As of the October CyberAB Town Hall, only 431 organizations had achieved a final Cybersecurity Maturity Model Certification (CMMC) Level 2 certification, representing just 0.5% of the roughly 80,000 companies the Department of Defense (DoD) estimates will require Level 2. That gap reflects confusion about the mechanics of a CMMC audit more than a lack of effort.
A CMMC audit, formally called a CMMC assessment, is the process of confirming that a contractor's security controls match the level a specific contract requires, either through self-assessment or through review by a Certified Third-Party Assessment Organization (C3PAO). Which path applies depends on the CMMC level named in a contract, the sensitivity of the data involved, and the current phase of the program's multi-year rollout. This article covers the mechanics of a CMMC assessment: the role a C3PAO plays, how self-assessment differs from third-party review, and the specific evidence assessors examine under CMMC 2.0's current requirements.
What Is a CMMC Audit, and Who Performs It?
A CMMC audit is the formal assessment that determines whether a defense contractor has implemented the cybersecurity practices required under the CMMC framework to protect federal contract information and Controlled Unclassified Information (CUI). For most companies handling CUI, this means a third-party assessment conducted by a C3PAO to verify alignment with National Institute of Standards and Technology (NIST) Special Publication 800-171 and other applicable requirements.
A C3PAO, by regulatory definition, is an organization authorized by the accreditation body to conduct Level 2 certification assessments. It carries specific roles and responsibilities under the CMMC program rule. C3PAOs operate as neutral evaluators rather than consultants. C3PAOs do not offer pre-audit consulting or implementation services, which preserves impartiality and avoids conflicts of interest. Becoming a C3PAO is itself demanding: firms must achieve and maintain compliance with an international inspection-body standard, ISO/IEC 17020, within 27 months of receiving initial authorization.
CMMC 2.0's Three Levels and Where Assessment Type Changes
CMMC 2.0 organizes requirements into three levels, each tied to data sensitivity rather than company size:
- Level 1 covers basic protection of federal contract information, built on 15 basic cyber hygiene practices specified in a federal contracting regulation predating CMMC. Level 1 relies only on self-assessment, and a plan of action to fix gaps later is not an option here.
- Level 2 covers protection of CUI. It verifies that a contractor has fully implemented 110 security controls from NIST SP 800-171 Revision 2, across 14 control families, to protect Controlled Unclassified Information. Assessment type is defined by the contract: some contracts require self-assessment, while others require a third-party assessment by a C3PAO.
- Level 3 applies to the most sensitive CUI. It adds 24 selected requirements from NIST SP 800-172 on top of the 110 Level 2 controls, for a total of 134 assessed controls. This level is government-led. DoD assessment personnel conduct it directly rather than a private C3PAO.
An accredited C3PAO awards certification, which remains valid for three years. A designated senior official must also submit an annual affirmation confirming that compliance continues between assessments.
CMMC Self-Assessment vs Third-Party Assessment: What Actually Changes
Organizations verify compliance through self-assessments, third-party audits, or government-led reviews, depending on the level of certification required. A CMMC self-assessment means the organization scores itself against the applicable control set and submits the result. A third-party assessment means a C3PAO independently examines the same controls and issues the certification.
Scoring mechanics matter for both paths at Level 2. Under the program rule, an organization qualifies for conditional status only if its assessment score reaches at least 0.8 out of the total number of Level 2 security requirements, meaning a minimum of 88 out of 110 points. If gaps remain, a C3PAO must perform a Plan of Action and Milestones (POA&M) closeout certification assessment within 180 days of the conditional status date. Missing that window causes the conditional status to lapse. Level 1 offers no such flexibility: assessors do not permit a plan of action at any time for Level 1 self-assessments.
What Does a C3PAO Actually Check During an Assessment?
During a CMMC audit, assessors review documentation, interview personnel, and test technical and administrative safeguards to confirm that required controls are in place and functioning. In practice, that review touches several areas:
- The system security plan, describing where CUI resides in the environment and how each control addresses it
- Scope confirmation: a C3PAO typically opens the engagement by verifying the scope of the assessment based in part on where CUI lives across the enterprise, then builds an assessment plan around it
- Documentary evidence and artifacts for each control, along with customer responsibility matrices for practices inherited from cloud or managed service providers
- Staff interviews: assessors examine the evidence of compliance an organization provides and test whether team members understand the practices and procedures
- Technical testing of access control, encryption, and logging configurations, which carry the heaviest point weighting in the Level 2 scoring model
Where CMMC Third-Party Assessment Stands Right Now
The requirement for mandatory C3PAO review has shifted more than once since CMMC 2.0's current rule took effect. The CMMC Final Rule, published September 10, 2025, became effective November 10, 2025. That began Phase 1, which introduced self-assessment obligations broadly across new solicitations.
A larger shift followed months later. On July 13, 2026, the Department of War announced the suspension of CMMC Phase 2, along with the C3PAO assessment requirements that were scheduled to begin appearing in contracts on November 10, 2026. A 60-day CMMC Reform Task Force is studying the program's future and is expected to report back around September 13, 2026. One driver behind the pause was capacity. The November 10 timeline would have required well over 100,000 companies in the defense industrial base to compete for assessment slots with only around 100 approved C3PAOs nationwide, a bottleneck a March 2026 government report had already flagged as a risk to smaller contractors.
The pause narrows to third-party certification only. Phase 1 self-assessment requirements remain firmly in place, and contractors in applicable solicitations must still complete and submit CMMC Level 1 and Level 2 self-assessments. Program managers currently retain only the option to require self-assessment, not certification through a C3PAO, while the review concludes. Given the task force's timeline lands close to this writing, contractors should expect updated guidance in the near term rather than a fixed reinstatement date.
Preparing for a CMMC Assessment, Self or Third-Party
Whether a contract calls for a CMMC self-assessment or a C3PAO review, preparation looks similar, since Level 2 applies the same 110 controls either way. A practical approach includes:
- Mapping current practices against the 110 practices NIST SP 800-171 lists as necessary to comply with CMMC Level 2, rather than assuming existing IT tools already satisfy them
- Building or refreshing a system security plan that reflects where regulated data actually moves through the environment
- Engaging an independent consulting firm familiar with the assessment methodology to close gaps before any outside reviewer becomes involved; this early diagnostic work helps identify weak security positions or control gaps before the C3PAO auditor steps in
- Building in enough time: most organizations require 6 to 12 months to fully prepare for a C3PAO assessment, depending on their current security posture
A rushed assessment, self-conducted or third-party, tends to surface avoidable gaps in the same higher-weighted areas: multifactor authentication, encryption, and system logging. Treating a CMMC audit as a compliance checkbox rather than a genuine operational review tends to produce that same outcome.
Understanding the mechanics of a CMMC audit, who performs it, and which requirements apply at a given moment matters more than memorizing a single fixed process, since the program itself keeps changing through phased rollouts and periodic review. Contractors that treat CMMC readiness as an ongoing operational discipline, rather than a one-time event tied to a single deadline, tend to move through whichever assessment path applies with far less disruption.
Planet 9 is a Bay Area cybersecurity consulting firm specializing in CMMC readiness for small and mid-sized businesses in defense contracting and government suppliers. Our vCISOs and compliance managers help organizations choose the right approach, configure governance, risk, and compliance tools if needed, and get audit-ready without wasted time.





