# CMMC Assessment Process (CAP) | Secureframe

> How the CAP structures CMMC assessments: pre-assessment scoping, the examine/interview/test method, MET/NOT MET scoring, and post-assessment Cyber AB quality review.

canonical: https://secureframe.com/glossary/cmmc-assessment-process

The CMMC Assessment Process (CAP) is the procedural document C3PAOs follow when conducting an official CMMC assessment. Published by the Cyber AB and reviewed by the CMMC PMO, it defines the phases, evidence expectations, scoring rules, and reporting requirements. If you want to know what a C3PAO is actually doing during your assessment, the CAP is the answer.

### Why a Standardized Process Matters

Two different C3PAOs assessing the same organization should produce the same result. The CAP is the instrument that makes this possible. It covers everything from conflict-of-interest rules to how to score a practice as MET vs NOT MET, with minimal room for interpretation.

### Pre-Assessment Phase

- **Scope definition:** The OSC and lead assessor agree on the CMMC Assessment Boundary (systems, networks, locations that process, store, or transmit CUI).
- **Document review:** SSP, POA&M, network diagrams, data flow diagrams, policies referenced in the SSP.
- **Logistics:** Schedule, who the assessors will interview, how evidence is shared, any required non-disclosure terms.

### Assessment Phase

Assessors score each of the 110 NIST SP 800-171 practices using three methods: examine (artifacts and documents), interview (people who perform the work), and test (actually exercise the control). Each practice scores MET, NOT MET, or NOT APPLICABLE. Partial credit does not exist at the practice level.

### Post-Assessment Phase

The lead assessor writes the assessment report. The C3PAO's Quality Assurance reviewer checks it. The report goes to the Cyber AB for a final quality review. If everything checks out, the Cyber AB issues the certification. Certifications are valid for three years, with an annual affirmation in SPRS.

### CAP vs DoD Assessment Methodology

CAP governs third-party CMMC assessments by C3PAOs. The DoD Assessment Methodology is the scoring framework DIBCAC (and contractors doing self-assessments) use under DFARS 252.204-7019/7020. They assess the same 110 practices but the scoring and procedural rules differ. CAP produces a pass/fail certification. DoDAM produces a numerical score from -203 to 110.

### How to Prepare

- **Do a mock asses**sment before the real one. An RPO can run this. You want to find gaps before the C3PAO does.
- **Match evidence to practices. C**reate one folder per NIST 800-171 requirement with the artifacts that prove implementation.
- **Brief the people who will b**e interviewed. They should describe the control from memory, not read a prepared statement.
- **Close or progress every POA&M item with a credible time**line. Open items without a plan are a concern.
