Documentation & Reporting

Assessment Guide C3PAO Questions · 320+ Objectives · Interview Prep

The CMMC Assessment Guide is the official document C3PAO assessors follow. It contains the specific questions they ask, the methods they use, and the evidence they look for. for every one of the 110 requirements. 1TEN embeds all of it and links it to your actual implementation data.

320+ Assessment objectives
Per-practice Assessor questions
Linked To your evidence
The problem this solves
Most contractors assess against the 110 practice statements without knowing what assessors actually verify at the objective level. A practice marked Met because the policy exists can fail assessment when the assessor asks to see the specific evidence that the control functions in the actual environment. The CMMC Assessment Guide defines exactly what assessors look for. but most contractors never read it, let alone build their compliance program around it. 1TEN surfaces those objectives during assessment so your documentation meets the standard assessors are actually applying.

Assessment Objectives and Examiner Questions

Each of the 110 CMMC practices maps to one or more assessment objectives. the granular statements that define what "met" actually means. For AC.L2-3.1.1 alone, there are multiple assessment objectives covering policy existence, system configuration, and demonstrated enforcement. 1TEN surfaces all of these objectives during your requirements assessment so you can document at the level of specificity assessors require, not just the level the practice statement implies.

For each objective, the module shows the assessor's examine, interview, and test questions. drawn directly from the CMMC Assessment Guide. When you review a practice before your C3PAO assessment, you see exactly what the assessor will ask and what they'll look for in your evidence. Preparation at the objective level eliminates the most common source of unexpected findings.

Dashboard Requirements Evidence POA&M Reports
1TEN Assessment Guide showing the official C3PAO assessment questions mapped to each requirement

Evidence Gaps and Interview Preparation

For each assessment objective, the module shows which evidence artifacts you've uploaded that support it. Objectives with no attached evidence are flagged. giving you a prioritized list of documentation to complete before your assessment. The gap view is organized by domain and weighted by the point value of the practice, so you work the highest-impact gaps first.

The interview preparation view organizes assessor interview questions by domain. For each question, you can review your current implementation statement alongside the question. walking through the answer before the assessor asks it. Personnel who have reviewed their domain's interview questions in advance answer with confidence, not uncertainty. That difference is visible to assessors and affects the overall tone of the assessment.

What You See Inside

  • *320+ assessment objectives mapped to all 110 CMMC Level 2 practices. the granular statements assessors actually verify
  • *Per-objective assessor questions for examine, interview, and test methods. drawn from the official CMMC Assessment Guide
  • *Your implementation statement displayed alongside the assessor question. review your answer before the assessor asks it
  • *Evidence linkage per objective. which artifacts you've uploaded that support each assessment objective
  • *Evidence gap view. objectives with no attached evidence flagged and organized by domain and point value
  • *Interview preparation view. assessor questions organized by domain for personnel briefing before assessment
  • *Assessment readiness report. exportable summary of objectives with evidence gaps for pre-assessment review

Assessment Objective Coverage by Domain

Domain Code Practices Assessment Objectives
Access ControlAC22~60
Awareness and TrainingAT3~8
Audit and AccountabilityAU9~24
Configuration ManagementCM9~26
Identification and AuthenticationIA11~30
Incident ResponseIR3~10
MaintenanceMA6~16
Media ProtectionMP9~22
Personnel SecurityPS2~6
Physical ProtectionPE6~16
Risk AssessmentRA3~10
Security AssessmentCA4~14
System and Comms ProtectionSC16~44
System and Info IntegritySI7~20

What this replaces

  • *Assessing against practice statements only. without knowing the objectives that assessors actually verify underneath each practice
  • *Printing the CMMC Assessment Guide PDF and attempting to manually cross-reference it with your compliance documentation
  • *No pre-assessment interview preparation. personnel first hear assessor questions during the actual assessment interview
  • *Evidence gaps invisible until an assessor asks for documentation that isn't linked to the objective it's meant to satisfy
  • *No connection between what the assessor will examine and the documentation you've prepared. finding gaps on assessment day instead of before it

Practices Satisfied

Practice IDDescription
CA.L2-3.12.1 Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. objective-level assessment is the standard of effectiveness the guide defines.
All Domains Assessment objectives and examiner questions mapped to all 110 CMMC Level 2 practices across all 14 domains.

Related Modules

Requirements Browser
Assessment objectives from the Guide are surfaced in the Requirements Browser during assessment. you document at objective level as you assess each practice.
Evidence Manager
The Assessment Guide's evidence gap view shows which objectives have no attached evidence. the Evidence Manager is where those gaps get closed.
Assessment Summary
The overall readiness view in Assessment Summary reflects objective-level completion, not just practice-level status.
Policy Generator
Generated policies can be validated against the Assessment Guide's examine questions. confirming the policy language meets the specificity assessors look for.
See Assessment Guide in action.

Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.

Request a demo