Assessment preparation
What a C3PAO assessment actually involves
How an assessment is structured
Assessors use three methods, and the distinction matters more than most contractors expect. Examine means reviewing artefacts: policies, configurations, records. Interview means asking your people what they actually do. Test means exercising the control directly to see whether it behaves as described.
A control that is beautifully documented, that nobody can describe, and that fails when tested, is not implemented. All three have to line up.
- 01
Selection and scheduling
You choose and contract an accredited C3PAO directly. We do not and cannot perform your certification assessment, and neither can any other provider who implemented your controls. Capacity is finite and lead times are real, so this conversation should start months before you want the assessment.
- 02
Pre-assessment planning
The assessment team reviews your scope, your asset inventory, and your System Security Plan, then agrees an assessment plan: what will be examined, who will be interviewed, what will be tested, and over how many days.
- 03
Assessment execution
Assessors work through the objectives using three methods: examining artefacts, interviewing your people, and testing the environment directly. Every objective must be substantiated. "It is in the policy" is examined evidence, not tested evidence, and for many objectives it will not be enough on its own.
- 04
Findings and disposition
Objectives are scored met or not met. If you land short but qualify, a limited POA&M may be permitted, giving you a conditional status and 180 days to close it out with a follow-up assessment. Otherwise you remediate and re-engage.
- 05
Result and affirmation
A successful assessment produces a CMMC status recorded in the government system, valid for three years, with an annual affirmation from a senior official in between.
The evidence package
Assessment day goes well or badly almost entirely on the strength of your evidence library. Contractors who assembled it as they implemented spend the week answering questions. Contractors who left it to the end spend the week hunting for screenshots.
- System Security Plan that matches the environment as built
- Asset inventory covering in-scope, security-protection, and specialised assets
- Network and data-flow diagrams showing the CUI boundary
- Policies and procedures, approved and version-controlled
- Configuration baselines and evidence they are enforced
- Screenshots and configuration exports for technical controls
- Audit log samples plus evidence that reviews actually occur
- Vulnerability scan reports and remediation history over time
- Training completion records by role
- Incident response plan plus after-action reports from testing
- Access review records and offboarding evidence
- Physical access logs and visitor control records
Six things that go wrong
The SSP describes a different company
The most damaging finding of all. When the plan and the environment diverge, assessors stop trusting the documentation entirely and start testing everything from scratch.
Scope that leaks
A claimed enclave boundary that CUI can demonstrably cross. If an engineer can email a controlled drawing to a personal mailbox, the boundary is not a boundary.
Partial multifactor authentication
MFA on email but not on the VPN, or not on local administrator accounts. Partial deployment scores as not implemented, and this one cannot be deferred to a POA&M.
"Encrypted" but not FIPS-validated
Encryption using a module that is not FIPS-validated does not satisfy the requirement. This one catches out a lot of otherwise competent environments.
Nobody reviews the logs
Collection is evidenced by the platform. Review is evidenced by a human artefact: a signed report, a ticket, a documented finding. Most contractors have the first and not the second.
Staff who cannot answer
Assessors interview real users, not just IT. If your machinist cannot say what they would do on finding a USB stick in the car park, that is a training finding.
Why a mock assessment is worth it
A mock assessment is a full dry run against the same objectives, using the same three methods, by people who have not been living inside your environment. It is substantially cheaper than a failed certification assessment and it surfaces the things you have stopped being able to see.
We run yours a few weeks before the real one: long enough to fix what it finds, close enough that nothing drifts in between. It includes interview coaching, because the most common preventable finding is a competent employee who freezes when a stranger with a clipboard asks them a question.
After certification
A CMMC status lasts three years with an annual affirmation in between. Programmes that go dormant the day the certificate arrives fail the next assessment expensively, because three years of undocumented change is very hard to reconstruct. Our continuous compliance management keeps the evidence current so re-assessment is a review rather than a rebuild.
Straight answers
Assessment questions
How long does a C3PAO assessment take?
For a small contractor with a tight enclave, on-site and remote activity typically runs a few days to a week, with planning before and reporting after. The size of your boundary is the main driver, which is another reason scope reduction pays for itself.
Can Axonai perform our certification assessment?
No, and be wary of anyone who says they can do both. Independence rules prevent the organisation that implemented your controls from also certifying them. We prepare you, run a mock assessment, and support you through the engagement. The certification itself comes from an accredited C3PAO you contract separately.
What happens if we fail?
If you meet the eligibility conditions, a limited POA&M gives you a conditional status and 180 days to close the open items, verified by a follow-up assessment. If you fall short of those conditions, you remediate and re-engage, which costs time and money, and is exactly what a mock assessment is designed to prevent.
How far in advance should we prepare?
Begin remediation eight to twelve months before your target assessment date, and engage a C3PAO for scheduling several months out. Assessor capacity across the accredited pool is limited and demand is concentrated around deadlines.
Do assessors talk to our regular staff?
Yes. Interviews are one of the three assessment methods and they are not confined to IT. Machinists, engineers, receptionists, and executives can all be asked what they do in specific situations. We coach your team beforehand so they answer accurately and without panic.
Next step
Do not find out on assessment day
A mock assessment costs a fraction of a failed certification attempt and tells you exactly where you stand while there is still time to act.
We reply within one business day.