Aron Freitag, Lead CCA at Redspin, a division of Clearwater, explains why documentation is only one of three ways a CMMC control actually gets validated, why the big M in CMMC stands for maturity rather than a one time event, and why the gap between what you wrote and what you're running can turn into more than a failed assessment.
Key Takeaways
- Documentation is only one of three ways assessors validate a control. Interview and test check whether the people and the systems actually match what's on paper.
- Polished documentation isn't the bar. Assessors expect to see what's operating behind a well-written plan, not just the writing itself.
- The M in CMMC stands for maturity: an organization's ability to keep getting better over time, not a one time certification event.
- A self-assessment that claims no significant changes have occurred, when that isn't true, can expose an organization to a potential False Claims Act violation.
- Organizations making real security changes, like moving into a more secure environment, are doing the program's actual job: getting better, not just staying compliant on paper.
Table of Contents
- Documentation Is Only One Of Three Checks
- Polished Paperwork Isn't The Bar
- The Big M Is Maturity, Not A Moment
- A False Self-Assessment Is A Legal Problem, Not Just A Compliance One
A lot of the current conversation about CMMC treats it like a documentation exercise: write the plan, file the paperwork, move on. Aron Freitag, Lead CCA at Redspin, a division of Clearwater, spends his time on the assessment side of that exercise, and his view of what actually gets checked looks different.
Across a recent conversation for BEMO's Security + Compliance Field Guide, Aron laid out how assessors actually validate a control, why polished paperwork doesn't satisfy that test, what the M in CMMC is actually measuring, and why the gap between a self-assessment and reality is not just an audit risk. It is a legal one.
Documentation Is Only One Of Three Checks
Assessors do not validate a control by reading about it. "You've got the three different ways to validate any one of these controls and assessment objectives: interview, examine, or test," Aron says.
Examine is the paperwork. That is one piece. "Your documentation, that it may or may not look great, but I'm also gonna talk to your people through interview," he says. Interview means confirming the people running a control actually understand it in their own words. Test means an assessor looks at the logs and the configuration directly, checking whether a control is really set the way the documentation claims, for 30 minutes, six hours, or 365 days.
Aron, who came up through the Army and the DOD, sees documentation less as a filing requirement and more as a forcing function. "That documentation is a forcing function to make leadership and management tell us a story," he says. The point is not the document itself. It is whether leadership can explain, in their own words, what the requirement means and how it is actually configured.
Polished Paperwork Isn't The Bar
That three-part check is also Aron's answer to a common criticism, that CMMC is just theater dressed up as security.
"Your documents may be great, maybe super well-polished, Hollywood style, red carpet level documentation, but then we're gonna wanna see behind the scenes," he says. "We wanna see, okay, how is the stage supported? Are the lights correctly wired?"
The metaphor is deliberate. A well-written plan is a script. Assessors are checking whether the production it describes is actually running: whether the environment, the people, and the process behind the paperwork match what the paperwork claims.
The Big M Is Maturity, Not A Moment
Aron is direct about what CMMC is ultimately measuring. "It's maturity, you know. That's the big M in CMMC," he says. "It's the maturity of each organization getting better over time, and giving the team of implementers and management the recognition that they really deserve."
That framing matters for how a contractor should think about certification. It is not a single event to pass once and file away. It is an organization's demonstrated ability to keep improving, with the people doing that work recognized for it.
A False Self-Assessment Is A Legal Problem, Not Just A Compliance One
The starkest point Aron makes is about what happens when a self-assessment does not match reality. "By signing on those self-assessments that no major changes or no significant changes have occurred, you're really setting yourself up for a potential False Claims Act violation," he says.
That risk cuts against the instinct to avoid changing anything so a self-assessment stays simple to sign. Aron points to the organizations doing this correctly instead: "Those organizations that are making those significant changes in the interest of security, they're making their systems better." He gives concrete examples: upgrading a router to a different product, or moving from an on-premise data center into a FedRAMP environment or a more secure enclave. "They're making these changes in the interest of security. The only option for us as assessors or these companies is complete reassessment."
Read together, the through line across all four points is the same. A CMMC program is judged on whether the documentation, the people, and the environment tell the same story, not on how well any one of them reads on its own.
The paperwork is not the product. The environment it describes is. An assessor's job, in Aron's framing, is to find out whether those two things actually match.
BEMO builds and operates the environment its documentation describes, so what a client represents in a self-assessment is something it can actually demonstrate, through interview and test, not just examine.
Frequently Asked Questions
What are the three ways a CMMC control gets validated?
Interview, examine, and test. Examine covers the documentation. Interview means assessors talk directly to the people running the control to confirm they understand it. Test means assessors check logs and configuration directly rather than relying on what is written.
Does well-written documentation mean an organization is ready for assessment?
No. Aron describes well-polished documentation as the script, not the production. Assessors check whether the environment and people behind the documentation actually match what it describes.
What does the M in CMMC stand for?
Maturity. Aron frames it as an organization's ability to keep getting better over time, not a one time certification event.
What is the risk of signing a false self-assessment?
According to Aron, signing a self-assessment that claims no significant changes have occurred, when that isn't true, can expose an organization to a potential False Claims Act violation.
Should organizations avoid making security changes to keep their self-assessments simple?
No. Aron points out that organizations making real security changes, such as moving into a more secure environment, are doing the program's actual job. Avoiding necessary changes to sidestep a reassessment works against the intent of the program.
Top 10 Posts
-
Office 365 MFA Setup: Step-by-Step Instructions
-
CMMC Phase 2 Suspended: What the Compliance Pause Changed
-
Google Workspace to Office 365 Migration: A Step-by-Step Guide
-
SharePoint vs. OneDrive (What's the Difference Again?)
-
How Much Does ISO/IEC 27001 Lead Auditor Certification Cost in 2025?
-
What is The CIA Triad?
-
What is Microsoft Purview ? Your A to Z Guide to Getting Secure Fast
-
How to Migrate from GoDaddy to Office 365
-
How to Set Up Office Message Encryption (OME)
-
Who Needs ISO 27001: Is This Critical Security Certification Right for Your Business?


Leave us a comment!