The Assessments page tracks your CMMC assessment engagements from planning through completion.

Assessment Types

TypeWhoWhen
Self-AssessmentYour organisationLevel 1 (all), Level 2 (non-critical CUI)
C3PAO AssessmentAccredited third-partyLevel 2 (critical CUI)
DIBCAC AssessmentU.S. GovernmentLevel 3
Internal ReviewYour organisationBest practice (any level)
Mock AssessmentConsultantBest practice (Level 2+)

Assessment Outcomes

CertifiedAll practices met; full certification (3 years with annual affirmation)
ConditionalSome practices on POA&M; 180-day closeout required
Not CertifiedToo many gaps; must remediate and reassess

Preparing for C3PAO Assessment

  • Complete your SSP covering all 110 Level 2 practices
  • Organise evidence by practice
  • Brief your team on assessment procedures
  • Run an internal review first
  • Review your POA&Ms for eligible practices only