CMMC audit

The CMMC audit: what happens, and what fails it.

A CMMC audit is a formal assessment of your systems against the CMMC requirements for your level — run by you at Level 1 and Level 2 (Self), by an accredited C3PAO at Level 2 (C3PAO), and by the government at Level 3. This page covers who can assess you, what the assessment actually consists of, how the score is calculated, what a Conditional status and a plan of action buy you, what it costs, and the failure modes that account for most bad outcomes.

Last reviewed

Scheduling, as at August 2026

The Department suspended CMMC Phase 2 on 13 July 2026, which removed the 10 November 2026 date at which Level 2 C3PAO certification would have begun appearing as a condition of award. A reform task force reports in mid-September 2026. This has taken the immediate pressure off the assessment queue — but the queue is the reason not to treat the pause as free time. C3PAO capacity is finite, and it was booked months out before the pause.

What a CMMC audit is

An evidence exercise, not an interview.

A CMMC assessment tests whether each security requirement at your level is implemented on the systems in scope, and whether you can prove it. The assessor works requirement by requirement and reaches one of three findings on each: MET, NOT MET, or NOT APPLICABLE. There is no partial credit on an individual requirement. “We have a policy that says we do” is not MET; a policy plus a configuration that enforces it plus evidence it has been operating is.

Evidence comes in three forms and assessors expect all three: what you show them (configurations, dashboards, records), what you tell them (interviews with the people who actually operate the control), and what they test (observing a control work). A requirement supported only by a document is the standard way to collect a NOT MET.

The scope is whatever handles CUI, plus the infrastructure that protects it. This is where assessments are won or lost commercially: a tight, genuinely segmented enclave is a fraction of the assessment effort of an undifferentiated corporate network, and the decision is made months before the assessor arrives.

What a C3PAO is, and how to choose one

The accredited organization that performs a Level 2 certification assessment — and the bottleneck in the whole program.

A C3PAO — CMMC Third-Party Assessor Organization — is authorized to conduct Level 2 certification assessments and to submit the result into the government’s system. C3PAOs are themselves assessed before they are authorized. They are not consultants: an organization that has prepared you for the assessment cannot also be the one that assesses you, and any provider blurring that line is telling you something useful about how it works.

The capacity picture matters when you plan. Fewer than 100 C3PAOs were authorized across the whole defense industrial base as at early 2026, against tens of thousands of companies that will eventually need certification. Lead times of six to nine months were being quoted before the Phase 2 suspension. If certification returns to the schedule with a firm date, the queue is the constraint — not your readiness.

Questions worth asking a C3PAO before you sign:

  • Have you assessed companies our size, in our sector? A machine shop and a software vendor fail in different places.
  • What is the lead time, and what does the schedule slip look like?
  • What is in the fee, and what is not? Travel, re-assessment after a plan of action closeout, and additional days if scope proves larger than described are the three that surprise people.
  • How do you handle a Conditional outcome? The closeout assessment inside 180 days should be priced and scheduled at the outset, not negotiated when the clock is running.
  • Who is on the team, and are they certified assessors?

The CMMC assessment process process

Six stages. Most of the outcome is decided in the first two.

  1. Scope the assessment
    Identify every asset that processes, stores or transmits CUI, plus security protection assets and anything else inside the boundary. Assets are categorized, and the categorization drives what gets assessed. Getting this wrong in either direction is expensive: too wide and you pay to assess the whole company, too narrow and the assessor rejects the boundary on day one.
  2. Write and finish the System Security Plan
    The SSP describes how each requirement is met on the systems in scope. Assessors work from it. An SSP that does not match the environment is the fastest route to a failed assessment, because it costs you credibility on every requirement that follows.
  3. Self-assess and remediate honestly
    Score yourself against all 110, fix what you can, and be candid about what remains. A gap you have found and planned is manageable; a gap the assessor finds first is a finding.
  4. Pre-assessment and readiness review
    The C3PAO confirms scope, evidence availability and logistics. This is where a scope disagreement surfaces cheaply rather than expensively.
  5. The assessment itself
    Examine, interview, test — requirement by requirement, typically over days rather than hours, on site or remotely depending on scope. Every requirement lands MET, NOT MET or NOT APPLICABLE.
  6. Result, plan of action, and affirmation
    A qualifying score produces a Final or Conditional status. Conditional means a plan of action, a 180-day clock and a closeout assessment. The status is recorded in SPRS, and an affirming official affirms continued compliance annually thereafter.

Scoring, Conditional status and the CMMC POA&M

What you can carry, for how long, and what you cannot carry at all.

Level 2 scoring starts at 110 and deducts 1, 3 or 5 points per unimplemented requirement, weighted by impact — so the floor is −203, not zero. A score of at least 88 out of 110, which is 80% of the maximum, is the threshold for a Conditional CMMC status. Below that there is no status to grant.

Conditional status is not a soft landing. It comes with a plan of action and milestones covering the remaining requirements and 180 days to close every one of them and be re-assessed. Miss the window and the conditional status expires rather than lapsing quietly into something lesser.

The constraint that catches people is what may go on the plan of action. Broadly, only the 1-point requirements are eligible: the 3- and 5-point requirements — the heavy ones, including multi-factor authentication — have to be implemented at the time of assessment, with a narrow carve-out around FIPS-validated cryptography. The practical consequence is that a plan of action cannot rescue a program that has deferred the expensive work. It exists to absorb the long tail, not the core.

CMMC certification cost

Wide ranges, for a reason worth understanding before you get quoted.

Three costs get conflated, and separating them makes the numbers far less alarming.

The assessment fee is what the C3PAO charges to assess you. Market figures reported through 2026 commonly sit in the tens of thousands of dollars for a Level 2 certification assessment, driven mostly by the number of in-scope assets and locations. It is a competitive market and it is quoted per engagement, not published.

Remediation is what it costs to become compliant — new tooling, an enclave, MFA everywhere, logging, someone’s time. This is usually the largest number by a distance, it varies enormously with your starting point, and it is not a CMMC cost: it is the cost of the 800-171 obligation you already had.

Recurring cost is the three-year cycle plus annual affirmations, plus keeping the controls operating. The Department’s own regulatory impact estimates for a triennial Level 2 certification cycle with its affirmations run to roughly six figures for a medium-sized entity — a figure worth quoting to a board, with the caveat that estimates and market rates are different animals.

The lever that moves all three is scope. Reducing the number of systems that touch CUI reduces assessment days, remediation surface and ongoing operating cost simultaneously. It is the only decision on this page that pays three times.

What actually fails CMMC audits fails

Recurring failure modes, in rough order of how often they turn up.

  • The SSP does not describe the real environment
    Written for a previous architecture, or aspirationally. Every subsequent requirement is then assessed against a document the assessor has stopped trusting.
  • Multi-factor authentication has a gap
    Deployed for the main identity provider, missing on a legacy application, a jump host or a service account. A 5-point requirement, and not POA&M-eligible.
  • Encryption is not FIPS-validated
    The product encrypts; the module is not validated, or is validated but not running in the validated mode. This is a specific, checkable claim and assessors check it.
  • Logs exist but nobody reviews them
    Audit records are generated and retained, and no evidence exists that a human ever looked. Review has to be demonstrable.
  • The boundary is on the diagram, not in the network
    A claimed enclave that shares a flat network, a hypervisor or an identity plane with everything else. The assessor expands the scope, and the assessment gets longer and more expensive on the spot.
  • Evidence was assembled for the assessment
    Undated screenshots produced in the final fortnight demonstrate that a control existed once. Requirements are about operation over time.
  • External service providers were never assessed
    A managed service provider, a cloud platform or a design partner inside the boundary, whose security is inherited without being examined. Their gaps become your findings.

After the audit

Three years is a long time for an environment to stay the way you left it.

A Level 2 status lasts three years, affirmed annually. In that window your network changes constantly, and so do the networks of every subcontractor you passed CUI to. The assessment is a photograph; the obligation is continuous, and the annual affirmation is you signing to say the photograph is still a fair likeness.

That is the argument for monitoring rather than remembering. Continuous external assessment shows what your perimeter — and your suppliers’ perimeters — look like today: new exposed services, expiring certificates, infrastructure appearing in unexpected places. It does not replace the assessment. It stops you affirming something that stopped being true in month seven. Attack surface monitoring and supplier risk management are the two halves of that.

CMMC audit questions.

Who performs a CMMC audit?
It depends on the level and assessment type. Level 1 and Level 2 (Self) are assessed by you and affirmed in SPRS. Level 2 (C3PAO) is assessed by an accredited CMMC Third-Party Assessor Organization. Level 3 is assessed by the government, through DCMA’s DIBCAC.
How long does a CMMC assessment take?
The assessment itself typically runs over several days, scaling with the number of in-scope assets and locations. The longer variables are the lead time to book a C3PAO — six to nine months was common before the July 2026 suspension — and your own remediation, which is usually measured in months.
How much does a CMMC audit cost?
The assessment fee is quoted per engagement and commonly runs to tens of thousands of dollars at Level 2, driven by scope. Remediation is usually the larger cost and depends entirely on your starting point. Assessment scope is the lever that reduces both.
What is a CMMC POA&M?
A plan of action and milestones covering requirements not met at assessment. It supports a Conditional status where the score is at least 88 of 110, and everything on it must be implemented and re-assessed within 180 days. Only the lower-weighted requirements are eligible — the 3- and 5-point ones must be met at assessment.
Can my consultant also be my C3PAO?
No. An organization that has provided consulting to prepare you for the assessment cannot also perform that assessment. Keep the two engagements separate and expect a reputable C3PAO to insist on it.
Is the CMMC audit still happening after the July 2026 suspension?
Level 1 and Level 2 self-assessments under Phase 1 continue and are in solicitations now. Phase 2, which would have started requiring C3PAO certification from 10 November 2026, is suspended along with the later phases while a reform task force reviews the program, reporting in mid-September 2026.

You get assessed every three years. Attackers look daily.

Book a 30-minute call and we will show you your external attack surface, and your subcontractors’, the way an assessor never sees it — continuously, from outside.