C3PAO assessment guide: how to prepare, what assessors check, how to choose
Third-party assessments are voluntary while Phase 2 is suspended, and still the strongest evidence behind an affirmation. How the assessment runs, what assessors examine, interview and test, and how to pick an assessor.
Key takeaways
- C3PAO assessments are voluntary while Phase 2 is suspended. They remain the strongest evidence behind an affirmation and are still valued by primes.
- Assessors examine documents, interview people and test systems, following the lists NIST publishes for every requirement.
- Most failures come from an incomplete system security plan, missing evidence, scope gaps and staff who cannot explain their own controls.
- Do not engage an assessor before your self-assessment is complete. Fees are not refundable.
July 2026 update
The Phase 2 third-party mandate is suspended pending a program review. C3PAO assessments continue on a voluntary basis. See what the suspension actually changed.
What a C3PAO is
A Certified Third Party Assessment Organization is an independent company authorized by the Cyber AB to conduct CMMC Level 2 assessments. Its certified assessors evaluate your implementation of all 110 NIST SP 800-171 requirements and decide whether you receive a Level 2 certification.
The assessment, step by step
-
Readiness
Complete a thorough self-assessment first: every requirement implemented or on an eligible POA&M, the system security plan written, evidence collected, SPRS score posted. Engaging a C3PAO before that wastes money.
-
Selecting the assessor
Choose on experience, availability, pricing and familiarity with your sector. Bedrock's C3PAO client lets an assessor receive your package directly.
-
Scoping and planning
The assessor reviews which systems, networks and people handle CUI, fixes the boundary, and schedules the work. Clear scoping prevents scope creep during the assessment.
-
Document review
Policies, procedures, the system security plan and the POA&M, usually reviewed remotely before the visit. Organized documentation shortens this phase considerably.
-
On-site assessment
Interviews, observation, evidence examination and testing, on site or remote for cloud-only environments. Each requirement receives a determination.
-
Results
Findings go to the Cyber AB. Every requirement met, or a limited number open on an eligible POA&M, earns a Level 2 certification valid for three years with annual affirmations.
What assessors look for
NIST SP 800-171A gives assessors three methods for every requirement, and names the objects for each:
- Examine: policies, plans, procedures, configuration settings, records and logs.
- Interview: the people responsible for implementing and operating the control.
- Test: the mechanisms that implement the control, exercised to see that they work.
The lists are public. Our guide prints them on every requirement's page under "For assessors", so both sides of the table can read the same thing before the visit.
Choosing a C3PAO
- Industry experience. An assessor who knows your sector understands your typical CUI environment.
- Availability. Capacity is thin; start early.
- Pricing transparency. Get quotes that say what is included and what a reassessment costs.
- Method. Some offer a readiness review at extra cost that finds gaps before the formal assessment.
- Tooling. An assessor using Bedrock's C3PAO client receives your evidence and determinations directly from your package.
Why assessments fail
- Incomplete system security plan. It does not cover every requirement or does not describe the real environment.
- Missing evidence. Controls are implemented but nothing proves it.
- Scope gaps. CUI flows through systems that were left out of the boundary. If CUI touches it, it is in scope.
- Staff cannot explain their controls. Interviews are part of the method.
- Stale documentation. Policies from years ago that no longer match practice.
- No continuous monitoring. Controls were set up once and nobody maintains them.
Bedrock CMMC prevents the first, second and fifth by construction: the plan is generated from the control implementations, every requirement has an evidence section, and documents update when the implementation does.
A realistic timeline
| Stage | Typical duration |
|---|---|
| Self-assessment and gap analysis | 1 to 2 months |
| Remediation and implementation | 3 to 12 months |
| Documentation and system security plan | 1 to 3 months |
| C3PAO selection and scheduling | 1 to 3 months |
| Assessment, document review through decision | 1 to 4 weeks |
Questions people ask
What is a C3PAO?
An independent organization authorized by the Cyber AB to conduct CMMC Level 2 assessments, employing certified assessors who evaluate contractors against the 110 NIST SP 800-171 requirements.
How much does an assessment cost?
Typically between $30,000 and $150,000 or more, depending on size, complexity, the number of systems in scope and the assessor. Small organizations with a tight CUI boundary sit at the low end.
How long does it take?
The assessment itself takes one to four weeks. From readiness review to decision, two to four months. Preparation usually takes six to eighteen months before that.
What if I fail?
A limited number of eligible gaps can produce a conditional certification with 180 days to close them. Larger failures mean remediating and scheduling a reassessment, usually at additional cost.
Are assessments still happening during the suspension?
Yes, on a voluntary basis. Many primes value them, and a completed certification is the strongest evidence behind an affirmation if the mandate returns in reformed shape.
Keep the proof, not just the plan.
Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.