"Failure" is too coarse a term. Per 32 CFR § 170.21 and the CAP v2.0, three distinct outcomes are possible, each with different remediation paths.
Path 1 — Score below 88
If the total assessment score — after deductions for NOT MET and POA&M-eligible items — is below 88 of 110:
- The assessment is failed. No CMMC Status is issued.
- The OSC must remediate the gaps, then engage a C3PAO for a new initial assessment.
- Re-assessment cost is generally similar to the original assessment cost.
- The original C3PAO is allowed to perform the re-assessment but is not required to.
Path 2 — A restricted practice is NOT MET
If a practice that cannot be placed on a POA&M (per 32 CFR § 170.21(a)(2)) is determined NOT MET, the assessment fails regardless of the total score. Examples that consistently appear on the restricted list include 3.5.3 (multi-factor authentication) and 3.13.11 (FIPS-validated cryptography). Remediate the specific practice to MET, then engage for a new initial assessment.
Path 3 — Conditional Status expires
If the initial assessment scores 88 or above with POA&M-eligible items, the OSC achieves Conditional Level 2 (C3PAO) CMMC Status. The 180-day clock starts when results are entered in CMMC eMASS. Within 180 days the C3PAO must perform a closeout assessment that verifies the POA&M items are MET. If the closeout does not happen within the window:
- The Conditional CMMC Status expires.
- A new initial assessment (not a closeout assessment) is required — full 110-practice evaluation again.
- You are not authorized to bid on or hold contracts that require Final Level 2 (C3PAO) status during the gap.
The most common failure causes (Wrightbrained APREP, Section 4)
- Scoping mistakes. Asset categorization that doesn't match what the assessor finds during walk-through (Active Directory, SIEM, backups, identity providers misclassified as out-of-scope).
- Missing or stale evidence. Evidence dated more than 90 days before assessment, evidence without system identifier, evidence that doesn't show the setting AND its value.
- Unprepared interview subjects. The administrator who can't demonstrate MFA enrollment, the end user who doesn't know how to report a security incident.
- NOT MET on a 5-point or otherwise restricted practice. MFA, FIPS, boundary protection failures hit hard because they cannot be POA&M'd.
- SSP that doesn't match the implementation. When the assessor compares the SSP to the live system and they diverge, the SSP gets a finding under CA.L2-3.12.4.
What to do at the moment of finding
From the APREP master guide:
- Acknowledge the finding factually — do not argue or minimize.
- Document the finding in real time for your follow-up tracker.
- Ask for clarification at the findings briefing — this is your last chance before the formal report.
- For each NOT MET, capture the specific reason cited.
Common errors after a failed assessment
- Engaging the same C3PAO without addressing the root cause. The findings will reproduce.
- Treating closeout as a do-over for restricted practices. Restricted practices cannot be on a POA&M. NOT MET on those practices means a new initial assessment, not a closeout.
- Letting the 180-day clock run out while preparing for closeout. Build the closeout schedule the day the initial assessment results are entered in eMASS.
- Underestimating the time to remediate scoping errors. Re-architecting an enclave or properly scoping identity is a multi-month project, not a closeout effort.
Sources
Surface failures before the C3PAO does.
The CMMC Compliance Engine includes the APREP-MASTER-01_Assessment_Preparation_Master_Guide (Section 4: Common Assessment Failures) plus the 14 domain-specific APREP probing-question guides.
Get the CMMC Compliance Engine