Interweave Technologies
Sep 23

What Happens in a CMMC Audit and How to Prepare

A CMMC audit is the formal evaluation that verifies a defense contractor actually protects the sensitive government information its contract covers. Assessors work through every security requirement at the contractor's CMMC level, examining documents, interviewing staff, and testing live systems, then score each requirement as MET, NOT MET, or NOT APPLICABLE.

The event follows the CMMC Assessment Process (CAP) v2.0 and moves through four phases: pre-assessment, assess conformity, report results, and issue certificate with POA&M closeout. At Level 2 the assessor evaluates 110 requirements broken into 320 assessment objectives, and a Conditional status requires a score of at least 88 of 110 with a 180-day window to close the rest.

One piece of current context shapes everything below. The Department of Defense suspended CMMC Phase II on July 13, 2026, which means contracting officers can currently require only self-assessments. The assessment mechanics, the scoring rules, and the preparation work did not change. Below we cover who performs the audit, what happens in each phase, how requirements are scored, what score passes, what happens if you fall short, when audits become mandatory again, and the full preparation sequence contractors should be running now.

What Is a CMMC Audit?

A CMMC audit is the formal assessment that determines whether a defense contractor has implemented the cybersecurity requirements tied to its Cybersecurity Maturity Model Certification level. Assessors verify implementation rather than discover it. Their job is to confirm that the controls described in your System Security Plan operate in your environment as written.

Verification rather than discovery is the mental model that separates clean outcomes from messy ones. An assessment working as intended produces no surprises: the documentation matches the environment, the environment matches the interviews, and the assessor confirms all three. Every surprise during an audit traces back to a gap between what was documented and what was built. Contractors pursuing CMMC certification succeed or fail on that gap long before an assessor arrives.

What Is the Difference Between a CMMC Assessment and a CMMC Audit?

The difference between a CMMC assessment and a CMMC audit is terminology rather than substance. "Assessment" is the program's official term, used throughout 32 CFR Part 170. "Audit" is the everyday word contractors use for the formal, pass-or-fail evaluation that an authorized third party performs.

Terminology aside, two genuinely different activities share the word. A diagnostic assessment run internally or by a consultant looks for gaps, produces findings, and carries no regulatory consequence. A formal assessment produces a CMMC Status recorded in the government's systems and determines contract eligibility. The first is rehearsal, the second is performance, and confusing them is how contractors end up rehearsing once and performing cold.

What Are the Different Types of CMMC Assessments?

There are three official types of CMMC assessment, one for each level, plus two diagnostic activities that sit around them. Level 1 is an annual self-assessment against the 15 basic safeguarding requirements. Level 2 is either a self-assessment or a certification assessment by an authorized third party against 110 requirements. Level 3 is a government-led assessment against 24 selected enhanced requirements on top of Level 2.

The two diagnostic activities are the gap assessment and the readiness assessment. A gap assessment measures current posture against the 110 requirements and produces an estimated score plus a prioritized remediation plan. A readiness assessment comes later and simulates the formal event itself. Neither produces a CMMC Status, and both exist to make the official assessment uneventful.

Who Performs a CMMC Audit?

Three parties perform CMMC audits depending on the level: the contractor itself for self-assessments, a CMMC Third-Party Assessment Organization (C3PAO) for Level 2 certification assessments, and the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) for Level 3. The Cyber AB accredits C3PAOs and maintains the public marketplace where contractors find them.

A C3PAO assessment team has a defined minimum composition. At least two Certified CMMC Assessors (CCAs) staff the engagement, one serving as Lead Assessor who determines which assessment methods best evaluate each requirement, and a second supporting the review. A separate quality assurance function is filled by a CCA who is not on the assessment team and who reviews the team's conduct rather than the contractor's environment. Certified CMMC Professionals (CCPs) may participate alongside the CCAs.

Assessor capacity is the constraint most contractors underestimate. Roughly 104 authorized C3PAOs and 988 CCAs served the entire Defense Industrial Base as of May 2026, according to Secureframe's federal cybersecurity reporting, against a supplier base numbering in the hundreds of thousands. That ratio is why scheduling a certification assessment has historically taken months rather than weeks, and it is one reason the Department cited cost and capacity when reviewing the program. Our own government contracting compliance work is led by Certified CMMC Assessors and Certified CMMC Professionals on staff, which is the same credential set that staffs a C3PAO team.

What Happens in a CMMC Audit?

A CMMC audit moves through four phases defined by the CMMC Assessment Process (CAP) v2.0: pre-assessment, assess conformity, report assessment results, and issue certificate with POA&M closeout. The Cyber AB published CAP v2.0 in December 2024 as the procedural guide C3PAOs follow, and the phases below draw their requirements from that document and from 32 CFR 170.17.

PhaseWhat Assessors DoWhat You ProvideTypical Timing1. Pre-AssessmentLead Assessor reviews the SSP, validates the assessment scope and boundary, confirms evidence readiness, builds the assessment planSSP, network and data flow diagrams, asset inventory, policies, hashed evidence artifactsTwo to four weeks before the assessment2. Assess ConformityEvaluate every requirement against its objectives using examine, interview, and testStaff availability, live system access, configuration demonstrationsThree to five days on site or hybrid3. Report Assessment ResultsPresent preliminary findings, score each requirement, run quality assurance review, upload resultsAdditional evidence during the re-evaluation windowDebrief on the final day, plus 10 business days4. Issue Certificate and Close OutIssue the CMMC Status, track eligible open items, perform the closeout assessmentRemediation of POA&M items, affirmation submissionWithin 180 days for Conditional status

Phase 2 is where the assessment is won or lost, and it is also the phase contractors picture least accurately. Assessors are not reading a binder. They are running three distinct evaluation methods against 320 separate objectives, and each method tests something the others cannot. Reviewing the current CMMC requirements before an assessment is the starting point, but the requirement text alone does not reveal what an assessor will accept as proof.

What Are the Four Main Steps Involved in Conducting a CMMC Audit?

The four main steps involved in conducting a CMMC audit are pre-assessment, assess conformity, report assessment results, and issue certificate with POA&M closeout. Preliminary proceedings sit ahead of the four, covering the contract between the contractor and the C3PAO, scheduling, and the initial document request.

Each step constrains the next. A scope defined loosely in pre-assessment pulls systems into the conformity phase that never needed to be there. Evidence submitted in draft form in pre-assessment gets rejected in the conformity phase, because assessors accept only approved, final documents. Errors made early cost the most to fix late, which is the single most repeated lesson from contractors who have been through the process.

How Long Does a CMMC Audit Usually Take?

A CMMC audit usually takes about one full work week of assessment activity, roughly three to five days for a mid-sized contractor, either on site or as a hybrid remote engagement. Larger or more complex environments run longer.

Total elapsed time is considerably longer than the assessment week. Pre-assessment document review typically starts two to four weeks ahead, and the span from engagement kickoff to a recorded result commonly runs four to eight weeks. Preparation before any of that begins is measured in months, not weeks, which the preparation section below covers in detail.

How Assessors Score Each Requirement

Assessors score each CMMC requirement as MET, NOT MET, or NOT APPLICABLE, using three evaluation methods defined in NIST SP 800-171A: examine, interview, and test. The 110 Level 2 requirements decompose into roughly 320 assessment objectives, and every objective behind a requirement must be satisfied for that requirement to score MET.

The three methods exist to catch different failures. Examine reviews documents, policies, procedures, diagrams, and configuration exports, and it finds what has been written down. Interview puts structured questions to IT administrators, security staff, system owners, HR for training controls, and leadership, and it finds what people actually know and do. Test verifies that mechanisms perform as documented and as described, through live demonstrations of access control enforcement, audit logging, configuration baselines, patch status, multi-factor authentication, and encryption. A control that survives examination and interview but fails technical testing scores NOT MET. Seeing is the standard, not saying.

Interview failures follow a recognizable pattern. A policy states that an administrator reviews audit logs weekly, and the administrator cannot describe what they look for or when they last looked. That is a NOT MET finding no matter how well the policy is written. This is why the system security plan has to describe the environment that exists rather than the environment intended, and why whoever wrote it needs to be in the room.

How Much Audit Evidence Is Needed for a CMMC Assessment?

A CMMC assessment needs enough evidence to satisfy every assessment objective behind all 110 requirements, in final approved form, organized by control family, and retrievable on request. Drafts, working papers, and unapproved policies are not accepted.

Evidence handling carries formal requirements most contractors discover late. Under 32 CFR 170.17, every artifact file used as evidence must be hashed with a NIST-approved hashing algorithm, and the contractor provides the C3PAO with the artifact names, hash values, and the algorithm used, which the C3PAO uploads into the CMMC instance of eMASS. The contractor then retains those hashed artifacts for six years from the CMMC Status Date, so the evidence can be shown to be unaltered afterward.

Volume matters less than history. Static evidence such as a configuration export or a firewall rule set proves a control is configured. Operational evidence such as a series of quarterly access reviews, a year of vulnerability scans with remediation records, training completion histories, and incident response exercise records proves the control operates continuously. A single access review from last month proves considerably less than four spanning the past year, and building that history requires starting evidence collection long before an assessment date exists.

What Score Do You Need to Pass a CMMC Assessment?

You need a score of at least 88 of 110 to achieve Conditional Level 2 status, and all 110 requirements scored MET or NOT APPLICABLE to achieve Final Level 2 status. The threshold comes from 32 CFR 170.21(a)(2)(i), which requires the assessment score divided by the total number of Level 2 requirements to be greater than or equal to 0.8.

Scoring counts points rather than checkboxes. Under the CMMC Scoring Methodology at 32 CFR 170.24, you start at 110 and subtract the weight of each NOT MET requirement, and requirements carry weights of 1, 3, or 5 points based on how consequential the protection is. The 5-point weights sit on the requirements that matter most, such as multi-factor authentication. Missing a handful of high-weight requirements drops you below 88 even while most of the list reads as MET, which is why counting met controls rather than points produces false confidence.

What Can Go on a CMMC POA&M?

Only requirements worth 1 point can go on a CMMC POA&M at Level 2, with one narrow exception, and six specific 1-point requirements are barred by name. Every 3-point and 5-point requirement must be fully implemented and scored MET before the assessor evaluates it. Across the 110 requirements, that leaves 63 that can never be deferred.

The six 1-point requirements excluded by name in 32 CFR 170.21(a)(2)(iii) are:

  • AC.L2-3.1.20 External Connections (CUI Data)
  • AC.L2-3.1.22 Control Public Information (CUI Data)
  • CA.L2-3.12.4 System Security Plan
  • PE.L2-3.10.3 Escort Visitors (CUI Data)
  • PE.L2-3.10.4 Physical Access Logs (CUI Data)
  • PE.L2-3.10.5 Manage Physical Access (CUI Data)

Several widely circulated summaries name a different six, substituting CA.L2-3.12.1 and SI.L2-3.14.7 for two of the physical protection requirements. The list above is the one in the regulation. Check any preparation checklist against the regulation text before building a remediation plan on it, because a POA&M built around the wrong exclusions defers exactly the items that cannot be deferred.

The single carve-out runs in the opposite direction. SC.L2-3.13.11 CUI Encryption is normally a higher-weight requirement, but it may be placed on a POA&M at a value of 3 points where encryption is employed for CUI and the cryptographic module simply is not FIPS-validated. The carve-out applies only where encryption is actually in use. Where no encryption is employed at all, the requirement is fully NOT MET and no POA&M is available, which puts file encryption among the first things to verify rather than among the last.

What Is Conditional CMMC Status?

Conditional CMMC Status is the outcome granted when a contractor scores at least 88 of 110, places only eligible requirements on a POA&M, and includes none of the six barred requirements. Conditional status allows contract award while remediation continues.

The clock attached to it is firm. Every open POA&M item must be closed within 180 days of the Conditional CMMC Status Date, confirmed by a closeout assessment that re-evaluates only the items on the POA&M. For a certification assessment the C3PAO that performed the original assessment performs the closeout. Items still open after 180 days cause the Conditional status to expire. Level 1 has no POA&M path at all, so every Level 1 requirement must be MET at the time of the self-assessment.

Can You Fail a CMMC Compliance Audit?

Yes, you can fail a CMMC compliance audit, and the two ways it happens are scoring below 88 of 110 or having a barred requirement scored NOT MET. Below 88 there is no Conditional path available, which means no CMMC Status is recorded and the assessment produces findings rather than a certificate.

One recovery mechanism exists before the result is locked, and most contractors do not know about it. Under 32 CFR 170.17(c)(2), any requirement scored NOT MET may be re-evaluated during the active assessment and for 10 business days following it, provided additional evidence is available, the new evidence does not undermine requirements already scored MET, and the CMMC Assessment Findings Report has not yet been delivered. Once that report is delivered, the scores are final.

Those 10 business days are worth planning for rather than discovering. A finding that rests on evidence the team could not locate during the assessment week is often a finding that a well-organized evidence library can answer in an afternoon. The window closes on report delivery, not on a fixed calendar date, so the response has to start at the debrief. Contractors who do fall short address the gaps and return through a new assessment, which is a delay rather than a permanent bar.

When Will CMMC Audits Start?

CMMC assessments already started, and third-party certification audits are currently suspended. Phase 1 began November 10, 2025, making Level 1 and Level 2 self-assessments a condition of award on new contracts carrying a CMMC requirement. The Department of War suspended CMMC Phase II on July 13, 2026, which had been scheduled to make C3PAO certification a condition of award on November 10, 2026.

What a contracting officer may require right now is narrower than what the rule contemplates. Program managers can designate CMMC Level 1 (Self) or Level 2 (Self) in new solicitations. They may not require a Level 2 C3PAO assessment or a Level 3 DIBCAC assessment during the interim, and active solicitations carrying those designations are being amended to remove them. The obligations underneath are untouched: DFARS clause 252.204-7012, NIST SP 800-171 Rev 2 implementation, a current score posted in the government's supplier system, and the annual affirmation all remain in force, and an inaccurate self-assessment still carries False Claims Act exposure.

Can You Still Get a CMMC Audit During the Suspension?

Yes, you can still get a CMMC audit during the suspension. The assessment infrastructure remains operational, C3PAOs are still performing assessments for organizations that want them, existing certifications remain valid, and results still post to the government's systems. What is paused is the Department's ability to require a certification assessment in a new solicitation.

Whether a voluntary assessment is worth buying depends on the customer rather than the regulation. Prime contractors have continued enforcing CMMC expectations down their supply chains ahead of the government, and a certificate is a commercial differentiator in a bid even where no clause demands it. Across North Alabama, where the density of Redstone Arsenal suppliers means a single prime's subcontractor tier can carry dozens of companies, that differentiation compounds quickly. Contractors running managed compliance programs through the interim are the ones positioned to move the moment a requirement returns.

How Defense Contractors Prepare for a CMMC Audit

Defense contractors prepare for a CMMC audit by scoping the environment first, measuring the gap against all 110 requirements, remediating while documenting, building an evidence library with history, rehearsing through a readiness assessment, and only then booking the formal event. Most organizations need at least six months, and nine to twelve is the realistic planning figure for a contractor starting from a partially implemented environment.

The sequence below is ordered by dependency, which is why skipping ahead wastes work rather than saving time:

  1. Define the scope and the boundary. Identify every asset, user, and system that processes, stores, or transmits FCI or CUI, then categorize assets into the four types set out in 32 CFR 170.19(c): CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets. Specialized Assets include IoT and industrial IoT devices, operational technology, government furnished equipment, restricted information systems, and test equipment. Confirm that isolation between in-scope and out-of-scope environments is technically enforced rather than merely described.
  2. Run a gap assessment. Measure current posture against the 110 requirements with enough technical detail that remediation can be scoped and sequenced. The output is a finding for each requirement, an estimated score, and a prioritized remediation roadmap.
  3. Remediate by assessment risk, not by effort. Close every 3-point and 5-point requirement first, along with the six requirements barred from a POA&M, since none of those has a conditional path. Lower-weight items that qualify for deferral can follow.
  4. Write documentation alongside implementation. When a control is deployed, write its SSP implementation description before starting the next task, with the configuration details, the account coverage, the enforcement mechanism, and a pointer to the evidence. Documentation reconstructed months later from memory is less accurate and reads that way to an assessor.
  5. Build the evidence library with history. Organize artifacts by control family, capture both static configuration evidence and operational evidence of continuous operation, and verify each artifact actually supports the claim attached to it.
  6. Run a readiness assessment four to six months out. Apply assessor evidence standards rather than advisory standards, and address every finding before the formal event.
  7. Select the assessor and submit the pre-assessment package. Complete, organized, final-form, through whatever platform the assessor specifies.
  8. Complete the assessment, then close out and affirm. Remediate any POA&M items inside 180 days and file the annual affirmation of continuous compliance.

Step one carries disproportionate weight. Scoping errors propagate through every subsequent step, and a boundary drawn after remediation begins can invalidate months of work. Building a defensible boundary is where CMMC readiness starts for every contractor we work with.

How Do You Prepare for a CMMC Audit?

You prepare for a CMMC audit by building a compliance program that operates continuously, then verifying it holds up under assessor standards before the assessor applies them. Preparation oriented toward looking right on the day consistently produces worse outcomes than preparation oriented toward being right every day.

One rule governs the final week. Do not implement new controls. A control deployed seven days before an assessment produces evidence that is seven days old, which an assessor reads accurately as a control implemented for the assessment rather than operated continuously. Late implementations also create inconsistencies between the SSP and the evidence library that careful preparation avoids. An honest POA&M entry beats a hasty deployment.

What Is a CMMC Readiness Assessment?

A CMMC readiness assessment is a full dry run of the formal assessment, also called a mock assessment or pre-assessment. It works through the SSP, verifies evidence against each objective, interviews staff the way an assessor would, and walks the technical controls, producing a findings report comparable to what a C3PAO would generate.

Timing determines its value. Run four to six months before the formal event, a readiness assessment surfaces findings there is still time to fix: controls implemented but producing thin evidence, SSP sections imprecise enough to generate questions, staff who understand their responsibilities generally but cannot describe execution specifically. Run two weeks out, the same findings become a list of things you now know you will be marked down for.

What Is the Difference Between a Gap Assessment and a Readiness Assessment?

The difference between a gap assessment and a readiness assessment is position in the sequence and depth of simulation. A gap assessment comes first, compares current posture against the 110 requirements, and produces a score estimate with a prioritized remediation plan. A readiness assessment comes after remediation and simulates the assessment event itself, including evidence verification and mock interviews.

Running only one of the two is the common shortcut. A gap analysis alone tells you what to build and nothing about whether what you built will be accepted. A readiness assessment alone, with no prior gap work, discovers structural problems at a point where fixing them means rescheduling. The sequence exists because each one answers a question the other cannot.

What Is a CMMC Audit Checklist?

A CMMC audit checklist is the set of documents and artifacts an assessor expects to receive before and during the assessment. The standard package covers the environment, the controls, and the proof that the controls operate.

Assessors typically request the System Security Plan reflecting the current environment, every policy and procedure the SSP references, a network topology diagram with the assessment scope boundary clearly marked, a CUI-boundary data flow diagram, an asset inventory covering all in-scope systems, asset categorization across the four types, policies covering all 14 requirement families, the Customer Responsibility Matrix for external service providers, vendor service level agreements, evidence of multi-factor authentication deployment, configuration baseline documentation, training records, and the most recent risk assessment. Preparing for a compliance audit of any kind starts with assembling this list before it is requested rather than after.

The Customer Responsibility Matrix deserves specific attention because it is the document most often missing. It sets out which security responsibilities sit with the contractor and which sit with each external service provider, and without it an assessor cannot determine who is accountable for the controls a vendor operates.

What Are Common Findings in a CMMC Audit?

The most common findings in a CMMC audit are incomplete asset inventories, uncounted Security Protection Assets, weak shared-responsibility documentation, evidence that cannot be retrieved or dated, and programs that exist as policy but were never exercised. Each traces back to preparation rather than to technical capability.

Incomplete inventories are the leading cause because scope is the first thing assessors validate. Systems get missed, and a missed system inside the boundary is a set of requirements nobody assessed internally. Security Protection Assets, meaning the tools that provide security functions to the environment rather than holding CUI themselves, get overlooked more often than CUI assets do. Shared-responsibility gaps appear when the Customer Responsibility Matrix does not spell out who does what with each external provider.

Evidence problems split into two kinds. Artifacts that cannot be retrieved on request read as artifacts that do not exist, and artifacts with no timestamp cannot demonstrate continuous operation. Across Huntsville-area contractors, the pattern we see most often is a solid technical environment with an evidence trail that was never designed to be produced on demand. The same discipline that makes an IT audit straightforward makes a CMMC assessment straightforward, and it is built months in advance.

What Not to Say During a CMMC Audit

What not to say during a CMMC audit is anything you cannot support, and the specific phrases to avoid are guesses dressed as answers. Assessors follow up on responses that do not hold up to the next question, and a confidently wrong answer creates a bigger problem than the original uncertainty would have.

"I don't know, but I can find out who does" is a legitimate and frequently correct answer. So is a straightforward description of what you actually do, even where it differs slightly from the written procedure, since a genuine discrepancy is better surfaced than papered over. What causes trouble is speculating about systems you do not administer, describing a process you have read about rather than performed, or volunteering detail about environments outside the assessment scope. Brief control owners on the interview format in advance so the conversation feels like a description of their job, because that is what it is.

How to Prepare for a CMMC Audit in Azure

Preparing for a CMMC audit in Azure starts with choosing the right Azure environment, because commercial Azure, Azure Government, and Microsoft 365 GCC High carry different compliance postures and different assessment consequences. The environment decision belongs in the scoping phase, before any remediation work begins.

The driver is DFARS clause 252.204-7012, which requires cloud service providers handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline and to satisfy additional requirements around cyber incident reporting, media preservation, and access for forensic analysis. Commercial Microsoft 365 and commercial Azure are not built to carry the full set of those commitments for CUI workloads, which is why contractors handling CUI commonly move to GCC High or Azure Government. A migration decided after remediation has started often means rebuilding work against the correct boundary.

Beyond environment selection, three pieces of Azure-specific preparation carry the most assessment weight. Document the shared-responsibility split in a Customer Responsibility Matrix, since Microsoft operates some controls and you operate others, and an assessor will ask which is which for every affected requirement. Verify that encryption in the tenant uses FIPS-validated cryptographic modules rather than encryption generally, because that distinction is what separates a fully MET requirement from the narrow POA&M carve-out. Export evidence in a form assessors can verify, meaning configuration exports, conditional access policy reports, sign-in and audit log retention settings, and multi-factor authentication coverage reports captured on a schedule rather than screenshotted the week before. Building that advanced security tooling into daily operations is what turns a tenant into assessable evidence.

How to Choose a CMMC Assessment Provider

Choose a CMMC assessment provider by verifying authorization through the Cyber AB marketplace, interviewing at least three candidates, and confirming their experience with organizations of comparable size and complexity. Assessor availability is limited enough that the selection conversation should start well before the environment is finished.

One structural rule shapes the whole decision. The program bars ecosystem members from assessing an organization they consulted for within the previous three years, which means readiness work and the certification assessment must be purchased from different firms. A C3PAO can run your mock assessment or your formal assessment, not both. Plan the two engagements as separate procurements rather than discovering the conflict after signing.

Evaluate candidates on assessor experience in your sector, communication approach during the assessment, references from completed engagements, and scheduling availability against your target date. The provider preparing you is the one worth choosing for depth of relationship, since that engagement runs for months. Our audit defense work sits on that side of the line, preparing the environment, the documentation, and the people so the assessment confirms work already finished.

How Much Does a CMMC Audit Cost?

A CMMC audit costs roughly $105,000 over a three-year cycle for a small entity pursuing Level 2 certification, against roughly $37,000 for a Level 2 self-assessment cycle, according to the Department of Defense Regulatory Impact Analysis published with the CMMC program final rule. Level 1 self-assessment and affirmation was modeled at approximately $6,000 for a small entity.

Those figures measure proving compliance rather than achieving it. The rule explicitly assumes the underlying security requirements are already implemented, so remediation, tooling, cloud migration, and documentation sit outside the estimate entirely. Treat the government numbers as the floor of an assessment budget and the implementation work as a separate line.

Frequently Asked Questions

How Long Is a CMMC Certification Valid?

A CMMC certification is valid for three years at Level 2 and Level 3, with an annual affirmation of continuous compliance filed in the intervening years by a designated Affirming Official. Level 1 requires a fresh self-assessment and affirmation every year. The affirmation is a representation to the government, so the posture demonstrated on assessment day has to be maintained between assessments.

Does Your MSP Get Assessed During a CMMC Audit?

Yes, your managed services provider gets assessed during a CMMC audit where it processes, stores, or transmits CUI or Security Protection Data on your behalf. Those services fall inside your assessment scope and the controls the provider operates are evaluated as part of your environment. Have provider staff available during the assessment to explain and demonstrate the tools and activities they operate.

What Is a Mock CMMC Audit?

A mock CMMC audit is a full rehearsal of the formal assessment, identical in structure to a readiness assessment. It reviews the SSP, verifies evidence against assessment objectives, runs practice interviews with control owners, and walks the technical controls. The value comes entirely from the remediation time it creates, so run it months ahead rather than weeks.

Can the Same Firm Do Your Readiness Work and Your Certification Assessment?

No, the same firm cannot do your readiness work and your certification assessment. CMMC ecosystem members are barred from assessing an organization they consulted for within the previous three years. Budget and procure the two engagements separately, and confirm the restriction with any firm offering both before signing.

What Happens After You Pass a CMMC Audit?

After you pass a CMMC audit, the assessor uploads the results into the government's eMASS instance, issues a Certificate of CMMC Status, and your status becomes visible to contracting officers reviewing eligibility. You then submit the affirmation of compliance, maintain the posture continuously, file the affirmation annually, and reassess in three years.

Does a CMMC Audit Cover Every System in Your Company?

No, a CMMC audit covers only the systems inside the defined assessment scope. Systems that never process, store, or transmit FCI or CUI, and that are genuinely separated from those that do, sit outside the boundary. Separation has to be technically enforced rather than described, which is why isolating CUI into a defined enclave is the most effective way to keep an assessment proportionate.

The Bottom Line

A CMMC audit is a four-phase verification event built on the CMMC Assessment Process v2.0. Assessors examine documents, interview the people who operate the controls, and test live systems against roughly 320 assessment objectives, scoring each of the 110 Level 2 requirements MET, NOT MET, or NOT APPLICABLE. Conditional status requires at least 88 of 110, only eligible requirements on the POA&M, none of the six requirements the regulation bars by name, and closure within 180 days.

Preparation is where the result is determined. Scope the environment first, measure the gap honestly, close every 3-point and 5-point requirement before anything else, write documentation as controls go in rather than afterward, and build an evidence trail with enough history to prove continuous operation. Phase II certification is suspended for now, which changes the timeline and nothing else, and the contractors who keep building through the interim will be the ones ready whenever the requirement returns.

We have spent over 20 years helping organizations across Huntsville and North Alabama weave technology into a compliant infrastructure, with Certified CMMC Assessors and Certified CMMC Professionals leading the process from scoping through evidence collection and audit preparation. If you would like an honest read on where your environment stands against the 110, the team at Interweave Technologies is glad to walk through it with you. You can reach us at (256) 837-2300.