The CMMC Assessment Process, known as the CAP, is the official procedural guide that governs how a CMMC Level 2 certification assessment is conducted. Cyber AB defines the required activities, roles, and responsibilities for each participant in a Level 2 assessment. It exists for one reason: consistency. Without a shared playbook, two assessors could reach different conclusions about the same organization. The CAP closes that gap.
The CAP is published and maintained by the Cyber AB. It is reviewed and approved by the CMMC Program Management Office. Adherence is mandatory for CMMC Third-Party Assessment Organizations (C3PAOs) and their Certified CMMC Assessors. It is not optional guidance. It is a requirement built into the C3PAO accreditation scheme.
One point to be clear on upfront. The CAP applies only to CMMC Level 2 certification assessments. Level 1 and certain Level 2 requirements use self-assessment under the DoD Assessment Methodology. The CAP is the rulebook for the formal, third-party audit that handles Controlled Unclassified Information (CUI).
The Four Key Phases of the CAP
The CAP organizes the assessment into four phases. Each one covers a distinct stage of the work: planning, evaluating, reporting, and certifying. Here is the short answer before we go deeper.
- Phase 1 is Pre-Assessment. The C3PAO and the organization confirm scope, review documentation, and verify readiness.
- Phase 2 is the Conformity Assessment. Assessors test, interview, and examine security controls against the requirements.
- Phase 3 is Reporting. The team compiles scores, runs a quality review, and uploads results.
- Phase 4 is Close-Out. The certificate is issued, and any open items in the Plan of Action and Milestones are tracked to completion.
There is also a set of preliminary proceedings that happen before Phase 1 begins. These cover entity confirmation, scope framing, conflict-of-interest management, and the signed contract between the C3PAO and the organization. Think of them as the groundwork that makes Phase 1 possible.
Now let’s walk through each phase in detail.
Preliminary Proceedings: Setting the Foundation
Before any phase officially starts, several administrative and contractual steps must be completed. The C3PAO confirms exactly which legal entity is being assessed. Both parties frame the assessment scope at a high level. The C3PAO identifies any organizational or individual conflicts of interest.
Conflict of interest matters here. If a C3PAO helped build your security program, it cannot then audit that same program. The CAP requires the assessment team to sign a statement confirming the absence of conflicts before work begins. If conflicts cannot be mitigated, the assessment does not proceed.
The last preliminary step is the contract. The C3PAO and the organization sign a formal agreement covering pricing, timing, and terms. That agreement must conform to the CMMC Code of Professional Conduct. Once it’s signed, Phase 1 can begin.
Phase 1: Pre-Assessment
Phase 1 builds the plan. Its goal is simple: confirm the organization is genuinely ready before the formal evaluation starts. A failed assessment is expensive for everyone. This phase exists to catch problems early.
The C3PAO reviews the System Security Plan (SSP). The SSP is the central document describing how the organization meets each security requirement. Assessors check it for completeness, accuracy, and consistency. They are not yet judging whether controls work. They are confirming that the documentation reflects the real environment.
The team also validates the assessment scope. This means agreeing on which systems, networks, and assets fall within the boundary. Any disagreement about scope must be resolved now, not later. If External Service Providers or cloud services are in scope, the team confirms the right documentation exists, including Customer Responsibility Matrices.
The C3PAO assembles the assessment team and completes the Pre-Assessment Form. That form records key details like the organization’s CAGE code, the SSP title, contact information, and the readiness determination. By the end of Phase 1, the assessment plan is set, and both parties know exactly what comes next.
Related: CMMC Scoping Guide: How to Avoid Scope Creep
Phase 2: Conduct the Assessment
Phase 2 is the core of the process. This is where assessors evaluate how well the organization actually implements its security requirements. CMMC Level 2 covers 110 practices drawn from NIST SP 800-171. Everyone is in scope.
Assessors use three methods to gather evidence: examination, interviews, and testing. Examine means reviewing artifacts like policies, configuration files, and logs. An interview means speaking with the people who run the controls day-to-day.
Test means observing whether a control performs as documented. A single requirement is often checked using more than one method.
Each practice receives a score of MET or NOT MET. The assessment team documents findings with traceability, meaning every score connects back to specific evidence. This is why surface-level compliance fails. Assessors dig into how controls are implemented, not just whether a policy exists on paper.
After scoring, the lead assessor reviews the results. To qualify for certification, an organization must score at least 80 percent of practices as MET. Under 32 CFR Part 170, an organization meeting that threshold with remaining gaps can receive a conditional certification, provided the open items are eligible for a Plan of Action and Milestones (POA&M). Certain requirements are not POA&M-eligible and must be met in full.
Phase 3: Report Assessment Results
Phase 3 turns the assessment findings into an official record. The assessment team compiles the final scores and findings into a complete results package. This includes a Final Report that details each practice score with traceability to the evidence behind it.
Quality assurance is central to this phase. The CMMC Quality Assurance Professional reviews the assessment documentation for accuracy and completeness. This individual checks the team’s conduct and confirms the package is sound before it goes anywhere.
The QA reviewer cannot have served on the assessment team. That separation protects the integrity of the result.
The C3PAO then uploads the results into the DoD’s Enterprise Mission Assurance Support Service, known as eMASS. All results are uploaded, regardless of whether the organization passed.
The package follows a prescribed format with practice scores, findings, and comments. This phase also covers the appeals process, giving organizations a defined route to dispute findings they believe are wrong.
Phase 4: Issue the Certificate and Close Out POA&Ms
Phase 4 is the finish line. The C3PAO issues the Certificate of CMMC Status to the organization. The type of certificate depends on the Phase 2 result.
An organization that meets all requirements receives final certification outright. An organization that scored at least 80 percent but still had eligible gaps receives a conditional certification. That conditional status comes with a deadline.
The organization has 180 days to close out every item on its POA&M. The C3PAO then verifies that all POA&M items are resolved. Once that verification is complete, the conditional certification converts to a final certification. Miss the 180-day window, and the conditional status lapses. At that point, the path forward is a new assessment.
Why the Right Preparation Matters
The CAP rewards organizations that treat readiness seriously. Most failed or delayed assessments trace back to the same root causes: an SSP that doesn’t match the live environment, scoping disputes that should have been settled earlier, or staff who can’t speak to the controls they own.
The fix is preparation that mirrors the real process. Conduct an internal readiness review against all 110 Level 2 practices. Confirm the SSP reflects your environment as it exists today, not as it existed a year ago. Organize evidence artifacts and map them to each practice. Prepare the people who will be interviewed, since assessors talk to operators, not just managers.
If you’re preparing for a Level 2 assessment, start with your SSP and your scope. Get those two right, and the four phases of the CAP become a process you can plan for with confidence. Read the official CMMC Assessment Process v2.0 from the Cyber AB, and build your readiness plan around what it actually requires.



