CMMC Level 2 Assessment Guide
Comprehensive reference for C3PAOs conducting Level 2 assessments, including evidence expectations and scoring criteria.
Engagement Resources
Implementation and assessment guidance for CMMC and SCF stakeholders navigating the cybersecurity conformity ecosystem.

Comprehensive reference for C3PAOs conducting Level 2 assessments, including evidence expectations and scoring criteria.
Eligibility criteria, organizational prerequisites, and documentation requirements for new C3PAO applicants.
Standards for collecting, storing, and reviewing assessment evidence in accordance with CMMC program requirements.
Step-by-step guidance for organizations approaching renewal, including timelines, required artifacts, and review milestones.
Framework for defining assessment boundaries, identifying in-scope assets, and documenting scope decisions.
Guidance on creating, maintaining, and closing Plans of Action and Milestones during and after assessments.
Minimum qualifications, continuing education requirements, and conflict-of-interest rules for CMMC assessors.
Instructions for submitting and updating Supplier Performance Risk System scores following a CMMC assessment.