CMMC Assessment Types: Level 1, 2 & 3 Explained

A CMMC assessment doesn't begin when the assessors arrive. It begins months earlier, with the evidence your organization creates, the cybersecurity practices it follows every day, and the decisions made long before certification is scheduled.
Many organizations focus heavily on implementing security controls, but far fewer understand that the assessment itself can take different forms. Depending on the contract and the sensitivity of the information being protected, your organization may complete a self-assessment, undergo an independent third-party certification assessment, or be evaluated directly by the U.S. Government.
Knowing which CMMC assessment type applies is essential because each follows a different evaluation process and requires a different level of preparation.
In this article, we'll explain the different CMMC Assessment Types, how they relate to the various CMMC assessment levels, and what organizations should expect throughout the certification journey.
What Is a CMMC Assessment?
A CMMC assessment is a formal evaluation that determines whether an organization has implemented the cybersecurity practices required under the Cybersecurity Maturity Model Certification (CMMC) Program. Its primary objective is to verify that defense contractors can adequately safeguard sensitive information used throughout the Department of Defense supply chain.
Moroever, a CMMC assessment evaluates whether security controls are implemented, operating as intended, and producing the expected cybersecurity outcomes. Assessors review objective evidence, interview personnel, examine technical configurations, and observe processes to determine whether an organization consistently meets the applicable requirements. The type of information an organization handles largely determines the applicable CMMC assessment levels and the assessment approach required by the Department of Defense.
The assessment also plays an important role in protecting two key categories of information:
- Federal Contract Information (FCI): Information provided by or generated for the Federal Government under a contract that is not intended for public release.
- Controlled Unclassified Information (CUI): Sensitive government information that requires safeguarding but is not classified.
Understanding the Different CMMC Assessment Types
One of the most common misconceptions about CMMC is that every organization follows the same certification process. As a matter of fact, there are multiple CMMC assessment categories, and the required assessment depends on several factors, including the CMMC level specified in the contract, the sensitivity of the information being protected, and the assessment requirements identified in the solicitation.
Organizations may encounter one of the following types of CMMC assessments:
CMMC Level 1 Self-Assessment
The CMMC Level 1 self-assessment is the simplest assessment type within the CMMC Program. It is intended for organizations that handle Federal Contract Information (FCI) but are not required to protect Controlled Unclassified Information (CUI).
Unlike independent certification assessments, organizations perform the evaluation internally by assessing their own implementation of the applicable Level 1 security requirements. Once completed, a senior company official must affirm that the assessment accurately reflects the organization's cybersecurity posture, and the results are submitted through the Supplier Performance Risk System (SPRS). Although this assessment is self-performed, it should not be viewed as a simple checklist exercise.
Organizations are expected to maintain objective evidence demonstrating that required cybersecurity practices have been implemented and are functioning effectively. During internal reviews, organizations should be able to demonstrate documented policies, system inventories, defined assessment boundaries, and evidence supporting the implementation of the required safeguarding practices.
One common mistake is assuming that a self-assessment requires less preparation than an independent assessment. But the official affirmation submitted to the Department of Defense represents a formal declaration that the organization meets the required Level 1 practices. Maintaining accurate records and objective evidence is therefore just as important as implementing the controls themselves.
CMMC Level 2 Assessments
Organizations handling Controlled Unclassified Information (CUI) typically fall under CMMC Level 2 assessment requirements. However, one important aspect of CMMC 2.0 is that not every Level 2 organization follows the same assessment path. Depending on the specific contract requirements, a Level 2 organization may complete either a self-assessment or an independent third-party certification assessment. Understanding this distinction is essential when comparing CMMC self-assessment vs third-party assessment, as the preparation, level of scrutiny, and certification outcomes differ significantly.
Level 2 Self-Assessment
Some contracts permit organizations to perform a Level 2 self-assessment instead of undergoing an independent certification assessment. In these cases, organizations evaluate themselves against the applicable security requirements from NIST SP 800-171, submit the assessment results to SPRS, and complete an annual affirmation confirming continued compliance.
Although the assessment is performed internally, organizations are still expected to maintain comprehensive evidence demonstrating that required controls have been implemented effectively. Policies, procedures, technical configurations, system security documentation, and supporting records should all be readily available to substantiate the assessment results.
Organizations should also recognize that self-assessment does not reduce the importance of maintaining a mature cybersecurity program. As regulatory expectations evolve, organizations that establish robust documentation and continuous monitoring practices are generally better prepared for future contractual or regulatory requirements.
Level 2 Certification Assessment
For many organizations handling Controlled Unclassified Information, a CMMC Level 2 certification assessment is mandatory. Unlike a self-assessment, this evaluation is performed by an authorized Certified Third-Party Assessment Organization (C3PAO) accredited within the CMMC ecosystem.
This independent assessment provides a higher level of assurance by verifying that an organization's security controls are fully implemented and operating effectively. Rather than relying solely on documentation, assessors validate evidence through interviews, technical reviews, system observations, and sampling of implemented controls. During a CMMC Level 2 assessment, assessors review the SSP, supporting policies, security controls, personnel practices, and evidence of consistent control implementation.
One of the most valuable lessons organizations learn during third-party assessments is that compliance is demonstrated through evidence. Well-written documentation is important, but it must accurately reflect day-to-day operations and be supported by technical and procedural evidence.
Organizations preparing for a third-party assessment often benefit from organizing documentation, validating assessment scope, and ensuring that system owners understand how security controls are implemented long before assessors arrive. Successful assessments are rarely the result of last-minute preparation; they are the outcome of consistent cybersecurity governance maintained throughout the year.
CMMC Level 3 Government Assessment
The highest of the CMMC assessment levels is Level 3, which is designed for organizations supporting the Department of Defense's most sensitive programs involving high-priority Controlled Unclassified Information (CUI).
Unlike the other types of CMMC assessments, a Level 3 assessment is performed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) rather than a Certified Third-Party Assessment Organization (C3PAO). Before an organization can pursue a Level 3 assessment, it must first achieve a valid CMMC Level 2 certification assessment.
Level 3 builds upon the security requirements of Level 2 by introducing additional cybersecurity practices that strengthen protection against advanced persistent threats (APTs). These enhanced requirements focus on improving the organization's ability to detect sophisticated attacks, respond effectively to emerging threats, and maintain resilience against highly capable adversaries.
Government assessors evaluate not only whether the additional controls have been implemented but also whether they are consistently operating as intended. This often involves reviewing technical evidence, interviewing personnel, validating system configurations, and confirming that security practices are embedded within daily operations.
Demonstrate compliance with CMMC Requirements through independent certification from INTERCERT and reinforce trust with government agencies and defense partners.
What Happens During a CMMC Assessment?
Regardless of the assessment type, the overall process follows a structured approach designed to verify that cybersecurity controls have been implemented effectively.
Assessment Planning
The assessment begins by confirming the assessment scope, identifying the systems involved, and determining which CMMC requirements apply. Clearly defining the assessment boundary at this stage helps prevent delays later in the process.
Documentation Review
Assessors examine key documents such as the System Security Plan (SSP), policies, procedures, asset inventories, and supporting records. These documents provide the foundation for understanding how the organization's cybersecurity program is designed.
Interviews
Personnel responsible for implementing and managing security controls are interviewed to verify that documented procedures are consistently followed in practice. This step allows assessors to understand how security responsibilities are carried out across the organization.
Technical Validation
Documentation alone is not enough. Assessors review technical configurations, observe implemented security controls, and examine system settings to confirm that cybersecurity practices are functioning as described.
Evidence Review
Objective evidence is one of the most important aspects of any CMMC assessment. Organizations should be prepared to present configuration records, system logs, training records, access reviews, change management records, and other evidence demonstrating that controls operate effectively over time.
Assessment Findings
After completing the evaluation, assessors document their findings, identify any deficiencies, and determine whether the organization satisfies the applicable CMMC requirements.
The most successful organizations view this process as an opportunity to validate the effectiveness of their cybersecurity program rather than simply obtaining a certification.
Common Mistakes Organizations Make Before an Assessment
Preparing for a CMMC assessment involves far more than organizing documentation a few weeks before assessors arrive. Several recurring mistakes often make the assessment process more difficult than necessary.
Underestimating Evidence Requirements
Many organizations invest significant effort in writing policies but fail to maintain objective evidence demonstrating that controls are consistently implemented. Evidence such as system logs, configuration records, access reviews, and training records often carries just as much weight as documented procedures.
Defining the Wrong Assessment Scope
An inaccurate assessment boundary can create unnecessary complexity or leave critical systems outside the assessment scope. Clearly identifying assets, users, and environments early in the preparation process reduces confusion during the assessment.
Incomplete System Security Plans
The System Security Plan is one of the most heavily reviewed documents during a Level 2 assessment. Generic or outdated SSPs rarely reflect actual operating environments and often create additional questions during the assessment.
Treating Compliance as a Documentation Exercise
CMMC evaluates implemented cybersecurity practices. Organizations that focus exclusively on documentation while neglecting operational effectiveness often struggle to demonstrate compliance during interviews and technical validation.
Waiting Until the Assessment Begins
Cybersecurity maturity cannot be developed overnight. Organizations that maintain documentation, monitor security controls, and collect evidence continuously are typically far better prepared than those attempting to organize everything immediately before the assessment.
Best Practices for Preparing for Any CMMC Assessment
Regardless of the applicable assessment type, organizations can significantly improve their readiness by adopting a proactive approach to cybersecurity governance.
Define the Assessment Scope Early
Clearly identify systems, users, assets, and information that fall within the assessment boundary. Accurate scoping reduces unnecessary complexity and ensures that all applicable requirements are addressed.
Maintain Accurate Documentation
Policies, procedures, the System Security Plan, and supporting records should accurately reflect current business operations rather than serving as static compliance documents.
Organize Objective Evidence
Objective evidence should be collected continuously instead of assembled shortly before the assessment. Well-organized evidence enables assessors to efficiently validate implemented controls and reduces delays during the assessment.
Review Security Controls Regularly
Periodic internal reviews help confirm that controls continue operating effectively as technologies, business processes, and organizational risks evolve.
Involve Multiple Business Functions
Cybersecurity is not solely the responsibility of IT teams. Human resources, procurement, operations, legal, and executive leadership all contribute to maintaining compliance with CMMC requirements. Cross-functional participation strengthens both security and governance.
Build Continuous Compliance
Organizations that treat CMMC as an ongoing cybersecurity program rather than a one-time certification project are better positioned to adapt to future regulatory changes, contract requirements, and evolving cyber threats.
Achieve CMMC Certification through INTERCERT's accredited certification process and showcase your organization's commitment to protecting Controlled Unclassified Information (CUI).
The Path to Successful CMMC Assessment and Certification
Understanding the different CMMC Assessment Types is essential for organizations participating in the Department of Defense supply chain. While many organizations focus primarily on achieving the appropriate CMMC assessment levels, selecting and preparing for the correct assessment path is equally important.
Whether your organization completes a CMMC Level 1 self-assessment, undergoes a CMMC Level 2 assessment, or pursues an independent CMMC Level 2 certification assessment, each evaluation is designed to verify that cybersecurity controls are implemented effectively and consistently protect sensitive government information.
The key difference in the CMMC self-assessment vs third-party assessment approach lies not only in who performs the assessment but also in the level of independent validation required. Organizations that maintain evidence and integrate cybersecurity into daily operations are better positioned to meet DoD expectations and strengthen resilience.
As an independent certification body, INTERCERT works with organizations seeking certification against internationally recognized standards and cybersecurity frameworks. A structured approach to governance, documented processes, and continual improvement enables organizations to demonstrate their commitment to protecting sensitive information while building confidence among customers, partners, and stakeholders.