CMMC Level 3 Assessment Guide

CMMC Level 3 Assessment Guide

CMMC Level 3 is the highest tier of the Cybersecurity Maturity Model Certification program. It applies to a small group of defense contractors working on the most sensitive programs. 

If your contract calls for it, the path is specific, and the bar is high. This guide walks through what the assessment covers, who conducts it, how scoring works, and how to prepare.

What CMMC Level 3 Certification Actually Requires

Level 3 has two parts. First, you must hold a Final Level 2 (C3PAO) certification for the same scope. Second, you must pass a government-led assessment of 24 additional security requirements.

Under 32 CFR 170.18, a Final Level 2 (C3PAO) status is a prerequisite to even start a Level 3 assessment. You cannot pursue both levels at once. You cannot skip Level 2. The Level 3 scope must equal or be a subset of your Level 2 scope.

The 24 requirements come from NIST SP 800-172. The list is set out in Table 1 to 32 CFR 170.14(c)(4). These controls target Advanced Persistent Threats: well-funded, patient attackers, often nation-state actors. They sit atop the 110 NIST SP 800-171 controls already required at Level 2.

So the full Level 3 picture is 110 baseline controls plus 24 enhanced ones. Every Level 2 control must already be implemented and verifiable before Level 3 begins.

Related: CMMC Level 3 Checklist 

Who Conducts the Assessment

Level 2 certification assessments are run by Certified Third-Party Assessment Organizations (C3PAOs). Level 3 is different. The Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducts all Level 3 certification assessments.

This is a government-led audit. The rule directs DIBCAC to assess against the procedures in NIST SP 800-171A and NIST SP 800-172A. The DoD chose direct oversight here because of the sensitivity of the programs involved.

You initiate the process by emailing a request to the DCMA DIBCAC point of contact. The request must include your Level 2 certification assessment unique identifier. DIBCAC then validates your Level 2 status and contacts you to schedule an appointment.

Who Needs Level 3

Most contractors handling CUI will never need Level 3. It is built for a narrow subset of the Defense Industrial Base. The DoD has estimated that fewer than 1% of defense contractors will require it.

You will know if your contract requires Level 3 by reading the solicitation. It specifies the minimum CMMC level for systems that process or transmit CUI. 

Programs tied to high-priority national security missions are the typical candidates. Most contractors processing CUI fall under Level 2, and that distinction matters for both compliance planning and bidding.

How Level 3 Scoping Works

Scoping defines which assets DIBCAC will assess. The rules sit in 32 CFR 170.19(d). Level 3 uses three asset categories instead of the four used at Level 2.

CUI Assets process, store, or transmit CUI. At Level 3, any asset that can do so, whether intended to or not, falls in scope. Assets you designated as Contractor Risk Managed Assets at Level 2 are treated as CUI Assets at Level 3.

Security Protection Assets provide security functions for the environment. Firewalls, SIEM tools, and monitoring systems are common examples. They get a full assessment.

Specialized Assets include IoT and IIoT devices, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment. They require documentation in your System Security Plan and are assessed against relevant Level 3 requirements.

One scoping detail trips people up. The Level 3 scope can be a subset of Level 2. Many contractors build a smaller, tightly controlled Level 3 enclave inside their broader Level 2 environment. Any open Level 2 POA&M items must be closed before the Level 3 assessment starts.

The 24 Enhanced Security Requirements

The 24 Level 3 requirements are drawn from NIST SP 800-172. DoD CIO materials confirm they target Advanced Persistent Threats and carry Organization-Defined Parameters (ODPs).

ODPs are a key difference from Level 2. Level 2 follows NIST SP 800-171 Revision 2, which has no ODPs. At Level 3, the DoD assigns specific values to certain controls. There is less flexibility, but it ensures a consistent security baseline across programs.

The requirements span the same practice domains used across CMMC, including Access Control, Awareness and Training, Configuration Management, Identification and Authentication, Incident Response, Personnel Security, Risk Assessment, and System and Communications Protection. 

Examples include restricting system access to organization-owned resources only and using secure information transfer solutions between security domains.

These are not documentation exercises. Achieving Level 3 means every enhanced control is technically enforced and verifiable, not just written into a policy.

How Scoring and Findings Work

Each requirement gets one of three findings. Under 32 CFR 170.24, those are MET, NOT MET, or Not Applicable. An objective marked Not Applicable counts the same as MET. All evidence must be in final form, not draft.

To reach Final Level 3 (DIBCAC), you must achieve a MET result for all required Level 3 security requirements. DIBCAC submits results to the CMMC instance of eMASS, which automatically feeds the Supplier Performance Risk System (SPRS).

A passing score can come from the initial assessment or from a later POA&M closeout assessment. The DoD also reserves the right to conduct a follow-up DIBCAC assessment, and those results take precedence over any existing status.

Conditional vs Final Status and the POA&M Rules

Level 3 allows a Conditional status, but the conditions are strict. Under 32 CFR 170.21, you can only reach Conditional Level 3 (DIBCAC) if your assessment score divided by the total number of Level 3 requirements is 0.8 or higher. Certain requirements cannot appear on a POA&M at all.

If you qualify for Conditional status, you have 180 days from the Conditional CMMC Status Date to remediate every POA&M item. DIBCAC then performs a closeout assessment covering only the NOT MET items.

Miss the 180-day window, and the Conditional status expires. If that happens during a contract’s period of performance, standard contractual remedies apply. You also become ineligible for new awards requiring Level 3 until you earn a fresh status.

One scheduling consequence is worth planning around. The CMMC Status Date does not reset when you close a POA&M. If you use the full 180 days, you effectively get only about two and a half years of full certification before re-assessment.

Maintaining Level 3 Certification

Certification is not permanent. The Level 3 assessment must be repeated every three years for all systems in scope. Because Level 2 is a prerequisite, you also need a fresh Level 2 (C3PAO) assessment every three years to keep Level 3 status active.

In addition to the three-year cycle, you must submit annual affirmations in SPRS. An appointed Affirming Official confirms ongoing compliance with the requirements. Skipping affirmations puts your status at risk.

Cloud Environments at Level 3

If you use a cloud service to process, store, or transmit CUI for a Level 3 contract, the cloud product must meet the FedRAMP Moderate baseline or higher. If it is not FedRAMP Authorized at that level, it must meet security requirements equivalent to FedRAMP Moderate under DoD policy.

Using a compliant cloud provider does not transfer your obligations. You still have to implement the 24 Level 3 requirements yourself.

A Note on What May Change

The current 24 requirements are based on NIST SP 800-172, February 2021. NIST has since published a revised version of SP 800-172 along with updated assessment procedures in SP 800-172A. 

The DoD has not announced a rulemaking timeline to adopt the revision. If and when it does, the number of enhanced requirements at Level 3 could grow well beyond 24. It is worth tracking, but today’s contracts are assessed against the current rule.

Getting Ready for a DIBCAC Assessment

DIBCAC assessors verify that controls actually work. They review artifacts, interview staff, and observe systems in operation. A polished policy document means little if the control behind it is not technically enforced.

The contractors most likely to pass already have a track record with DFARS clause 252.204-7012 and experience with government-led reviews. If that describes you, Level 3 is an extension of work you already know. If it does not, the gap is closeable, but it takes time, skilled people, and infrastructure built to withstand continuous threat.

Start with a clean Level 2 foundation. Every Level 3 control assumes the 110 NIST SP 800-171 controls are implemented and verifiable, so any weakness there will surface at Level 3. Build a defined Level 3 enclave, document it precisely in your SSP, and test your controls before DIBCAC does. 

If your contract pipeline points toward a Level 3 requirement, begin scoping and remediation now. Waiting for the solicitation that forces the issue leaves you short on the one resource you cannot buy back: time.

Scroll to Top