Skip to content
Back to blog

Both Sides of a CMMC Assessment: The Questions Assessors and Companies Ask

Both Sides of a CMMC Assessment: The Questions Assessors and Companies Ask

A CMMC assessment has two sides of the table. The assessor tests evidence and scope. The company defends both, and pushes back where it sees room. The questions each side brings reveal where assessments get won and lost.

Sera Brynn is an Authorized C3PAO, CyberAB CPN 59175, operating from Chesapeake, Virginia since 2011. Eight members of our staff hold the Certified CMMC Assessor credential. We sit on the assessor's side of these exchanges. The questions below come from that work, both the ones our assessors ask and the ones companies ask us.

Bottom Line Up Front

A CMMC assessment runs on evidence, not intent. Assessors ask companies to prove each control operates and to justify what sits outside scope. Companies ask what counts as evidence, what they can still fix, and when the certificate arrives. The answers point one direction: proof that holds, scope that is documented, and a Not Applicable claim that is justified. 

Questions the Assessor Asks

1. Can you show me this control works, not just that it is configured? Configuration shows intent. The assessor scores effectiveness. We want the control producing the outcome the requirement calls for, not a settings screen that says it should.

2. If this system or vendor is out of scope, where is your justification? An out-of-scope claim needs support. The assessor looks for a shared responsibility matrix, an inheritance rationale, or a boundary that places the asset outside it. Without that, the asset stays in scope.

3. Can you walk me through how you handle this activity? The assessor compares the procedure you describe against the procedure your evidence shows. When the two diverge, the gap becomes the finding. A practiced answer counts for less than matching records.

4. Can you show me evidence from the last 90 days? A single artifact proves a moment, but some controls need more evidence. In that case, the assessor tests sustained operation. Logs, tickets, and records across a window show the control lives in the environment, not the binder.

5. Where is this configured in the system? Description gives way to demonstration. The assessor wants to see the setting, the policy, or the enforcement inside the system, live.

6. Do you have Customer Responsibility Matrixes for every in-scope vendor? That includes non-CUI Security Protection Assets. A provider that helps protect the environment carries responsibilities, and the assessor needs those responsibilities defined and split between you and the provider.

7. Is your CRM aligned to NIST 800-171? A Customer Responsibility Matrix mapped to NIST 800-53 does not answer a 171 assessment. The assessor needs responsibilities mapped to the framework under assessment, not an adjacent one. A FedRAMP High matrix from a cloud provider is a common mismatch.

8. You said you “do not do this.” What is stopping it? When you describe what you would do if a function were required, or state that you have not implemented a control, the assessor asks why it is not happening now. Is it prohibited by policy? Blocked by technical means? Not Applicable, or simply not implemented? The distinction sets the score.

9. Do you follow a naming convention for your artifacts? Evidence hygiene moves an assessment. Consistent, organized artifacts speed the assessor's review and signal a program that runs on discipline.

Questions the Company Asks

1. Can we fix this finding before the assessment ends? No. The assessor scores what shows up during the assessment window. You cannot correct a material control that does not exist while the assessor watches and have it count as met. Some findings qualify for a Plan of Action and Milestones (POA&M) with a limited closeout window. Remediation in the moment does not change the result.

2. Why is this asset in scope? Scope follows the asset. An asset that processes, stores, or transmits Controlled Unclassified Information sits inside the boundary, and so does an asset that protects the ones that do. Move it out with valid documentation and technical controls, not verbal assertion.

3. When will our certificate be issued? Not on the last day. The assessor completes scoring, then results move through validation and upload before a status is recorded. An open POA&M produces a conditional status first, with final status following once it closes and passes verification.

4. If we plan to demonstrate this live, why send screenshots first? Pre-assessment artifacts let the assessor plan the engagement and confirm readiness. Live demonstration verifies what the artifacts claim. Sending evidence early shortens live sessions and cuts surprises for both sides.

5. The SSP is a document. Can we document controls that require a defined value in the SSP and be done? Writing the definition in the System Security Plan covers the requirement to define it. It does not cover implementation. The assessor still needs evidence that the defined standard operates. A documented value with no operating proof reads as a gap.

6. Do screen shares and physical reviews still need evidence? Yes. Every assessment method generates a record, screen shares and physical walkthroughs included. If the assessor examined or tested it, it gets documented.

7. Do we provide evidence for controls marked Not Applicable? Yes. Not Applicable is a claim, and the assessor tests it. You show the condition triggering the control does not exist in your environment. A bare N/A invites a finding, but a policy stating that you do not do it, or a description of what you might do and then technical/physical evidence that it does not exist is a winning combination.

Choosing Your C3PAO

The two sides of the table are not adversaries. The strongest assessments run when the assessor holds a clear line on evidence and the company knows that line going in. The C3PAO you choose sets the tone. Sera Brynn's Certified CMMC Assessors run CMMC Level 2 assessments from Chesapeake, Virginia. Book a scoping call with our assessors. You leave knowing what your boundary covers, what evidence the assessment demands, and how the engagement runs.

Frequently Asked Questions

With CMMC Phase 2 suspended, is a third-party assessment still worth pursuing?

The July 2026 suspension paused the mandate that made C3PAO certification a condition of award. It did not pause the obligations underneath it. Self-assessments, DFARS 252.204-7012, NIST SP 800-171 compliance, SPRS scores, and annual affirmations stay in force. Companies that complete a third-party assessment now hold a market advantage when the requirement returns and carry less exposure on the attestations they sign today.

What separates a self-assessment from a C3PAO assessment?

A self-assessment is your own review of your NIST SP 800-171 implementation, scored and posted to SPRS by your team. A C3PAO assessment is an independent third-party review that produces a CMMC Level 2 certification. Same control set, different scrutiny. Your self-assessment rests on your signature. The certification rests on an authorized assessor's.