Buyer's Checklist

Questions to Ask a C3PAO Before You Sign an Assessment Agreement

An assessment agreement is not the place for surprises. These are the questions that separate a smooth engagement from an expensive one. Bring them to your first call and use the answers to compare firms.

Last reviewed: August 6, 2026 · 5 min read

The short version

Before you sign, confirm the C3PAO is currently authorized on the Cyber AB Marketplace, get scope and fees in writing, ask who is actually on your assessment team, clarify what evidence they expect, and understand exactly what happens if you do not meet every requirement. If a firm promises a guaranteed pass or offers to both prepare and certify you, walk away.

Authorization and standing

Are you currently Authorized or Accredited, and can I confirm it on the Cyber AB Marketplace today?

Only Authorized or Accredited C3PAOs can run an official Level 2 assessment. Ask for the exact name they are listed under, then check it yourself on the Marketplace.

When was your last DIBCAC assessment and FOCI determination?

C3PAOs must complete a DIBCAC Level 2 assessment and a Foreign Ownership, Control, or Influence review, renewed every three years. A current firm will answer this without hesitation.

Scope and fees

How will you define my assessment boundary, and what will you consider in scope versus out of scope?

Scope is the single biggest driver of cost and effort. You want their scoping approach in writing before money changes hands.

What exactly is included in the fee, and what is billed separately?

Ask whether readiness reviews, travel, re-testing, and POA&M closeout are included or extra, so there are no surprises later.

The assessment team

Who will be on my assessment team, and are they Certified CMMC Assessors?

The final rule requires a team that includes Certified CMMC Assessors plus a quality-assurance reviewer. Ask for the named people, not just the firm.

Have you assessed companies like mine?

Similar size, similar CUI footprint, similar cloud stack. Relevant experience means fewer surprises and a smoother assessment.

Evidence and process

What evidence will you expect for each requirement, and in what format?

Retroactive evidence-gathering is a common cause of delay. Knowing the expectation up front lets you prepare properly.

Will the assessment be on-site, remote, or hybrid, and how long will it take?

This affects cost, scheduling, and how much of your team needs to be available.

What happens after the assessment

What happens if we do not meet every requirement?

Under the rule, an organization that meets enough of the requirements can receive a Conditional status and use a Plan of Action and Milestones (POA&M) to close remaining gaps, followed by a closeout assessment within 180 days. Confirm how they handle this and what it costs.

What is your appeals process if we disagree with a finding?

C3PAOs must maintain a documented appeals and complaints process aligned with ISO/IEC 17020. Ask how it works before you need it.

Red flags to watch for

A firm that offers to both prepare you and run your official assessment for the same engagement.

Reluctance to put scope, fees, and team in writing.

A guaranteed pass, a guaranteed score, or a promised outcome. No honest assessor can promise that.

No clear answer on current authorization status or DIBCAC history.

Why the "no guarantees" rule matters (August 6, 2026)

C3PAOs operate under independence rules and the ISO/IEC 17020 standard. That independence is the whole point of a third-party assessment, and it is why a credible firm will decline to promise a result. Getting ready properly, with help if you need it, is what improves your odds, not a vendor's assurance.

Not sure which C3PAOs to even call?

Share your scope and timeline once, and we will match you with verified C3PAOs from our directory so you can ask these questions to the right shortlist. Free, no obligation, every provider cross-checked against the Cyber AB Marketplace.

Sources

  1. 32 CFR Part 170, Section 170.17 (assessment and POA&M), eCFR
  2. CMMC Assessment Guide, Level 2, DoD CIO
  3. C3PAO Authorization Requirements (R2001), The Cyber AB
  4. C3PAO Accreditation Requirements (R2002), The Cyber AB
  5. Cyber AB Marketplace (verify a provider)

This guide is general information for defense contractors, not legal or compliance advice for your specific situation. CMMC rules and DoD contract clauses change over time. Confirm current obligations against your contract language and official DoD and Cyber AB sources before making decisions.

Keep reading