Inside a C3PAO Assessment: What Level 2 Assessors Actually Ask For | Stealth Technology Group
Update — July 13, 2026: DoD paused CMMC Phase 2 certification. NIST 800-171 and your signed affirmation did not pause. See What Still Applies →
Compliance & Certification

Inside a C3PAO Assessment: What Level 2 Assessors Actually Ask For

Michael Bannach, CISSP June 2026
~7 min read

Most contractors preparing for CMMC Level 2 have read the 110 controls. Far fewer know what the assessment itself feels like from the inside — what gets requested, who gets interviewed, and what actually determines whether a control passes. Having prepared organizations for exactly this scrutiny, here's the honest picture.

It's Bigger Than 110 Controls

The first surprise: assessors don't evaluate 110 things. They evaluate roughly 320 assessment objectives — because each NIST 800-171 control decomposes into multiple discrete objectives, every one of which must be met for the control to score as implemented. Take multifactor authentication: it isn't one checkbox. It's separate objectives covering local access, network access, and privileged accounts. Meet two of three and the control fails.

This is why self-assessments run against the control text alone routinely overstate readiness. The objectives, published in NIST SP 800-171A, are the actual test.

The Three Ways Assessors Verify Everything

For each objective, assessment teams use three methods — usually in combination:

  • Examine: Reviewing artifacts — policies, system security plans, configurations, diagrams, logs, screenshots. This is where your evidence package lives or dies.
  • Interview: Talking to the people who run the controls. Not just your IT lead — system admins, HR staff who handle onboarding, engineers who touch CUI daily.
  • Test: Watching things actually work. "Show me a failed login lockout. Show me what happens when someone plugs in a USB drive. Pull up the audit log for this event."

Key Takeaway: The interview is where prepared organizations stumble. If your SSP says one thing and your sysadmin describes another, that inconsistency does more damage than a missing document. Your people need to know how your controls work — because they'll be asked without you in the room.

What the Evidence Request Actually Looks Like

Expect the assessment team to request artifacts in these families, mapped objective by objective:

Governance documents

System Security Plan (the anchor document — every assessment starts here), policies and procedures for each control family, roles and responsibilities, and your CUI data-flow and boundary documentation.

Technical evidence

Configuration exports, MFA enrollment reports, encryption settings with FIPS validation certificates, firewall rules, SIEM/audit log samples, vulnerability scan results, and patch records.

Operational records

Access review sign-offs, security awareness training completions, incident response test records, media sanitization logs, visitor logs, and change management tickets.

The pattern to notice: much of this is records of things happening over time. You cannot generate six months of access reviews the week before an assessment. Evidence has to be lived, not staged — and experienced assessors can tell the difference immediately.

The Assessment Timeline

A typical Level 2 assessment runs in phases: a planning phase where scope and logistics are locked; an evidence review phase, often conducted remotely; the assessment week itself, mixing interviews, demonstrations, and testing; and an out-brief where preliminary findings are shared. Organizations with a limited number of unmet objectives may be able to close them through a constrained POA&M window rather than failing outright — but the controls eligible for that treatment are limited, and the heavyweight controls aren't among them.

The Mistakes That Sink Prepared Contractors

  • The SSP describes the aspiration, not the environment. Assessors treat your SSP as a set of claims to verify. Every gap between the document and reality is a finding.
  • Evidence exists but can't be found. Fumbling for twenty minutes per artifact across a three-hundred-objective assessment destroys the schedule and the assessors' confidence.
  • Inherited controls without responsibility documentation. Using a compliant cloud provider transfers implementation, not accountability. You need a shared-responsibility matrix showing which objectives you inherit and which remain yours.
  • Scope surprises. An undisclosed system that touches CUI, discovered mid-assessment, is the fastest way to derail everything.

What "Ready" Actually Means

Ready isn't "we implemented the controls." Ready is: every one of ~320 objectives mapped to named evidence, staff who can describe their controls unprompted, an SSP that matches reality, and a dry run that tested all of it under assessment conditions. That's the standard we prepare clients against — because it's the standard they'll be measured against.

Michael Bannach

Michael Bannach, CISSP

Michael Bannach is the President & CEO of Stealth Technology Group, a CyberAB Registered Provider Organization. He holds the Certified Information Systems Security Professional (CISSP) credential and brings 25+ years of enterprise IT and cybersecurity experience guiding defense contractors through NIST 800-171 implementation and CMMC readiness.

Want your evidence tested before an assessor tests it?

Our readiness work builds and pressure-tests the exact evidence package a C3PAO will ask for — led by the same expert from kickoff to assessment day.

Get Started Today