
CMMC Pre-Assessment Checklist: 6 Steps Before Your C3PAO Assessment
One of the most reliable predictors of CMMC Level 2 assessment outcomes is whether a contractor has conducted a structured internal walkthrough before the formal assessment begins. Not a document review. Not a gap analysis spreadsheet. An actual structured walkthrough — one that applies the same Examine, Interview, and Test methods that a C3PAO assessor will use, against the same 110 practices, and identifies the inconsistencies before someone else does.
Most contractors who generate findings in formal CMMC assessments could have identified those findings themselves in advance. The gaps that produce not-met determinations are almost never invisible. They are gaps in documentation currency, evidence coherence, staff familiarity, and scope defensibility — all of which are discoverable through internal review. The challenge is knowing how to look.
This post outlines a six-step internal walkthrough process that mirrors the assessment methodology, identifies the specific failure modes each step is designed to surface, and explains what remediation looks like when a gap is found.
Step 1: Audit Your SSP for Current-State Accuracy
The System Security Plan is the document your assessor will use as a reference point for every control in the Examine phase. If it does not accurately describe your current environment, every inconsistency between the SSP and the live system is a potential finding.
Begin by reviewing the SSP section by section — not at a high level, but control by control. For each control, ask a specific question: Is what this section describes actually in place today, in the exact configuration described? Pay particular attention to sections that were written early in the implementation process and may not have been updated as the environment evolved.
Common SSP accuracy failures include: MFA described as applied to all users when contractor administrators are still using single-factor authentication; network segmentation described as implemented when firewall rules have not been finalized; audit logging described as configured for specific event types when those event types are not yet captured in your SIEM or log management platform.
When you find a discrepancy, you have two options: update the SSP to reflect what is actually in place, or remediate the gap so that what is in place matches what the SSP describes. In either case, date-stamp the review and document what was changed and why. An assessor who sees evidence of regular SSP maintenance is looking at a document that is more credible than one with no visible review history.
Step 2: Map Evidence Artifacts to All 110 Practices
For every one of the 110 CMMC practices, you should be able to answer three specific questions before the assessment: What documentary evidence exists for this practice? Which personnel can speak to it in an interview? And how can it be demonstrated technically?
The practice-to-evidence mapping is not a theoretical exercise. It produces a specific, actionable gap list. Practices where you cannot identify documentary evidence, a capable interviewee, and a technical demonstration method are practices where you will struggle during the assessment — regardless of whether the underlying control is functioning correctly.
Build the mapping as a working document. For each of the 110 practices, list the artifact name and location, the staff member who owns the control and can speak to it, and the specific system or configuration that would be accessed during a Test activity. When you cannot fill in one or more of those columns, you have identified a preparation gap.
This step is particularly valuable for the control families that generate the most assessment findings: AC (Access Control), AU (Audit and Accountability), CM (Configuration Management), IA (Identification and Authentication), and SC (System and Communications Protection). These families typically require evidence across all three assessment methods, and gaps in any one method create findings even when the other methods produce positive evidence.
Step 3: Conduct Internal Evidence Walkthroughs Using the EIT Framework
Reviewing documents internally is not sufficient preparation for an assessment that includes live interview and test activities. You need to simulate the assessment itself — sitting staff members down and walking through what an assessor would ask, in the order an assessor would ask it.
For each control, run through the sequence. Examine: pull the relevant SSP section and policy documentation and read it aloud. Interview: ask the staff member responsible for the control to describe how it is implemented and maintained, without referring to the documentation. Test: ask them to demonstrate it — pull the logs, show the configuration, run the authentication flow while you watch.
Then compare. Does the verbal description match what the SSP says? Does the technical demonstration produce output consistent with both? Does the log history reflect ongoing operations or a recent activation?
Inconsistencies identified during internal walkthroughs are remediable before the formal assessment. Inconsistencies identified during the formal assessment are findings. The walkthrough is the mechanism that moves gaps from the assessment column to the remediation column, where you can address them on your schedule rather than the assessor's.
Pay particular attention to controls in the IA family. Under IA.L2-3.5.3, your MFA implementation needs to be demonstrable in practice — not just documented in policy. If MFA enforcement has exceptions or workarounds that staff describe differently from what the SSP states, that inconsistency needs to be resolved before the assessment, not during it.
Step 4: Validate Your Assessment Boundary Documentation
Your assessment boundary is the line between systems that are in scope for CMMC and systems that are not. That line needs to be clearly drawn in your network architecture documentation and asset inventory — and it needs to hold up under the kind of scrutiny a trained assessor applies.
Begin the boundary review by pulling your current network diagram and walking through it from the perspective of CUI flow. Where does CUI originate? What systems process it? What systems store it? What systems transmit it? Every system that touches CUI in any of those ways belongs inside the assessment boundary unless there is a documented and technically enforced reason it does not.
Then look at connectivity. What systems outside the defined boundary have network access to systems inside it? How is that access controlled? Is the segmentation documented in your network architecture? Is it enforced by firewall rules you can demonstrate during a Test activity? Is the rationale for each out-of-scope system's exclusion documented in your SSP?
Boundary documentation that cannot answer those questions clearly is boundary documentation that invites scope expansion. The assessor's default position, when a system's relationship to CUI-bearing assets is ambiguous, is to treat it as in scope. Your documentation's job is to make the boundary unambiguous before that decision is made.
If you identify systems that are currently connected to in-scope assets without adequate segmentation or documentation, you have two remediation paths: bring those systems into scope and implement controls for them, or implement and document the segmentation that justifies their exclusion. Both paths take time. Neither is available to you during the assessment. Identifying them now is the point of the exercise.
Step 5: Review Open POA&M Items and Classify by Criticality
If you have open Plans of Action and Milestones from a prior assessment, a self-assessment, or an ongoing compliance review, those open items need to be evaluated against two criteria before your formal assessment: whether they are deferrable under current CMMC guidance, and whether the control family they fall in carries zero tolerance for open findings at the time of certification.
The first criterion — deferrability — is defined by the CMMC rulemaking. Not all findings can be addressed through a POA&M. Certain practices in foundational control families must be fully implemented before a C3PAO can issue a certification recommendation. Knowing which items on your open POA&M list fall into that category is a precondition for realistic timeline planning.
The second criterion — aggregate impact — is less often discussed but equally important. Even when individual POA&M items are technically deferrable, the aggregate of deferred findings can affect the certification outcome. Review your open items not just item by item, but as a set. What does the total picture of open findings communicate about your security posture? And is that picture one that supports a certification recommendation?
Close or remediate every open POA&M item that is not clearly deferrable before the formal assessment begins. For items that are deferrable, document the remediation timeline, the resource allocation, and the rationale for the deferral in enough detail that the assessor reviewing the POA&M has a clear picture of the plan.
Step 6: Brief All Personnel Who May Be Interviewed
The final preparation step is the one most often addressed too late or too superficially. Every staff member who may be interviewed during the assessment — and that includes system administrators, security staff, IT managers, and potentially end users — needs to be familiar with the relevant sections of the SSP before the assessor sits down with them.
This is not coaching. It is not scripting. It is ensuring that the people responsible for your controls have read what the documentation says about those controls and can confirm it accurately. The goal is accuracy and consistency, not rehearsed responses. A staff member who describes a process accurately and consistently with the SSP is a staff member whose interview supports your evidence. A staff member who describes what they actually do, if what they actually do differs from what the SSP says, is a staff member whose interview generates a finding.
The briefing should be control-specific. Pull the SSP sections relevant to each staff member's responsibilities. Have them read the sections. Ask them to describe the control in their own words. Where their description diverges from the SSP, identify whether the SSP needs updating or the practice needs adjusting. Resolve the divergence before the assessment — not during the interview.
For larger organizations with multiple personnel across multiple departments, this step requires coordination. Map the 110 practices to the staff members responsible for each, and ensure each person has been briefed on the specific practices within their scope. A single unbriefed administrator describing a process differently than the SSP states can generate findings that affect controls well beyond their individual area of responsibility.
The Internal Walkthrough Is Not a Rehearsal — It Is the Real Work
Running an internal assessment walkthrough is not a rehearsal for the real assessment. It is the real work of CMMC preparation. The formal assessment conducted by a C3PAO is a verification event. The internal walkthrough is where you verify first — where you find the gaps, close them, and build the evidentiary posture that the formal assessment will confirm.
Contractors who walk into a CMMC Level 2 assessment without having conducted this kind of structured internal review are betting that their controls are documented accurately, that their staff can describe them consistently, and that their boundary is defensible — without having tested any of those assumptions. That is not preparation. It is optimism.
The six steps described here are not complex. They are time-consuming, and they require coordination across technical, operational, and documentation functions. But they are the work that separates contractors who receive a not-met finding on a control they believed was implemented from contractors who walk out of the assessment with a certification recommendation.
Download the Free Resource
The CMMC Level 2 Assessment Evidence Guide is a control family-by-control family reference that maps each of the 110 practices to the artifacts assessors commonly request across the Examine, Interview, and Test methods. If you are running your internal walkthrough and need a structured reference for what evidence each practice requires, this guide is the tool that supports that work. Download it now.
