Most CMMC content covers how to prepare for certification. Less gets written about what the assessment itself actually involves, and almost nothing addresses the part that matters most once you’ve passed: staying compliant afterward. Certification is a snapshot. The controls it verifies need to keep working for years, not just on assessment day.

This guide covers both halves — what a C3PAO or self-assessment actually reviews, and what ongoing compliance requires once certification is behind you.

Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Self-assessment and existing certifications are unaffected. See CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for full detail.

/

Executive Summary

Main Idea: A CMMC assessment — whether self-conducted or performed by a C3PAO — evaluates documented evidence against every required control, not just a general impression of security maturity. Passing that assessment starts, rather than ends, an ongoing compliance obligation that includes continuous monitoring, incident reporting, and eventual recertification.

Why You Should Care: Organizations that treat certification as a finish line often find their compliance posture has quietly drifted by the time recertification comes around — a lapsed control, an undocumented system change, an expired affirmation. Understanding what sustained compliance actually requires is what prevents recertification from becoming a scramble to reconstruct evidence you should have been maintaining continuously.

Key Takeaways

  1. A CMMC assessment evaluates documented evidence, not a general impression of security. Whether self-conducted or performed by a C3PAO, the assessment checks your System Security Plan against each specific required control — a control that’s implemented but undocumented is treated the same as one that doesn’t exist.
  2. C3PAO assessments involve document review, interviews, and technical verification — not just a checklist. Assessors examine your SSP and supporting artifacts, interview personnel to confirm documented processes match actual practice, and directly test technical controls rather than taking documentation at face value.
  3. Certification has an expiration date, and continuous monitoring is required in between. Level 2 and Level 3 certifications are valid for three years, but annual affirmations of continued compliance are required throughout that period — a missed affirmation can invalidate an otherwise current certification.
  4. Staying compliant means your environment can change without your compliance posture silently breaking. New employees, new systems, new vendors, and configuration changes all have the potential to open gaps in a previously certified environment. Ongoing monitoring is what catches this before an assessor — or a breach — does.
  5. Recertification is far less disruptive for organizations that maintained continuous evidence than for those that let it lapse. An organization with an always-current audit trail and regularly reviewed SSP can approach recertification as a review of existing evidence. An organization that let documentation go stale has to reconstruct its compliance posture from scratch under deadline pressure.

What a CMMC Assessment Actually Reviews

Whether your organization is self-assessing or undergoing a C3PAO third-party assessment, the fundamental evaluation is the same: does documented, verifiable evidence support a claim of compliance with each specific required control, not a general sense that “we take security seriously.”

The centerpiece of that evidence is your System Security Plan (SSP) — a document describing, control by control, how your organization implements each requirement. An assessor reviews this document line by line, checking it against the specific control language in NIST SP 800-171. Supporting artifacts back up what the SSP claims: configuration exports, access control policies, training records, incident response logs, and the audit trail demonstrating that logging and monitoring controls are actually operating, not just documented as a policy.

For any control not yet fully implemented, a Plan of Action and Milestones (POA&M) documents the specific gap, the remediation steps, and the timeline — an acceptable state under CMMC 2.0, provided it’s disclosed rather than discovered. An SSP that claims full implementation of a control that isn’t actually in place is a materially different and more serious problem than an honest gap with a documented remediation plan.

What a Self-Assessment Involves

Self-assessment applies at Level 1 always, and at Level 2 for contracts not requiring third-party certification. The organization reviews its own environment against the required controls, documents the results, and a senior company official formally affirms the accuracy of that assessment in the Supplier Performance Risk System (SPRS).

Self-assessment doesn’t mean lower rigor is acceptable — it means the verification burden sits with the organization rather than an external assessor, and the affirming official is personally attesting to the accuracy of what’s reported. Given the Department of Justice’s Civil Cyber-Fraud Initiative’s focus on False Claims Act cases involving misrepresented cybersecurity compliance, an inaccurate self-assessment carries real legal exposure, not just a compliance risk.

What a C3PAO Third-Party Assessment Involves

Third-party assessment applies to Level 2 programs involving the most critical national security information, and to Level 3 programs generally (though Level 3 assessment is government-led rather than conducted by a C3PAO). A C3PAO assessment is a more extensive process than self-assessment, typically involving three components.

Document review. The assessor examines your SSP and every supporting artifact — policies, configuration baselines, audit logs, training records — checking each claim against the specific control requirement it’s meant to satisfy.

Interviews. Assessors talk directly to personnel responsible for implementing and maintaining specific controls, confirming that documented processes reflect what actually happens day to day, not just what’s written down. A gap between what the SSP describes and what staff actually report doing is a common and serious finding.

Technical verification. Rather than relying solely on documentation, assessors directly examine system configurations, test access controls, and review actual audit logs to confirm technical controls are operating as described — not just configured correctly on paper at some point in the past.

The timeline for a C3PAO assessment varies with organizational complexity, but preparation — ensuring documentation is accurate and current before the assessment begins — is what determines whether the process moves smoothly or surfaces gaps that delay certification. For guidance on that preparation specifically, see our CMMC 2.0 Roadmap and CMMC 2.0 Compliance Checklist.

What Staying Compliant Requires After Certification

Certification verifies your compliance posture at a single point in time. Maintaining that posture over the following months and years requires deliberate, ongoing work — not a return to the topic only when recertification approaches.

Continuous monitoring. Controls need to keep operating, not just have operated correctly during the assessment. Ongoing vulnerability scanning, log review, and periodic internal testing catch drift before it becomes a finding at recertification — or worse, an actual security incident.

Annual affirmation. Level 2 and Level 3 certifications are valid for three years, but organizations must affirm continued compliance annually throughout that period. A missed affirmation can undermine an otherwise valid certification, and it’s a purely procedural failure that’s entirely avoidable with a documented internal calendar.

Keeping documentation current as your environment changes. A new employee, a new vendor relationship, a system reconfiguration, or a new tool adopted by a team — all of these can open compliance gaps in a previously certified environment if the SSP and access controls aren’t updated to reflect the change. Compliance drift usually isn’t dramatic; it’s the accumulation of small, undocumented changes over time.

Incident reporting readiness. DFARS 252.204-7012 requires reporting cyber incidents involving covered defense information within 72 hours. An organization’s incident response capability needs to be operational and rehearsed, not just described in a policy document that hasn’t been tested since certification.

How Kiteworks Supports Both Assessment and Ongoing Compliance

Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box, and its value extends past the assessment event itself into the continuous monitoring that sustained compliance actually requires.

A unified Data Policy Engine enforces access controls, encryption, and audit logging consistently across secure email, secure file sharing, managed file transfer, and SFTP — giving assessors, whether self-assessment or C3PAO, a single, consolidated source of evidence rather than fragments across disconnected systems. AES-256 encryption with FIPS 140-3 validated cryptographic modules addresses System and Communications Protection requirements directly.

Critically for the “staying compliant” half of this page’s focus, a single, immutable, consolidated audit trail stays continuously current across every channel — meaning the evidence supporting your annual affirmation and eventual recertification is always available, not something reconstructed under deadline pressure every time it’s needed. Kiteworks also holds FedRAMP Moderate Authorization, independently assessed and continuously monitored since June 2017 — a live demonstration of exactly the kind of sustained, ongoing compliance posture CMMC ultimately requires.

To see how Kiteworks supports your organization through assessment and beyond, schedule a custom demo.

Frequently Asked Questions

A C3PAO assessment typically involves three components: document review, where the assessor examines your System Security Plan and supporting artifacts against each required control; interviews with personnel responsible for implementing specific controls, to confirm documented processes match actual practice; and technical verification, where the assessor directly examines system configurations and audit logs rather than relying solely on documentation. The goal is confirming that documented compliance reflects actual, operating practice — not just paperwork.

In a self-assessment, the organization evaluates its own environment against required controls and a senior official formally affirms the results in SPRS — the verification burden sits internally. A C3PAO assessment involves an accredited, independent third party conducting document review, interviews, and technical verification, with certification issued based on that external evaluation. Self-assessment applies at Level 1 always and at Level 2 for many contracts; C3PAO assessment applies to Level 2 contracts involving the most critical national security information.

Level 2 and Level 3 certifications are valid for three years, but organizations must affirm continued compliance annually throughout that period — missing an annual affirmation can undermine an otherwise valid certification. Beyond the formal affirmation, maintaining compliance requires continuous monitoring of controls, keeping documentation current as the organization’s systems and personnel change, and maintaining an operational, tested incident response capability rather than a policy document that’s never been exercised.

Changes to your environment — new employees, new vendor relationships, system reconfigurations, newly adopted tools — can open compliance gaps in a previously certified environment if your System Security Plan and access controls aren’t updated to reflect them. Compliance drift is usually gradual rather than dramatic, accumulating from small, undocumented changes over time rather than a single obvious failure. Organizations that review and update their compliance documentation on an ongoing basis, rather than only at recertification, catch this drift before it becomes a finding or a security incident.

Back to Risk & Compliance Glossary

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Share
Tweet
Share
Explore Kiteworks