11.2 CAP Phase 2: Assess Conformity to Security Requirements
Key Takeaways
- Phase 2 begins with the in-brief and evaluates conformity through Examine, Interview, and Test procedures.
- CAP uses focused, nonstatistical sampling chosen to address objectives and scope, not statistical population inference.
- CCAs assess Level 2 requirements; eligible CCPs may verify Level 1 practices without final determination authority.
- Daily checkpoints communicate status and requests without becoming consulting or premature certification.
- The team documents traceable evidence and results, applies scoring, and completes required quality controls before Phase 3.
11.2 CAP Phase 2: Assess Conformity to Security Requirements
Phase 2 is Assess Conformity to Security Requirements. The team moves from readiness into execution, applying the validated scope and assessment plan to every applicable Level 2 requirement.
In-brief
The Phase 2 in-brief confirms the assessment purpose, scope, team roles, OSC participants, schedule, locations, secure evidence process, communication path, daily checkpoints, test constraints, health or safety matters, and the handling of questions or additional requests. It does not negotiate exemptions or promise a score. Scope changes discovered after the in-brief follow controlled review rather than silent exclusion.
Three methods
NIST SP 800-171A defines:
- Examine: review specifications, mechanisms, and activities, such as policies, configurations, logs, inventories, diagrams, tickets, and records.
- Interview: question individuals or groups about responsibilities, knowledge, and actual performance.
- Test: exercise or observe mechanisms and activities to compare actual behavior with the required result.
Methods are selected for the assessment objective and desired confidence. CAP requires adequate and sufficient evidence; it does not impose a universal two-method minimum. A policy can establish a defined procedure but may not prove technical enforcement. A direct configuration observation can be strong, but the assessor still considers authenticity, scope, currency, and whether the sample supports the objective.
Focused sampling
CAP uses focused sampling, a nonstatistical approach. The team selects items and people that illuminate the assessment objective, technologies, locations, roles, and risk. The goal is defensible coverage, not a statistical confidence interval for every asset.
For MFA, a focused sample might include privileged and nonprivileged users, local and remote access, representative identity providers, administrative paths, and different in-scope asset types. A single easy VPN demonstration would not support a conclusion about an omitted local administrative path. The sample and rationale belong in the work record.
Requirement determination
Each Level 2 requirement has assessment objectives. CCAs map evidence to those objectives and determine whether every applicable objective is satisfied. If any applicable objective is not satisfied, the requirement is NOT MET. N/A requires a justified factual basis; absence of evidence is not N/A.
The DoD scoring methodology starts at 110 and deducts the assigned one, three, or five points for a NOT MET requirement. Scoring follows the actual methodology, including dependencies, rather than simply counting unmet objectives.
Roles during evidence work
CCAs assess Level 2 requirements, and the Lead CCA leads execution and team conclusions. Eligible CCPs may verify Level 1 practices as additional team members under current guidance and may perform authorized support. A CCP does not make final Level 2 determinations.
OSC personnel demonstrate their implementation and provide records. Assessors may request clarification or additional existing evidence within the allowed process. They may not configure the OSC's firewall, rewrite a procedure, or coach a witness to create a passing answer.
Providers and shared responsibility
When CSPs or ESPs affect the scope, the team tests the division of responsibility rather than accepting a marketing claim. It examines contracts, customer responsibility matrices, provider evidence, remote access, incident obligations, service boundaries, and the OSC's implementation of customer-controlled requirements. If an ESP provides a security protection function, its people, technology, and facilities may be part of the evidence and scope.
FedRAMP authorization or Moderate-equivalency evidence for a cloud service addresses a defined service boundary. It does not prove every OSC responsibility or every CMMC requirement.
Daily checkpoints and evolving evidence
CAP uses daily status communication to avoid surprises, track completed work, identify outstanding requests, and communicate preliminary observations appropriately. A checkpoint is not a consulting session or an appeal. Findings remain subject to evidence completion, team review, and quality controls.
Limited practice deficiency correction may be available only under CAP's defined conditions. It is not a general right to redesign controls during the assessment. The OSC performs any permitted correction; the team re-evaluates it under the required procedure and records both the original condition and verified result.
Documentation and transition
Evidence records should identify the source, owner, date, system or sample, method, objective, protection, and assessor conclusion. The OSC retains assessment artifacts and supplies hash values as required; the C3PAO protects its assessment records. Workpapers must allow independent QA to trace each determination.
Before Phase 3, the team completes the required assessment work, scoring, internal review, and Phase 2 quality activities. Unresolved evidence requests cannot be converted into MET by optimism. The output is a controlled set of results ready for completion, reporting, independent QA, and out-brief—not yet an issued certificate.
What sampling approach is used in CAP Phase 2?
Which statement about assessment methods is correct?
Who makes Level 2 assessment determinations?