The CMMC audit: what happens, and what fails it.
A CMMC audit is a formal assessment of your systems against the CMMC requirements for your level — run by you at Level 1 and Level 2 (Self), by an accredited C3PAO at Level 2 (C3PAO), and by the government at Level 3. This page covers who can assess you, what the assessment actually consists of, how the score is calculated, what a Conditional status and a plan of action buy you, what it costs, and the failure modes that account for most bad outcomes.
Last reviewed
Scheduling, as at August 2026
What a CMMC audit is
An evidence exercise, not an interview.
A CMMC assessment tests whether each security requirement at your level is implemented on the systems in scope, and whether you can prove it. The assessor works requirement by requirement and reaches one of three findings on each: MET, NOT MET, or NOT APPLICABLE. There is no partial credit on an individual requirement. “We have a policy that says we do” is not MET; a policy plus a configuration that enforces it plus evidence it has been operating is.
Evidence comes in three forms and assessors expect all three: what you show them (configurations, dashboards, records), what you tell them (interviews with the people who actually operate the control), and what they test (observing a control work). A requirement supported only by a document is the standard way to collect a NOT MET.
The scope is whatever handles CUI, plus the infrastructure that protects it. This is where assessments are won or lost commercially: a tight, genuinely segmented enclave is a fraction of the assessment effort of an undifferentiated corporate network, and the decision is made months before the assessor arrives.
What a C3PAO is, and how to choose one
The accredited organization that performs a Level 2 certification assessment — and the bottleneck in the whole program.
A C3PAO — CMMC Third-Party Assessor Organization — is authorized to conduct Level 2 certification assessments and to submit the result into the government’s system. C3PAOs are themselves assessed before they are authorized. They are not consultants: an organization that has prepared you for the assessment cannot also be the one that assesses you, and any provider blurring that line is telling you something useful about how it works.
The capacity picture matters when you plan. Fewer than 100 C3PAOs were authorized across the whole defense industrial base as at early 2026, against tens of thousands of companies that will eventually need certification. Lead times of six to nine months were being quoted before the Phase 2 suspension. If certification returns to the schedule with a firm date, the queue is the constraint — not your readiness.
Questions worth asking a C3PAO before you sign:
- Have you assessed companies our size, in our sector? A machine shop and a software vendor fail in different places.
- What is the lead time, and what does the schedule slip look like?
- What is in the fee, and what is not? Travel, re-assessment after a plan of action closeout, and additional days if scope proves larger than described are the three that surprise people.
- How do you handle a Conditional outcome? The closeout assessment inside 180 days should be priced and scheduled at the outset, not negotiated when the clock is running.
- Who is on the team, and are they certified assessors?
The CMMC assessment process process
Six stages. Most of the outcome is decided in the first two.
- Scope the assessmentIdentify every asset that processes, stores or transmits CUI, plus security protection assets and anything else inside the boundary. Assets are categorized, and the categorization drives what gets assessed. Getting this wrong in either direction is expensive: too wide and you pay to assess the whole company, too narrow and the assessor rejects the boundary on day one.
- Write and finish the System Security PlanThe SSP describes how each requirement is met on the systems in scope. Assessors work from it. An SSP that does not match the environment is the fastest route to a failed assessment, because it costs you credibility on every requirement that follows.
- Self-assess and remediate honestlyScore yourself against all 110, fix what you can, and be candid about what remains. A gap you have found and planned is manageable; a gap the assessor finds first is a finding.
- Pre-assessment and readiness reviewThe C3PAO confirms scope, evidence availability and logistics. This is where a scope disagreement surfaces cheaply rather than expensively.
- The assessment itselfExamine, interview, test — requirement by requirement, typically over days rather than hours, on site or remotely depending on scope. Every requirement lands MET, NOT MET or NOT APPLICABLE.
- Result, plan of action, and affirmationA qualifying score produces a Final or Conditional status. Conditional means a plan of action, a 180-day clock and a closeout assessment. The status is recorded in SPRS, and an affirming official affirms continued compliance annually thereafter.
Scoring, Conditional status and the CMMC POA&M
What you can carry, for how long, and what you cannot carry at all.
Level 2 scoring starts at 110 and deducts 1, 3 or 5 points per unimplemented requirement, weighted by impact — so the floor is −203, not zero. A score of at least 88 out of 110, which is 80% of the maximum, is the threshold for a Conditional CMMC status. Below that there is no status to grant.
Conditional status is not a soft landing. It comes with a plan of action and milestones covering the remaining requirements and 180 days to close every one of them and be re-assessed. Miss the window and the conditional status expires rather than lapsing quietly into something lesser.
The constraint that catches people is what may go on the plan of action. Broadly, only the 1-point requirements are eligible: the 3- and 5-point requirements — the heavy ones, including multi-factor authentication — have to be implemented at the time of assessment, with a narrow carve-out around FIPS-validated cryptography. The practical consequence is that a plan of action cannot rescue a program that has deferred the expensive work. It exists to absorb the long tail, not the core.
CMMC certification cost
Wide ranges, for a reason worth understanding before you get quoted.
Three costs get conflated, and separating them makes the numbers far less alarming.
The assessment fee is what the C3PAO charges to assess you. Market figures reported through 2026 commonly sit in the tens of thousands of dollars for a Level 2 certification assessment, driven mostly by the number of in-scope assets and locations. It is a competitive market and it is quoted per engagement, not published.
Remediation is what it costs to become compliant — new tooling, an enclave, MFA everywhere, logging, someone’s time. This is usually the largest number by a distance, it varies enormously with your starting point, and it is not a CMMC cost: it is the cost of the 800-171 obligation you already had.
Recurring cost is the three-year cycle plus annual affirmations, plus keeping the controls operating. The Department’s own regulatory impact estimates for a triennial Level 2 certification cycle with its affirmations run to roughly six figures for a medium-sized entity — a figure worth quoting to a board, with the caveat that estimates and market rates are different animals.
The lever that moves all three is scope. Reducing the number of systems that touch CUI reduces assessment days, remediation surface and ongoing operating cost simultaneously. It is the only decision on this page that pays three times.
What actually fails CMMC audits fails
Recurring failure modes, in rough order of how often they turn up.
- The SSP does not describe the real environmentWritten for a previous architecture, or aspirationally. Every subsequent requirement is then assessed against a document the assessor has stopped trusting.
- Multi-factor authentication has a gapDeployed for the main identity provider, missing on a legacy application, a jump host or a service account. A 5-point requirement, and not POA&M-eligible.
- Encryption is not FIPS-validatedThe product encrypts; the module is not validated, or is validated but not running in the validated mode. This is a specific, checkable claim and assessors check it.
- Logs exist but nobody reviews themAudit records are generated and retained, and no evidence exists that a human ever looked. Review has to be demonstrable.
- The boundary is on the diagram, not in the networkA claimed enclave that shares a flat network, a hypervisor or an identity plane with everything else. The assessor expands the scope, and the assessment gets longer and more expensive on the spot.
- Evidence was assembled for the assessmentUndated screenshots produced in the final fortnight demonstrate that a control existed once. Requirements are about operation over time.
- External service providers were never assessedA managed service provider, a cloud platform or a design partner inside the boundary, whose security is inherited without being examined. Their gaps become your findings.
After the audit
Three years is a long time for an environment to stay the way you left it.
A Level 2 status lasts three years, affirmed annually. In that window your network changes constantly, and so do the networks of every subcontractor you passed CUI to. The assessment is a photograph; the obligation is continuous, and the annual affirmation is you signing to say the photograph is still a fair likeness.
That is the argument for monitoring rather than remembering. Continuous external assessment shows what your perimeter — and your suppliers’ perimeters — look like today: new exposed services, expiring certificates, infrastructure appearing in unexpected places. It does not replace the assessment. It stops you affirming something that stopped being true in month seven. Attack surface monitoring and supplier risk management are the two halves of that.
CMMC audit questions.
Who performs a CMMC audit?
How long does a CMMC assessment take?
How much does a CMMC audit cost?
What is a CMMC POA&M?
Can my consultant also be my C3PAO?
Is the CMMC audit still happening after the July 2026 suspension?
Related reading.
You get assessed every three years. Attackers look daily.
Book a 30-minute call and we will show you your external attack surface, and your subcontractors’, the way an assessor never sees it — continuously, from outside.