04
What happens during a CMMC Level 2 assessment week?
If you have never been through a CMMC Level 2 certification assessment, assessment week can feel like the unknown. Who needs to attend? What will the assessors ask? Will they look directly at your systems? How much evidence will you need to produce? The smoother assessments tend to have one thing in common: most of the work was done before assessment week began.
A CMMC Level 2 assessment is not simply a document review. The assessment team is evaluating whether your organization has implemented the applicable security requirements and whether you can demonstrate that implementation through evidence.
The five-week path we describe on our homepage applies to most engagements: an intro call and scoping in week zero, a kickoff meeting in week one, evidence collection with an optional mock assessment in weeks two and three, the assessment week itself, and the certification decision in the week that follows.
Before assessment week: establish the scope
A successful assessment starts with a clearly defined assessment scope. Before evaluating individual security requirements, the assessment team needs to understand the environment being assessed: where Controlled Unclassified Information (CUI) is stored, processed, and transmitted; the systems and assets involved; the people who interact with the environment; external service providers; connections to other systems; and the security technologies protecting the environment.
Your network and CUI data-flow diagrams matter here. The assessment team needs to understand not only where CUI is intended to reside, but how it actually moves through the organization. An unclear boundary creates problems throughout the rest of the assessment.
Weeks two and three: get your evidence organized
Your organization should not wait until the assessment begins to figure out how it will demonstrate implementation. Depending on the requirement, the evidence the assessment team needs may include:
- Your System Security Plan
- Policies and procedures
- Network and CUI data-flow diagrams
- System inventories and security configurations
- Access-control records, audit logs, and monitoring records
- Vulnerability scans and remediation records
- Training records and incident response documentation
- Change-management records, screenshots, reports, and tickets
But more evidence is not necessarily better evidence. The goal is not to hand the assessors thousands of files and expect them to determine what matters. Evidence should be relevant, current, organized, and tied to the implementation being evaluated.
Many organizations use this window for a mock assessment. We run mocks with the same methodology and rigor as an official evaluation, so you learn exactly where you stand before the real thing, while there is still time to do something about it.
Assessment week begins with an opening meeting
The formal assessment typically begins with an opening meeting between the assessment team and key members of your organization, where both teams confirm the scope, schedule, communication process, logistics, and the personnel who will participate. Your entire company does not need to sit through the assessment. The people who should be available are the people who actually understand and perform the processes being evaluated: your system administrator, security lead, IT provider, HR representative, incident response personnel, management, or others with responsibilities relevant to CMMC.
What assessors actually do: examine, interview, test
Examine. The assessment team reviews documentation and artifacts that demonstrate how a requirement has been implemented — a policy, a system configuration, an audit log, a vulnerability scan, or records showing that a recurring security activity actually occurred. The assessor is looking for evidence of implementation, not simply evidence that a document exists.
Interview. Assessors speak with the people responsible for performing security activities. If your procedure says the security administrator reviews audit logs, the team may interview the person performing that review. The purpose is not to quiz employees on CMMC terminology; your employees should be able to explain what they do, not memorize your policies.
Test. Some requirements require the team to validate implementation directly: observing system behavior, reviewing configurations in the live environment, testing security functionality, or having personnel demonstrate how a process works. A policy may say something happens; testing helps establish whether it actually does.
Your SSP will be compared with reality
Your System Security Plan is one of the most important documents in the assessment. The team compares what the SSP says against other evidence, interviews, and the systems themselves. If your SSP says one technology performs a security function but the environment shows something different, the discrepancy will need to be resolved. The same applies when procedures describe activities that employees say are not performed. Your SSP should describe the system you have today, not the system you intended to build six months ago.
Expect assessors to follow the evidence
Assessments do not always proceed as a perfectly scripted series of 110 questions. One piece of evidence may lead to another question. An architecture diagram may identify another system that needs to be understood. An interview may reveal a process that operates differently than the written procedure. That is normal. Assessors need enough objective evidence to make a determination. If you do not know an answer, say so and bring in the person who does.
Your MSP or MSSP may need to participate
If an external provider performs security functions for your organization, do not assume the assessment team will only need to speak with your internal staff. Your MSP may manage user accounts, patch systems, review alerts, perform vulnerability scans, maintain endpoint security, or administer network devices. If the answer to an assessment question is consistently “Our MSP handles that,” someone needs to be able to explain and demonstrate exactly what the MSP does.
What happens when an assessor finds a problem?
Finding a problem does not mean the assessment stops. The team first determines what the evidence shows and whether the applicable assessment objective has been satisfied. Sometimes what initially appears to be a gap is actually an evidence problem, and additional documentation, another interview, or a technical demonstration establishes that the requirement is implemented. Other times the requirement is simply not met. That distinction matters.
One thing does not happen during the assessment week: we do not fix or advise. Assessment week is not the time for the C3PAO to become your consultant and redesign your security program. We evaluate the implementation objectively and record the results. That independence is the entire basis on which an authorized C3PAO is allowed to conduct the assessment.
Can you fix something during the assessment?
Organizations sometimes assume they can use assessment week to identify deficiencies and correct them while the assessors wait. That is not how you should approach certification. You should enter the assessment believing the applicable requirements are already implemented. Depending on the nature of a finding and the applicable CMMC rules, certain requirements may be eligible for a Plan of Action and Milestones (POA&M), while others may not. That makes readiness before the formal assessment especially important.
How long does a CMMC Level 2 assessment take?
There is no single schedule that applies to every organization. The time required depends on the size and complexity of the environment, the assessment scope, the number and types of assets, the architecture, the availability and quality of evidence, and how efficiently you can provide access to the right personnel. A tightly scoped environment with well-organized evidence moves very differently from a complex enterprise with multiple locations, technologies, service providers, and business units.
The week after: the certification decision
At the conclusion of the assessment activities, the team consolidates and reviews the results, and your organization receives an outbrief explaining the results and any findings identified. We then complete the required assessment documentation and certification process, issuing the certification decision with the package that supports it — the evidence, the findings, and the basis for the decision, so your organization and your contracts have a record that stands up to scrutiny. If there are eligible requirements that have not been fully satisfied and your organization qualifies to use a POA&M, additional steps may be required before final certification.
How to make assessment week uneventful
A good assessment week should not contain many surprises. Before it begins, you should know:
- Where your CUI is and what systems are in scope.
- How each requirement is implemented and who is responsible for each security process.
- Where the evidence is located.
- Whether your SSP accurately reflects the environment.
- What your MSP and other external providers are responsible for.
- Whether the people who perform your security processes can explain and demonstrate them.
The best prepared organizations do not enter assessment week wondering whether they are compliant. They have already evaluated their environment, corrected known deficiencies, validated their technical configurations, updated their documentation, and organized their evidence. Assessment week is then what it is supposed to be: an independent evaluation of an already implemented cybersecurity program.
ManageIT Security is an authorized C3PAO conducting independent CMMC Level 2 certification assessments across the Defense Industrial Base. Book an intro call to discuss your assessment scope, timing, and what to expect.