Process · CMMC Guide

The CMMC Certification Process: A Defense Contractor's Real Timeline

Certification is not a single event. It is a ten-step sequence, and the writing can slip as badly as the remediation.

ProcessCMMC Level 2

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published May 20, 2026 · 6 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

CMMC certification is not a single event. It is a process with ten distinct steps, each with its own deliverable and its own way of eating your calendar if you run it out of order. This is the sequence, what each step produces, and where the time goes for a contractor that wants the certification, not a participation trophy.

Status note, September 2026. On July 13, 2026 the Department of War suspended the November 2026 Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and Level 2 (C3PAO) requirements are to be removed from active solicitations and existing contracts (DoW CIO memorandum, Attachment 1, cleared for open publication July 13, 2026). This guide describes the Level 2 (C3PAO) path as written in 32 CFR Part 170. See what the suspension changed and what still applies.

Before You Start: Confirm Your Level

Level 1 if you handle Federal Contract Information only. Level 2 if you handle Controlled Unclassified Information under DFARS 252.204-7012. Level 3 only if the solicitation or contract specifies it. The level is set by the solicitation, so verify the data type and the stated requirement before you spend a dollar. Our Level 1 vs. Level 2 guide walks through the distinction.

Step 1: Define and Minimize Scope

Map where CUI actually lives, moves, and is processed, then make that footprint as small as possible. Scope is a major cost driver in CMMC. An enclave that contains the CUI keeps the assessment narrow and the tooling spend rational. A flat network that touches CUI everywhere makes the entire corporate environment in-scope, and the bill follows. Deliverable: a documented system boundary and data-flow diagram.

Step 2: Gap Assessment

A requirement-by-requirement evaluation against the applicable set. Level 2 covers the 110 NIST SP 800-171 Rev 2 requirements; Level 1 covers the 15 basic FAR 52.204-21 requirements. The deliverable is a finding set: each requirement rated MET, NOT MET, or NOT APPLICABLE, the CMMC finding types (32 CFR 170.24), with evidence references. Do not skip this. Without a real gap finding, you can end up discovering in front of an assessor that your MFA is not actually enforced on the right accounts.

Step 3: Remediate

Close the gaps. This can be the longest step in calendar time and a large line item in dollars: network segmentation, MFA, FIPS-validated cryptography, malicious code protection such as EDR, centralized logging, vulnerability management, incident response, training, configuration management, encrypted backups, and physical and personnel controls. Sequence the work by risk and by control dependency. Implementing audit logging before you have defined what to log produces an expensive nothing.

Step 4: Document the SSP and Policies

An SSP is not a binder of policies. It is the narrative of how each control is implemented in your specific environment. The SSP that survives an assessment is the one an outsider could read and then predict what they will see when they look at your systems. Policies should be specific to your environment, dated, version-controlled, and approved: 32 CFR 170.24 lists drafts and unofficial or unapproved policies among the unacceptable forms of evidence. Boilerplate that does not describe your environment will not match what the assessor sees on your systems.

Want a quick read before you commit to the full process? The free gap check asks ten questions on ten NIST SP 800-171 requirements and gives you a directional self-assessment, not an official SPRS score, to start from. It does not map your scope.

Run the free gap check →

Step 5: Build the Evidence Pipeline

Assessors do not accept verbal assurance. They accept evidence: configuration exports, log samples, training rosters, incident reports, change tickets, vulnerability scans, access reviews. Build the pipeline before the assessment, not during it. Treat evidence as an ongoing capability rather than a binder-stuffing exercise, so it is current when the assessor asks.

Step 6: Pre-Assessment

A dry run, ideally with a different team than the one that wrote your SSP. The goal is to find your weak controls before the C3PAO does. Time-box it so it does not turn into a second project. The output is a tight list of fixes you can close in the runway before the real assessment.

Step 7: Schedule the C3PAO or Finalize Self-Assessment

C3PAOs have lead times, so ask for them and book early. For self-assessment paths, finalize the SPRS affirmation workflow and the executive signoff so the basis and timing of the affirmation are documented. Either way, confirm scope with the assessor in writing before they walk in. We are a readiness Agent-as-a-Service (AaaS) provider, not a C3PAO, so the assessment itself always sits with an authorized third party.

Step 8: The Assessment

An assessment is interviews, document review, and technical examination. Expect the assessor to verify that what your SSP claims is what your systems actually do. Check these before the assessor does: stale documentation, unowned controls, inconsistent answers across interviewees, and unmet foundational practices like MFA, FIPS validation, and audit logging.

Step 9: POA&M and Affirmation

At Level 2, not every requirement must be MET at assessment time: a score of at least 80 percent with only the requirements 32 CFR 170.21 allows on the POA&M earns a Conditional status, and the POA&M must close within 180 days. At Level 1, no POA&M is permitted (32 CFR 170.21(a)(1)). The affirmation is yours to own: your Affirming Official, a senior representative with authority over the organization’s CMMC compliance, affirms in SPRS that the requirements are implemented and will be maintained, after each assessment and annually (32 CFR 170.22). Treat that signature with the care of any signed attestation.

Step 10: Maintain

CMMC is not a once-a-year exercise. It is ongoing. Annual affirmations (32 CFR 170.17), evidence freshness, change-management discipline, and reassessment readiness all need to be operating capabilities, not project artifacts. Skip this step and the three-year reassessment starts from a decayed baseline.

A Realistic Timeline

The honest answer is that timelines vary widely with starting posture and scope. Remediation is engineering work you can plan; documentation and evidence, the writing-things-down work, is where schedules slip when nobody owns it. That is the part worth attacking first if you want a predictable calendar.

Where AaaS Removes Time and Cost

Documentation and evidence are where Agent-as-a-Service (AaaS) gives a contractor operational leverage. Enclave AI re-scans the read-only configuration of the sources you connect about every seven days, drafts SSP content from measured findings and your attestations, shows in your workspace how many days ago your posture was last measured and which controls regressed since the last cycle, and re-issues the SSP and POA&M on your tier’s cycle. Requirements no connected source can show are answered from your team’s evidence. Your Affirming Official still reviews and decides. Repetitive labor becomes machine work, with a human deciding. For the condensed seven-step view, see our step-by-step process guide, and for budget, our Level 2 compliance cost breakdown.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-control NIST 800-171 baseline and returns a PDF within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Readiness subscriptions are billed annually, with a month-to-month option on every tier.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures are the DoD's published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee any CMMC status or certification. A Level 2 certification assessment is conducted by an authorized or accredited C3PAO (32 CFR 170.17). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.