
Your CMMC Level 2 Assessment Checklist for Defense Contractors: What to Have Ready Before the C3PAO Walks In
The C3PAO assessment is not a surprise test — it’s a structured review, and the contractors who come out on top are the ones who treated it like a military operation: deliberate preparation, clear documentation, and no gaps left to chance. For Defense Industrial Base (DIB) companies working toward CMMC Level 2 certification, the weeks before an assessment can feel like a sprint. But the truth is, if you’ve been building your compliance posture correctly, the assessors showing up at your door should confirm what you already know — that your environment is ready.
This checklist is built for IT decision-makers and compliance officers at defense contractors who need to walk into their CMMC assessment with confidence. We’ll cover the documentation, the technical controls, the cloud environments, and the people-side of compliance that C3PAOs are trained to examine under 32 CFR Part 170.
1. Get Your Documentation House in Order
The System Security Plan (SSP) is the single most important document your organization owns in the context of a CMMC assessment. Without a current, complete SSP at the time of assessment, DoD regulation is clear: the C3PAO will find that “an assessment could not be completed due to incomplete information and noncompliance with DFARS 252.204-7012.” That is not a finding you recover from quickly.
Your SSP must accurately describe every information system within your defined CMMC Assessment Scope — including hardware, software, system boundaries, data flows, and how each of the 110 NIST SP 800-171 security requirements is implemented (or planned for implementation). It needs to be current as of the day assessors arrive, not from six months ago.
Alongside your SSP, your Plan of Action and Milestones (POA&M) must be in place for any requirements not yet fully implemented. A POA&M is not a hall pass — requirements listed there are still assessed as “NOT MET” — but a properly structured POA&M opens the door to achieving Conditional Level 2 (C3PAO) status provided your overall score meets the 80% threshold and no critical requirements are outstanding.
Checklist items:
- Current SSP covering all in-scope systems, dated and version-controlled
- POA&M for any NOT MET requirements (no critical requirements such as CA.L2-3.12.4 or AC.L2-3.1.20 may appear on it)
- CUI data flow diagrams and asset inventory
- All documentation available in English and organized for rapid access during assessment interviews
2. Know Your CUI Boundaries — And Prove You Do
Assessors will want to see exactly where Controlled Unclassified Information lives, how it moves, and who touches it. If you haven’t formally defined your CMMC Assessment Scope — meaning the boundary that encloses all CUI assets — you’re not ready.
This means identifying every asset category: CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and out-of-scope assets. Each category carries different handling expectations under the CMMC scoping guidance. Confusion between categories is one of the most common gaps assessors uncover in pre-assessment walkthroughs.
For contractors running CUI workloads in the cloud, your enclave architecture needs to be clearly documented and properly configured before the assessment begins. If you’re operating in Microsoft Azure Government or a comparable government-authorized cloud, your boundary documentation should reflect the specific services used, data residency settings, and how the shared responsibility model applies to each NIST 800-171 requirement. The same applies if your environment includes AWS GovCloud — assessors will review your cloud architecture, not just take your word for it.
Checklist items:
- CMMC Assessment Scope formally defined and documented
- Asset inventory categorized per CMMC scoping guidance
- Enclave architecture diagrams for all CUI-processing environments (on-premises and cloud)
- Azure Government or AWS GovCloud tenant configurations documented with applicable controls mapped

3. Validate Your Technical Controls Are Actually Working
Documentation tells the story — but assessors will test the controls to verify that story is true. This is where a lot of organizations discover the gap between what’s in the SSP and what’s actually enforced in the environment. The three assessment methods C3PAOs use are examine, interview, and test. That last one matters.
Walk your environment against the 110 NIST SP 800-171 requirements before the C3PAO does. Pay particular attention to the domains that consistently produce findings: Access Control (AC), Identification and Authentication (IA), Audit and Accountability (AU), and System and Communications Protection (SC). Multi-factor authentication must be enforced — not just configured — across all privileged and non-privileged user access to CUI systems. Audit logging must be active, retained, and reviewed on a defined schedule.
If your organization uses managed services for any part of your security stack — including your NOC, SOC, or endpoint protection — have written agreements in place that clearly define the managed service provider’s role in your CMMC compliance posture. Assessors will ask. If you can’t produce a contract or SLA that maps to specific NIST controls, that’s a gap.
Checklist items:
- MFA enforced on all accounts with access to CUI systems
- Audit logs active, retained per policy, and review procedures documented
- Incident response plan tested and documented within the past year
- Vulnerability scan results on file with remediation timelines
- Encryption validated as FIPS-validated (not just “encryption in use”)
- MSP or managed security agreements on hand with control mapping
4. Prepare Your People, Not Just Your Systems
Some of the most preventable assessment failures come from the human side — employees who can’t answer basic questions about their role in protecting CUI, or who point to processes that haven’t been practiced in months. C3PAOs are trained to interview personnel at multiple levels of your organization: executives, IT staff, and end users.
Your security awareness training needs to be current and documented. Records should show who completed training, when, and what was covered. If you’ve never tested your incident response procedures with a tabletop exercise, do one before the assessment. Make sure your team knows the CUI handling procedures, understands how to recognize a potential incident, and knows who to call.
Also ensure your System Security Plan authorship is understood by at least one person beyond the person who wrote it. An assessor asking “who owns this control?” should never produce a blank stare.
Checklist items:
- Security awareness training records current for all personnel with CUI access
- Incident response plan assigned to a named owner and tested within the past 12 months
- Key personnel (system owner, ISSO, IT lead) briefed and available during assessment days
- User access reviews completed and documented
5. Confirm Your SPRS Score Is Current and Defensible
Your Supplier Performance Risk System (SPRS) score reflects your organization’s current self-assessed NIST SP 800-171 compliance posture. Assessors know what your SPRS score says before they walk in the door. If there’s a significant gap between what that score reflects and what they observe during assessment, it creates a credibility problem that goes beyond any individual finding.
Before your C3PAO assessment, revisit your SPRS entry. Make sure the score accurately reflects your current state — not an optimistic projection. If your managed services partner helped you build or document controls since your last self-assessment, update the score accordingly. Document the basis for every point value you claim.
After the C3PAO completes your Level 2 certification assessment, results are submitted into the CMMC instantiation of eMASS, which feeds directly back to SPRS. That score becomes your public compliance record for contract eligibility purposes. Getting it right — on the way in and on the way out — is the mission.
Checklist items:
- SPRS self-assessment score current and reconciled with your SSP
- Score methodology documented and defensible
- Any prior DCMA DIBCAC assessment results reviewed and addressed
- Affirmation of compliance submitted per 32 CFR § 170.22
Conclusion
A CMMC Level 2 C3PAO assessment is not something you can sprint your way through the week before it happens. The defense contractors who earn Final Level 2 (C3PAO) status — not just a conditional pass — are the ones who built their compliance posture with intention, documented it rigorously, and tested it honestly against the standard. For companies in the Defense Industrial Base, this certification is increasingly the price of admission to DoD contract opportunities. The question isn’t whether you’ll pursue it — it’s whether you’ll be ready when the assessors arrive.
VSO’s team of veteran-led compliance and managed IT specialists helps DIB contractors build and validate CMMC-ready environments — from enclave design and Azure Government configuration to SSP development and ongoing managed security services. We know the standard because we live it.
Ready to Prepare for Your CMMC Assessment?
Don’t walk into your C3PAO assessment unprepared. VSO works with defense contractors across the DIB to close compliance gaps, build audit-ready documentation, and manage the technical controls that CMMC Level 2 demands.
Contact VSO today: 📞 (888) 805-0510 📧 sales@vso-inc.com 🌐 vso-inc.com
Frequently Asked Questions
What is a C3PAO and why do I need one for CMMC Level 2?
A C3PAO (Certified Third-Party Assessment Organization) is a DoD-authorized entity that conducts CMMC Level 2 certification assessments for defense contractors. Unlike Level 1, which allows self-assessment, Level 2 certification requires a third-party assessor to examine your environment, interview your personnel, and test your controls against all 110 NIST SP 800-171 requirements. The C3PAO submits your results to SPRS via the CMMC instantiation of eMASS, making your certification official for contract eligibility purposes.
What is the difference between Conditional Level 2 and Final Level 2 (C3PAO)?
Conditional Level 2 (C3PAO) is achieved when a contractor passes their assessment but has remaining gaps documented in a POA&M that meets all CMMC requirements — provided the overall score is at or above 80% and no critical requirements are in the POA&M. Those gaps must be remediated and confirmed through a POA&M closeout assessment within 180 days. Final Level 2 (C3PAO) means all 110 requirements were assessed as MET, either at initial assessment or after successful POA&M closeout.
Can my cloud environment (Azure Government or AWS GovCloud) satisfy CMMC Level 2 requirements?
Yes, but with important caveats. Your cloud environment must be authorized at the appropriate impact level (typically IL4 or IL5 for CUI), and your enclave architecture must be documented with clear control implementation mapping. The shared responsibility model means some controls are handled by the cloud provider and some remain your responsibility. During a CMMC assessment, auditors will want to see your architecture documentation, not just the fact that you’re using a government cloud.
What happens if I fail my CMMC Level 2 assessment?
A fa
iling result means you will not achieve CMMC Status and will be ineligible to compete for contracts requiring Level 2 certification until you remediate deficiencies and undergo a new assessment. If you receive a Conditional Level 2 and fail to close your POA&M within 180 days, your Conditional status expires, and standard contractual remedies apply. This is why pre-assessment preparation — including a gap assessment with a qualified managed services partner — is so important.
How long does a CMMC Level 2 certification last?
A CMMC Level 2 (C3PAO) certification is valid for three years from the CMMC Status Date. Annual affirmations of continued compliance are required. If your environment changes materially — new systems in scope, significant architectural changes — you should reassess whether your SSP and controls still accurately reflect your posture between triennial assessments.
Does VSO provide CMMC readiness support?
Yes. VSO offers end-to-end CMMC readiness support for defense contractors, including gap assessments against NIST SP 800-171, SSP development, enclave design for Azure Government and AWS GovCloud environments, and ongoing managed security services to maintain your compliance posture between assessments. Our team is veteran-led and purpose-built for the Defense Industrial Base. Reach us at (888) 805-0510 or sales@vso-inc.com.





