Level 2 assessment day: what a C3PAO actually checks
By the Atom Cybersecurity team
A CMMC Level 2 certification assessment is not a document review and it is not a conversation about intentions. A Certified Third-Party Assessment Organization — a C3PAO — comes to test whether the environment described in your System Security Plan is the environment that actually exists, control by control. Knowing how the day runs is the difference between a team that demonstrates its posture calmly and one that improvises. Here is what a C3PAO actually checks.
All 110 controls, three ways
A Level 2 assessment covers the full set of 110 NIST SP 800-171 controls — not a sample of them. For each control, the assessor gathers evidence through three complementary methods, and no single method is enough on its own.
- Examine. Reviewing artifacts — policies, configurations, screenshots, logs, tickets — that show the control exists and is documented.
- Interview. Talking to the people who operate the control, to confirm they understand and actually perform it. A policy no one follows is not a met control.
- Test. Observing the control in action — watching an administrator demonstrate that MFA challenges a login, that an account lockout triggers, that logs are being generated and reviewed.
Walkthroughs, interviews, and evidence sampling
The day typically opens with a scoping confirmation and a walkthrough of the environment: the assessor validates the boundary in your SSP against what is really deployed. From there the work is methodical. The assessor samples evidence — they do not inspect every endpoint or every account, but they pull representative examples and expect them to hold up. If they ask to see MFA on five accounts and one is exempt without justification, that is a problem for the whole control.
Interviews are conducted with the people who actually do the work, not only leadership. An assessor may ask a systems administrator to walk through how a user is offboarded, or ask a help-desk technician what they do when they suspect an incident. The answers must match the documented procedures. This is why coaching the team matters as much as fixing the technology.
MET, NOT MET, NOT APPLICABLE
Each control receives one of three determinations, and the scoring is strict.
- MET — the control is fully satisfied, with evidence across examine, interview, and test. There is no partial credit; "mostly implemented" is NOT MET.
- NOT MET — the control, or any required element of it, is not fully satisfied. Depending on the control's weight and POA&M eligibility, this can be closed on a limited POA&M or can fail the assessment outright.
- NOT APPLICABLE — the control genuinely does not apply to the scoped environment (for example, a wireless control where no wireless exists). N/A must be justified and documented; it is not an escape hatch.
To pass, foundational high-weight controls must be MET on the day. Only a narrow set of lower-weight items may sit on a POA&M, and only if you clear the minimum score threshold — with a hard closeout window on the order of 180 days. This is the verification that DFARS 252.204-7021 layers on top of the long-standing obligation in DFARS 252.204-7012.
The SSP is the assessor's map
Everything runs off the System Security Plan. It defines the boundary the assessor evaluates and, for each control, states how it is met. The assessor's core task is to confirm the SSP is accurate. When the document and the environment disagree, the environment wins for scoring — and the credibility of the whole plan drops, which means more probing everywhere. An SSP that precisely describes reality makes the assessment shorter and calmer; a fictional one guarantees a long, adversarial day.
Evidence is what connects the SSP claim to the finding. Each control the plan says is met should have findable, current evidence behind it. Assessors are not impressed by volume; they want the right artifact, quickly, that clearly demonstrates the control operating.
The three-year cycle and annual affirmations
A Level 2 certification is valid for three years, but it is not fire-and-forget. Each year you must submit an annual affirmation in SPRS confirming you continue to meet the requirements — a senior official attesting that the posture assessed on day one still holds. If a CUI system materially changes, that is a trigger to reassess your standing, not something to reconcile at the next three-year mark. Certification is a snapshot; the affirmations keep it honest between assessments.
How to prepare your team
The technology is only half the readiness picture. The other half is people who can demonstrate their controls without stumbling.
- Rehearse the walkthrough. Run a mock assessment so administrators practice pulling evidence and demonstrating controls live, on the systems, under mild pressure.
- Brief the interviewees. The people who operate controls should know their procedures well enough to describe them in their own words — matching, not reciting, the SSP.
- Organize evidence in advance. Map each control to its artifact so nothing is hunted for during the assessment. Slow retrieval reads as weak control.
- Answer only what is asked. Honest, precise answers. Volunteering an unrelated weakness invents a finding that was not on the table.
- Fix the heavy gaps first. Ensure every high-weight control is genuinely MET before the date, because those are the ones that fail an assessment rather than land on a POA&M.
Where Atom fits — and where we do not
We prepare contractors for assessment day: scoping the boundary, building an SSP that survives sampling, remediating the controls that matter most, assembling evidence, and running mock assessments so the team performs when the C3PAO arrives. Then we keep the controls running so the annual affirmations stay honest. We are direct about one boundary: Atom is not a C3PAO and does not perform or issue the certifying assessment. That is, by design, an independent third party. Our job is to make their assessment confirm what you already know to be true.
Make assessment day a formality, not a gamble.
Request a readiness assessment. We scope your CUI environment, remediate to all 110 controls, assemble your evidence, and rehearse your team before the C3PAO arrives.
Request a Readiness Assessment →