Tracing levels of Assessment to the depth of the requirement
As of December 2021, the array of supporting documentation for CMMC Assessors includes Levels 1 and 2 scoping guidance, two assessment guides, and one technical document titled The Artifact Hashing Guide. DoD assessors are required to use this documentation.

Figure 7 CMMC PMO CMMC 2.0 Documents
The Assessment Method for the NIST 171 series aligns with the levels of maturity applied to each requirement, organized as Basic, Focused, and Comprehensive. It is reasonable to expect that Basic compliance is necessary to Basic SPRS reporting, that Focused attributes would align with the entire Basic and Derived requirements, and that Comprehensive would support “Expert” and Level 3 assessments. For organizations determined to manage High-risk assets for the Federal Government, their controls would be assessed at the Comprehensive tier, including the additional 35 requirements from the NIST 172. Their assessment would be a Triennial or have its conclusion only once every three years. At Level 3, where there is an increased Cybersecurity requirement, including 35 NIST SP 800-172 requirements, one can also expect an increase in the derived controls requirement. The Level Three CMMC has not yet been published, so any organization identified as requiring Level 3 Assessment will likely have until 2026 to fully comply.
Figure 8 NIST 171A Assessment Methodology
The NIST SP 800-171 Assessment Methodology Version 1.2 6.24.2020.pdf (osd.mil) currently supports the scoring methodology used within the SPRS system. While additional Level 3 controls arrive soon - CMMC Interim Final Rule 2.0 · (cmmc-eu.com), the scoring for the 110 NIST 171 Level 1 and 2 requirements is unlikely to change.
The NIST SP 800-171 DoD Assessment consists of three levels of assessments. These three levels of reviews reflect the depth of the evaluation and the associated level of confidence in the assessment results. Evaluation of contractors with contracts containing DFARS clause 252.204-7012 is anticipated to be once every three years unless other factors, such as program criticality/risk or a security-relevant change, drive the need for a different assessment frequency.
The NIST SP 800-171 Assessment Methodology breaks out the exact steps for Basic, Medium, and High Assessment. The current level High is not associated with CMMC Level 3. The DCMA determines the risk rating. The result of a High-Level Assessment is to attain a DoD validated score of “High” confidence.


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics