Nexeris

Who Can Conduct a CMMC Level 3 Assessment?

Organizations preparing for CMMC Level 3 need to understand an important distinction before planning their assessment: the organization that prepares them for Level 3 is not necessarily authorized to assess them.

Unlike Level 2 certification assessments, which are performed by authorized C3PAOs, Level 3 uses a government-led assessment model. That difference affects who contractors work with, what they must complete first, how the assessment is requested, and who ultimately determines their CMMC Level 3 status.

In This Guide

  1. 01
    Who Can Conduct a CMMC Level 3 Assessment?
  2. 02
    Who Is DCMA DIBCAC?
  3. 03
    Why Are CMMC Level 3 Assessments Government-Led?
  4. 04
    Can a C3PAO Conduct a CMMC Level 3 Assessment?
  5. 05
    C3PAO vs. DIBCAC: Who Assesses Each CMMC Level?
  6. 06
    What Is the Current Status of Level 3 Assessments in 2026?
  7. 07
    Who Needs a CMMC Level 3 Assessment?
  8. 08
    What Must You Complete Before DIBCAC Can Assess You?
  9. 09
    How Do You Request a CMMC Level 3 Assessment?
  10. 10
    What Does DIBCAC Assess at CMMC Level 3?
  11. 11
    How Does DIBCAC Conduct a Level 3 Assessment?
  12. 12
    Who Decides Whether You Pass a CMMC Level 3 Assessment?
  13. 13
    How Long Is a DIBCAC Level 3 Assessment Valid?
  14. 14
    Can a Consultant Prepare You for a Level 3 Assessment?
  15. 15
    How to Prepare for a DIBCAC Level 3 Assessment
  16. 16
    How Nexeris Helps Contractors Prepare for CMMC Level 3 Assessments
  17. 17
    Frequently Asked Questions

Who Can Conduct a CMMC Level 3 Assessment?

CMMC Level 3 certification assessments are conducted exclusively by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center, or DCMA DIBCAC. A C3PAO cannot conduct or issue a CMMC Level 3 assessment. C3PAOs remain important because Final Level 2 (C3PAO) status is required before the government-led Level 3 assessment can begin.

DCMA describes DIBCAC as the DoD’s sole entity designated to assess CMMC Level 3. Under 32 CFR Part 170, DIBCAC conducts the Level 3 certification assessment, records the assessment results, and issues the resulting Level 3 CMMC status.

Who Is DCMA DIBCAC?

DIBCAC stands for the Defense Industrial Base Cybersecurity Assessment Center.

It operates within the Defense Contract Management Agency and supports the government’s cybersecurity oversight of organizations in the Defense Industrial Base.

DIBCAC’s broader responsibilities include assessing contractor compliance with requirements associated with DFARS 252.204-7012, NIST SP 800-171, and applicable DoD cybersecurity assessment requirements.

For CMMC specifically, DIBCAC has several important responsibilities. It conducts CMMC Level 3 certification assessments, records Level 3 assessment results, handles applicable assessment activities, and performs Level 3 POA&M closeout assessments.

For organizations pursuing Level 3, the key point is straightforward: DIBCAC is the sole designated CMMC Level 3 assessor.

Why Are CMMC Level 3 Assessments Government-Led?

Level 3 is intended for selected environments where Controlled Unclassified Information requires protection against sophisticated threats, including Advanced Persistent Threats.

NIST SP 800-172 supplements the standard CUI protection baseline with enhanced security requirements for information associated with critical programs or high-value assets. These enhanced requirements are designed to increase resilience against adversaries with significant expertise, resources, and the ability to maintain persistent access to targeted environments.

This helps explain why Level 3 uses a government-led assessment rather than relying on a commercial third-party assessor.

Level 3 can involve capabilities such as advanced threat hunting, Security Operations Center operations, rapid cyber incident response, supply chain risk management, advanced system monitoring, and enhanced cyber resiliency.

The government therefore maintains direct assessment authority over organizations required to demonstrate this higher level of protection.

Can a C3PAO Conduct a CMMC Level 3 Assessment?

No. A CMMC Third-Party Assessment Organization, or C3PAO, cannot conduct a Level 3 certification assessment or award Level 3 status.

Authorized C3PAOs perform applicable Level 2 certification assessments. CMMC Level 3 certification assessments are performed by DCMA DIBCAC.

The distinction matters because contractors sometimes assume that the C3PAO performing their Level 2 assessment can simply continue into Level 3.

That is not how the framework works.

What Role Does a C3PAO Play Before Level 3?

Although a C3PAO cannot conduct the Level 3 assessment itself, it performs an essential step in reaching Level 3 eligibility.

A contractor must first undergo an applicable Level 2 certification assessment performed by an authorized C3PAO and achieve Final Level 2 (C3PAO) status.

Only after that prerequisite has been satisfied can the organization proceed to the Level 3 government assessment.

The sequence is:

C3PAO → Final Level 2 certification → DCMA DIBCAC → Level 3 certification assessment

The C3PAO establishes that the applicable Level 2 foundation has been independently assessed. DIBCAC then evaluates the additional Level 3 requirements.

Why Final Level 2 (C3PAO) Status Is Required First

32 CFR Part 170 requires an organization to achieve Final Level 2 (C3PAO) status for the information systems included in the Level 3 assessment scope before initiating the Level 3 assessment.

This has three important implications.

First, a Level 2 self-assessment is not sufficient.

Second, Conditional Level 2 (C3PAO) status is not sufficient while POA&M deficiencies remain unresolved.

Third, the Level 3 assessment scope must be equal to or a subset of the scope covered by the organization’s Final Level 2 C3PAO certification.

The organization therefore cannot obtain a narrow Level 2 certification and then present completely different systems for Level 3 assessment.

Can Level 2 and Level 3 Assessments Be Done at the Same Time?

No.

Level 2 and Level 3 certification assessments are sequential.

The organization must first complete the Level 2 C3PAO assessment and achieve Final Level 2 status. Only then can it initiate the Level 3 certification assessment with DIBCAC.

Level 3 is designed as an augmentation of an already assessed Level 2 environment. Contractors cannot skip the Level 2 certification prerequisite or complete both certification assessments simultaneously.

C3PAO vs. DIBCAC: Who Assesses Each CMMC Level?

Assessment Who Conducts It? Purpose
Level 1 Organization self-assessment Validate foundational FCI safeguarding requirements
Level 2 Self Organization self-assessment Evaluate the applicable NIST SP 800-171 Rev. 2 requirements where self-assessment is permitted
Level 2 Certification Authorized C3PAO Independently assess the 110 NIST SP 800-171 Rev. 2 requirements
Level 3 Certification DCMA DIBCAC Assess the 24 additional Level 3 requirements and validate continued Level 2 conformity where applicable

The key distinction is between third-party certification at Level 2 and government certification assessment at Level 3.

What Is a C3PAO Responsible For?

A C3PAO is an organization authorized to perform CMMC Level 2 certification assessments.

During an applicable Level 2 certification assessment, the C3PAO determines whether the organization’s implementation of the 110 NIST SP 800-171 Revision 2 security requirements satisfies the applicable CMMC assessment objectives.

The C3PAO can also perform the POA&M closeout certification assessment when an organization receives Conditional Level 2 (C3PAO) status and has eligible deficiencies to remediate.

Its authority does not extend to issuing Level 3 status.

What Is DIBCAC Responsible For?

DIBCAC performs several forms of government cybersecurity assessment across the Defense Industrial Base, but its most important role for this discussion is clear.

It conducts CMMC Level 3 certification assessments for the DoD.

Under the CMMC framework, DCMA DIBCAC assessors may:

  • Conduct Level 3 certification assessments
  • Record assessment results
  • Support applicable assessment appeals
  • Conduct Level 3 POA&M closeout assessments
  • Validate relevant Level 2 status information before Level 3 begins

DCMA identifies DIBCAC as the DoD’s sole designated Level 3 assessment authority.

What Is the Current Status of Level 3 Assessments in 2026?

Understanding the current status requires separating who is authorized to perform Level 3 assessments from when CMMC Level 3 requirements are being introduced through acquisitions.

Those are different questions.

The CMMC regulations still define DCMA DIBCAC as the Level 3 assessment authority. However, the broader procurement rollout changed significantly in July 2026.

How the July 2026 CMMC Suspension Affects Level 3

On July 13, 2026, the Department suspended CMMC Phase II requirements and began a broader review of the CMMC program.

Phase I self-assessment requirements remain in place while that review continues.

As a result, contractors should not treat older Phase II, Phase III, or future Level 3 implementation dates published before July 13 as active deadlines.

The important distinction is:

The CMMC regulations continue to define the Level 3 framework and DIBCAC assessment authority.

The broader procurement implementation beyond Phase I is currently under review.

Did the Suspension Change Who Is Authorized to Assess Level 3?

The suspension changed implementation timing, not the assessment authority currently defined in the CMMC framework.

32 CFR Part 170 continues to assign Level 3 certification assessments to DCMA DIBCAC, and DCMA continues to identify DIBCAC as the sole entity designated to assess CMMC Level 3.

However, an organization should not interpret those regulatory procedures as proof that a particular 2026 contract currently requires Level 3.

Because the broader rollout is under review, contractors should verify current acquisition requirements with the applicable contracting or requiring activity before relying on previously scheduled implementation milestones.

What Requirements Still Apply During the Suspension?

The suspension did not eliminate cybersecurity obligations already imposed through applicable contracts.

Phase I self-assessment requirements remain in effect, and applicable organizations may still have obligations involving:

  • NIST SP 800-171 Revision 2
  • DFARS 252.204-7012
  • CUI safeguarding
  • Applicable self-assessments
  • SPRS
  • Cyber incident reporting
  • Contractual flow-down requirements

For more detail on what changed and what remains in effect, see the CMMC Phase 2 suspension.

Who Needs a CMMC Level 3 Assessment?

Not every defense contractor needs a DIBCAC Level 3 assessment.

Level 3 is intended for selected contracts and programs requiring enhanced protection.

Level 3 Is Determined by Contract Requirements

Contractors should not self-select Level 3 simply because they handle CUI.

The applicable CMMC level is tied to DoD acquisition requirements and identified through the relevant solicitation, contract, or other applicable acquisition documentation.

A company handling CUI will commonly encounter Level 2 requirements. Level 3 applies when the government determines that the applicable program requires the enhanced level of protection.

Company size, revenue, or number of defense contracts does not independently determine the level.

The broader CMMC compliance requirements explain how Levels 1, 2, and 3 correspond to different information and assessment requirements.

What Type of CUI May Require Enhanced Level 3 Protection?

Level 3 is intended for selected CUI environments that require stronger protection against sophisticated adversaries and Advanced Persistent Threats.

Potential considerations may include work associated with:

  • Critical defense programs
  • High-value or advanced technologies
  • Significant concentrations of sensitive CUI
  • Missions where compromise could create broader defense risk
  • Environments likely to attract sophisticated adversaries

These examples should not be treated as automatic Level 3 triggers.

The government determines the applicable contractual cybersecurity requirement.

Do All Contractors Handling CUI Need a DIBCAC Assessment?

No.

Handling CUI does not automatically mean an organization needs CMMC Level 3 or a DIBCAC Level 3 assessment.

Most CUI-focused CMMC requirements are associated with Level 2.

Level 3 applies only when the applicable acquisition requirement calls for Level 3 status.

Before investing in Level 3 preparation, contractors should establish what their solicitation or contract actually requires.

What Must You Complete Before DIBCAC Can Assess You?

Preparing for DIBCAC involves much more than sending an assessment request.

Several prerequisites should already be satisfied.

Achieve Final Level 2 (C3PAO)

The first eligibility requirement is Final Level 2 (C3PAO) status.

The certification must apply to the systems included within the planned Level 3 assessment boundary.

Federal regulations require Final Level 2 C3PAO status before the Level 3 certification assessment can begin.

Close All Level 2 POA&M Items

An organization that receives Conditional Level 2 certification has not yet achieved the Final Level 2 status needed for Level 3.

Eligible Level 2 POA&M deficiencies must first be remediated and validated through the applicable Level 2 POA&M closeout assessment.

Only after the organization achieves Final Level 2 (C3PAO) can that status serve as the prerequisite for Level 3.

Implement the 24 Level 3 Requirements

CMMC Level 3 builds on the complete Level 2 baseline.

Level 2 includes 110 requirements from NIST SP 800-171 Revision 2.

Level 3 adds 24 selected requirements derived from NIST SP 800-172.

That means an organization preparing for Level 3 is maintaining the complete Level 2 environment while adding enhanced capabilities designed to address advanced threats.

Important Level 3 capability areas include:

  • Security Operations Center operations
  • Cyber Incident Response Team capabilities
  • Threat-informed risk assessment
  • Threat hunting
  • Supply chain risk management
  • Advanced configuration management
  • Specialized asset protection
  • Enhanced monitoring
  • Secure information movement

Confirm Your Level 3 Assessment Scope

The Level 3 assessment boundary must be defined before DIBCAC evaluates the organization.

For Level 3, relevant asset categories include:

  • CUI Assets: Assets that process, store, or transmit CUI, along with certain assets capable of doing so.
  • Security Protection Assets: Systems that provide security functions or capabilities protecting the CMMC environment.
  • Specialized Assets: Technologies such as IoT, IIoT, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and test equipment.

The organization should document applicable assets in its asset inventory, SSP, and network diagrams.

An important distinction is that Level 3 scoping is not necessarily identical to Level 2 asset treatment. Organizations should validate the boundary again before requesting the government assessment.

Prepare Objective Evidence

DIBCAC assesses implementation, not simply the existence of written policies.

Organizations should be prepared with objective evidence such as:

  • System Security Plan
  • Asset inventories
  • Network diagrams
  • Policies and procedures
  • Technical configurations
  • Security logs
  • Monitoring records
  • Threat intelligence records
  • Threat-hunting evidence
  • Incident response evidence
  • Supply chain risk documentation
  • Training records
  • Configuration-management evidence
  • Security testing results

Evidence should be current, approved, and consistent with the organization’s actual environment.

How Do You Request a CMMC Level 3 Assessment?

DCMA maintains the official process for organizations requesting a CMMC Level 3 DIBCAC assessment.

Because contact information and administrative procedures can change, contractors should always use the current instructions published by DCMA rather than relying on an older blog, checklist, or saved contact detail.

Confirm Your Final Level 2 Status

Before submitting the request, confirm that:

  • The organization has Final Level 2 (C3PAO) status.
  • The certification remains current.
  • The certification covers all information systems that will be included in the Level 3 scope.
  • No unresolved Level 2 POA&M prevents the status from being Final.

This avoids attempting to begin a process for which the organization is not yet eligible.

Submit the Level 3 Assessment Request to DIBCAC

DCMA maintains the official process for requesting a CMMC Level 3 DIBCAC assessment.

Organizations should follow the most current instructions published on the official DCMA DIBCAC website when they are ready to initiate the assessment.

Using the current government instructions is important because contact details, request formats, and administrative procedures can change over time.

Provide Your Final Level 2 Certification Information

The Level 3 request must demonstrate that the prerequisite has been satisfied.

The organization should be prepared to provide the identifying information associated with its Final Level 2 C3PAO certification so that DIBCAC can validate the prerequisite.

The Level 3 assessment should not move forward until Final Level 2 status has been verified.

Coordinate Assessment Readiness and Scheduling

Once eligibility has been validated, DIBCAC coordinates the assessment process.

An organization should reach this point only after validating:

  • Assessment scope
  • Level 3 security requirements
  • Continued Level 2 implementation
  • SSP accuracy
  • Asset inventories
  • Network architecture
  • Documentation
  • Objective evidence
  • Personnel readiness

Requesting the government assessment before those elements are ready creates unnecessary assessment risk.

What Does DIBCAC Assess at CMMC Level 3?

The Level 3 assessment focuses primarily on the 24 selected enhanced requirements derived from NIST SP 800-172.

The 24 NIST SP 800-172-Based Requirements

The 24 requirements build on the Level 2 baseline and introduce enhanced protection against sophisticated threats.

Capability areas include:

  • Security Operations Center capabilities
  • Cyber Incident Response Team capabilities
  • Threat-informed risk assessment
  • Threat hunting
  • Supply chain risk management
  • Automated component discovery
  • Advanced configuration management
  • Secure information transfer
  • Specialized asset security
  • Advanced monitoring and intrusion detection
  • Penetration testing
  • Cyber resiliency

The formal assessment evaluates whether the organization has implemented the applicable assessment objectives supporting each requirement.

Can DIBCAC Recheck Level 2 Requirements?

Yes, in limited circumstances.

Achieving Final Level 2 does not mean DIBCAC must completely ignore Level 2 implementation during the Level 3 assessment.

The Level 3 process can include limited checks of relevant Level 2 security requirements where appropriate.

If DIBCAC identifies a Level 2 requirement that is no longer properly implemented, that issue can affect the organization’s ability to continue through the Level 3 assessment.

This is why contractors should continue maintaining Level 2 controls after obtaining their C3PAO certification.

What Assessment Scope Does DIBCAC Review?

Level 3 assessment scope can include:

  • CUI Assets
  • Security Protection Assets
  • Specialized Assets

Out-of-scope assets must meet the applicable criteria for exclusion, including being unable to process, store, or transmit CUI and not providing security protection for CUI Assets.

The organization should be prepared to justify the treatment of assets classified as outside the assessment boundary.

How Does DIBCAC Conduct a Level 3 Assessment?

CMMC Level 3 assessments use evidence-based assessment methods rather than a simple policy checklist.

The primary assessment methods are examination, interviews, and testing.

The CMMC Level 3 Assessment Guide and applicable NIST SP 800-172A procedures provide the framework for evaluating implementation.

Under the current CMMC framework, organizations should follow the NIST SP 800-172A version incorporated into applicable CMMC requirements rather than independently substituting a newer publication without a corresponding regulatory or contractual update.

Examination

Examination involves reviewing and analyzing assessment objects.

DIBCAC may evaluate:

  • Policies
  • Procedures
  • Security plans
  • Network diagrams
  • Data-flow diagrams
  • Asset inventories
  • Configuration records
  • System settings
  • Security reports
  • Logs
  • Monitoring evidence
  • Training materials
  • Incident records

The objective is to determine whether the available evidence demonstrates that the security requirement has actually been implemented.

Draft policies and unfinished working papers do not provide the same assurance as approved, operational documentation.

Interviews

Assessors can interview individuals responsible for implementing, operating, or overseeing security requirements.

Personnel may include:

  • Security leaders
  • System administrators
  • Network administrators
  • SOC personnel
  • Incident responders
  • GRC teams
  • System owners
  • Other responsible employees

Interviews help DIBCAC determine whether personnel understand the documented processes and whether those processes operate as described.

A policy stating that threat hunting occurs, for example, is not the same as having personnel who can explain the process, demonstrate how it is performed, and show the evidence it generates.

Testing

Testing requires the organization to demonstrate how safeguards and security processes behave in practice.

Depending on the requirement, teams may need to show how they:

  • Detect unauthorized components
  • Transfer information securely
  • Monitor security events
  • Perform threat hunting
  • Authenticate systems or components
  • Escalate incidents
  • Protect specialized assets
  • Apply configuration controls

Testing compares actual implementation with the expected security outcome.

Who Decides Whether You Pass a CMMC Level 3 Assessment?

DCMA DIBCAC determines the results of the official CMMC Level 3 certification assessment.

DIBCAC evaluates the requirements and applicable assessment objectives, records the results, and determines whether the organization qualifies for the relevant Level 3 status.

How DIBCAC Records MET, NOT MET and N/A Findings

CMMC requirements can receive one of three assessment findings:

  • MET: All applicable assessment objectives for the requirement are satisfied based on acceptable evidence.
  • NOT MET: One or more required assessment objectives have not been satisfactorily demonstrated.
  • N/A: The requirement or objective does not apply within the relevant environment.

For scoring purposes, a properly determined N/A is treated equivalently to MET.

Level 3 requirements are each worth one point, producing a maximum Level 3 assessment score of 24.

What Is Final Level 3 Status?

An organization receives Final Level 3 when it successfully satisfies all applicable Level 3 requirements.

Final status can be achieved directly through the initial certification assessment or following successful closeout of eligible POA&M deficiencies where conditional status was initially awarded.

The strongest outcome is entering the assessment with all applicable requirements already demonstrated as MET.

What Is Conditional Level 3 Status?

Limited Conditional Level 3 status may be available where the assessment meets the regulatory scoring and POA&M criteria.

The Level 3 score divided by the total Level 3 requirements must be at least 80%.

Because Level 3 contains 24 scored requirements, 19 out of 24 equals approximately 79.17%. Therefore, at least 20 MET-equivalent requirements are needed mathematically to reach or exceed the 80% threshold.

Even then, conditional status is unavailable if certain critical requirements are among the open deficiencies.

Examples of requirements that cannot remain open on the Level 3 POA&M include those associated with:

  • Security Operations Center
  • Cyber Incident Response Team
  • Threat-Informed Risk Assessment
  • Security Solution Rationale
  • Supply Chain Risk Response
  • Supply Chain Risk Plan
  • Specialized Asset Security

Who Conducts the Level 3 POA&M Closeout Assessment?

DCMA DIBCAC conducts the CMMC Level 3 POA&M closeout certification assessment.

This is different from a Level 2 C3PAO certification assessment, where the relevant C3PAO conducts the applicable Level 2 POA&M closeout.

The distinction is:

Level 2 certification POA&M closeout → C3PAO

Level 3 certification POA&M closeout → DCMA DIBCAC

How Long Is the POA&M Closeout Period?

Eligible Level 3 deficiencies must be successfully closed within 180 days of the Conditional Level 3 status date.

DIBCAC conducts the applicable closeout assessment.

If the eligible deficiencies are not successfully remediated within the allowed period, the Conditional Level 3 status expires.

The organization may then need to complete another applicable assessment process before it can obtain the Level 3 status required for an award.

How Long Is a DIBCAC Level 3 Assessment Valid?

Final CMMC Level 3 status operates on a three-year assessment cycle, subject to continuing compliance and annual affirmation requirements.

Level 3 Assessment Cycle

A Level 3 certification assessment must be performed every three years for information systems within the applicable Level 3 assessment scope.

This means contractors should view Level 3 as an ongoing cybersecurity obligation rather than a one-time audit.

Annual Level 3 Affirmation

A three-year assessment cycle does not mean an organization can ignore CMMC requirements between assessments.

An authorized Affirming Official must attest to continuing compliance after assessment and annually thereafter.

Applicable affirmations are submitted through SPRS.

Organizations should therefore maintain the same controls, documentation, and evidence discipline between formal assessments.

Level 2 Must Also Stay Current

Level 3 does not replace Level 2.

Because Level 2 certification forms the prerequisite foundation, a contractor maintaining Level 3 must also keep Final Level 2 (C3PAO) status current.

Organizations must continue maintaining the 110 Level 2 requirements along with the 24 additional Level 3 requirements.

The two layers can be understood as:

Level 2: The 110 NIST SP 800-171 Revision 2 requirements.

Level 3: The 24 selected additional NIST SP 800-172 requirements.

Can a Consultant Prepare You for a Level 3 Assessment?

Yes. A cybersecurity or CMMC consultant can help an organization prepare for Level 3, but a consultant cannot conduct the official Level 3 certification assessment or award Level 3 status.

Preparation and assessment are separate functions.

Who Can Help With Level 3 Readiness?

Experienced consultants and cybersecurity specialists can support activities such as:

  • Determining readiness
  • Defining the Level 3 assessment scope
  • Reviewing CUI flows
  • Conducting Level 3 gap assessments
  • Mapping requirements to evidence
  • Reviewing NIST SP 800-172 implementation
  • Developing and validating the SSP
  • Reviewing policies and procedures
  • Addressing technical gaps
  • Preparing assessment evidence
  • Planning POA&M remediation
  • Preparing personnel for interviews
  • Conducting mock demonstrations

A qualified CMMC compliance consultant can help prepare the organization, documentation, scope, controls, and evidence before the government assessment begins.

Can a Consultant Award CMMC Level 3 Status?

No.

Neither a readiness consultant nor a general cybersecurity provider can issue official CMMC Level 3 status.

The consultant’s role is assessment preparation.

The official Level 3 assessment role belongs to DCMA DIBCAC.

This distinction should also be understood at Level 2, where a readiness consultant is not the same as the authorized C3PAO performing the official certification assessment.

Why Assessor Independence Matters

Assessment independence helps preserve confidence in the result.

An organization that helps implement controls, write policies, organize evidence, and remediate security gaps has a different role from the entity responsible for determining whether the implementation satisfies government requirements.

For contractors, the practical distinction is simple:

Readiness provider: Helps the organization prepare.

Official assessor: Determines the formal assessment result.

At CMMC Level 3, the official assessor is DIBCAC.

How to Prepare for a DIBCAC Level 3 Assessment

Preparation should begin well before the formal assessment request.

Confirm That Level 3 Actually Applies

Start with the acquisition requirement.

Review:

  • Solicitation language
  • Contract requirements
  • Prime contractor requirements
  • Government guidance
  • Current CMMC implementation status

Do not invest in Level 3 solely because the organization handles CUI.

During the current 2026 program review, confirming the actual acquisition requirement is particularly important.

Build Level 3 on a Strong Level 2 Foundation

Final Level 2 certification is more than an administrative gateway.

The Level 2 security environment must remain operational throughout Level 3 preparation and assessment.

Before moving forward, verify that:

  • All 110 Level 2 requirements remain implemented
  • Level 2 evidence is current
  • The SSP remains accurate
  • Asset inventories are maintained
  • CUI flows have not changed unexpectedly
  • Technical safeguards continue operating
  • Personnel understand their responsibilities

DIBCAC can perform limited verification of Level 2 implementation during the Level 3 assessment.

Perform a Level 3 Gap Assessment

Evaluate the organization against each of the 24 selected Level 3 security requirements and their associated assessment objectives.

The gap assessment should identify weaknesses across:

  • Technology
  • Governance
  • Processes
  • Documentation
  • Evidence
  • Personnel
  • Security operations
  • Threat intelligence
  • Incident response
  • Supply chain risk

A requirement should not be marked complete merely because a relevant technology exists.

The organization should determine whether the requirement can actually be demonstrated the way DIBCAC will evaluate it.

Validate Your CUI Boundary and Asset Inventory

Confirm which assets belong within the Level 3 assessment scope.

Review:

  • CUI Assets
  • Security Protection Assets
  • Specialized Assets
  • External services
  • Cloud environments
  • CUI transmission paths
  • Network segmentation
  • Remote access
  • Out-of-scope assets

Make sure the asset inventory, SSP, and network diagrams describe the same environment.

Collect Evidence Against Assessment Objectives

Organize evidence around the actual assessment objectives rather than gathering generic cybersecurity documentation.

For each requirement, determine:

  1. What will DIBCAC need to verify?
  2. What evidence demonstrates implementation?
  3. Which system produces that evidence?
  4. Who can explain the process?
  5. What can the organization demonstrate during testing?
  6. Is the evidence current and final?

This creates a much stronger assessment package than simply collecting policies.

Conduct an Internal Readiness Review

Before requesting the formal DIBCAC assessment, conduct an internal review using the applicable:

  • CMMC Level 3 Assessment Guide
  • CMMC Level 3 scoping requirements
  • NIST SP 800-172 requirements incorporated into CMMC
  • Applicable NIST SP 800-172A assessment procedures

Simulate examination, interview, and testing wherever practical.

Ask responsible personnel to demonstrate controls without depending entirely on the person who originally implemented them.

Assessment readiness should mean the environment can withstand independent verification, not simply that the compliance team believes every requirement is complete.

How Nexeris Helps Contractors Prepare for CMMC Level 3 Assessments

Nexeris helps defense contractors prepare for CMMC assessments without confusing readiness support with the government’s assessment authority.

Level 3 preparation support can include:

  • Level 2 and Level 3 gap assessments
  • CUI scoping
  • NIST SP 800-172 readiness
  • SSP development and validation
  • Evidence review
  • Policy and procedure alignment
  • POA&M remediation planning
  • Technical implementation gap identification
  • Mock assessment preparation
  • DIBCAC assessment readiness

The objective is to enter the formal government assessment with a clearly defined environment, operating security requirements, consistent documentation, organized evidence, and personnel who can demonstrate how the security program actually works.

Frequently Asked Questions

1. Who is authorized to conduct a CMMC Level 3 assessment?

DCMA DIBCAC is the sole designated authority for conducting CMMC Level 3 certification assessments.

The Defense Industrial Base Cybersecurity Assessment Center operates within the Defense Contract Management Agency and conducts Level 3 assessments on behalf of the government.

C3PAOs and consultants cannot issue official Level 3 status.

2. Can a C3PAO conduct a CMMC Level 3 assessment?

No.

A C3PAO performs applicable CMMC Level 2 certification assessments.

Level 3 certification assessments are conducted by DCMA DIBCAC.

A C3PAO still plays an important role because the contractor must first achieve Final Level 2 (C3PAO) status before requesting Level 3 assessment.

3. What is DCMA DIBCAC?

DCMA DIBCAC is the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center.

It performs government cybersecurity assessments of defense contractors and serves as the DoD’s sole designated CMMC Level 3 assessment authority.

Its responsibilities also extend to other applicable DoD cybersecurity assessments.

4. Do you need CMMC Level 2 before a Level 3 assessment?

Yes.

An organization must achieve Final Level 2 (C3PAO) status for the applicable systems before initiating a CMMC Level 3 certification assessment.

A Level 2 self-assessment is not sufficient, and Conditional Level 2 status does not satisfy the prerequisite until eligible POA&M deficiencies have been successfully closed.

5. How do you request a CMMC Level 3 assessment from DIBCAC?

Organizations should follow the current CMMC Level 3 assessment request instructions published on DCMA’s official DIBCAC website.

The organization must demonstrate that it has achieved Final Level 2 (C3PAO) status for the applicable assessment scope before the Level 3 process can proceed.

6. What does DIBCAC evaluate during a Level 3 assessment?

DIBCAC evaluates the 24 selected Level 3 security requirements derived from NIST SP 800-172 and their applicable assessment objectives.

The assessment may involve examination of documentation and system evidence, interviews with responsible personnel, and testing of security processes and technical safeguards.

DIBCAC may also perform limited checks of underlying Level 2 requirements where appropriate.

7. Who conducts a Level 3 POA&M closeout assessment?

DCMA DIBCAC conducts the CMMC Level 3 POA&M closeout assessment.

Eligible open deficiencies must be remediated and validated within 180 days of the Conditional Level 3 status date.

A C3PAO handles applicable Level 2 certification POA&M closeouts, not Level 3 closeouts.

8. Are CMMC Level 3 assessments currently affected by the 2026 CMMC suspension?

The July 13, 2026 suspension affects the broader CMMC implementation timeline and paused the planned transition beyond Phase I while the Department reviews the program.

Previously published future rollout dates should therefore not be treated as active deadlines.

However, the defined CMMC framework continues to identify DCMA DIBCAC as the Level 3 assessment authority. Contractors should confirm whether a Level 3 assessment requirement currently applies to their specific solicitation or contract before proceeding.

Zach Tracy, Nexeris founder and CEO

Zach Tracy, CISA, CISSP

Zach Tracy is the CEO and a cybersecurity executive with more than 10 years of experience in security program management and regulatory compliance. He has served as a fractional Chief Information Security Officer for over 40 organizations and has led more than 100 audits across frameworks including SOC 2, CMMC, NIST CSF, ISO 27001, HIPAA, and HITRUST.

Zach specializes in helping defense contractors and regulated organizations build practical, audit-ready security programs that protect contract eligibility and reduce operational risk. He holds CISA, CISSP, CMMC-RP, and ISO 27001 and 9001 Lead Implementer certifications, along with a B.S. in Cybersecurity from Thomas College.

A Marine Corps veteran and former law enforcement officer, Zach brings a mission-focused, disciplined approach to cybersecurity leadership.

Connect with Zach on LinkedIn

Scroll to Top