Step 1: Understand the Assessor’s Role and Chain of ResponsibilityDuring a CMMC assessment, the assessor ispart of the team organized by a C3PAO (Certified Third-Party Assessment Organization). If the assessor determines thatevidence is insufficient or inadequate, they arenot authorizedto act independently in terms of halting or postponing the assessment.
Source Reference: CMMC Assessment Process (CAP) v1.0 – Section 3.5.4 & 3.5.6
"If the Assessment Team identifies gaps in the sufficiency or adequacy of evidence, they must work with the Lead Assessor and C3PAO to determine the appropriate course of action."
The C3PAO is responsible for overseeing the assessment lifecycle.
If evidence isnot adequate, the assessor mustescalate within their organization(i.e., to the Lead Assessor or C3PAO point of contact) to:
Request clarifications from the OSC,
Determine if additional evidence can be requested,
Decide on continuing, pausing, or modifying the assessment schedule.
✅Step 2: Why Contacting the C3PAO Is the Correct Action
A. Notify the CMMC-AB✘ Incorrect. The Cyber AB (formerly CMMC-AB) isnot involved in operational aspectsof assessments. They do not manage day-to-day assessment decisions.
B. Cancel the assessment✘ Incorrect. An assessorcannot unilaterally cancelan assessment. Only theC3PAO, in consultation with all parties, may take such action.
C. Postpone the assessment✘ Incorrect. Postponements are logistical decisions that must be managed through theC3PAO, not an individual assessor.
❌Why the Other Options Are Incorrect
When an assessor determines that the evidence submitted by an OSC is inadequate or insufficient to meet a CMMC practice, thecorrect and required course of action is to consult with the C3PAO. The C3PAO will provide guidance or coordinate appropriate next steps.
Submit