In this article:

What Happens in a CMMC Audit (and How to Prepare)

Compliance
/
July 6, 2026
What Happens in a CMMC Audit (and How to Prepare)

A CMMC Level 2 certification assessment is a formal third-party audit conducted by a C3PAO, a CMMC Third Party Assessment Organization authorized by the Cyber AB, against all 110 security requirements of NIST SP 800-171. Over one to two weeks, the assessment team reads your System Security Plan, interviews the people who operate your controls, watches those controls run live, and samples artifacts to confirm the paperwork matches the environment. Every requirement is scored MET or NOT MET. Score at least 88 of 110 with every gap on an eligible remediation plan and you earn conditional status, which starts a 180 day clock to close the rest. Close them and the result is final certification, valid for three years.

That is the process in outline. What follows is what each phase looks like in practice, how the scoring actually works, and the failure patterns that account for most bad outcomes.

Before the assessment: scope is decided, not discovered

The single biggest cost and risk driver is settled before an assessor ever logs on: the assessment scope. Scope is defined by where Controlled Unclassified Information is stored, processed, or transmitted, plus the assets that protect that environment. The CMMC scoping guidance sorts everything into categories: CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out of scope assets. The C3PAO validates your scoping at the start of the engagement, and a scope the assessor does not accept is the worst possible opening, because it can stall the assessment before a single control is examined.

Most defense contractors under about 500 employees are better served by an enclave, a contained environment where CUI lives, than by certifying the entire corporate network. A well built enclave can cut in-scope assets by 60 to 90 percent, and every asset you remove is one fewer laptop to sample, one fewer administrator to interview, and one fewer configuration to defend.

The evidence package

Assessors work from NIST SP 800-171A, which breaks the 110 requirements into roughly 320 assessment objectives. Each objective needs evidence, and the evidence package is assembled before the assessment begins: policies, procedures, network diagrams, configuration exports, screenshots, log samples, tickets, and training records, organized so any requirement can be answered in minutes rather than hours.

The System Security Plan anchors everything. It is the first document the team reads and the map they use for the entire engagement. An SSP that states how each requirement is implemented, by system and by name, sets up a fast assessment. An SSP that restates the requirement in the future tense sets up a failed one. The other going-in artifact is the POA&M, and the goal is for it to be short or empty, because anything open on it is a NOT MET finding by definition.

The assessment itself: interviews, demonstrations, sampling

The assessment team, typically a lead assessor plus one or two additional assessors with a quality reviewer behind them, works through the three methods defined in 800-171A: examine, interview, and test.

Examination is document and artifact review, and much of it happens early. Interviews put the actual control operators in front of the assessor: the administrator who manages access, the person who reviews logs, HR on screening and terminations, facilities on visitor control. Assessors are trained to notice when the person who supposedly runs a control cannot describe it. Demonstrations are live: sign in and show MFA challenge a privileged account, pull the audit log for a specific day, open the last vulnerability scan and the ticket that closed its worst finding, walk through exactly how a departed employee lost access.

Sampling is what makes the week unpredictable. The assessor does not check every laptop; they pick several and expect the hardened baseline on each one. They pick a handful of accounts and check the authorizations, a few change tickets and check the approvals, an incident and check the timeline. You do not choose the sample, which is the point of sampling.

Expect daily debriefs, a running list of items to produce, and a final out-brief where preliminary results are presented. The results then pass through the C3PAO's internal quality review before the package is submitted and your status is posted in SPRS, the Supplier Performance Risk System.

Scoring: MET, NOT MET, and the 88 point floor

Each of the 110 requirements is scored MET or NOT MET, with N/A available only where a requirement truly cannot apply and the justification holds up. There is no partial credit. A control implemented on 19 of 20 servers is NOT MET. Behind the binary result sits the DoD scoring methodology, which starts at 110 and deducts 5, 3, or 1 points per unmet requirement depending on its weight.

Two thresholds matter. Everything MET is a final certification outright. A score of at least 88, where every unmet requirement is eligible for a Plan of Action and Milestones, earns conditional status. Below 88, or with any ineligible requirement NOT MET, the assessment fails, and the path back is remediation followed by reassessment.

The POA&M allowance and the 180 day clock

The POA&M allowance is narrower than most teams expect. Only select one point requirements are eligible, plus a small set of defined exceptions, the best known being encryption that is in place but not yet FIPS validated. The heavyweight five point requirements, multifactor authentication and incident response capability among them, cannot be deferred at all.

The clock is fixed: 180 days from the date the conditional status is issued. Close the items, and the C3PAO performs a POA&M closeout assessment covering just those requirements. Pass it and conditional converts to final. Miss the window and the conditional status expires, which means a full certification assessment again, at full price. Treat the 180 days as a funded project with a named owner, not as a grace period.

Conditional versus final certification

Both statuses are posted in SPRS, and during the current phase-in both can support contract eligibility, but they are not equivalent. Conditional status is temporary by design and carries the closeout obligation. Final certification stands for three years, with a senior company official affirming continuing compliance in SPRS every year. Those affirmations are signed statements the government can hold you to, which is why letting controls decay after assessment day is a legal problem and not only a security one.

Where assessments go wrong

Three failure patterns account for most of the bad outcomes we see in readiness work:

  • Scope that was never engineered. CUI spread across file shares, email, and personal drives for years, so the whole network is in scope and every gap is multiplied by every system.
  • An SSP that does not match reality. The document says logs are reviewed weekly; the interview reveals nobody has opened the SIEM since spring. One contradiction like that and the team starts probing everything harder.
  • Evidence that cannot be produced live. The screenshot from eight months ago does not count. The assessor wants the console, today, showing the control working now, and the only administrator who knows the tool is on leave.

Two quieter killers sit behind those. External providers first: if your MSP touches in-scope systems or your cloud service handles CUI, their obligations follow them into your assessment, and cloud services processing CUI need FedRAMP Moderate authorization or documented equivalency. Cryptography second: FIPS validated means a validated module with a certificate number you can point to, not a vendor page that says military grade.

How to prepare, and a boundary worth stating

Preparation that works runs in sequence: engineer the scope first, assess the gap against all 110 requirements and their assessment objectives, remediate, then operate the controls long enough to generate real evidence. A quarter of operating history is a reasonable floor, because assessors can tell a program from a sprint. Finish with a mock assessment that samples and interviews the way a C3PAO will. Budget realistically as well: C3PAO fees for a small, well scoped environment commonly run $40,000 to $100,000 and up, driven by asset count, locations, and external providers, and that is before remediation spend.

One boundary worth stating plainly: BD Emerson is not a C3PAO and does not certify anyone. We work the readiness side only, which means we can be aggressive about finding problems without any conflict of interest in how they are scored. A CMMC gap assessment tells you where each of the 110 requirements stands and what your score defensibly is. Our CMMC consulting practice carries scoping, remediation, SSP development, and mock assessment through to assessment day. And because CMMC is NIST SP 800-171 underneath, the same work strengthens the rest of your federal posture through NIST compliance consulting.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director