CMMC • Assessment readiness • Act
Preparing for a CMMC Level 2 assessment
The strongest preparation is not a last-minute document collection. It is a scoped, operating security program whose people, technology, records, and System Security Plan tell the same story.
Direct answer
Prepare to demonstrate implementation—not to defend a binder.
A Level 2 assessment evaluates the 110 security requirements in NIST SP 800-171 Revision 2 through 320 underlying assessment objectives. Reviewers may examine records, interview responsible people, and test mechanisms or activities.
Before treating the environment as assessment-ready, confirm the contractual obligation, define and defend the CUI boundary, reconcile the SSP with reality, evaluate every objective, correct the score and POA&M, and rehearse how evidence will be retrieved and explained.
The active DFARS assessment stack
The CMMC pause did not pause 7012, 7019, or 7020.
7012 — Protect and report
DFARS 252.204-7012 requires adequate security for covered contractor information systems, implementation of the applicable NIST SP 800-171 baseline, cyber-incident reporting, cloud-provider conditions, and applicable flow-down.
7019 — Prove a current assessment exists
For award eligibility when NIST SP 800-171 applies, each covered contractor information system relevant to the offer must have a current DoD assessment score in SPRS—normally not more than three years old unless the solicitation requires less.
7020 — Support verification
A Basic Assessment must follow the DoD Assessment Methodology. The contractor must also provide the facilities, systems, and personnel needed for a Government Medium or High Assessment when required, and must address applicable subcontractor assessment obligations.
Six readiness gates
Do not schedule around a calendar. Schedule around verified readiness.
Confirm the obligation
Identify the controlling solicitation, contract, order, modification, or subcontract; required CMMC level and assessment type; covered information; systems; timing; and flow-down duties.
Freeze the scope
Map CUI assets, security protection assets, contractor risk managed assets, specialized assets, out-of-scope assets, people, locations, cloud services, external providers, and information flows.
Make the SSP match reality
Describe the actual boundary, environment, responsibilities, connections, implementation, and dependencies. Resolve contradictions between diagrams, inventories, procedures, contracts, and configurations.
Validate every objective
Use the Level 2 Assessment Guide to map each requirement and determination statement to sufficient examine, interview, and test evidence. Record gaps without turning draft artifacts into false proof.
Resolve score and POA&M risk
Know the expected score, which unmet requirements are not eligible for a POA&M, the minimum threshold for conditional status, and the 180-day closeout requirement before relying on a conditional path.
Rehearse controlled presentation
Assign evidence owners, verify access, test retrieval, prepare interviewees, protect sensitive records, and make sure the team can explain exceptions and shared responsibilities consistently.
Start with the boundary
Scope determines what must be assessed—and what can invalidate the story.
A Level 2 scope may cover an enterprise network or a defined enclave. The boundary is not just the place where CUI is stored. It includes the assets that process, store, or transmit CUI and other assets that provide protection or may affect the security of the environment, as defined in the current scoping guidance.
Boundary record
- CUI categories, sources, recipients, markings, and lifecycle
- Data-flow and network diagrams tied to current inventories
- Identities, privileged roles, endpoints, servers, applications, and locations
- Cloud service providers and external service providers
- Remote access, administration, monitoring, backup, support, and incident paths
- Asset-category decisions with rationale and ownership
- Shared-responsibility and inherited-control evidence
- Change triggers that require scope or status review
eTrepid professional standard
A Basic Assessment is not a basic checklist.
eTrepid does not treat an SPRS score as a spreadsheet exercise or accept unsupported control-owner assertions.
As an RPO using credentialed CMMC professionals and assessors, eTrepid evaluates the 110 requirements through their 320 underlying assessment objectives. That objective-level method is how we establish a supportable conclusion, expose incomplete implementation, and prepare the organization for later Government or CMMC verification.
Before eTrepid supports a score
- The contract and information obligations are identified
- The CUI boundary and relevant asset categories are documented
- CUI assets, security protection assets, adjacency, external providers, and shared responsibilities are addressed
- An SSP accurately describes the boundary, environment, implementation, and system relationships
- All 320 objectives receive an evidence-based determination
- The 110-requirement score is calculated from those determinations
- POA&M items, limitations, evidence gaps, and target dates agree with the score
- An accountable client official reviews the factual basis before submission
Representation risk
Low confidence does not mean low accountability.
A self-generated score can affect award eligibility and Government risk decisions. An unsupported or knowingly inaccurate cybersecurity representation may create contractual, award, repayment, reputational, and potential civil False Claims Act exposure.
The appropriate response to an unmet objective is not to inflate the score or narrow the boundary without support. Record the actual condition, evidence limitation, accountable owner, remediation, target date, and any authorized exception.
Why this must be defensible
In a 2025 Department of Justice settlement, a defense contractor acknowledged submitting a score of 104 after lacking full implementation and an adequate consolidated SSP; a later third-party review calculated a score of –142. The company paid $4.6 million to resolve False Claims Act allegations.
Evidence workspace
Organize proof around determinations, not file names.
| Evidence layer | What it should establish | Typical records | Quality check |
|---|---|---|---|
| Requirement and objective | The exact determination being supported | Requirement-to-objective matrix, applicability and responsibility record | Can a reviewer tell what conclusion the evidence supports? |
| Scope | Where and for whom the claim is true | SSP, diagrams, inventories, data flows, provider and location records | Do all representations describe the same current boundary? |
| Implementation | How the requirement operates | Policies, procedures, configurations, tickets, approvals, logs, review records | Do documented intent and operating behavior agree? |
| People | Authority, accountability, and recurring execution | Role descriptions, interviews, training, approvals, escalation paths | Can responsible people explain what actually happens? |
| Test | Whether the mechanism produces the intended outcome | Test plan, conditions, expected and observed results, retest record | Is the result reproducible and linked to the assessed environment? |
| Integrity and time | Authenticity and relevance to the assessed state | Source, owner, version, timestamps, export context, approval, change history | Would a change make the record stale or misleading? |
Internal readiness review
Run the assessment method before an assessor or affirming official depends on it.
A useful rehearsal is independent enough to challenge assumptions and practical enough to expose retrieval, ownership, and operating failures.
- Select representative requirements across all 14 requirement families.
- Trace each from requirement to objective, scope, SSP statement, evidence, interview owner, and test.
- Ask someone other than the control owner to retrieve and interpret the record.
- Compare policy language, technical state, operating records, and interview answers.
- Record unmet objectives, evidence limitations, ownership, remediation, and retest criteria.
- Expand the review until every objective has a supportable determination.
- Have the accountable executive review unresolved risk before any affirmation or scheduling decision.
Common failure modes
Six shortcuts create false readiness.
“The tool makes us compliant.”
GCC High, an enclave, an EDR platform, or another service may support requirements. It does not establish governance, scope, configuration, operations, evidence, supplier duties, or accountable affirmation.
“The policy says we do it.”
A policy shows intent. Reviewers may also need current operating records, interviews, configurations, observations, and tests.
“Low confidence means low effort.”
The Basic Assessment’s Low confidence rating reflects that the score is self-generated. It does not remove the need for an adequate SSP, a defined boundary, accurate determinations, and a methodology-based score.
“The MSP owns the requirement.”
Providers may implement or support part of a requirement. The organization still must define shared responsibility and demonstrate how the complete requirement is satisfied.
“A POA&M can cover every gap.”
CMMC permits only limited POA&M use. Some requirements are ineligible, a minimum score is required, and conditional items must be closed within the allowed period.
“Passing is the finish line.”
Status depends on continued compliance, annual affirmation, and material stability. Readiness must become an operating cadence, not a one-time project.
A practical 30–60–90 sequence
Use the first 90 days to reduce uncertainty before accelerating remediation.
Days 1–30: establish truth
- Confirm acquisition and information obligations
- Identify the accountable executive and working owners
- Map CUI and the proposed boundary
- Inventory assets and providers
- Assess the SSP and evidence baseline
- Build a risk-ranked gap register
Days 31–60: remediate and operate
- Resolve high-value scope and architecture issues
- Implement missing technical and administrative safeguards
- Assign recurring control activities
- Correct policies and procedures to match operations
- Collect native evidence from authoritative systems
- Test changes and preserve results
Days 61–90: validate and decide
- Complete objective-level internal assessment
- Reconcile score and permitted POA&M items
- Conduct interview and retrieval rehearsals
- Review provider and supplier evidence
- Obtain executive risk decisions
- Make a documented readiness or defer decision
Source and review record
Primary sources used for this draft.
- DoD CIO — Current CMMC program status and assessment overview
- DoD CIO — CMMC Level 2 Assessment Guide, Version 2.13
- DoD CIO — CMMC Level 2 Scoping Guide, Version 2.13
- DoD — NIST SP 800-171 Assessment Methodology, Version 1.2.1
- DFARS 252.204-7012 — Safeguarding and reporting
- DFARS 252.204-7019 — Current assessment award requirement
- DFARS 252.204-7020 — Basic, Medium, and High assessment requirements
- The Cyber AB — 2026 CMMC reform response and 110/320 explanation
- Department of Justice — MORSECORP cybersecurity settlement
- NIST SP 800-171A, June 2018
Understand the Basic Assessment first
For the underlying clause stack, scoring foundation, and meaning of a Low-confidence self-assessment, read What a DFARS 7020 Basic Assessment requires.
Assessment preparation path
Start with the readiness check, then review eTrepid’s CMMC readiness approach for scoping, evidence, remediation, and sustained operations.
Change triggers
Review after changes to DoD implementation status, 32 CFR Part 170, DFARS, the Level 2 assessment or scoping guides, the NIST baseline, SPRS, enforcement guidance, or eTrepid’s credentials and service method.
Contextual next step
Find the readiness risks before they control your assessment date.
eTrepid can help define the CUI boundary, reconcile the SSP, validate implementation and evidence, prioritize remediation, and establish the recurring operations needed to sustain a supportable status.
Assessment questions
Questions to answer before scheduling.
Does every Level 2 assessment require a C3PAO?
No. CMMC distinguishes Level 2 self-assessment and Level 2 C3PAO assessment paths. The required path depends on the acquisition and current implementation rules. As of this review, DoD states that implementation is paused in Phase I and may only require self-assessments at Level 1 and Level 2; verify current status and the acquisition record.
Is a DFARS 7020 Basic Assessment a lightweight review?
No. It is a self-generated assessment based on the SSP and conducted under the DoD Assessment Methodology. Its Low confidence rating describes the Government’s confidence in a self-generated score, not permission to skip scope, SSP, implementation, scoring, or evidence work. eTrepid applies an objective-level professional standard before supporting a score.
Do we have to implement all 110 Level 2 requirements?
Level 2 is based on all 110 NIST SP 800-171 Revision 2 security requirements, which contain 320 assessment objectives. CMMC permits limited POA&M use for certain unmet requirements and conditional status, subject to eligibility, scoring, affirmation, and closeout rules. A POA&M is not a general exception.
Is an SSP enough to show readiness?
No. The SSP is essential, but determinations also require support from policies, procedures, technical configurations, operating records, interviews, and tests that agree with the SSP and assessed scope.
Can an inaccurate SPRS score create False Claims Act exposure?
Potentially. Liability is fact-specific and depends on elements including knowledge, falsity, materiality, and claims or representations to the Government. Contractors should obtain legal advice for particular submissions and correct material inaccuracies through authorized channels.
Can our MSP or cloud provider supply all required evidence?
No. Provider evidence may support inherited or shared responsibilities. Your organization still must define the boundary, configure and operate customer responsibilities, govern identities and people, protect information, manage exceptions, and support the complete determination.
How long does preparation take?
It depends on scope, architecture, starting score, evidence maturity, provider dependencies, and the remediation required. Begin with a scoped readiness assessment before committing to a date.
Does eTrepid certify organizations?
No. eTrepid provides implementation and readiness support. Certification assessments, when required, are performed through the authorized CMMC assessment ecosystem. Readiness work does not guarantee an assessor’s determination or a government contracting outcome.