Updated August 26, 2026

CMMC • Assessment readiness • Act

Preparing for a CMMC Level 2 assessment

The strongest preparation is not a last-minute document collection. It is a scoped, operating security program whose people, technology, records, and System Security Plan tell the same story.

Direct answer

Prepare to demonstrate implementation—not to defend a binder.

A Level 2 assessment evaluates the 110 security requirements in NIST SP 800-171 Revision 2 through 320 underlying assessment objectives. Reviewers may examine records, interview responsible people, and test mechanisms or activities.

Before treating the environment as assessment-ready, confirm the contractual obligation, define and defend the CUI boundary, reconcile the SSP with reality, evaluate every objective, correct the score and POA&M, and rehearse how evidence will be retrieved and explained.

The active DFARS assessment stack

The CMMC pause did not pause 7012, 7019, or 7020.

7012 — Protect and report

DFARS 252.204-7012 requires adequate security for covered contractor information systems, implementation of the applicable NIST SP 800-171 baseline, cyber-incident reporting, cloud-provider conditions, and applicable flow-down.

7019 — Prove a current assessment exists

For award eligibility when NIST SP 800-171 applies, each covered contractor information system relevant to the offer must have a current DoD assessment score in SPRS—normally not more than three years old unless the solicitation requires less.

7020 — Support verification

A Basic Assessment must follow the DoD Assessment Methodology. The contractor must also provide the facilities, systems, and personnel needed for a Government Medium or High Assessment when required, and must address applicable subcontractor assessment obligations.

A “Low” confidence label describes the Government’s confidence in a self-generated Basic Assessment score. It does not mean the work can be superficial.

Six readiness gates

Do not schedule around a calendar. Schedule around verified readiness.

Confirm the obligation

Identify the controlling solicitation, contract, order, modification, or subcontract; required CMMC level and assessment type; covered information; systems; timing; and flow-down duties.

Freeze the scope

Map CUI assets, security protection assets, contractor risk managed assets, specialized assets, out-of-scope assets, people, locations, cloud services, external providers, and information flows.

Make the SSP match reality

Describe the actual boundary, environment, responsibilities, connections, implementation, and dependencies. Resolve contradictions between diagrams, inventories, procedures, contracts, and configurations.

Validate every objective

Use the Level 2 Assessment Guide to map each requirement and determination statement to sufficient examine, interview, and test evidence. Record gaps without turning draft artifacts into false proof.

Resolve score and POA&M risk

Know the expected score, which unmet requirements are not eligible for a POA&M, the minimum threshold for conditional status, and the 180-day closeout requirement before relying on a conditional path.

Rehearse controlled presentation

Assign evidence owners, verify access, test retrieval, prepare interviewees, protect sensitive records, and make sure the team can explain exceptions and shared responsibilities consistently.

Start with the boundary

Scope determines what must be assessed—and what can invalidate the story.

A Level 2 scope may cover an enterprise network or a defined enclave. The boundary is not just the place where CUI is stored. It includes the assets that process, store, or transmit CUI and other assets that provide protection or may affect the security of the environment, as defined in the current scoping guidance.

Boundary record

  • CUI categories, sources, recipients, markings, and lifecycle
  • Data-flow and network diagrams tied to current inventories
  • Identities, privileged roles, endpoints, servers, applications, and locations
  • Cloud service providers and external service providers
  • Remote access, administration, monitoring, backup, support, and incident paths
  • Asset-category decisions with rationale and ownership
  • Shared-responsibility and inherited-control evidence
  • Change triggers that require scope or status review

eTrepid professional standard

A Basic Assessment is not a basic checklist.

eTrepid does not treat an SPRS score as a spreadsheet exercise or accept unsupported control-owner assertions.

As an RPO using credentialed CMMC professionals and assessors, eTrepid evaluates the 110 requirements through their 320 underlying assessment objectives. That objective-level method is how we establish a supportable conclusion, expose incomplete implementation, and prepare the organization for later Government or CMMC verification.

Before eTrepid supports a score

  • The contract and information obligations are identified
  • The CUI boundary and relevant asset categories are documented
  • CUI assets, security protection assets, adjacency, external providers, and shared responsibilities are addressed
  • An SSP accurately describes the boundary, environment, implementation, and system relationships
  • All 320 objectives receive an evidence-based determination
  • The 110-requirement score is calculated from those determinations
  • POA&M items, limitations, evidence gaps, and target dates agree with the score
  • An accountable client official reviews the factual basis before submission

Representation risk

Low confidence does not mean low accountability.

A self-generated score can affect award eligibility and Government risk decisions. An unsupported or knowingly inaccurate cybersecurity representation may create contractual, award, repayment, reputational, and potential civil False Claims Act exposure.

The appropriate response to an unmet objective is not to inflate the score or narrow the boundary without support. Record the actual condition, evidence limitation, accountable owner, remediation, target date, and any authorized exception.

Why this must be defensible

In a 2025 Department of Justice settlement, a defense contractor acknowledged submitting a score of 104 after lacking full implementation and an adequate consolidated SSP; a later third-party review calculated a score of –142. The company paid $4.6 million to resolve False Claims Act allegations.

Enforcement outcomes are fact-specific. This example does not mean every mistake creates False Claims Act liability. Legal counsel should evaluate particular representations and disclosure duties.

Evidence workspace

Organize proof around determinations, not file names.

Examples are illustrative. The applicable assessment guide and selected methods and objects control.
Evidence layer What it should establish Typical records Quality check
Requirement and objective The exact determination being supported Requirement-to-objective matrix, applicability and responsibility record Can a reviewer tell what conclusion the evidence supports?
Scope Where and for whom the claim is true SSP, diagrams, inventories, data flows, provider and location records Do all representations describe the same current boundary?
Implementation How the requirement operates Policies, procedures, configurations, tickets, approvals, logs, review records Do documented intent and operating behavior agree?
People Authority, accountability, and recurring execution Role descriptions, interviews, training, approvals, escalation paths Can responsible people explain what actually happens?
Test Whether the mechanism produces the intended outcome Test plan, conditions, expected and observed results, retest record Is the result reproducible and linked to the assessed environment?
Integrity and time Authenticity and relevance to the assessed state Source, owner, version, timestamps, export context, approval, change history Would a change make the record stale or misleading?

Internal readiness review

Run the assessment method before an assessor or affirming official depends on it.

A useful rehearsal is independent enough to challenge assumptions and practical enough to expose retrieval, ownership, and operating failures.

  1. Select representative requirements across all 14 requirement families.
  2. Trace each from requirement to objective, scope, SSP statement, evidence, interview owner, and test.
  3. Ask someone other than the control owner to retrieve and interpret the record.
  4. Compare policy language, technical state, operating records, and interview answers.
  5. Record unmet objectives, evidence limitations, ownership, remediation, and retest criteria.
  6. Expand the review until every objective has a supportable determination.
  7. Have the accountable executive review unresolved risk before any affirmation or scheduling decision.

Common failure modes

Six shortcuts create false readiness.

“The tool makes us compliant.”

GCC High, an enclave, an EDR platform, or another service may support requirements. It does not establish governance, scope, configuration, operations, evidence, supplier duties, or accountable affirmation.

“The policy says we do it.”

A policy shows intent. Reviewers may also need current operating records, interviews, configurations, observations, and tests.

“Low confidence means low effort.”

The Basic Assessment’s Low confidence rating reflects that the score is self-generated. It does not remove the need for an adequate SSP, a defined boundary, accurate determinations, and a methodology-based score.

“The MSP owns the requirement.”

Providers may implement or support part of a requirement. The organization still must define shared responsibility and demonstrate how the complete requirement is satisfied.

“A POA&M can cover every gap.”

CMMC permits only limited POA&M use. Some requirements are ineligible, a minimum score is required, and conditional items must be closed within the allowed period.

“Passing is the finish line.”

Status depends on continued compliance, annual affirmation, and material stability. Readiness must become an operating cadence, not a one-time project.

A practical 30–60–90 sequence

Use the first 90 days to reduce uncertainty before accelerating remediation.

Days 1–30: establish truth

  • Confirm acquisition and information obligations
  • Identify the accountable executive and working owners
  • Map CUI and the proposed boundary
  • Inventory assets and providers
  • Assess the SSP and evidence baseline
  • Build a risk-ranked gap register

Days 31–60: remediate and operate

  • Resolve high-value scope and architecture issues
  • Implement missing technical and administrative safeguards
  • Assign recurring control activities
  • Correct policies and procedures to match operations
  • Collect native evidence from authoritative systems
  • Test changes and preserve results

Days 61–90: validate and decide

  • Complete objective-level internal assessment
  • Reconcile score and permitted POA&M items
  • Conduct interview and retrieval rehearsals
  • Review provider and supplier evidence
  • Obtain executive risk decisions
  • Make a documented readiness or defer decision

The appropriate duration depends on scope, starting condition, evidence maturity, provider dependencies, and remediation complexity. A 90-day sequence is a planning model, not a certification promise.

Source and review record

Primary sources used for this draft.

Reviewed August 26, 2026. The current CMMC Level 2 Assessment Guide uses NIST SP 800-171 Revision 2 and the June 2018 NIST SP 800-171A objectives. eTrepid’s 320-objective method is its professional standard for supportable readiness and scoring; it is not a representation that a contractor-led Basic Assessment becomes a Government High Assessment or CMMC certification assessment.

Change triggers

Review after changes to DoD implementation status, 32 CFR Part 170, DFARS, the Level 2 assessment or scoping guides, the NIST baseline, SPRS, enforcement guidance, or eTrepid’s credentials and service method.

Contextual next step

Find the readiness risks before they control your assessment date.

eTrepid can help define the CUI boundary, reconcile the SSP, validate implementation and evidence, prioritize remediation, and establish the recurring operations needed to sustain a supportable status.

Do not submit CUI, credentials, vulnerability data, configurations, logs, diagrams, contracts, or assessment evidence through a public website form or chat.

Assessment questions

Questions to answer before scheduling.

Does every Level 2 assessment require a C3PAO?

No. CMMC distinguishes Level 2 self-assessment and Level 2 C3PAO assessment paths. The required path depends on the acquisition and current implementation rules. As of this review, DoD states that implementation is paused in Phase I and may only require self-assessments at Level 1 and Level 2; verify current status and the acquisition record.

Is a DFARS 7020 Basic Assessment a lightweight review?

No. It is a self-generated assessment based on the SSP and conducted under the DoD Assessment Methodology. Its Low confidence rating describes the Government’s confidence in a self-generated score, not permission to skip scope, SSP, implementation, scoring, or evidence work. eTrepid applies an objective-level professional standard before supporting a score.

Do we have to implement all 110 Level 2 requirements?

Level 2 is based on all 110 NIST SP 800-171 Revision 2 security requirements, which contain 320 assessment objectives. CMMC permits limited POA&M use for certain unmet requirements and conditional status, subject to eligibility, scoring, affirmation, and closeout rules. A POA&M is not a general exception.

Is an SSP enough to show readiness?

No. The SSP is essential, but determinations also require support from policies, procedures, technical configurations, operating records, interviews, and tests that agree with the SSP and assessed scope.

Can an inaccurate SPRS score create False Claims Act exposure?

Potentially. Liability is fact-specific and depends on elements including knowledge, falsity, materiality, and claims or representations to the Government. Contractors should obtain legal advice for particular submissions and correct material inaccuracies through authorized channels.

Can our MSP or cloud provider supply all required evidence?

No. Provider evidence may support inherited or shared responsibilities. Your organization still must define the boundary, configure and operate customer responsibilities, govern identities and people, protect information, manage exceptions, and support the complete determination.

How long does preparation take?

It depends on scope, architecture, starting score, evidence maturity, provider dependencies, and the remediation required. Begin with a scoped readiness assessment before committing to a date.

Does eTrepid certify organizations?

No. eTrepid provides implementation and readiness support. Certification assessments, when required, are performed through the authorized CMMC assessment ecosystem. Readiness work does not guarantee an assessor’s determination or a government contracting outcome.