Skip to content
Foxx Cyberfoxxcyber/docs

Completing an Assessment

Submit for approval, record the final determination, and handle correction cycles.

When scoring is done, the engagement moves through submission, lead approval, and a recorded determination. The action buttons in the top-right of the engagement workspace change with the phase and your role.

Submit for approval (assessors)

Assessors assigned to the engagement (who are not the lead) see a Submit for Approval button during the Assess phase.

  1. Click Submit for Approval.
  2. Optionally add Notes for the lead assessor.
  3. Click Submit for Approval in the dialog.

The engagement shows a Pending Lead Assessor Approval banner until the lead acts.

Approve or send back (lead assessor)

While an engagement is pending approval, the lead has two buttons:

  • Complete Assessment — record the final determination (below).
  • Send Back — return the assessment to the team. The Send Back for More Work dialog requires a Reason for Sending Back; the workspace then shows a Reworking findings banner and the team can revise and resubmit.

Record the determination

Clicking Complete Assessment opens the completion dialog:

  • The dialog shows the auto-detected CMMC status based on the recorded control results and POA&Ms, with a confidence badge (High confidence or Verify with lead) and Met / Not Met / Not Assessed counts. If nothing has been assessed yet, a No Objectives Assessed warning blocks completion.
  • Under Final Status (Lead Assessor Override), confirm or change the outcome:
    • Final Level 2 — All requirements met (3-year certificate)
    • Conditional Level 2 — Valid POA&M exists (180-day certificate)
    • No CMMC Status — Requirements not met
  • Add Result Notes (Optional) if needed.
  • Click Confirm (the button shows the selected status label).

For certification assessments the dialog reminds you of CAP Section 3.15: result notes must not include remediation advice.

After completion

The workspace shows an Assessment Complete — View Only banner and a result banner with the determination and the certificate expiry or POA&M closeout deadline. All data is preserved read-only. From here you can:

  • Export to eMASS — see eMASS export.
  • View Assessment Summary (for Final Level 2) or Start New Assessment from Record (for other outcomes) — opens a dialog summarizing the findings with Copy as Markdown and Download as JSON buttons for a reference baseline you can hand to the OSC or use to scope a future engagement.

Correction cycles

If the determination was not Final Level 2, the engagement's designated lead assessor sees a Give Correction Opportunity button on the completed banner:

  1. Click Give Correction Opportunity, review the confirmation dialog, and click Start Correction Cycle. The workspace shows an Awaiting OSC Corrections banner while the OSC updates the items flagged Not Met.
  2. When the OSC indicates their updates are ready, click Resume Re-Evaluation and confirm with Resume. The package locks again and you can continue scoring against the updated state.
  3. Complete the assessment again. Each determination captures a snapshot; the snapshot timeline on the workspace records every determination and correction cycle, and the eMASS export can target any snapshot.

Cancelling

A Decline Request / Cancel Assessment / Cancel Engagement button (the label depends on the engagement's state) is available in most phases. Cancelling an active assessment removes its assessment data and cannot be undone; the dialog lets you record an optional reason.

Last updated July 29, 2026