What Is a C3PAO?
A C3PAO (Certified Third-Party Assessment Organization) is a company authorized by the CMMC Accreditation Body (The Cyber AB) to conduct official CMMC Level 2 assessments. C3PAOs employ Certified CMMC Assessors (CCAs) who carry individual credentials issued by the Cyber AB and perform the actual assessment work under a Lead Assessor.
Not every cybersecurity consultancy is a C3PAO. The Cyber AB maintains the official marketplace of authorized organizations at cyberab.org. Before engaging any firm for a CMMC assessment, verify they are listed as authorized in the marketplace. Only assessments conducted by Cyber AB-authorized C3PAOs result in valid CMMC Level 2 certifications recorded in the DoD's eMASS system.
The Three Assessment Methods
C3PAO assessors follow the CMMC Assessment Guide Level 2, which defines exactly how each of the 110 requirements must be evaluated. Every requirement is assessed through one or more of three methods.
| Method | What It Means | Examples |
|---|---|---|
| Examine | Review documentation, policies, records, and configurations | SSP, policies, audit logs, configuration records, training records, network diagrams |
| Interview | Discuss implementation with personnel responsible for the control | IT staff, security officer, HR, physical security, end users, senior leadership |
| Test | Directly exercise or observe the security control in operation | Attempt access with invalid credentials, observe MFA prompt, review live firewall rules, run a vulnerability scan |
The Assessment Guide specifies which methods apply to each requirement and what evidence artifacts are expected. Your System Security Plan should map directly to these expectations — when you document your implementation, you are preparing exactly what the assessor will need to verify.
The Four Assessment Phases
Phase 1 — Plan and Prepare
You select a C3PAO and engage them through an initial contract covering NDAs, scope definition, and logistics. The C3PAO assigns a Lead Assessor who reviews your pre-assessment documentation: your System Security Plan, network diagrams, asset inventory, and proposed assessment boundary.
The Lead Assessor conducts a readiness review to determine if your organization is prepared to proceed to formal assessment. This is not the assessment itself — it is a gate check. If your SSP is incomplete or your evidence is disorganized, the assessor may delay the formal assessment until preparation is more complete. This phase can take several weeks depending on the quality of your documentation.
During this phase, the assessor also confirms your organization's legal entity (HQ Organization, Host Unit, or Enclave), verifies your CAGE code and SAM.gov registration, and establishes the specific systems, personnel, and locations that fall within the assessment scope.
Phase 2 — Conduct the Assessment
This is the core assessment activity. Depending on your environment and the scope of your assessment, this phase typically runs 2 to 5 days on-site, remotely, or in a hybrid format. Assessors work through each of the 110 requirements systematically, applying the examine, interview, and test methods specified in the Assessment Guide.
Expect daily check-in meetings with the Lead Assessor to review progress and preliminary findings. There should be no surprises at the end. If a requirement appears to be heading toward a NOT MET finding, a competent assessor will flag it during the assessment so you have the opportunity to provide additional evidence before the finding is finalized.
Key personnel who should be prepared and available during assessment:
| IT Manager or ISSO | Primary technical point of contact, responsible for most system-level controls |
| System Administrators | Detailed technical questioning on configurations, patching, and logging |
| HR Representative | Personnel Security (PS) and Awareness and Training (AT) controls |
| Facilities or Physical Security | Physical Protection (PE) controls |
| Senior Leadership | Attestation authority and organizational policy ownership |
| End Users with CUI Access | Assessors may interview regular users to verify their understanding of security responsibilities |
Phase 3 — Report Results
After assessment activities conclude, the C3PAO prepares a report detailing MET, NOT MET, or NOT APPLICABLE status for each of the 110 requirements. This report is typically delivered within two weeks of completing the assessment.
Based on the findings, your organization receives one of three outcomes. A Final CMMC Level 2 Certificate is issued when all requirements are MET or NOT APPLICABLE. A Conditional CMMC Level 2 Certificate is issued when some requirements are NOT MET but all failures are in requirements eligible for a POA&M. A Determination Letter is issued when one or more high-value requirements are NOT MET, indicating the assessment did not result in certification.
Phase 4 — POA&M Validation (If Applicable)
If you received a Conditional certificate, this phase covers the 180-day window to remediate your POA&M items. You must address each NOT MET finding within the timeframe defined in 32 CFR Part 170. The C3PAO reviews your remediation evidence and, if satisfied, upgrades your status to a Final certificate. Failure to close POA&M items within the 180-day window results in loss of your Conditional status.
How CMMC Assessment Scoring Works
Each of the 110 CMMC Level 2 requirements has an assigned point value in the SPRS scoring model: 1, 3, or 5 points. Higher-value requirements represent foundational or high-impact controls whose absence represents significant risk. The full score for 100% implementation is 110 points. Missing controls are subtracted from 110, with the minimum possible score being -203.
The scoring also determines whether a finding can be placed on a POA&M. High-value requirements (those worth 3 or 5 points) that receive a NOT MET finding will typically result in a determination letter rather than a conditional certificate. This is the critical distinction: not every gap is survivable with a 180-day POA&M window. Understanding which requirements carry higher point values before your assessment is part of effective preparation.
After assessment, your score is submitted to the DoD through the C3PAO and recorded in eMASS. Your SPRS entry is updated to reflect the C3PAO-assessed score, replacing or supplementing your prior self-assessment score.
The Most Common Assessment Failures
Based on DoD OIG findings, assessor accounts, and documented enforcement cases, these are the issues that most frequently result in NOT MET findings or assessment failures.
| SSP that does not match reality | Your SSP must describe your actual environment, not your intended or aspirational one. If your SSP states that MFA is implemented enterprise-wide but assessors find legacy systems without it, that is a finding. Every implementation statement in your SSP must be verifiable. |
| Missing or thin evidence | Claiming you do something is not the same as demonstrating it. Assessors need logs, configuration exports, screenshots, records, and other artifacts that prove a control is operating as described. Evidence collection should be an ongoing process, not a last-minute scramble before the assessment. |
| Inconsistent interview responses | When different personnel describe the same control differently, or when staff cannot explain their security responsibilities, assessors treat it as a finding. Everyone responsible for a control domain needs to understand what they do and why. |
| Scoping errors | If a system touches CUI and was not included in your assessment boundary, that is a significant finding. Your scope must include every asset that stores, processes, or transmits CUI — or you must implement controls that prevent those assets from touching CUI. |
| Incomplete or non-credible POA&Ms | A POA&M that lists gaps without realistic timelines, named owners, or interim mitigations will not satisfy assessors. A well-maintained POA&M demonstrates maturity and a genuine commitment to remediation. |
| Anti-malware gaps | The Georgia Tech settlement in 2025 centered on the absence of anti-malware software on systems handling CUI. This is one of the most basic controls, yet it remains a common gap. System and Information Integrity requirements are frequently underimplemented. |
How to Choose a C3PAO
With C3PAOs in high demand and assessment quality varying across the market, choosing the right organization matters as much as any preparation you do. Key questions to ask before signing a contract:
| Are you authorized by the Cyber AB? | Verify directly at cyberab.org before engaging. This is non-negotiable — only authorized C3PAOs can issue official certifications. |
| How many CCAs do you have? | Ask whether assessors are employees or contractors. Full-time CCAs with direct employment relationships typically offer more consistency than contractor-heavy teams assembled per engagement. |
| Do you have experience with our environment? | An assessor experienced with small manufacturers has different depth than one primarily assessing large defense primes. Match their experience to your size, industry, and technology stack. |
| Who specifically will be on our team? | Avoid situations where you meet one person during sales and encounter a completely different team during the actual assessment. |
| What is your current lead time? | With Phase 2 approaching in November 2026, lead times are extending rapidly. Ask now and build your timeline backward from their available slot. |
| What does your readiness review look like? | Quality C3PAOs conduct a pre-assessment readiness review rather than walking in blind. This protects both parties and reduces the risk of unexpected findings. |
| What are your fees, and what is included? | Get clarity on what is in the base fee versus what triggers additional charges. Travel, evidence review time, and POA&M validation can be significant add-ons. |
How Much Does a C3PAO Assessment Cost?
C3PAO assessment costs are not standardized and vary considerably based on your organization size, the number of assets in scope, complexity of your environment, and the C3PAO's pricing model. Publicly available accounts from contractors in the market suggest the following general ranges.
Small organizations with a well-defined and limited assessment boundary — typically 20 to 50 in-scope users and a handful of systems — have reported assessment costs in the $30,000 to $75,000 range. Mid-size organizations with more complex environments and distributed facilities commonly see costs of $75,000 to $150,000 or more. Large or complex environments with multiple locations, significant legacy infrastructure, or large in-scope system counts can reach $200,000 and above.
These figures cover the C3PAO assessment only. Preparation costs — remediation work, documentation, gap assessment, RPO consulting, and tool implementation — are often the larger investment and can exceed the assessment cost itself, particularly for organizations starting from a low baseline. One publicly documented case involved a contractor spending over $180,000 preparing for a Level 2 assessment before the assessment fees were even added.
Network segmentation to reduce your assessment scope is one of the most cost-effective preparation investments. By architecting your environment so that fewer systems touch CUI, you shrink both the compliance burden and the assessment fees.
What to Prepare Before Your Assessment
The single most impactful thing you can do before engaging a C3PAO is ensure your documentation is complete, accurate, and organized by requirement. Assessors follow the Assessment Guide systematically, and your documentation should be organized to match that structure.
| System Security Plan (SSP) | Your primary artifact. Must describe how each of the 110 requirements is implemented in your specific environment, naming specific systems, tools, configurations, and responsible personnel. Generic or template-based SSPs that do not reflect your actual environment are a leading cause of assessment problems. |
| Plan of Action & Milestones (POA&M) | For any requirements not yet fully implemented. Must include the specific gap, named owner, interim mitigation, and a credible completion date within 180 days. |
| Network diagrams | Showing your CUI boundary, data flows, external connections, and which systems are in and out of scope for the assessment. |
| Asset inventory | All hardware, software, and services that are in scope, with each asset's role in handling or touching CUI documented. |
| Policy library | Written policies for each security domain, approved by leadership and demonstrably communicated to staff before the assessment. |
| Evidence artifacts | Audit logs, configuration exports, vulnerability scan results, training completion records, access review records, incident response test documentation, and any other artifacts that demonstrate controls are operating as described. |
| Personnel briefings | Before the assessment, brief every person who may be interviewed on what controls they are responsible for and how to describe implementation consistently with your SSP. |
A mock assessment conducted by an RPO or internal staff before the formal C3PAO engagement is one of the most valuable investments you can make. It surfaces gaps in evidence, inconsistencies between your SSP and reality, and prepares your team for the interview process.