Skip to content

Types of CMMC Assessments

 

Learn about Self-Assessment for CMMC Level 1 & Level 2, C3PAO Assessment for Level 2, Level 3 DIBCAC Assessment, Virtual Assessments, and more, through the Frequently Asked Questions (FAQs) below. If you are looking for certified CMMC Professionals and a customized solution for your organization, please schedule a free consultation.

Table of Contents

What is a CMMC Level 1 self-assessment and how is it conducted? 

 

Summary: A CMMC Level 1 self-assessment is an internally conducted evaluation by the defense contractor of its own implementation of the 17 safeguarding practices in FAR clause 52.204-21, with results reported annually to SPRS along with an affirmation by a senior company official, no independent assessor is required. 

The self-assessment follows the CMMC Assessment Guide, Level 1, which defines 17 assessment controls evaluated across 59 assessment objectives. The contractor reviews each objective as either MET (fully implemented) or NOT MET. All 59 objectives must be MET for a compliant Level 1 result. If any objective is NOT MET, no POA&M is available,the deficiency must be remediated before a compliant SPRS entry can be submitted. 

The scope of the assessment encompasses all systems that process, store, or transmit Federal Contract Information (FCI). Following the assessment, the contractor submits results to SPRS including the CAGE code, assessment date, scope designation, employee count in scope, compliance result, and the Affirming Official’s identity. The senior official then affirms the submission. This process must be repeated every 12 months. No C3PAO, Cyber AB registration, or payment to an external assessor is required. 

 

What is a CMMC Level 2 self-assessment and when is it permitted? 

 

Summary: A CMMC Level 2 self-assessment is a rigorous internal evaluation by the contractor of its own implementation of all 110 NIST SP 800-171 Rev 2 controls, with a numerical SPRS score submitted annually to SPRS along with a senior official affirmation, and it is permitted only for contractors whose CUI handling is limited to categories outside the National Archives CUI Registry Defense Organizational Index Grouping (DOIG). 

Level 2 self-assessment requires the contractor to evaluate all 110 controls and their 320 assessment objectives, calculate a weighted SPRS score, complete a comprehensive System Security Plan (SSP), and document any deficiencies in a POA&M. Unlike Level 1, a SPRS score below 110 is permissible for Level 2 self-assessment submission, and the contractor can post their current score even if controls are not fully implemented. 

The score must be accurate, intentionally inflating a Level 2 self-assessment score to misrepresent compliance triggers False Claims Act liability. Level 2 self-assessment is not appropriate for contractors handling DOIG-category CUI such as Controlled Technical Information, those contractors are required to obtain C3PAO certification regardless of preference or cost. Organizations uncertain about their CUI category should seek formal guidance from their contracting officer before pursuing self-assessment.

 

What is a CMMC Level 2 C3PAO third-party assessment and when is it required? 

 

Summary: A CMMC Level 2 C3PAO third-party assessment is an independent, formal evaluation of a contractor’s CMMC compliance conducted by a Cyber AB-authorized C3PAO, following the assessment methodology defined in the CMMC Assessment Guide, Level 2 Version 2.13, and it is required for contractors whose DoD contracts specify CMMC Level 2 (C3PAO) as the required certification. 

The C3PAO assessment is the only pathway to formal CMMC Level 2 certification for CUI-handling contractors whose CUI falls within the DOIG. During the assessment, the C3PAO evaluates all 110 NIST SP 800-171 Rev 2 controls across their 320 assessment objectives using three methods: Examine (document and artifact review), Interview (personnel interviews), and Test (technical control testing). Each objective is assigned a determination of MET, NOT MET, or NOT APPLICABLE. 

The C3PAO submits its findings to the DoD’s eMASS system and the Cyber AB issues the certification based on those findings. Beginning in CMMC Phase 2 (November 10, 2026), C3PAO assessment is expected to be the required certification path for most Level 2 contracts involving CUI, making it the de facto standard for the majority of the Defense Industrial Base. 

 

What is a CMMC Level 3 DIBCAC assessment and who qualifies for Level 3? 

 

Summary: A CMMC Level 3 DIBCAC assessment is a government-conducted evaluation of a contractor’s compliance with NIST SP 800-171 Rev 2 plus 24 enhanced requirements from NIST SP 800-172, performed by assessors from the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), and it is required for contractors whose contracts involve CUI associated with critical defense programs, breakthrough technologies, or systems meeting the ubiquity criterion. 

Level 3 qualification is determined by the DoD program office or contracting authority based on three criteria: the contractor handles CUI involving breakthrough, unique, or advanced technology; the contractor handles large aggregations or compilations of CUI in a single environment whose exfiltration would create significant damage; or the contractor handles CUI in an environment whose compromise would create widespread vulnerability across the DoD. 

The DIBCAC assessment cannot be scheduled until the contractor holds a valid Final CMMC Level 2 C3PAO certification, this is a hard prerequisite. DIBCAC assessments are scheduled through the Defense Contract Management Agency and are not available as voluntary assessments; they are initiated in response to contract requirements. Assessment procedures follow NIST SP 800-172A. 

 

What is a Joint Surveillance Voluntary Assessment (JSVA) and is it still available in 2026? 

 

Summary: A Joint Surveillance Voluntary Assessment (JSVA) was a voluntary CMMC assessment conducted jointly by a Cyber AB-authorized C3PAO and the DoD’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), available to defense contractors as an early certification pathway before the CMMC Level 2 program became fully operational. 

JSVAs were initiated by the DoD in 2023 to allow DIB organizations with active DFARS 252.204-7012 contracts to voluntarily undergo CMMC Level 2 assessment methodology testing before mandatory enforcement. As of 2026, with the CMMC program fully operational under both 32 CFR Part 170 and the 48 CFR DFARS acquisition rule, the JSVA program has been superseded by the standard C3PAO assessment pathway. 

Contractors who completed JSVAs should confirm with the Cyber AB whether their JSVA results translate to a formal CMMC Level 2 certification status in eMASS under the current program rules, or whether a formal C3PAO assessment is needed to obtain a current certification. New organizations seeking CMMC Level 2 certification in 2026 should pursue the standard C3PAO pathway. 

 

What is the eMASS system and how is it used in the CMMC certification process? 

 

Enterprise Mission Assurance Support Service (eMASS) is the DoD’s official risk management and compliance system used by C3PAOs to submit CMMC Level 2 assessment findings to the DoD, through which the DoD issues formal CMMC certifications and maintains the authoritative record of contractor certification status. 

eMASS is DoD-operated and is not directly accessed by contractors or the general public for CMMC submissions, only Cyber AB-authorized C3PAOs submit assessment results through eMASS. When a C3PAO completes a CMMC Level 2 assessment, they input all findings, including the determination for each of the 320 assessment objectives, any POA&M items, the SPRS score, and certification recommendation, into eMASS. 

The Cyber AB then reviews the submission and, if consistent with program requirements, issues the formal CMMC Level 2 certification. The resulting certification status is reflected in SPRS, which contracting officers and prime contractors use to verify contractor CMMC status. Any discrepancy between what a C3PAO assessed and what appears in eMASS should be raised with the C3PAO and the Cyber AB. 

 

Can a CMMC Level 2 C3PAO assessment be conducted remotely or virtually? 

 

Summary: CMMC Level 2 C3PAO assessments can be conducted partially or fully remotely using secure virtual meeting and document sharing platforms, subject to the C3PAO’s methodology and the practical requirements of technical control testing, though on-site presence is sometimes preferable or required for certain technical testing activities. 

The CMMC Assessment Guide, Level 2 permits the use of remote assessment techniques for the Examine (document review) and Interview (personnel questioning) assessment methods. Many C3PAOs conduct the pre-assessment scoping, documentation review, and personnel interviews entirely remotely using encrypted collaboration tools. 

The Test method, which involves actively testing technical controls such as firewall configurations, MFA enforcement, and network segmentation, sometimes requires on-site presence or specialized remote access arrangements to the contractor’s environment. Organizations hosting CUI in cloud environments often find that fully remote assessments are feasible because cloud configurations can be examined and tested without physical site access. Organizations with on-premises data centers or industrial environments may require at least partial on-site assessment for physical and technical control testing. Contractors should confirm the C3PAO’s remote assessment capability during the selection process and document the agreed methodology in the engagement agreement.

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties