For most teams, the anxiety around a CMMC Level 2 assessment comes from not knowing what the day is like. It is less an interrogation than an evidence review — a trained assessor from a C3PAO checking whether the controls in your System Security Plan actually operate the way the plan says. Here is the shape of it.
Before the assessor arrives
Most of the work is done by the time the assessment starts. Your SSP describes how each requirement is met; your evidence — configurations, logs, records, tickets — backs it up. A good assessor has read the SSP in advance and arrives with a list of things to verify.
During the assessment
Assessors use three methods, and you will see all three:
- Examine — reading policies, plans, configurations, and records.
- Interview — asking the people who actually run a control to describe how it works. This is where shelfware gets exposed: a policy no one can explain is not a control.
- Test — watching a control operate, or checking a system setting directly.
Each of the 110 requirements is scored met or not met against defined objectives. There is no partial credit for good intentions.
After
You get a result. If only a limited set of items are open, a conditional outcome with a POA&M may be possible, with a fixed window to close them. Then the real work begins — because the certification reflects a point in time, and the obligation to keep the controls running is continuous.
How to be ready
The teams that have the smoothest day are the ones that rehearsed: they ran their own dry run against the same objectives, found the gaps while they were cheap to fix, and made sure every control had an owner who could speak to it. That is readiness — not a binder, but a program that can answer for itself.
Start with our CMMC Readiness Check to find your gaps before an assessor does.