NotMet

Guidelines

What NotMet publishes

NotMet publishes members' first-hand experiences of assessments. The platform does not verify factual claims. Records reflect the author's account of an engagement, not a finding by NotMet.

First-hand only

Record only engagements you personally worked. Second-hand accounts, rumours, and summaries of what another member told you are removed.

OSC confidentiality

Never name or identify the OSC. Do not include system details: IP addresses, hostnames, domains, email addresses, contract identifiers, or CUI. Records shared outside your organization are scanned for these before submission and again by a moderator.

Assessment dates are collected as a quarter only, never as exact dates.

Confidentiality of site content

All content on NotMet is confidential to member organizations. There are no export or print features, and every view of a shared record is logged. Leaking content is grounds for permanent removal of the individual and the member organization.

Moderation

Records shared with selected organizations or with all members go through platform admin review. A moderator may approve, reject with a reason, or request an edit. Flagged discussion posts are reviewed after the fact and may be hidden. Every moderator action is written to an immutable log.

Optional publication delay

A record shared with all members publishes as soon as a moderator approves it, unless the author chooses to delay it. A delayed record publishes at a random point 30 to 90 days after approval, which reduces the chance that the timing of publication identifies the OSC.

Whether a record was delayed, and the date it is scheduled for, are visible only to the author's organization and platform admins. An author can switch a delayed record to publish on approval at any time. A delay counts toward the contribution requirement as soon as the record is approved.

Who may join: organizations

An organization answers YES to the C3PAO relationship question if it is a C3PAO; owns a C3PAO, is owned by one, or shares a parent company with one; or provides assessors or assessment team members to a C3PAO under contract.

An organization answers NO if its only connections are that it or its OSCs were assessed by a C3PAO, that it holds a CMMC certification, or that it purchased other services from a C3PAO. A disclosed relationship is not an automatic rejection: it goes to platform admin review with the description the applicant provided.

Who may join: individuals

Every member confirms at first sign-in, and again each year, that they do not currently work for a C3PAO in any capacity, as an employee, contractor, or 1099 assessor (CCA, Lead CCA, CCP on assessment teams, or QA).

Being assessed by a C3PAO, holding a CMMC credential, or having worked for a C3PAO in the past does not count. People currently performing assessment work do not have access.

Disputes, not accusations

Describe what the OSC implemented, what the assessor wanted instead, the basis the assessor cited, and how it resolved. Accusations of misconduct belong with the relevant certification body, not here.