CMMC Level 2 is a process, not a product. You cannot buy your way to certification. You have to execute a defined sequence, generate the right evidence, pass the assessment your contract requires, and keep the controls operating between assessments. This guide walks the sequence end-to-end, in the order you should actually run it.
A note on timing: while the July 13, 2026 suspension of CMMC Phase 2 is in effect, solicitations may require only CMMC Level 1 (Self) or Level 2 (Self) assessments, not Level 2 (C3PAO) (Department of War memorandum, July 13, 2026, Attachment 1). Steps 1 through 5 and Step 7 apply to a Level 2 self-assessment too; Step 6 applies when a contract calls for a C3PAO assessment.
The Seven-Step Process at a Glance
- Scope CUI: identify every system, person, and process that touches Controlled Unclassified Information.
- Gap assessment: measure current state against the 110 NIST 800-171 controls.
- Build the SSP and POA&M: document how each control is met or how you will meet it.
- Remediate: implement the missing controls and close the gaps.
- Internal pre-assessment: score yourself before the C3PAO does.
- C3PAO assessment: the third-party Level 2 certification audit.
- Ongoing compliance: keep the controls operating between assessments.
Running these steps out of order, for example starting the SSP before scoping CUI, means redoing work. Sequence matters.
Step 1: Scope CUI
Before you touch a single control, map every place CUI lives, moves, and is processed: email, file shares, ERP, engineering and CAD/CAM applications, mobile devices, and any vendor or subcontractor environment that touches your data. Output: a CUI data-flow diagram, a list of in-scope systems and users, and a decision between full-network and enclave architecture. Mistake to avoid: assuming CUI lives only on the engineering file share. It travels in email replies, drafts on laptops, and backups. Scope wider than you think.
Step 2: Gap Assessment Against NIST 800-171
CMMC Level 2 maps to the 110 controls in NIST SP 800-171. A gap assessment scores your current state against each control the way the assessment will: MET, NOT MET, or NOT APPLICABLE (32 CFR 170.24). Output: a control-by-control scorecard, a gap register, and a remediation backlog ranked by risk and effort. Mistake to avoid: treating the gap assessment as a one-time event. Controls drift, so plan to re-score regularly.
Step 3: Build the SSP and POA&M
The System Security Plan documents how each of the 110 controls is implemented in your environment. The Plan of Action and Milestones documents the gaps you have not yet closed, with target dates and ownership, alongside the supporting policy set. Mistake to avoid: writing an SSP that describes the controls you want instead of the ones you have. Assessors check evidence against what the SSP says, and a requirement the evidence does not support is scored NOT MET.
Want a first read before Step 2? The free 10-question gap check is a directional self-assessment of ten controls, not an official SPRS score, but it shows you where to begin.
Run the free gap check →Step 4: Remediate and Implement Controls
Close the gaps from Step 2. Requirements that need technology include multi-factor authentication (3.5.3), FIPS-validated cryptography protecting CUI (3.13.11), audit logging (3.3.1), baseline configurations (3.4.1), and malicious code protection (3.14.2). Output: an environment where every in-scope control has supporting evidence. Mistake to avoid: deploying tools without configuring evidence collection. A requirement you cannot show evidence for is scored NOT MET.
Step 5: Internal Pre-Assessment
Score yourself with the CMMC Scoring Methodology (32 CFR 170.24) before the assessor does. The methodology assigns weighted point values (5, 3 or 1) to the 110 controls; the exact thresholds and weighting should be confirmed against the current published methodology version. Output: a scored self-assessment, an evidence library mapped to every control, and a go or no-go decision on engaging a C3PAO. Mistake to avoid: using the same firm for both the pre-assessment and the remediation. Use independent eyes. For the path comparison, see self-assessment vs. C3PAO.
Step 6: C3PAO Assessment
When a contract calls for it, engage a CMMC Third-Party Assessment Organization (C3PAO). The C3PAO reviews your SSP, POA&M, and evidence library and conducts interviews and technical validation. The outcome is a Final Level 2 (C3PAO) status, a Conditional Level 2 (C3PAO) status with a POA&M to close within 180 days, or neither (32 CFR 170.17 and 170.21). Output: a CMMC status the C3PAO enters in the CMMC instantiation of eMASS, which transmits it to SPRS. Mistake to avoid: treating the assessment as adversarial. Findings rest on evidence, so bring it organized and cooperate rather than litigate every finding.
Step 7: Ongoing Compliance
A Level 2 status runs on a three-year assessment cycle, and your Affirming Official affirms continuing compliance after each assessment and annually thereafter (32 CFR 170.22). The controls have to keep operating in between. Output: ongoing monitoring, regular evidence refresh, annual self-affirmation, and change-triggered control reviews. Mistake to avoid: filing the certificate and ignoring drift. Drift is what makes the next assessment expensive. See our Level 2 cost guide for budgeting the ongoing phase.
Where AI Agents Take On the Labor
Four of these steps are labor-heavy when run by hand: gap assessment, SSP authoring, evidence collection, and ongoing monitoring. An Agent-as-a-Service (AaaS) provider runs those four as one workflow. ai4cmmc.ai reads the read-only configuration of the commercial cloud and identity systems you connect, re-scans them about every seven days, generates the gap register, pre-populates the SSP and POA&M, builds the evidence library with each item's source and, where one is recorded, its SHA-256 hash, and flags drift when a re-scan finds a control has regressed. Requirements no connected source can show are answered from your team's evidence. Your Affirming Official reviews the output and decides. This is operational leverage for your team, not a replacement for it. For the full ten-step view, see our CMMC certification process walkthrough.
What It Means for Sequencing
The practical takeaway is simple: scope first, document against reality, and treat evidence and monitoring as ongoing capabilities rather than pre-audit scrambles. Sequencing the process correctly avoids paying for the same work twice.