Outlet Title
2026 IEEE Cyber Awareness and Research Symposium (CARS)
Document Type
Conference Proceeding
Publication Date
Fall 10-28-2026
Abstract
The Cybersecurity Maturity Model Certification program requires that third-party assessments be conducted under a non-consultative model. The model is intended to ensure impartiality for organizations seeking certification. While this structure defines expectations for assessor behavior, assessor experiences and interpretations of these constraints remain underexamined. The study examines the lived experiences of CMMC-Certified Assessors and how they navigate role expectations within the non-consultative model. Using Role Conflict Theory as a guiding framework, the study applied Interpretative Phenomenological Analysis (IPA) to semi-structured interviews to explore how assessors make sense of their roles. The analysis identified experiential themes that describe how assessors construct professional credibility, execute structured assessment work, and manage the practical challenges of maintaining non-consultative boundaries. Findings indicate that assessors rely on technical competence, procedural discipline, and boundary management strategies to reconcile competing expectations. As an exploratory study, the results are not intended to be generalizable. The findings provide initial empirical insight into assessor experiences and highlight considerations related to boundary clarity and assessor/organization interaction. The study also demonstrates IPA's suitability for examining practitioner experience within cybersecurity compliance contexts.
Recommended Citation
Heuchert, S., & Hastings, J.D. (2026). Assessor Experiences in CMMC Level 2 Certification Assessments: An Interpretative Phenomenological Analysis of Role Expectations. ArXiv, abs/2605.27587.
Included in
Information Security Commons, Other Sociology Commons, Quantitative, Qualitative, Comparative, and Historical Methodologies Commons
