A photorealistic flat-lay image of three labeled document folders arranged in a row on a clean desk — each folder labeled with a tab reading "EXAMINE," "INTERVIEW," and "TEST." A government-style seal is partially visible beneath the folders. Soft overhead lighting, navy and warm cream tones. No people. Clean, editorial photography style.

What CMMC Assessors Look For: Examine, Interview, and Test Explained

July 06, 20268 min read

Defense contractors preparing for CMMC Level 2 certification often focus their preparation on whether controls are implemented. That question matters, but it is not the right starting point. The more important question is whether a trained assessor from a licensed C3PAO — a CMMC Third Party Assessment Organization — will be able to confirm that those controls are implemented using the methods and evidence standards the assessment defines.

Those are different questions. A control with no evidence is a finding. A policy that exists in documentation but is not followed in practice is a finding. A configuration that works correctly in production but cannot be demonstrated during the assessment is a finding. Understanding that distinction — between implementing controls and proving them — is the foundation of any serious CMMC preparation effort.

This post explains how a CMMC Level 2 assessment actually works, what assessors are evaluating when they review your environment, and why the assessment method itself is the thing most contractors fail to prepare for.


The Certification Stakes Are Binary

CMMC Level 2 certification is required to handle controlled unclassified information (CUI) under most DoD contracts invoking DFARS 252.204-7012. The assessment is conducted by a licensed C3PAO and evaluated against 110 practices derived from NIST Special Publication 800-171.

The stakes are straightforward: if your assessment results in findings that cannot be closed, you do not receive CMMC Level 2 certification. Without that certification, you cannot perform or compete for contracts requiring it. This is not a risk management calculation or a compliance gap to manage over time. It is a contract eligibility determination.

What many contractors underestimate is the margin for error. A single unresolved finding in a critical control can block certification even when 109 other practices are fully implemented. Your SPRS score — your Supplier Performance Risk System score — reflects where you stand numerically, but the certification decision itself is binary. You either receive it or you do not.

That reality reshapes what preparation means. The question is not whether you have implemented the controls. The question is whether you can prove it to a trained assessor using methods they will accept, within the time frame of the assessment. That distinction is where most contractors get into serious trouble.


How the Assessment Actually Works: The Three Methods

The CMMC Assessment Process — known as the CAP — defines three assessment methods: Examine, Interview, and Test. Every one of the 110 practices is assessed through one or more of these methods. Understanding what each method involves and what assessors are looking for within each one is not optional preparation. It is the foundation of readiness.

Examine means the assessor reviews documentation. This includes your System Security Plan (SSP), policies, procedures, configuration baselines, network diagrams, asset inventories, audit logs, training records, and any other artifacts relevant to the practice being evaluated. The assessor is asking three questions when reviewing each document: Does this documentation exist? Is it current? And does it accurately reflect what is actually in place in your environment right now?

That last question is where the Examine method generates the most findings. It is extremely common for contractors to build an SSP to plan their implementation, begin assessment without updating it to reflect what was actually deployed, and then watch an assessor identify the inconsistency between the SSP and the live environment. That inconsistency is a finding — even if the technical implementation is correct. Your SSP must describe current state, not planned state.

Interview means the assessor speaks with personnel. This includes system administrators, security staff, and sometimes end users. The interview is not an interrogation, and assessors are not trying to catch staff making mistakes. They are verifying that the people responsible for implementing and maintaining controls understand what they are doing and why. Inconsistency between what your documentation says and what your staff describes is a significant red flag — not just for the control being discussed, but for the reliability of your evidence overall.

This is a failure mode that appears repeatedly in assessments: policies written by a consultant or external advisor, implemented by a technical team that was never fully briefed on what the policy says, and then described differently by staff during interviews because they are recounting what they actually do rather than what the policy states. When those two accounts diverge, the assessor treats it as a reliability signal that affects how they evaluate every subsequent piece of evidence.

Test means the assessor observes or interacts with the system directly. This can include reviewing firewall rule sets, observing multifactor authentication in practice, pulling audit log samples, inspecting configuration settings on endpoints or servers, or reviewing access control lists. Test activities confirm that controls are not just documented and described — they are operational.

The Test method is also where the timing of your evidence preparation becomes visible. Assessors can tell when audit logs were activated the week before the assessment. They can tell when configuration baselines were written but never enforced. They will ask questions like: When was this policy last reviewed? Who approved this configuration change? Show me a recent log sample. If your evidence only exists for the assessment, it will not hold up under the combined scrutiny of Interview and Test.


How Findings Are Generated

For each of the 110 practices, the assessor determines one of two outcomes: met or not met. A practice is met when the evidence across Examine, Interview, and Test is sufficient and consistent. A practice is not met when evidence is missing, contradictory, or does not demonstrate that the requirement is fully implemented.

Not-met findings are documented in the assessment report. Some findings may be eligible for a Plan of Action and Milestones — a POA&M — depending on their nature and current CMMC rulemaking guidance. But not all findings can be deferred. Practices in certain control families may require immediate remediation before certification is granted.

This is a point that contractors frequently misunderstand. A POA&M documents a planned remediation for a finding. It does not eliminate the finding. Contractors who overrely on POA&Ms as a mechanism to defer remediation work often discover, late in the assessment process, that certain findings are not deferrable under current guidance — or that the aggregate of deferred findings prevents certification from being granted.

Knowing which controls carry zero tolerance for open findings before the assessment begins is a requirement, not a best practice.


The Control Families That Generate the Most Findings

Assessors do not walk into an assessment treating all 110 practices equally. Certain control families receive more intense scrutiny because they require both technical implementation and operational evidence — and because gaps in these families tend to cascade into findings across multiple related practices.

The families most commonly associated with assessment findings include Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), and System and Communications Protection (SC).

Consider how these interact in practice. Under IA, you may have an MFA policy fully documented. But your AU logs need to show authentication events. Your IA configurations need to enforce MFA consistently across all covered users and systems. And your staff need to be able to describe, accurately and consistently, how exceptions are handled and what the escalation path looks like when authentication fails. The assessor is building a coherent picture across all three methods. If one method produces an inconsistency, it calls the others into question.


Scope: The Boundary That Protects or Exposes You

One of the most consequential decisions in CMMC preparation is where you draw the assessment boundary — and how you document it. Contractors sometimes believe that if a system is not in scope for CMMC, they do not need to demonstrate its controls. But if that out-of-scope system has network connectivity to CUI-bearing systems and is not properly isolated and documented, the assessor may expand scope.

Your network architecture documentation and your asset inventory need to clearly define the assessment boundary. That boundary needs to be defensible — meaning it needs to hold up under examination of actual network flows, actual system configurations, and actual CUI handling practices. Boundary ambiguity does not stay ambiguous. It gets resolved by the assessor, and the resolution typically expands your scope and your exposure.


What the Assessment Is — and Is Not

The CMMC assessment is a structured verification process. It is not a paperwork audit, and it is not a penetration test. Assessors are not looking for perfection. They are looking for evidence that your controls are real, operational, and consistently maintained across your environment.

The distinction matters for how you prepare. Preparation that focuses only on documentation without ensuring operational consistency will fail the Test method. Preparation that focuses only on technical implementation without ensuring SSP accuracy will fail the Examine method. Preparation that does not include briefing staff on what is implemented and why will fail the Interview method.

Readiness means being able to demonstrate — through documents, through conversations, and through live system evidence — that your controls exist and function as described. That is the standard the assessment holds you to. Preparing to that standard, rather than to a general sense of being compliant, is what separates contractors who pass from contractors who generate findings.


Download the Free Resource

The CMMC Level 2 Assessment Evidence Guide is a control family-by-control family reference that maps each of the 110 practices to the artifacts assessors commonly request across the Examine, Interview, and Test methods. If you are preparing for a formal C3PAO assessment and need a clear picture of what evidence is expected for each practice, this guide provides that reference. Download it now.

Back to Blog