CMMC Assessment Checklist
If you think you are ready for a CMMC assessment, use this resource to test where you actually are before contacting a professional.
As the Defense Industrial Base edges closer to seeing CMMC requirements in contracts, here are twelve quick pointers regarding what to look for when seeking a C3PAO (CMMC Third-Party Assessor Organization) and what to expect (or look out for) when discussing your CMMC assessment.
1. If you are working with an MSP to help with your compliance, you need to determine how much access to your CUI data do they need to do their job. If they have access to the CUI data, the CSP, its people, and their processes become part of the assessment scope.
2. Make sure you and your MSP have a Customer Responsibility Matrix (CRM) in relation to the 320 NIST SP 800-171r2 objectives. This will help ensure nothing slips through the cracks.
3. Documentation is key. Screen captures should be able to be recreated in real time (or at least close approximations).Learn more about our C3PAO services and feel free to contact us with any questions. You can also click the "Request a Quote" button on this page to send us your questions and information.
Founded in 1925 and headquartered in Akron, Ohio, Smithers is a multinational provider of testing, consulting, information, and compliance services. With laboratories and operations in North America, Europe, and Asia, Smithers supports customers in the transportation, life science, packaging, materials, components, consumer, cannabis, dry commodities, and energy industries. Smithers delivers accurate data, on time, with high touch, by integrating science, technology, and business expertise, so customers can innovate with confidence. Smithers is one of the most respected authorized C3PAOs and can be found on the CyberAB Marketplace.