A formal process used to test and evaluate security controls to confirm they are properly implemented, functioning as intended, and effectively meeting an organization’s cybersecurity requirements.
In the context of CMMC, an assessment may be:
A third-party assessment conducted by a C3PAO to determine a contractor’s CMMC level, or
A self-assessment performed by a DIB contractor to evaluate their own compliance.
