← All Videos

Inside a CMMC Assessment

C3 Integrated Solutions’ Bill Wootton sits down with Fernando Machado, Managing Principal and CISO at Cybersec Investments, to walk through what actually happens during a CMMC assessment — from the first document review to the final certification decision. It’s a candid, assessor’s-eye view of where companies succeed and where they stumble.

Inside a CMMC assessment, phase by phase

In this conversation:

  • The four phases: pre-assessment, execution, reporting, and certification
  • What assessors review in your System Security Plan (SSP)
  • How evidence is validated against NIST SP 800-171
  • The most common reasons companies lose points
  • How conditional status and remediation plans work
  • How to prepare so assessment day goes smoothly