CMMC Assessment Levels · 2 of 3
Level 2 certification by a C3PAO
In short
- A C3PAO assessment must be repeated within three years.
- NOT MET findings may be re-evaluated for 10 business days.
- Hashed evidence is kept for six years.
1. The third-party route to Level 2
Where a contract requires a Level 2 certification assessment, the Cybersecurity Maturity Model Certification (CMMC) rule requires an outside assessor. The organization seeking certification must complete and achieve a MET result for every Level 2 security requirement (32 CFR 170.17(a)(1)). It must obtain a Level 2 certification assessment from an authorized or accredited CMMC Third-Party Assessment Organization (C3PAO). A C3PAO is an organization authorized or accredited by the Accreditation Body to conduct Level 2 certification assessments (32 CFR 170.4).
A Level 2 (C3PAO) status also covers the Level 1 (Self) and Level 2 (Self) requirements within that scope (32 CFR 170.17(a)). To keep the status, the certification assessment must be repeated within three years, counted from the CMMC status date tied to Conditional Level 2 (C3PAO) (32 CFR 170.17(a)(1)). The assessment team consists of CMMC Certified Assessors and CMMC Certified Professionals, and does not include the organization’s own participants (32 CFR 170.4).
2. How the assessment is run and reported
The C3PAO performs the assessment under National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171A of June 2018 and the CMMC Level 2 scoping requirements (32 CFR 170.17(c)(1)). It scores the results under the CMMC scoring methodology and uploads them into the CMMC instance of the Enterprise Mission Assurance Support Service (eMASS). Final results reach the organization through a CMMC Assessment Findings Report. eMASS then transmits the results automatically to the Supplier Performance Risk System (SPRS) (32 CFR 170.17(a)(1)).
The eMASS entry must include at least ten items (32 CFR 170.17(a)(1)(i)). They are the date and level of the assessment, the C3PAO’s name, a unique assessment identifier, and each assessor’s name and business contact details. They also include all industry Commercial and Government Entity (CAGE) codes for the systems in scope, the name, date and version of the system security plan, and the CMMC status date. The remaining items are the result for each requirement objective, use of a plan of action and milestones (POA&M) and its compliance status, and a list of artifact names with their hash values and the hashing algorithm used.
Before a Level 2 assessment, the organization must specify the CMMC Assessment Scope, based on asset categories (32 CFR 170.19(c)(1)). Assets that process, store or transmit Controlled Unclassified Information (CUI) are assessed against all Level 2 requirements. Security Protection Assets, which provide security functions to the scope, are assessed against the requirements relevant to the capabilities they provide. Contractor Risk Managed Assets can, but are not intended to, handle CUI because of the policies in place. They are reviewed through the system security plan, and the assessor may conduct a limited check if questions arise. Specialized Assets, such as operational technology, test equipment and Government Furnished Equipment, are documented but not assessed against other requirements.
3. Re-evaluation during the assessment
A requirement scored NOT MET may be re-evaluated during the assessment and for 10 business days after the active assessment period (32 CFR 170.17(c)(2)). Three conditions must all exist. Additional evidence must be available to show the requirement is MET. The change cannot alter or limit the effectiveness of other requirements already scored MET. And the CMMC Assessment Findings Report must not yet have been delivered.
4. Conditional and final status
The organization achieves Conditional Level 2 (C3PAO) if its assessment ends with a POA&M that satisfies the CMMC POA&M rules (32 CFR 170.17(a)(1)(ii)). It must remediate every NOT MET requirement and undergo a POA&M closeout certification assessment by a C3PAO. The C3PAO must post the results into eMASS within 180 days of the conditional status date. Without a timely closeout, the conditional status lapses. A lapse during a contract brings standard contractual remedies, and no further awards requiring Level 2 (C3PAO) or higher can be made for those systems until a new status is obtained.
Final Level 2 (C3PAO) is reached when the assessment, or a POA&M closeout certification assessment, results in a passing score (32 CFR 170.17(a)(1)(iii)). The Department reserves the right to conduct an assessment of the organization by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), as provided under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7020 (32 CFR 170.17(a)(1)(iv)). Adverse DIBCAC findings, showing the requirements were not achieved or not kept in place, override any existing status.
5. Affirmation, eligibility and evidence
An affirmation of Level 2 (C3PAO) status must accompany each assessment and be renewed every year (32 CFR 170.17(a)(2)). No contract or subcontract requiring Level 2 (C3PAO) may be awarded unless the organization has a Conditional or Final Level 2 (C3PAO) status and an affirmation of compliance on file in SPRS (32 CFR 170.17(b)).
The hashed artifacts used as evidence are retained for six years, counted from the CMMC status date (32 CFR 170.17(c)(4)). To show the artifacts have not been altered, the organization must hash the files using a NIST-approved hashing algorithm. It then gives the C3PAO the list of artifact names, the hash values and the algorithm, for upload into eMASS.
6. Cloud and external service providers
An organization may use a cloud environment to process, store or transmit CUI under a Level 2 (C3PAO) requirement in two cases (32 CFR 170.17(c)(5)). The cloud offering may be authorized at the Moderate baseline or higher under the Federal Risk and Authorization Management Program (FedRAMP). Or it may meet security requirements equivalent to that baseline, under Defense policy. Either way, the organization’s on-premises infrastructure connecting to the cloud offering is part of the assessment scope. The security requirements from the provider’s customer responsibility matrix must be documented or referenced in the organization’s system security plan.
An organization may also use an external service provider that is not a cloud provider (32 CFR 170.17(c)(6)). Its use, its relationship to the organization and its services must be documented in the system security plan and described in the provider’s service description and customer responsibility matrix. The provider’s services used to meet the organization’s requirements are assessed within the organization’s assessment against all Level 2 requirements. The self-assessment route is covered in Level 2 self-assessment and conditional status.
Key terms
| C3PAO | An organization authorized or accredited to conduct Level 2 certification assessments. |
|---|---|
| eMASS | The system into which C3PAOs upload results, which transmits them to SPRS. |
| Assessment Findings Report | The report that communicates final assessment results to the organization. |
| Re-evaluation window | The assessment period plus ten business days, during which a NOT MET requirement may be re-evaluated. |
| Hashed artifacts | Evidence files hashed with a NIST-approved algorithm and kept for six years. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Third-party certification is a condition of award on many Defense contracts. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.