A Lead CCA’s Perspective on Preparing for Your CMMC Certification

By Ned Butler, Lead Certified CMMC Assessor (CCA), Redspin

If you’re an Organization Seeking Certification (OSC), you already know what’s on the line: contract eligibility, revenue, reputation, and the CUI protections that ultimately support the warfighter.

What you may not know is what the assessment actually feels like from the other side of the table.

I’ve sat on both sides of this ecosystem. Before I was an assessor, I was a cybersecurity compliance and CMMC program manager, the person whose calendar, sleep, and stress level were tied to getting an organization ready. I know what it costs to build the buy-in, the documentation, and the operational discipline this requires, because I did it myself. So, when I tell you I’m not out to fail you, I mean it. I want to see you earn a Met on every objective and walk out with a 110. At minimum, I want to see you clear the bar for a conditional certification. But I’m also thorough, because the warfighters relying on the confidentiality of CUI in your environment deserve nothing less.

Here’s what I’ve learned, from both sides, about preparing for a CMMC assessment with confidence.

Table of Contents

Write Your SSP for Someone Who’s Never Seen Your Environment

Your System Security Plan doesn’t exist for the assessor. It exists for anyone who needs to understand your information system and how your safeguards work – a new hire, an auditor, your own IT staff six months from now, and yes, me. Write it for that reader, and the assessment gets easier as a side effect. Vague, incomplete, or inconsistent documentation is what slows an assessment down and multiplies findings.

When I open an SSP, I’m looking for four things, and I’m looking for them fast:

  1. A clear, unambiguous system boundary. What’s in scope? What’s out? Where does CUI live, move, and rest? If I have to guess at the edges of your environment, we have a problem before we’ve started.
  2. A complete description of the environment of operation. This includes hardware, software, personnel, physical locations, and the conditions the system runs under.
  3. Implementation described at the NIST SP 800-171A objective level, not the control level. Each objective is what I’m actually evaluating. If your SSP only describes the parent control, you’ve left me to infer how each objective is satisfied and inference isn’t evidence.
  4. Every connection to other systems – external systems, SaaS providers, ESPs, FedRAMP-equivalent cloud services documented along with trust boundaries and inherited or shared responsibilities.

Read your own SSP as if you’d never seen your network.

If you can’t answer “where does CUI flow, and where does it stop?” from the document alone, neither can I.

And please, don’t let it turn into word salad.

Get the CUI Data Flow Diagram Right

A detailed, accurate CUI data flow diagram is one of the most valuable artifacts in your assessment package. Along with your SSP, it anchors nearly every conversation we’ll have.

Your diagram should represent every system, subsystem, user, external connection, and storage location that creates, receives, transmits, processes, or stores CUI. It should also show the direction that CUI flows between them.

If it’s generic, outdated, or inconsistent with what your team tells me during interviews? Expect long days.

If it’s precise and current? Expect the conversation to move faster.

Assign Control Ownership, and Bring the Owners to the Interviews

Every one of the 320 assessment objectives needs an owner. Not “IT owns it.”

A named person who can describe how the control works, where the evidence lives, and what they personally do day to day to keep it operating. Organizations that skip this step consistently struggle in interviews.

Plan for those owners to sit in on the interviews themselves. Nothing weakens an assessment faster than one proxy trying to speak for 14 domains, 110 requirements, and 320 objectives they don’t personally run. Nothing strengthens it faster than the actual administrator explaining, in their own words, how they configure, monitor, and respond.

Run a Real Risk Assessment and a Real Internal Security Assessment

Two requirements get chronically underestimated: 3.11.1 (Risk Assessment) and 3.12.1 (Security Assessment). Done right, neither is a check-the-box exercise. They’re the substance of how a mature program governs itself.

  1. Risk assessment (3.11.1): This should be a documented, defensible analysis of the risks to your operations, assets, and people from operating systems that process CUI.

Run it at your defined frequency, no less than annually.

  1. Internal security assessment (3.12.1): This is a self-assessment against every control and objective in NIST SP 800-171A. It’s the work that surfaces your real gaps before I do.

The same frequency rule applies.

Treat these as two paragraphs and a spreadsheet, and the assessment will show it. Treat them as genuine internal due diligence, and you’ll walk in having already remediated issues that could otherwise become findings.

Run a Mock Assessment

Once your internal security assessment is done, bring in an RPO or C3PAO for a full mock assessment. A well-run mock does two things a self-assessment can’t:

  1. Third-party validation against the actual assessment methodology, not just the control language.
  2. Preparation for what an assessment actually feels like: the cadence of interviews, how questions get asked, the artifacts requested on the spot, the follow-up probes when an answer is incomplete.

Then remediate.

Findings from your internal assessment and your mock should be closed before the certification assessment starts, not logged as “in progress.”

Mind the 90-Day Window on Evidence

Artifacts you submit – screenshots, configuration exports, log samples, ticket records – should generally be within 90 days of the assessment. Stale evidence raises a legitimate question: is this control still operating? The exception is anything tied to a defined frequency. A risk assessment or security assessment report just needs to be current relative to your own policy’s cadence.

Annual policy and a ten-month-old report? Fine.

Quarterly policy, eight-month-old report? That’s a finding.

In the Final Weeks: Practice, Then Rest

If you have time before the assessment, run short practice sessions.

Pull a control owner aside for fifteen minutes and have them walk you through how their control works and where the evidence lives, in plain language. It keeps everyone sharp without burning them out.

Then, the week of, do something that might sound out of place in an article like this: make sure your team rests. A CMMC assessment is thorough and genuinely tiring, and interviews are stressful even when they go well. A well-rested control owner who answers clearly beats an exhausted one who second-guesses every word.

During the Assessment: Be Calm. Be Honest. Be Yourself.

There are two things worth internalizing before we start:

This is a conformance assessment, not an audit. I’m not trying to trick you or lay traps. I’m working through objectives, asking questions, examining evidence, and recording findings. A follow-up question almost always means I need to understand something more precisely, not that I’m trying to corner you.

Be honest, always. If you don’t know an answer, say so and let the right person answer. If a control isn’t implemented the way your SSP describes, tell me. Mislead an assessor successfully, and you’ve traded a finding today for potential False Claims Act liability later – a far worse outcome. Get caught misrepresenting something during the assessment, which is the far more likely scenario, and it makes for a genuinely uncomfortable day. In some cases, it halts the assessment outright.

What I Want for You

I suspect most Lead CCAs and CCAs would say the same: I’m not out to fail you. I’ve stood where you’re standing, and I know exactly what’s riding on this. I’ll keep the atmosphere calm and the process moving, and I’ll give you every real opportunity to put your best foot forward.

We want you to succeed.

But I’m thorough. If a requirement isn’t met, you’ll get a Not Met for it. That’s not personal, and it’s not adversarial. It’s the job, and the integrity of that job is the entire reason a CMMC certificate means anything.

Prepare like a professional. Bring your real environment, your real people, and your real evidence. Rest beforehand. Be honest throughout. Then let the assessment do what it’s built to do: give you, your clients, and the U.S. Department of War confidence that the CUI entrusted to your organization is genuinely protected.

That’s the assessment I want to conduct with you. That’s the certification worth earning.

How Redspin Can Help

Preparing for a CMMC assessment isn’t just about getting your documentation in order. It’s about making sure your documentation, people, processes, technology, and evidence all tell the same story about how CUI is actually protected.

Redspin has sat across the assessment table from organizations throughout the DIB. We know what strong preparation looks like, where organizations tend to struggle, and how quickly small inconsistencies can turn into long assessment days.

Whether you’re trying to understand how close you are, identify gaps before an assessment, prepare your control owners, or get ready for certification, Redspin can help you walk into the assessment room knowing what to expect.

Walk Into Your CMMC Assessment Ready

Don’t wait until the assessment starts to find out whether your SSP, evidence, and team are ready to stand up to scrutiny.

Prepare the environment. Prepare the evidence. Prepare your people. Then let them show the work they’ve already been doing.

Stay up to date on the latest CMMC news.

More from our NIST SP 800-171 Rev. 2 to Rev. 3 Transition Series:
Where Does Your CUI Actually Go? Why Rev. 3 Wants You to Keep a Register
Where Does Your CUI Actually Go? Why Rev. 3 Wants You to Keep a Register
No results found.