Skip to main content
Guide

Future C3PAO Assessment Planning: An Illustrative 30-Day Checklist

An illustrative future-planning checklist for a CMMC Level 2 C3PAO assessment, with current guidance on DOD's Phase 2 suspension and contract-specific applicability.

CMMC Command Team
Compliance Engineering
Mar 8, 202610 min read
Table of Contents(24 sections)

Current-status note — August 1, 2026: During DOD's Phase 2 suspension, program managers and requiring activities may not designate Level 2 C3PAO or Level 3 assessments, and DOD directed active solicitations and contracts to remove those designations. Verify the latest solicitation and contract modification before relying on an earlier C3PAO requirement.

Planning for a Future C3PAO Assessment

This is an illustrative final-month review sequence for future planning after DOD permits Level 2 C3PAO designations. It is not a universal preparation timeline, completeness determination, or assurance of an assessment result. Coordinate any actual plan with the contracting officer or prime, an authorized C3PAO, and qualified advisers.

Week 1 (Days 30-24): Documentation Review

Day 30-28: SSP Deep Review

  • Review every section of your System Security Plan
  • Verify system boundary descriptions match your actual environment
  • Confirm all 110 controls have implementation statements
  • Check that personnel names and roles are current
  • Validate network diagrams reflect current architecture
  • Ensure CUI data flow diagrams are accurate

Day 27-25: POA&M Validation, If Applicable

  • If a POA&M exists, review whether all milestone dates are realistic
  • Verify that no POA&M items have passed their target dates without resolution
  • Document progress on each open item
  • Ensure each POA&M entry has: finding, milestone, responsible party, target date
  • Remove any items that have been completed (move to evidence)

Day 24: Policy Currency Check

  • Confirm each policy was reviewed on its organization-defined cadence and after relevant changes
  • Check that policy version numbers and review dates are current
  • Verify all team members have signed acknowledgments
  • Ensure policies cover all 14 NIST control families

Week 2 (Days 23-17): Evidence Gathering

Day 23-21: Technical Evidence

  • Capture fresh screenshots of security configurations
  • Export representative audit logs covering the period agreed in the assessment plan
  • Document MFA enrollment status for all CUI-access users
  • Capture vulnerability scan results (recent, not stale)
  • Export endpoint protection deployment reports
  • Screenshot access control lists and permission matrices

Day 20-18: Administrative Evidence

  • Gather training completion records for all personnel
  • Collect signed acceptable use agreements
  • Document incident response test results (tabletop or live)
  • Compile background check completion records
  • Gather maintenance logs for systems in CUI scope

Day 17: Evidence Organization

  • Map every piece of evidence to specific controls
  • Ensure no control is missing evidence entirely
  • Verify file names are descriptive (not "screenshot1.png")
  • Organize by control family for assessor navigation
  • Check that timestamps on evidence are recent

Week 3 (Days 16-10): Team Preparation

Day 16-14: Role-Based Interview Prep

Assessors will interview personnel in key roles. Prepare each person:

IT Administrator / System Admin

  • How are user accounts provisioned and deprovisioned?
  • Walk me through your patch management process
  • Show me your baseline configuration documentation
  • How do you monitor for unauthorized software?

Security Officer / CISO

  • Describe your incident response process
  • When was the last time you tested your IR plan?
  • How do you track CUI throughout your environment?
  • What's your risk assessment methodology?

General Staff

  • What is CUI and how do you handle it?
  • What would you do if you received a phishing email?
  • Where do you report security incidents?
  • What are your password requirements?

Day 13-11: Mock Interview Sessions

  • Conduct mock interviews with each key role
  • Document any knowledge gaps and provide targeted training
  • Ensure everyone knows the location of key documents (SSP, policies)
  • Practice walking through CUI data flow on the network diagram

Day 10: Logistics

  • Confirm assessment dates and agenda with C3PAO
  • Reserve meeting rooms for interviews
  • Prepare systems for live demonstrations
  • Coordinate secure, least-privilege evidence and demonstration access with the C3PAO
  • Designate a primary point of contact

Week 4 (Days 9-1): Final Preparation

Day 9-7: Dry Run

  • Walk through every control as if you're the assessor
  • For each control, can you show: policy, procedure, evidence, implementation?
  • Identify last-minute gaps and document them accurately; use a POA&M only when permitted and eligible
  • Verify all systems in scope are functioning normally

Day 6-4: Environment Check

  • Run a final vulnerability scan and assess findings against the applicable requirements, risk, and remediation plan
  • Verify all endpoints have current antivirus signatures
  • Check that all user accounts with CUI access still require MFA
  • Confirm audit logging is active and collecting events
  • Test your incident response communication chain

Day 3-1: Final Touches

  • Print and organize all documentation for quick reference
  • Brief the executive team on the assessment process
  • Confirm applicable self-assessment and affirmation records in SPRS are current; C3PAO results are transmitted through DOD-designated systems
  • Get a good night's sleep. You've prepared well

Common Assessment Pitfalls

1. Stale Evidence

Evidence should demonstrate that a requirement is implemented and operating during the assessment period. There is no universal 90-day freshness rule for every artifact; follow the assessment plan and retain date context.

2. Disconnected Documentation

Your SSP says one thing, but your actual environment looks different. Walk through every SSP statement with fresh eyes.

3. Untrained Staff

Personnel should be able to explain the responsibilities and procedures relevant to their roles. Treat this as one important evidence area, not a universal ranking of assessment findings.

4. Missing POA&M Items

An eligible NOT MET requirement may be documented on a POA&M for conditional status, but it is still deducted and POA&M restrictions apply. Some requirements cannot be placed on a POA&M for conditional status. Document known gaps accurately and confirm eligibility against 32 CFR 170.21.

5. Scope Creep

Maintain an accurate, validated assessment scope and SSP. Answer assessor questions fully and accurately, including questions about assets or services that process, store, transmit, protect, or can affect the security of CUI.

Post-Assessment: What Happens Next

  1. Assessment report: The assessment team documents its findings and result
  2. Conditional status, when eligible: A score of at least 88 and compliance with POA&M restrictions can support Conditional CMMC Status. Eligible remaining items must be closed within 180 days through a closeout assessment.
  3. Results recorded: The authorized assessment organization records the result and CMMC status in the DoD-designated system
  4. Status maintenance: Final Level 2 C3PAO status remains current for up to three years, subject to annual affirmation and the rule's status-maintenance conditions; Conditional status lasts no more than 180 days

Start your assessment prep with CMMC Command. Review estimated preparation indicators and AI-generated suggestions that require qualified human validation.

C3PAOAssessmentCMMC Level 2Audit Preparation

Organize your CMMC preparation

Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.