← All Videos
C3 Integrated Solutions
Inside a CMMC Assessment
Transcript & Notes
C3 Integrated Solutions’ Bill Wootton sits down with Fernando Machado, Managing Principal and CISO at Cybersec Investments, to walk through what actually happens during a CMMC assessment — from the first document review to the final certification decision. It’s a candid, assessor’s-eye view of where companies succeed and where they stumble.
Inside a CMMC assessment, phase by phase
In this conversation:
- The four phases: pre-assessment, execution, reporting, and certification
- What assessors review in your System Security Plan (SSP)
- How evidence is validated against NIST SP 800-171
- The most common reasons companies lose points
- How conditional status and remediation plans work
- How to prepare so assessment day goes smoothly