govcon.forum

How do I get CMMC Level 2 certified, and what does a C3PAO assessment actually involve?

Ask a question
Asked Active Viewed 5 timesQuestion
2answers

My firm is an engineering company with 25 people, doing drawings for an Army subcontract. We handle CUI and have a system security plan in place, with a self-assessed score for CMMC. We are trying to get CMMC Level 2 certified. We understand that Level 2 is either a self-assessment or a certification assessment by a C3PAO, and our prime is pushing us towards the latter. What is the actual sequence of events for a C3PAO assessment? I am trying to understand the scoping process, how to engage with the assessment organization, what specific evidence they look for, and what happens with any open findings or corrective actions during the assessment.

asked Priya S. Verified vendorCapture manager, IT services · Herndon, VA · 301 rep

2 answers

0

A C3PAO assessment for Cybersecurity Maturity Model Certification (CMMC) Level 2 involves a multi-step process, from preparation to final certification, focusing on the 110 requirements of NIST SP 800-171 Revision 2. My firm doesn't do federal work because of all this cybersecurity stuff. We do county and school work, where we have to meet some state and local requirements, but nothing like this CMMC. For a CMMC Level 2 certification assessment, you need to first make sure your System Security Plan (SSP) is complete and all 110 controls are implemented. The C3PAO will review your SSP and Plan of Action and Milestones (POA&M), conduct interviews with your staff, and examine evidence like policies, procedures, and system configurations. They will look for objective evidence that each control is met, not just described. Any deficiencies found during the assessment will result in a finding, and you will need to implement corrective action to address them before certification can be granted. The CMMC Level 2 self-assessment is conducted every three years, and the resulting CMMC Status is valid for three years from the CMMC Status Date. A CMMC Level 2 certification assessment is also valid for three years.

answered Marcus T. Verified vendorOwner, janitorial and facilities firm · Columbus, OH · 567 rep
0

The actual sequence for a C3PAO assessment starts with the contractor establishing a contract with an accredited C3PAO firm. Your firm will need to provide the C3PAO with access to your system security plan and any other documentation related to your cybersecurity posture, including your self-assessment score. The C3PAO will then conduct a readiness review, which involves examining your documentation and systems to identify any gaps before the formal assessment begins. During the formal assessment, the C3PAO will verify the implementation of all 110 controls of NIST SP 800-171 Revision 2. They will look for objective evidence of compliance, not just documented policies. Any findings that require corrective action must be addressed to achieve certification. The CMMC Level 2 self-assessment is conducted every three years, and the resulting CMMC Status is valid for three years from the CMMC Status Date. A CMMC Level 2 certification assessment is also valid for three years.

answered Dave H. Verified vendorParts distributor, DLA and DIBBS · Dayton, OH · 327 rep

Your answer

Sign up to answerCite the FAR clause or procurement code where you can.