reporting, and flow-down duties.
- CMMC Final Rule cost analysis: DoD's modeled small and other-than-small Level 2 assessment costs.
- Department of War July 13, 2026 suspension release and official CMMC materials: immediate Phase II suspension, 60-day review, continued Phase I self-assessment requirements, continued NIST SP 800-171 Revision 2 enforcement through self-assessments and select government-led assessments, and continued DFARS 252.204-7012 obligations.
The eCFR displayed Title 32 as current through August 12, 2026 when checked. We found no amendment to Part 170 implementing a different Level 2 NIST revision or a codified conversion procedure.
Dated Town Hall clarifications used with explicit attribution
- February 2026: a contemporaneous CMMC.com recap reports that a certification assessment may be paused and converted to a non-certification assessment, while a mock cannot become an official certification assessment midstream.
- May 2026: a contemporaneous CMMC.com recap reports the one-way direction again in response to a claim circulating in the market that a successful mock could be upgraded mid-process.
- July 2025: a contemporaneous CMMC.com recap reports the “existing evidence” interpretation of the 10-business-day route and the comment that reported failure numbers might omit unreported false starts.
We did not locate an official machine-readable Cyber AB transcript for those conversion remarks. That is why the article attributes them to the dated recaps instead of presenting them as CFR, CAP, or Code language.
DCR independently assembled or counted
- The five-service Independence & Fidelity Matrix
- The “fits vs. crosses into consulting” boundary table
- The source-tier table
- The C3PAO Assessment Off-Ramp Map
- The convert, postpone, evidence-window, or finish decision table
- The conversion amendment checklist
- The mock-assessment SOW checklist
- The Mock Result Receipt
- The Mock-to-Formal Go/No-Go Gate
- The seven-row cost comparison combining seller-stated and DoD modeled figures
- A manual count of 320 lettered determination statements across 110 requirement-level objective sets in the current DoD CMMC Assessment Guide — Level 2, Version 2.13. The guide does not present “320” as a separately labeled official total; this is DCR's transparent count.
Current seller-stated observation
The roughly $3,000–$20,000 mock or readiness-support example is seller-published, dated, not an audited invoice, and not a representative market average.
What we could not verify
- A universal CAP stage at which conversion becomes unavailable.
- That formal-stage records are removed, erased, or superseded when an engagement converts.
- A universal conversion fee, refund, credit, or reassessment discount.
- That the reported one-way conversion direction applies to government-led DIBCAC or Level 3 assessments.
- An official machine-readable Cyber AB transcript for the February and May 2026 conversion remarks.
- Any provider success rate or “typical outcome” supported by primary data.
- Hands-on provider performance or customer invoices; we did not test providers or review customer billing records.
We rank no providers and endorse none on this page.
Frequently asked questions about CMMC mock assessments
Is a CMMC mock assessment mandatory?
No. It is an optional readiness decision. The CMMC Program Rule and DFARS acquisition provisions and clauses establish the actual assessment, status, and affirmation obligations; none requires a mock.
Is a mock assessment the same as a gap assessment?
Not necessarily. Terminology varies. “Gap assessment” usually means an earlier consultative diagnosis that tells you how to fix things; “mock assessment” usually means a later assessment-style pressure test. The Cyber AB acknowledges that these labels are used interchangeably for some non-certification work, which is exactly why the SOW matters more than the title.
Is a mock the same as the CAP pre-assessment?
No. A mock is outside the formal certification process. CAP Phase 1 is part of the formal C3PAO engagement, and the C3PAO uploads the Pre-Assessment Form to CMMC eMASS.
Can the same C3PAO perform my mock and formal assessment?
Conditionally, yes. The non-certification engagement must satisfy the three Code of Professional Conduct § 3.4 conditions, the C3PAO must retain the results deliverable for three years, and no other conflict may exist. If the C3PAO provides preparation or remediation advice, the three-year consultant prohibition applies. The C3PAO makes and documents its own conflict determination.
Can you convert a C3PAO assessment to a mock assessment?
Contemporaneous published recaps of the Cyber AB's February and May 2026 Town Halls report yes, at the organization's request, in one direction only: formal Level 2 certification assessment to non-certification assessment. The published regulation, Code, and CAP do not set a universal stage cutoff or commercial procedure, so confirm stage, eMASS activity, effective time, deliverable, independence, and fees in writing.
Can a mock assessment become an official CMMC certification assessment?
Not mid-process, according to the same reported Town Hall clarifications. A formal certification assessment must begin as the formal process. The regulation requires an attributed eMASS data package tied to the assessment identifier, team, scope, SSP version, per-objective results, and artifact hashes; private work outside that process cannot simply be relabeled after the fact.
At what CAP phase does conversion stop being available?
No controlling published source reviewed sets a universal cutoff. “Phase 1 only” and “at any time” are both too absolute. Get the C3PAO's written position for the exact stage and reporting status.
Does converting to a mock erase a failed or active assessment record?
No source reviewed says that it does. A non-certification assessment is not itself reported as a CMMC certification assessment, but that does not prove prior formal-stage activity disappears. Ask exactly what has already been uploaded or submitted.
Is the 10-business-day re-evaluation window a conversion route?
No. Section 170.17(c)(2) is a narrow formal re-evaluation mechanism when all three written conditions are met. A July 2025 Town Hall recap reports that the Cyber AB interprets “additional evidence” as existing evidence that was not presented, not time to implement a missing control.
Do I get a refund or credit if I convert?
Only if the agreement provides it or you negotiate it. No regulation or reviewed Cyber AB policy sets a universal conversion fee, refund, credit, or reassessment discount.
Does the July 2026 Phase II suspension cancel my C3PAO engagement?
No. It directs the Department's acquisition workforce to suspend higher-phase designations and amend solicitations and contracts as specified. It does not automatically terminate a private agreement with an assessor. Check the actual government amendment or modification, prime or customer requirement, and C3PAO contract.
Can a contractor still complete a private C3PAO assessment during the suspension?
The suspension policy prevents program managers and requiring activities from designating new Level 2 (C3PAO) or Level 3 (DIBCAC) requirements during the suspension and directs removal from covered solicitations and contracts. It does not itself amend Part 170 or automatically cancel private C3PAO work. Before paying to proceed, confirm with the C3PAO that the engagement can be completed and processed as intended, and confirm the business value with the contracting officer, prime, or customer.
Does the one-way conversion rule apply to DIBCAC or Level 3 assessments?
The sources reviewed address Level 2 C3PAO certification and non-certification assessments. We found no source extending the reported one-way direction to government-led DIBCAC or Level 3 assessments, so this page does not claim that it does.
Can the mock assessor tell us how to fix a NOT MET finding?
An advisory mock provider can. A C3PAO preserving eligibility to certify you later cannot provide recommendations, advice, or consultative remediation information.
Are mock results reported to the government in eMASS or SPRS?
A C3PAO non-certification assessment is not reported as a CMMC certification assessment to CMMC eMASS. A contractor may separately use qualifying work as the basis for an applicable self-assessment and report that self-assessment in SPRS. That does not turn the mock into an official certification assessment or make the provider's report the required SPRS record.
Does a mock create CMMC certification or status?
No.
Who can perform a CMMC mock assessment?
The label is not limited to one provider category. Consultants, Registered Practitioners and RPOs, MSPs and MSSPs, assessment-experienced specialists, and C3PAOs all sell services called mocks. The provider category and engagement terms — not the word “mock” — determine what the service can do and whether the same C3PAO can assess you later.
Should a mock cover all 110 Level 2 requirements?
A full mock should define coverage across the entire assessment scope and all applicable determination statements. A partial mock can focus on named areas, but the report must not imply that untested areas were validated.
How many assessment objectives or determination statements are there?
The current DoD CMMC Assessment Guide — Level 2 contains 110 requirement-level assessment-objective sets. DCR counted 320 lettered determination statements across those sets. Industry often calls all 320 “assessment objectives,” but 32 CFR § 170.4 defines an assessment objective as the set of determination statements for one requirement. A serious mock works at the determination-statement level and states what it covered.
Do Examine, Interview, and Test apply to every requirement?
Not necessarily. A Level 2 assessment uses Examine, Interview, and Test as applicable. The provider must obtain enough appropriate evidence to support each finding and should state the methods, depth, and coverage used for the tested areas.
Is CMMC Level 2 assessed against NIST SP 800-171 Revision 2 or Revision 3?
Revision 2 for CMMC purposes under the current rule. NIST published Revision 3 in May 2024, but DoD has not amended the CMMC Level 2 rule basis to Revision 3 as of this review. A separately labeled Revision 3 transition-readiness engagement is a different service.
What about NIST SP 800-172 Revision 3 for CMMC Level 3?
NIST published SP 800-172 Revision 3 in May 2026 and withdrew the February 2021 edition as a NIST publication. The current CMMC rule still incorporates selected requirements from the February 2021 edition for Level 3 unless DoD changes the rule. Do not silently substitute the newer publication as the controlling CMMC Level 3 basis.
How much does a CMMC mock assessment cost?
There is no official price and public examples are not comparable enough to support a universal range. Compare scope, advice boundary, assessment depth, travel, deliverable, data handling, and future C3PAO role before comparing price.
How long does a mock take?
Public seller examples range from several days to a few weeks, driven by scope, sites, interviews, evidence condition, methods, testing depth, and travel. No authoritative universal duration exists.
How far before the formal assessment should we schedule it?
After remediation and evidence preparation, with enough buffer to fix findings and evaluate resulting changes. There is no universal calendar rule — the buffer depends on what the mock finds.
Can we do a partial mock?
Yes. The Cyber AB's non-certification definition permits full or partial work. A partial mock should clearly identify what was and was not evaluated.
Does a favorable mock mean we will pass?
No. It is a dated read of a defined scope and evidence set. It reduces surprises; it does not guarantee the official result.
Is a “CMMC mock audit” the same thing?
“CMMC mock audit” is common shorthand, not an official CMMC term. Do not assume two sellers mean the same service. Verify the SOW, advice boundary, scope, methods, reporting treatment, data handling, and future C3PAO role.
Can an AI tool run a CMMC mock assessment?
No. AI can help organize a non-sensitive evidence index, identify document inconsistencies, or generate practice interview questions, but it cannot replace assessor judgment, the authorized assessment process, or an official status determination. The Cyber AB Code of Professional Conduct prohibits covered CMMC Ecosystem members from providing customer data to internet-accessible AI applications. Never paste CUI, SSP content, network diagrams, credentials, vulnerabilities, evidence, or sensitive contract information into a public chatbot.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, environment, and timeline, and we will map the situation to source-checked provider categories.
We first determine whether the facts point to readiness help, an advisory mock, a true no-advice C3PAO mock, evidence and workflow support, a CUI enclave, or a formal assessment conversation. Routing is by provider category and fit — not a paid ranking and not an endorsement.
Already know the category and need an introduction? Use the CMMC request-a-quote form.
Do not submit CUI, drawings, export-controlled technical information, evidence files, credentials, network diagrams, vulnerability details, or sensitive contract details in either form. These tools provide educational provider-category routing only. Share sensitive information only through an appropriate secure channel after independently verifying and engaging a provider.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and Defense Industrial Base compliance. We may receive compensation for qualified introductions, sponsorships, affiliate relationships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial & Advertising Policy.
This page is educational research, not legal, contractual, assessment, cybersecurity, or compliance advice. Confirm technical scope and readiness with a qualified Registered Practitioner, Registered Practitioner Organization, or other appropriate technical professional; confirm contractual applicability with the contracting officer and, when needed, a qualified federal-contracts attorney. The actual solicitation, contract, subcontract, information handling, and current government direction determine the required path — not this page or an online checklist.
The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, or any U.S. government agency.
Editorial trust links: Methodology · Editorial Standards · Corrections Policy · Editorial & Advertising Policy