
The United States Department of Defense (“DoD”) has been hard at work on its Cybersecurity Maturity Model Certification (“CMMC”) program since 2019. With the CMMC Program Rule becoming effective on December 16, 2024, there will be a lot of discussions about the fact that CMMC certification assessments will soon begin. This is a very exciting time!
However, we are hearing many assessment vendors (i.e., CMMC 3rd Party Assessment Organizations (“C3PAOs”)), assessors (including CMMC Certified Professionals (“CCPs”) and CMMC Certified Assessors (“CCAs”)), government contractors (i.e., Organizations Seeking Certification (“OSCs”)), and others use the generic term “assessment” in various contexts. This appears to be creating confusion in the marketplace.
There are, after all, several different “flavors” of assessments that are part of the CMMC process. Referring to these generically as assessments, without any additional adjectives, leads to a lot of confusion.
This article summarizes the various formal CMMC assessment types defined in the CMMC Program Rule and defines a few types of informal CMMC assessments. The goal is to help provide a common lexicon that can be used throughout the entire CMMC Ecosystem.
DoD’s Definitions
In the CMMC Program Rule, DoD defines an assessment as “the testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization, as defined in §§ 170.15 through 170.18.” They also define several different types of assessments, including self-assessments, certification assessments, and POA&M close-out assessments.
Although DoD’s definitions are useful for defining formal assessment types, they leave out several other types of assessments that occur before an OSC/OSA undergoes a formal assessment for CMMC status or certification. We therefore recommend augmenting the formal assessment types defined by DoD.
Our Recommended Terms
Informal Assessments | Formal Assessments | |||||
Gap Assessment | Validation Assessment | Mock Assessment | Status Assessment | POA&M Close-out Assessment | ||
Self-Assessment | Certification Assessments | |||||
| Stage of CMMC Certification Journey | Early | Middle | Late | End | End | End (after Level 2 or Level 3 Status Assessment) |
| Formal Requirement for CMMC Certification | No | No | No | Yes (Level 1 and some Level 2) | Yes (Level 3 and most Level 2) | No |
| Purpose | Evaluating the organization’s System Security Plan (if one exists) and its assets (people, processes, systems, locations) against the Assessment Objectives in the appropriate CMMC Assessment Guide to identify compliance gaps. | Reviewing the organization’s System Security Plan and related documentation to ensure the organization’s information security program is adequately and sufficiently documented for CMMC assessment purposes. | Training OSC personnel and the OSC assessment team on what to expect during a third-party CMMC assessment; ensuring the organization is prepared for a CMMC assessment conducted by a third party. | Formal CMMC Status in SPRS of Level 1 (Self) or Level 2 (Self). | Formal CMMC Status in SPRS of Level 2 (C3PAO) or Level 3 (DIBCAC) and receipt of CMMC certification. | Verifying closeout of POA&Ms resulting from a CMMC Level 2 or Level 3 Status Assessment. |
| Results Reported to The Cyber AB and/or DoD | No | No | No | Yes | Yes | Yes |
| Available as an option under CMMC Level 1 | Yes | Yes | N/A | Yes | No | No |
| DoD Assessment Methodology Score Calculated for SPRS Reporting | Yes (Optional) | Yes (Optional) | Yes (Optional) | Yes (only Level 2) | Yes (Level 2 and Level 3) | Yes |
| CMMC Certification Issued Upon Successful Completion | No | No | No | No | Yes | Yes |
| May result in the issuance of a Letter of Attestation if conducted by a third party | No | Yes | Yes (if all requirements are assessed) | N/A | N/A (issuance of CMMC certification renders this moot) | N/A |
| Must only be conducted by a C3PAO/DIBCAC Assessment Team | No (CCP or CCA recommended) | No (CCP or CCA recommended) | No (CCP or CCA recommended) | No (CCP or CCA recommended) | Yes (C3PAO for Level 2, DIBCAC for Level 3) | Yes (C3PAO for Level 2, DIBCAC for Level 3) |
| May result in consulting, implementation, or remediation advice | Yes | Yes | Yes | N/A | No | No |
| Can be conducted by someone providing consulting, implementation, or remediation advice or services to the OSC | Yes | Yes | Yes. However, to help ensure objectivity, not recommended. | Yes | No | No |
| All requirements and corresponding Assessment Objectives are reviewed | Yes | Yes | Yes, generally. However, subsets can be reviewed to reduce cost. | Yes | Yes | No. Only requirements that were not met during the Status Assessment are reviewed. |
Applying the Terms
To put the various assessment types into context, a typical OSC’s CMMC journey for a CMMC Level 2 (C3PAO) status and certification will roughly follow this approach:
- INVENTORY – Inventory the organization’s assets that are used to store, process, transmit, secure, or otherwise have access to the government’s information (i.e., FCI and/or CUI). Assets include the following broad categories:
- People – these are the individuals, including vendors, service providers, consultants, business partners, etc., who have access to the facilities where, and/or technologies through which, FCI and/or CUI are stored, processed, transmitted, or secured.
- Technology – this is the software, hardware, or other systems, including cloud systems and network components, that are used to store, process, transmit, or secure FCI or CUI.
- Facilities – these are the physical locations where FCI and/or CUI are stored, processed, transmitted, or secured.
- Business Processes – these are the policies, procedures, plans (including a System Security Plan), and other business practices that govern how the organization operates on a day-to-day basis. Although, in most cases, NIST SP 800-171 does not require that business practices be reduced to writing, as a practical matter it is exceptionally difficult for an assessor to review, and for an organization to demonstrate compliance with, ad hoc policies. It is, therefore, advantageous to ensure the organization has appropriate evidence, including written policies, procedures, and plans, as well as screen captures of configurations, log files, etc. that demonstrate that the business practices are being followed.
- DIAGRAM – Create corresponding diagrams
- Network Diagram – illustrates the notional architecture of the information system(s), including any means for safeguarding the government’s information.
- Data Flow Diagram – illustrates how sensitive information, including FCI and CUI, are received by the organization, how it flows through the organization’s assets, and how it leaves the organization.
- Floor Plan – illustrates the layout of the facilities at which FCI or CUI are stored, processed, transmitted, and/or secured, including any physical security mechanisms deployed in those facilities.
- Organizational Chart – illustrates the organizational hierarchy and helps define delegations of authority and justify access to sensitive information.
- ANALYZE – Conduct a Gap Assessment to compare the current state of the organization’s assets against the requirements specified for the OSC’s CMMC level.
- PLAN – Create Plans of Action and Milestones (“POA&Ms”) which define how the organization will remediate any gaps identified in step 3.
- REMEDIATE – Remediate the gaps and document how the organization has addressed the gaps.
- VALIDATE – Conduct a Validation Assessment to ensure that the organization has adequately and sufficiently documented its compliance with the requirements at the appropriate CMMC level. To help ensure objectivity, we recommend that the Validation Assessment be performed by someone who was not involved in the remediation process.
- ADDRESS – Address any remaining gaps identified as part of the Validation Assessment process. If a significant number of gaps were found in the previous step, repeat Step 6 to ensure everything is ready.
- TRAIN – Conduct a Mock Assessment to help ensure that the organization understands and is prepared for a CMMC assessment. To get the most out of a Mock Assessment, we recommend that the Mock Assessment be led by a CMMC Certified Assessor (“CCA”) who has participated in a CMMC assessment as part of a C3PAO’s Certification Assessment Team. Although the Mock and Validation Assessment steps can be combined, we recommend keeping them separate to provide an additional level of assurance before engaging a C3PAO.
- ATTAIN – Engage a C3PAO authorized/accredited by The Cyber AB to conduct the Status Assessment. DoD refers to this as a “Level 2 certification assessment” in the CMMC Program Rule.
- CLOSE OUT – In the event the Status Assessment of Step 9 results in one or more POA&Ms, close out the POA&Ms
- VERIFY CLOSE OUT – Engage the C3PAO from Step 9 to conduct a POA&M Close-out Assessment. DoD refers to this as a “POA&M closeout certification assessment” in the CMMC Program Rule.
- AFFIRM – Submit an affirmation of compliance to SPRS.
