Skip to content
Foxx Cyberfoxxcyber/docs

CMMC Level 2 Results for eMASS

Fill in the DoD's CMMC Level 2 Assessment Results template with a client's answers for their assessor, see what an upload still needs, and import a filled-in workbook back.

For a client working toward CMMC Level 2, Bedrock GRC can fill in the DoD's CMMC Level 2 Assessment Results template (the workbook used for CMMC eMASS, template version 3.8) with the client's answers, and read a filled-in workbook back.

What this is, and what it is not

Only a C3PAO uploads results to CMMC eMASS. The export is a pre-filled workbook for the assessor, not a submission, and fields only the assessor can complete stay blank. The export has not yet been checked against a real eMASS upload, so treat the workbook as a head start for your assessor and expect them to review and complete it. Nothing here certifies anyone or predicts an assessment result.

Open it

On the client's CMMC Level 2 assessment page (Frameworks → CMMC L2 → Assess or Open), choose eMASS results template; it is also in the CMMC Level 2 row's menu on the Frameworks tab. It is for Foxx Cyber staff; assessors from a partner firm do not see it. The page shows:

  • Practices assessed out of 110;
  • the SPRS score (unassessed practices count as not met);
  • SSPs listed: approved system security plans linked to CA.L2-3.12.4;
  • Still needed: how many things stand between this workbook and an upload.

Download the filled template (.xlsx) builds the workbook on the spot. It is never stored on the server. Each download is written to the audit log.

How the workbook is filled in

Bedrock GRC fills in the official template, unchanged: nothing is renamed, added or removed, and only empty input cells are written. The template is embedded in the application and pinned by its SHA-256.

  • Every objective gets its practice's result. The export works from each practice's status, even where objectives were answered one by one, so each of a practice's objectives is written as Met, Not Met or Not Applicable to match.
  • Partial counts as Not Met, because CMMC has no partial result. The two exceptions are the practices where the template gives partial credit, IA.L2-3.5.3 and SC.L2-3.13.11. They are written so that the workbook's own score equals the SPRS score shown in Bedrock GRC.
  • Not assessed practices are left blank and listed as blocking.
  • Findings come from the narrative and artifacts from the evidence field, with the date and person who assessed each practice. Text longer than the template allows is shortened, and the page tells you where.
  • Requirement in POA&M is Yes only where the practice may be on a POA&M and an open roadmap item covers it. A practice with an open roadmap item that cannot be left on a POA&M is flagged.
  • The OSC name, the assessment dates (when the answers were recorded) and the approved SSPs linked to CA.L2-3.12.4 are filled in.

The filled workbook carries the template's "CUI (when filled in)" marking. Handle it accordingly.

What an upload still needs

The page lists what is still blank before the assessor can upload, for example:

  • practices not yet assessed, by reference;
  • assessment dates, if nothing has been assessed;
  • the assessor's own fields: lead and quality assurance CPNs, the executive summary and the artifact hash block;
  • Time to Assess and Inherited on all 320 objectives, left for the assessor;
  • a system security plan, if none is approved and linked to CA.L2-3.12.4;
  • findings, for assessed practices with no narrative.

It also warns about things worth checking, such as a system security plan practice that is not met.

Import a filled-in workbook

When the assessor sends back a filled-in workbook, bring the results in from Import results from a filled-in template on the same page:

  • Each practice's status is worked out from its objectives: all Met is implemented, all Not Applicable is not applicable, any Not Met is not implemented (or partial, where the template allows partial credit).
  • A practice with objectives left unscored keeps its current status.
  • Findings and artifacts fill empty narratives and evidence. Tick Replace narrative and evidence to overwrite them instead.
  • Maturity ratings are never changed.
  • A practice that comes out not applicable needs a reason, from the workbook's findings or the existing narrative, or it is listed as a problem and left out.
  • If a partner firm holds the client's CMMC Level 2 framework, its answers are skipped and counted. See Assigning a Firm.
  • If the workbook's result matches the client's current status, the status is left alone, so exporting and importing the same file changes nothing.

Like every import, you see each change in a preview before anything is saved. The uploaded file is not kept: only what was read from it waits for your decision, for up to two hours.

Last updated October 9, 2026