Most guides to CMMC readiness assessments blur them together with the self-assessment, the mock assessment, and the C3PAO assessment as if they are one thing. They are not. Confusing them is one of the fastest ways to walk into an assessment with the wrong expectations.
A readiness assessment is preparation. The self-assessment, mock testing, and, when required, third-party certification all depend on how honestly that preparation was done.
A CMMC readiness assessment evaluates your current security requirements, documentation, scope, and evidence against the CMMC Level your contracts require before results are formally reported or, when applicable, a C3PAO assessment begins. It is not itself a formal CMMC assessment status. A useful readiness assessment should produce a prioritized gap list, an estimated Level 2 assessment score, and a remediation roadmap, not just a report describing where you stand today.
In July 2026, the Department suspended the planned CMMC Phase II requirements and pending or future implementation milestones while it reviews the program. Phase I self-assessment requirements remain in place. During the interim period, the Department is enforcing NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments, while DFARS 252.204-7012 safeguarding obligations remain in effect. The CMMC regulations still define Level 2 (Self) and Level 2 (C3PAO) statuses, so contractors should follow the requirements in their current solicitations and contracts together with the latest Department guidance.
Source: Department announcement, July 13, 2026; 32 CFR Part 170; DFARS 252.204-7025.
Readiness Assessment, Self-Assessment, Mock Assessment, and C3PAO Assessment
These terms often get used interchangeably, and that is where a lot of confusion starts. The important distinction is whether the activity is preparatory or is a formal CMMC assessment required by the solicitation or contract.
| Term | What It Is | Who Performs It |
|---|---|---|
| Readiness Assessment | A preparatory review that identifies gaps in security requirements, documentation, scope, and evidence before formal results are reported. | Internal team, consultant, or a partner with direct assessment experience. |
| Self-Assessment | A formal scored evaluation the organization performs on itself. When required, the results and affirmation are entered in SPRS. | The organization itself, using its own internal team. |
| Mock Assessment | A dress rehearsal that simulates an assessment experience, including evidence review, interviews, testing, and scoring, to surface what may still require remediation. | Internal team or a third party familiar with the assessment process. |
| C3PAO Assessment | An independent Level 2 certification assessment performed when the applicable requirement is CMMC Level 2 (C3PAO). | An authorized or accredited Certified Third-Party Assessment Organization. |
A readiness assessment should take place before the formal assessment that applies to the opportunity. It does not replace a Level 2 self-assessment, a mock assessment, or a C3PAO assessment when those activities are required or appropriate, it gives you time to find and fix gaps before they become assessment findings.
What a CMMC Readiness Assessment Evaluates
A readiness assessment looks at whether the security requirements applicable to your CMMC Level are implemented, documented, and supported by sufficient evidence, not just whether a policy exists describing them. For Level 2, that includes scope and boundary definition, implementation of the 110 NIST SP 800-171 Rev. 2 security requirements, the System Security Plan, any permissible Plan of Action and Milestones, and the current assessment score that will ultimately be reported through the applicable CMMC process.
For a full breakdown of CMMC Level 2 requirements and NIST SP 800-171, Sentinel Blue's CMMC Readiness Services page covers that background alongside how Sentinel Blue approaches this work directly.
What Current DIB Readiness Research Shows
Independent research on defense industrial base readiness gives a clear picture of where most organizations stand as CMMC enforcement moves from policy into practice.
Source: State of the DIB Report, based on independent research by Merrill Research, as reported by Cybersecurity Dive and its follow-up reporting.
The practical takeaway is that readiness takes time, and organizations that start with a stronger NIST SP 800-171 foundation and pressure-test their evidence before a formal assessment are less likely to discover major gaps late in the process. The July 2026 Phase II suspension changes the implementation timeline, but it does not remove the underlying NIST SP 800-171 Rev. 2 safeguarding obligations.
How to Know You Are Ready
Security Requirements Are Implemented and Evidenced, Not Just Documented
A policy stating that access is reviewed quarterly means little without evidence showing the review happens. Evidence should be current, traceable to the requirement or assessment objective it supports, and sufficient to demonstrate that the practice is operating as described.
Your SSP and POA&M Reflect the Environment as It Is Today
An SSP written a year ago may describe systems, users, and workflows that have since changed. Documentation should be a living record, not a one-time deliverable that quietly falls out of date.
Your SPRS Score Has Been Recalculated Recently
A score based on last year's environment may not reflect today's implementation. Recalculate the Level 2 assessment score against the current environment and make sure the SSP, evidence, and any allowable POA&M items support the result you expect to report.
Any Remaining POA&M Items Are Permitted
CMMC does not allow every unmet Level 2 requirement to be placed on a POA&M. Conditional Level 2 status requires the applicable 80% score threshold, restricts which requirements may remain open, and requires successful POA&M closeout within 180 days. A readiness review should identify gaps that must be closed before assessment rather than assuming every deficiency can be deferred.
Your People Can Speak to Their Own Controls
Formal CMMC assessments can include interviews as well as examination and testing. If a control owner cannot explain how a requirement is implemented in day-to-day operations, or the explanation conflicts with the SSP and evidence, that is a readiness gap.
You Have Pressure-Tested Readiness with a Real Mock Assessment
A mock assessment is not a regulatory prerequisite, but it is a strong readiness practice when preparing for an independent assessment. It should simulate the experience as closely as practical, including evidence review, interviews, testing, and scoring. Sentinel Blue's post on best practices for CMMC assessment preparation goes deeper on what that should look like once readiness confirms you are close.
What a Readiness Assessment Should Produce
There is no formal CMMC artifact called a readiness assessment report, so the value comes from what the review gives you next. At Sentinel Blue, we consider a readiness assessment most useful when it produces a prioritized list of gaps ranked by risk and effort, an estimated Level 2 assessment score based on current implementation, and a remediation roadmap with owners and realistic timelines. The goal is a path through the gaps, not just a description of them.
Common Reasons Organizations Think They Are Ready and Are Not
- Documentation exists, but no one can produce sufficient evidence that the security requirement is operating
- The SSP describes an environment that has since changed through migrations, new vendors, or org changes
- The Level 2 assessment score was calculated once and never revisited as the environment changed
- Employees know policies exist but cannot describe how they apply to their own work
- No realistic mock assessment was performed before a C3PAO assessment, when one is required, so the first independent test of the evidence happens during the formal assessment
- Scope was defined loosely, leaving systems or CUI workflows outside the original assessment boundary
Readiness Timeline and Cost Expectations
There is no universal CMMC readiness timeline or price. The diagnostic review itself may take weeks, while remediation can take months or longer depending on scope, technical debt, documentation quality, staffing, and the number of systems and suppliers involved. Independent research on DIB readiness has consistently found that most organizations underestimate how long full compliance takes, and that self-reported readiness often outpaces what a validated assessment would show. Cost varies just as widely because most of the expense is driven by the remediation and operating changes required to meet the security requirements, not by the readiness review alone.
Steps to Take Before Your CMMC Assessor Arrives
Once a readiness assessment confirms you are close and an independent assessment is required, Sentinel Blue's field guide on steps to take before your CMMC assessor arrives covers the final stretch before assessment day in practical detail.
Navy Contractor Achieves CMMC Level 2
Sentinel Blue's Navy contractor case study shows how readiness work translated into a successful certification outcome for one organization.
For organizations that hold a certification, passing is not the finish line. CMMC also requires ongoing affirmation, and the environment keeps changing after assessment day. Sentinel Blue's post on managed CMMC compliance covers what it takes to keep the program operating after the initial assessment work is complete.
Frequently Asked Questions
What is a CMMC readiness assessment?
Is a readiness assessment the same as a self-assessment?
How is a readiness assessment different from a C3PAO assessment?
How long does a CMMC readiness assessment take?
What does a readiness assessment produce?
What is an SPRS score and why does it matter for readiness?
Can software alone tell an organization if it is ready?
What is the most common reason organizations think they are ready and are not?
Should a readiness assessment include a mock assessment?
What does the July 2026 CMMC Phase II suspension mean for readiness?
Who should conduct a CMMC readiness assessment?
Find out where you stand before an assessment exposes the gaps
Sentinel Blue helps you find Level 2 gaps before they become assessment findings.