CMMC Scope Questionnaire

This questionnaire is designed for Lazarus Alliance, a CMMC-accredited Third-Party Assessment Organization (C3PAO), to document and validate the in-scope boundary of an Organization Seeking Certification (OSC) prior to conducting a full security assessment. It aligns with CMMC requirements for defining the CUI boundary, data flows, external dependencies, and other key scoping elements.

The questionnaire is structured into sections to ensure a comprehensive scope determination. It should be completed based on OSC-provided documentation, interviews, diagrams, and evidence.

About this Questionnaire

Lazarus Alliance, an accredited CMMC Third-Party Assessment Organization (C3PAO), will coordinate directly with your organization to prepare for and schedule your official CMMC assessment. Our experienced CMMC C3PAO assessors and advisors will help determine the appropriate impact level (L1, L2, or L3) and certification path based on your federal customer requirements. Upon successful completion of the independent C3PAO assessment and issuance of a certification or provisional certification.

Lazarus Alliance, an accredited CMMC Third-Party Assessment Organization (C3PAO), is historically about 46% faster than traditional C3PAO firms meaning that your certification can be achieved in 2-5 months. — Michael Peters, CEO & Founder"

Source Information:

https://lazarusalliance.com/services/audit-compliance/cmmc/

Section 1: General Information

Section 2: System Description and CUI Boundary

Section 3: Data Flows and External Connections

Section 4: Components and Assets

Section 5: Facilities and Physical Scope

Section 6: Personnel and Roles

Section 7: Documentation and Readiness Confirmation

Section 8: Next Steps

Thank you for completing this questionnaire. A Lazarus Alliance CMMC C3PAO Cybervisor will be in contact with you soon.

For the official FedRAMP templates (including the SSP and RAR), refer to the FedRAMP website (fedramp.gov) and the 3PAO Readiness Assessment Report Guide.

Frequently Asked Questions

The CMMC is a framework created by the U.S. Department of Defense (DoD) to evaluate and strengthen the cybersecurity practices of organizations in the Defense Industrial Base (DIB), including contractors and subcontractors. It ensures the protection of sensitive unclassified information like Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Unlike previous self-attestation methods, CMMC requires third-party verification to confirm compliance with standards such as NIST SP 800-171.

Assessment duration varies according to scope, complexity, evidence readiness, number of locations, and other engagement-specific factors. In the Lazarus Alliance 2026 CMMC Assessment Benchmark Report, 47 completed formal Level 2 C3PAO assessments had a median formal assessment duration of 17 business days. Preparation and remediation occur separately and can substantially affect the organization's overall path to certification. Historical benchmark results are not guaranteed timelines for individual assessments.

CMMC Level 2 assessment pricing depends on the defined assessment scope, organizational complexity, number of in-scope locations, enclave architecture, number and type of external service providers, evidence readiness, and other engagement-specific factors. Lazarus Alliance establishes fixed-fee assessment pricing after confirming the applicable assessment boundary and scope.

  • Level 1: Only Federal Contract Information (FCI) → annual self-assessment
  • Level 2: Controlled Unclassified Information (CUI) → third-party C3PAO certification (most common)
  • Level 3: High-risk CUI programs → government-led (DIBCAC) Lazarus Alliance performs a free scoping call to confirm your exact level.

As a certified CMMC Third-Party Assessment Organization (C3PAO), Lazarus Alliance coordinates assessments, determines your required certification level based on business needs, and conducts evaluations using experienced Cybervisor™ teams. Upon successful demonstration of maturity in cybersecurity capabilities and processes, we award certification valid for three years, with annual affirmations required.

The process involves: (1) Identifying your level based on data handled; (2) Implementing required controls (with Plans of Action and Milestones for minor gaps in Levels 2/3); (3) Undergoing assessment by a C3PAO (like Lazarus Alliance) for Levels 1-2 or DIBCAC for Level 3; (4) Posting results and affirmations in the Supplier Performance Risk System (SPRS); and (5) Maintaining compliance annually. Certifications last three years, with full rollout phased through 2028.

All DoD prime contractors and subcontractors handling FCI or CUI in the DIB must comply at the appropriate level. This includes most defense-related businesses, but exemptions may apply to commercial off-the-shelf (COTS) items. If your organization deals with sensitive DoD data, even indirectly through the supply chain, certification is essential.

CMMC 2.0 is the U.S. Department of Defense’s mandatory cybersecurity certification program that protects FCI and CUI. Requirements begin appearing in DoD contracts in late 2025, with full enforcement for all applicable contracts by 2028. Non-compliance will disqualify you from bidding.

Continuum GRC, the platform with the A.ITAMBot AI-powered auditor, dramatically reduces the time and cost of CMMC compliance by automating evidence collection, control mapping, continuous monitoring, risk scoring, and POA&M management. For clients nationwide and internationally, it enables real-time collaboration, inheritance of controls, and streamlined documentation, often cutting preparation time. This gives our C3PAO assessment process a significant efficiency advantage over traditional manual approaches.