Most contractors preparing for CMMC Level 2 have read the 110 controls. Far fewer know what the assessment itself feels like from the inside — what gets requested, who gets interviewed, and what actually determines whether a control passes. Having prepared organizations for exactly this scrutiny, here's the honest picture.
It's Bigger Than 110 Controls
The first surprise: assessors don't evaluate 110 things. They evaluate roughly 320 assessment objectives — because each NIST 800-171 control decomposes into multiple discrete objectives, every one of which must be met for the control to score as implemented. Take multifactor authentication: it isn't one checkbox. It's separate objectives covering local access, network access, and privileged accounts. Meet two of three and the control fails.
This is why self-assessments run against the control text alone routinely overstate readiness. The objectives, published in NIST SP 800-171A, are the actual test.
The Three Ways Assessors Verify Everything
For each objective, assessment teams use three methods — usually in combination:
- Examine: Reviewing artifacts — policies, system security plans, configurations, diagrams, logs, screenshots. This is where your evidence package lives or dies.
- Interview: Talking to the people who run the controls. Not just your IT lead — system admins, HR staff who handle onboarding, engineers who touch CUI daily.
- Test: Watching things actually work. "Show me a failed login lockout. Show me what happens when someone plugs in a USB drive. Pull up the audit log for this event."
Key Takeaway: The interview is where prepared organizations stumble. If your SSP says one thing and your sysadmin describes another, that inconsistency does more damage than a missing document. Your people need to know how your controls work — because they'll be asked without you in the room.
What the Evidence Request Actually Looks Like
Expect the assessment team to request artifacts in these families, mapped objective by objective:
Governance documents
System Security Plan (the anchor document — every assessment starts here), policies and procedures for each control family, roles and responsibilities, and your CUI data-flow and boundary documentation.
Technical evidence
Configuration exports, MFA enrollment reports, encryption settings with FIPS validation certificates, firewall rules, SIEM/audit log samples, vulnerability scan results, and patch records.
Operational records
Access review sign-offs, security awareness training completions, incident response test records, media sanitization logs, visitor logs, and change management tickets.
The pattern to notice: much of this is records of things happening over time. You cannot generate six months of access reviews the week before an assessment. Evidence has to be lived, not staged — and experienced assessors can tell the difference immediately.
The Assessment Timeline
A typical Level 2 assessment runs in phases: a planning phase where scope and logistics are locked; an evidence review phase, often conducted remotely; the assessment week itself, mixing interviews, demonstrations, and testing; and an out-brief where preliminary findings are shared. Organizations with a limited number of unmet objectives may be able to close them through a constrained POA&M window rather than failing outright — but the controls eligible for that treatment are limited, and the heavyweight controls aren't among them.
The Mistakes That Sink Prepared Contractors
- The SSP describes the aspiration, not the environment. Assessors treat your SSP as a set of claims to verify. Every gap between the document and reality is a finding.
- Evidence exists but can't be found. Fumbling for twenty minutes per artifact across a three-hundred-objective assessment destroys the schedule and the assessors' confidence.
- Inherited controls without responsibility documentation. Using a compliant cloud provider transfers implementation, not accountability. You need a shared-responsibility matrix showing which objectives you inherit and which remain yours.
- Scope surprises. An undisclosed system that touches CUI, discovered mid-assessment, is the fastest way to derail everything.
What "Ready" Actually Means
Ready isn't "we implemented the controls." Ready is: every one of ~320 objectives mapped to named evidence, staff who can describe their controls unprompted, an SSP that matches reality, and a dry run that tested all of it under assessment conditions. That's the standard we prepare clients against — because it's the standard they'll be measured against.