Self-assessment vs. readiness vs. C3PAO assessment
Three different things, often conflated:
- Self-assessment. The SPRS score you post to the DoD on your own. Required for Level 1 and as an interim Level 2 step. No third party involved.
- Readiness assessment. A diagnostic performed by you or a consultant before the C3PAO. Not a CMMC artifact — its job is to surface gaps while you can still fix them.
- C3PAO assessment. The certifying assessment by an authorized Third-Party Assessor Organization. Binding. Results posted to SPRS.
A readiness assessment is not optional in practice. Walking into a C3PAO without one is how organizations end up with conditional certs or outright failures — both of which cost more to recover from than the readiness assessment would have cost up front.
What a real readiness assessment produces
- Gap list per objective. Not per control — per NIST 800-171A objective (320 of them). A control can be partially met; the objective grain is what the C3PAO grades against.
- SPRS score projection. Where you score today, and where each remediation moves you. Honest math, not the optimistic 110/110.
- POA&M draft. Pre-populated with eligible gaps, scheduled closure dates, owner assignments.
- Evidence inventory. What you have, what you are missing, what is stale. Per-objective.
- Hours-to-close estimate. How long the remediation work actually takes — by control family, by team, with dependencies.
- Defensibility narrative. The story your affirming official can sign and your C3PAO can verify.
Red flags in a cheap readiness assessment
The ones to walk away from:
- "110 controls, all green" delivered in two days. NIST 800-171A has 320 objectives; you cannot honestly grade them that fast.
- No evidence inventory — just an opinion that controls are "implemented."
- POA&M with non-eligible controls on it. (Some controls are not POA&M-eligible under the final rule.)
- No scoping discussion. Without a defensible boundary, the whole assessment is grading the wrong system.
- No SPRS projection math. Just "you're mostly there."
How Athena runs a readiness assessment
Athena's Assessment Pack runs the readiness assessment as a software-driven workflow rather than a slide-deck deliverable. Evidence collection, objective-level scoring, POA&M draft, SPRS projection, and the defensibility narrative are all generated from the same evidence ledger — and they regenerate when state changes. You leave the readiness phase with the artifacts the C3PAO is going to ask for, not a PDF that ages out in 30 days. The workflow automation pillar covers the end-to-end pipeline.