· CMMC  · 8 min read

Selecting a C3PAO: Practical Criteria for CMMC Level 2 Assessments

Contractors should verify Cyber AB authorization, independence, ISO/IEC 17020 status, and alignment to the CAP and NIST SP 800-171 when choosing a C3PAO for future CMMC Level 2 assessments, while using Microsoft resources as implementation references, not as assessment criteria.

Contractors should verify Cyber AB authorization, independence, ISO/IEC 17020 status, and alignment to the CAP and NIST SP 800-171 when choosing a C3PAO for future CMMC Level 2 assessments, while using Microsoft resources as implementation references, not as assessment criteria.

Only Authorized or Accredited firms listed as a C3PAO in the Cyber AB Marketplace can perform formal CMMC Level 2 assessments once DoD resumes third-party reviews. You can prepare your selection now and avoid last-minute surprises by focusing on verifiable authorization, independence, accreditation, and method fit to your environment.

Program status and planning

The DoD CIO CMMC portal states that Phase II, which includes third-party C3PAO assessments for Level 2, remains suspended. Phase I self-assessment requirements continue during the review period. Build your plan now, then engage formally after DoD restores third-party assessments.

The CMMC Program rule at 32 CFR Part 170 remains in effect. The rule requires contractors that process FCI and CUI to implement prescribed standards and undergo assessments under the program. DFARS 252.204-7012 obligations and alignment to NIST SP 800-171 also continue. You should keep implementing and documenting the 110 requirements and maintain your SPRS score. If you need a refresher on the control set, review our mapping guidance in NIST 800-171 to CMMC Level 2.

Cyber AB roles and authorization

The Cyber AB defines how firms enter and operate in the ecosystem. A C3PAO contracts and manages CMMC assessments. The Cyber AB FAQ describes the path from Candidate C3PAO to Authorized C3PAO. The Cyber AB C3PAO detail page adds the specific requirements. A firm applies, passes background checks, completes a DCSA FOCI review, signs the C3PAO Agreement and Code of Professional Conduct, and carries required insurance. DCMA DIBCAC then assesses the firm at CMMC Level 2. After authorization, the firm maintains associations with certified assessors and achieves ISO/IEC 17020 accreditation within 27 months.

You should confirm status directly in the Cyber AB Marketplace. The catalog entry shows whether a firm is Authorized or Accredited. Candidate status does not permit formal Level 2 assessments. RPO or individual assessor roles do not grant authority to issue certificates.

Selection criteria you can verify

You do not need a long checklist. Target the items that predict a clean assessment experience and a durable relationship.

Authorization and scope fit. Check the Cyber AB Marketplace listing and verify Authorized or Accredited status. Ask the firm to describe the scope it currently supports, for example enclave size, on-premises inclusion, and use of cloud services such as Microsoft 365 GCC High or Azure Government.

Independence and conflicts. Ask for the firm’s conflict-of-interest policy and how it separates consulting from assessment work. The Cyber AB emphasizes independence. Your assessor should not remediate your controls during the same engagement.

Accreditation posture. Ask for current ISO/IEC 17020 accreditation or the status plan to meet the 27-month window after authorization. Confirm the accreditation body and scope statement. This frames how the firm runs its conformity assessment system.

CAP method adherence. The Cyber AB CMMC Assessment Process (CAP) defines four phases. Your assessor should plan a pre-assessment, assess conformity to security requirements, complete and report results, then close out the certification and any limited POA&M items the rule allows. Ask for a method briefing that maps their workpapers, evidence handling, and reporting to CAP v2.0.

Assessor team depth. Ask who will lead the assessment and the specific product and control domains they handle. Press for named resumes with CMMC assessor certifications and relevant platform experience. You will live with their interpretation of evidence.

Dispute and appeals handling. The Cyber AB requires an appeals process. Ask for the written procedure and the contact path that bypasses the delivery team. You want a clear route if you need to challenge a scoring decision.

Insurance and terms. The Cyber AB sets insurance expectations. Request certificates of insurance and the contract terms that reference the Cyber AB code and your data handling requirements.

Method alignment to NIST SP 800-171 and the Level 2 guide

A C3PAO should ground its objectives in the Level 2 Assessment Guide and the 110 NIST SP 800-171 requirements. Ask the team to walk through sample objectives and evidence for representative controls across families.

  • Access control example: AC.L2-3.1.1. The team should review authorization logic, device trust, and session controls across your CUI boundary. Expect evidence from identity, endpoint, and application layers.
  • Identification and authentication example: IA.L2-3.5.3. The team should verify multifactor authentication for privileged and non-privileged accounts, on network and local access paths, and confirm coverage for service accounts where applicable.

Keep the same rigor across monitoring and configuration management.

  • Audit example: AU.L2-3.3.1. The team should request log retention settings, forwarding paths, and sampling of event types that trace administrative and data access actions.
  • Configuration management example: CM.L2-3.4.1. The team should examine baselines, inventories, and change control records that prove you maintain defined configurations.

Cover data handling and cryptography with concrete checkpoints.

  • Media protection example: MP.L2-3.8.3. The team should verify sanitization processes and records for media that contained CUI.
  • System and communications protection example: SC.L2-3.13.11. The team should confirm use of FIPS-validated cryptography for CUI confidentiality on storage, in transit, and in key management.

You will move faster if your documents match assessor expectations. Bring a current SSP, the body of implementation evidence, and your POA&M entries. If you need to tune your SSP or evidence library before you engage, use our primer on System Security Plans for NIST 800-171. Align your self-assessment score and artifacts as well. Our guide on SPRS scoring for NIST 800-171 covers common pitfalls.

Microsoft cloud factors without overreach

Microsoft provides useful references for NIST SP 800-171 implementation in Microsoft 365 and Azure, but these do not replace the CAP or the Level 2 Assessment Guide. Treat them as implementation aids.

  • Microsoft 365 GCC High. Microsoft documents support for CMMC Level 2 and Level 3 when you configure the services appropriately. GCC High aligns with FedRAMP High, DFARS expectations, DISA CC SRG IL4, and ITAR. You still need to configure identity, device, and data controls to meet the NIST requirements.
  • Microsoft Product Placemat for CMMC 2.0, Preview. Microsoft describes the placemat as an interactive mapping and labels it a sample resource. Microsoft does not serve as a CMMC accrediting body and does not guarantee outcomes. Use the placemat to frame internal design discussions and to prepare evidence views for common practices.

You can also use service-specific tools to monitor alignment.

  • Microsoft Sentinel CMMC 2.0 solution. Microsoft publishes analytics rules derived from Defender for Cloud regulatory mappings that trace to NIST SP 800-171. These rules can flag gaps for Level 1 and Level 2 alignment and help you stage evidence for audit records and monitoring.
  • Microsoft Entra ID configuration guidance. Microsoft Learn documents policies that support CMMC access control and identity requirements through Conditional Access, strong authentication, and session controls.

Ask the C3PAO to explain how they will evaluate cloud platform evidence. A capable team will accept platform-native logs and configuration exports, and will trace them to the relevant objectives without asking for screenshots alone. If you plan a move to GCC High, factor that into timing and scope. Our GCC High migration decision framework outlines the drivers and tradeoffs.

Engagement structure and cadence

A C3PAO that follows CAP v2.0 will structure the engagement into a pre-assessment, an on-site or remote evidence review, a formal report, and a closeout that references any allowed POA&M items. Ask for clear entry criteria for each phase and for the document list the team expects before scheduling fieldwork. You want agreement on system scope, enclaves, inherited services, and the CUI boundary before the team starts testing. See our guide on POA&M management for CMMC if you need to frame residual risks and closeout plans.

DoD FAQs state that Level 2 assessments recur every three years. That cadence creates a multi-year relationship. Ask the firm how it retains workpapers and how it will handle re-assessments. Confirm that the team will map any environmental changes to scoping decisions and that they will request updated evidence, not a repeat of the initial submission.

Red flags that cost you time

Two items signal risk early.

  • Marketplace status that shows Candidate, RPO, or any role other than Authorized or Accredited C3PAO. That firm cannot issue a Level 2 certificate.
  • A proposal that bundles readiness consulting and formal assessment in the same engagement. That structure compromises independence.

Putting it together

You can select a C3PAO with high confidence by confirming authorization in the Cyber AB Marketplace, testing independence and ISO/IEC 17020 posture, and validating method alignment to the CAP and the Level 2 Assessment Guide. Pair that diligence with a complete SSP, current SPRS score, and a clear CUI boundary. Use Microsoft resources to structure configurations and monitoring. Do not treat vendor references as assessment criteria. That balance sets you up for an efficient assessment when DoD restores third-party reviews.

Sources

CMMC (Department of Defense CIO)

CMMC Resources and Documentation (Department of Defense CIO)

Cybersecurity Maturity Model Certification (CMMC) Program (Federal Register)

CMMC Assessment Process v2.0 (The Cyber AB)

Cyber AB FAQ (The Cyber AB)

C3PAO Detail (The Cyber AB)

Cyber AB Marketplace Catalog (The Cyber AB)

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, SP 800-171 Rev. 2 (NIST)

Microsoft Product Placemat for CMMC 2.0, Preview (Microsoft)

Microsoft and the CMMC Program for US Government Clouds (Microsoft)

Azure CMMC offering and Microsoft Sentinel CMMC 2.0 solution (Microsoft)

Microsoft Product Placemat for CMMC — October 2024 update (Microsoft)

Want a structured starting point?

Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.

Back to Blog

Related Posts

View All Posts »
Audit Log Sources Required for a CMMC Level 2 Assessment

Audit Log Sources Required for a CMMC Level 2 Assessment

CMMC Level 2 assessors expect complete audit coverage across your CUI boundary, so identify, collect, protect, retain, and review logs from identity, endpoints, networks, applications, cloud services, and security tools in line with NIST SP 800-171 AU controls.