Free Consultation
#nist
#cmmc
#compliance

Inside a CMMC Audit: What a C3PAO Actually Checks Under CMMC 2.0

September 10, 2026

As of the October CyberAB Town Hall, only 431 organizations had achieved a final Cybersecurity Maturity Model Certification (CMMC) Level 2 certification, representing just 0.5% of the roughly 80,000 companies the Department of Defense (DoD) estimates will require Level 2. That gap reflects confusion about the mechanics of a CMMC audit more than a lack of effort.

A CMMC audit, formally called a CMMC assessment, is the process of confirming that a contractor's security controls match the level a specific contract requires, either through self-assessment or through review by a Certified Third-Party Assessment Organization (C3PAO). Which path applies depends on the CMMC level named in a contract, the sensitivity of the data involved, and the current phase of the program's multi-year rollout. This article covers the mechanics of a CMMC assessment: the role a C3PAO plays, how self-assessment differs from third-party review, and the specific evidence assessors examine under CMMC 2.0's current requirements.

What Is a CMMC Audit, and Who Performs It?

A CMMC audit is the formal assessment that determines whether a defense contractor has implemented the cybersecurity practices required under the CMMC framework to protect federal contract information and Controlled Unclassified Information (CUI). For most companies handling CUI, this means a third-party assessment conducted by a C3PAO to verify alignment with National Institute of Standards and Technology (NIST) Special Publication 800-171 and other applicable requirements.

A C3PAO, by regulatory definition, is an organization authorized by the accreditation body to conduct Level 2 certification assessments. It carries specific roles and responsibilities under the CMMC program rule. C3PAOs operate as neutral evaluators rather than consultants. C3PAOs do not offer pre-audit consulting or implementation services, which preserves impartiality and avoids conflicts of interest. Becoming a C3PAO is itself demanding: firms must achieve and maintain compliance with an international inspection-body standard, ISO/IEC 17020, within 27 months of receiving initial authorization.

CMMC 2.0's Three Levels and Where Assessment Type Changes

CMMC 2.0 organizes requirements into three levels, each tied to data sensitivity rather than company size:

An accredited C3PAO awards certification, which remains valid for three years. A designated senior official must also submit an annual affirmation confirming that compliance continues between assessments.

CMMC Self-Assessment vs Third-Party Assessment: What Actually Changes

Organizations verify compliance through self-assessments, third-party audits, or government-led reviews, depending on the level of certification required. A CMMC self-assessment means the organization scores itself against the applicable control set and submits the result. A third-party assessment means a C3PAO independently examines the same controls and issues the certification.

Scoring mechanics matter for both paths at Level 2. Under the program rule, an organization qualifies for conditional status only if its assessment score reaches at least 0.8 out of the total number of Level 2 security requirements, meaning a minimum of 88 out of 110 points. If gaps remain, a C3PAO must perform a Plan of Action and Milestones (POA&M) closeout certification assessment within 180 days of the conditional status date. Missing that window causes the conditional status to lapse. Level 1 offers no such flexibility: assessors do not permit a plan of action at any time for Level 1 self-assessments.

What Does a C3PAO Actually Check During an Assessment?

During a CMMC audit, assessors review documentation, interview personnel, and test technical and administrative safeguards to confirm that required controls are in place and functioning. In practice, that review touches several areas:

Where CMMC Third-Party Assessment Stands Right Now

The requirement for mandatory C3PAO review has shifted more than once since CMMC 2.0's current rule took effect. The CMMC Final Rule, published September 10, 2025, became effective November 10, 2025. That began Phase 1, which introduced self-assessment obligations broadly across new solicitations.

A larger shift followed months later. On July 13, 2026, the Department of War announced the suspension of CMMC Phase 2, along with the C3PAO assessment requirements that were scheduled to begin appearing in contracts on November 10, 2026. A 60-day CMMC Reform Task Force is studying the program's future and is expected to report back around September 13, 2026. One driver behind the pause was capacity. The November 10 timeline would have required well over 100,000 companies in the defense industrial base to compete for assessment slots with only around 100 approved C3PAOs nationwide, a bottleneck a March 2026 government report had already flagged as a risk to smaller contractors.

The pause narrows to third-party certification only. Phase 1 self-assessment requirements remain firmly in place, and contractors in applicable solicitations must still complete and submit CMMC Level 1 and Level 2 self-assessments. Program managers currently retain only the option to require self-assessment, not certification through a C3PAO, while the review concludes. Given the task force's timeline lands close to this writing, contractors should expect updated guidance in the near term rather than a fixed reinstatement date.

Preparing for a CMMC Assessment, Self or Third-Party

Whether a contract calls for a CMMC self-assessment or a C3PAO review, preparation looks similar, since Level 2 applies the same 110 controls either way. A practical approach includes:

A rushed assessment, self-conducted or third-party, tends to surface avoidable gaps in the same higher-weighted areas: multifactor authentication, encryption, and system logging. Treating a CMMC audit as a compliance checkbox rather than a genuine operational review tends to produce that same outcome.

Understanding the mechanics of a CMMC audit, who performs it, and which requirements apply at a given moment matters more than memorizing a single fixed process, since the program itself keeps changing through phased rollouts and periodic review. Contractors that treat CMMC readiness as an ongoing operational discipline, rather than a one-time event tied to a single deadline, tend to move through whichever assessment path applies with far less disruption.

Planet 9 is a Bay Area cybersecurity consulting firm specializing in CMMC readiness for small and mid-sized businesses in defense contracting and government suppliers. Our vCISOs and compliance managers help organizations choose the right approach, configure governance, risk, and compliance tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What is a CMMC audit?
A CMMC audit, more precisely a CMMC assessment, is the formal process confirming that a defense contractor's cybersecurity practices meet the level required by a specific DoD contract. Depending on the level and the contract's terms, that verification happens through internal self-assessment or through an independent review by a C3PAO.
What does a C3PAO do?
A C3PAO is a firm authorized by the CMMC accreditation body to conduct Level 2 certification assessments for defense contractors. The C3PAO reviews documentation, tests technical safeguards, interviews personnel, and issues a certificate of CMMC status based on the results, while remaining barred from providing pre-audit consulting on the same engagement to preserve independence.
What is the difference between CMMC self-assessment and third-party assessment?
A CMMC self-assessment involves an organization scoring its own compliance against the applicable control set and submitting that score. A third-party assessment involves an accredited C3PAO independently verifying the same controls before certification is issued, which most Level 2 contracts specify depending on program criticality.
Is a C3PAO assessment currently required for CMMC Level 2?
As of mid-2026, mandatory third-party certification for Level 2 remains paused while the Department of War completes a program review that began in July 2026. Self-assessment remains the applicable requirement for most contracts during this period, though contractors already engaged with a C3PAO can typically continue that process voluntarily.
How long does it take to prepare for a CMMC assessment?
Most organizations need roughly six to twelve months to reach readiness for a CMMC assessment, depending on their starting security posture. Organizations with little existing documentation or technical control maturity generally need time on the longer end of that range.

Related blog posts