Process · CMMC Guide

The CMMC Level 2 Certification Process: Every Step, In Order

CMMC Level 2 is not opaque, it is just long, and each step depends on the ones before it, so the order matters.

ProcessCMMC Level 2

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 10, 2026 · 6 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

CMMC Level 2 certification has a reputation for being opaque. It is not. It is just long. There are nine steps between "we should probably deal with this" and a CMMC Status in SPRS, and each step depends on the ones before it.

Here is the full sequence and what each step actually involves.

Step 1: Confirm your level and define your scope

If you only handle Federal Contract Information (FCI), Level 1 self-assessment may be all you need. If you handle Controlled Unclassified Information (CUI), such as drawings, specs, and technical data marked or identified as CUI, you are in Level 2 territory. Then define the assessment scope: which systems, networks, and people touch CUI. A well-designed CUI enclave can shrink the assessment scope, and everything that follows, under the scoping rules in 32 CFR 170.19. For the dividing line, see CMMC Level 1 vs Level 2.

Step 2: Run a gap assessment against NIST SP 800-171

Level 2 is the 110 security requirements of NIST SP 800-171 Rev. 2 (32 CFR 170.14(c)(3)), assessed against the objectives in NIST SP 800-171A (32 CFR 170.17(c)(1)). The gap assessment tells you which controls you meet, which you partially meet, and which are missing. An AaaS platform can produce this control by control and re-issue it every cycle: measured where a connected source can observe a control, answered from your team's recorded evidence where not. Your team should check the findings before relying on them.

Step 3: Post your self-assessment score to SPRS

DFARS provision 252.204-7019 and clause 252.204-7020 require a current NIST SP 800-171 self-assessment score in the Supplier Performance Risk System (SPRS), as the final CMMC rule describes (89 FR 83092). An honest score with a credible improvement plan beats an inflated one, and false claims can carry legal exposure, so keep the score accurate.

Get a directional first read before step 2; it is a self-assessment, not an official SPRS score. Start the free 10-question gap check →

Step 4: Remediate the gaps

Close the missing controls: access management, encryption, logging, incident response, and the rest. Prioritize by assessment weight and implementation lead time. Some controls take an afternoon, some take a procurement cycle.

Step 5: Build the documentation

Your System Security Plan (SSP) is the central artifact of the entire assessment, and assessors work from it. Add the policies and procedures behind each control and a Plan of Action and Milestones (POA&M) for anything unfinished. Only certain 1-point controls (plus one encryption case, SC.L2-3.13.11) may sit on a POA&M at assessment time, the score must be at least 80% of the maximum, and POA&M items must be closed out within 180 days (32 CFR 170.21).

Step 6: Choose your C3PAO

CMMC Third-Party Assessment Organizations (C3PAOs) perform Level 2 certification assessments (32 CFR 170.17), and the CMMC Accreditation Body keeps the public list of authorized ones (32 CFR 170.8(b)(8)). Since July 13, 2026, with Phase 2 suspended, a DoW CIO memorandum bars requiring activities from designating Level 2 (C3PAO) and directs its removal from active solicitations, so confirm whether your contract calls for a C3PAO assessment before you book. Availability and lead times are set by each C3PAO; ask when you request a quote. (We are not a C3PAO and do not issue certifications; our agents do the readiness work that gets you to the assessment in good shape.)

Step 7: The assessment itself

The C3PAO reviews your SSP, examines evidence, interviews staff, and tests controls against the 800-171A objectives. Evidence that is organized, current, and mapped to each requirement is easier for the assessor to verify. Our step-by-step walkthrough of the assessment covers each phase.

Step 8: Conditional vs. final certification

Meet every requirement and you receive Final Level 2 (C3PAO) status. Score at least 80% of the maximum with only POA&M-eligible items open and you receive Conditional status, with 180 days to close them out through a POA&M closeout certification assessment. Miss that window and the Conditional status expires (32 CFR 170.17, 170.21).

Step 9: Maintain it

Certification runs on a three-year cycle with annual affirmations of continuing compliance in between (32 CFR 170.17, 170.22). The affirmation is an on-the-record statement your Affirming Official enters in SPRS, so treat it accordingly. NIST SP 800-171 Rev. 2 requirement 3.12.3 asks you to monitor security controls on an ongoing basis.

The Pattern Behind Every Step

Much of the effort sits in analysis, documentation, evidence, and upkeep. That is systematic work, which is where Agent-as-a-Service fits. On a readiness subscription, ai4cmmc.ai re-scans connected cloud and identity sources about every seven days and re-issues the step 2 gap analysis and the step 5 SSP and POA&M on your tier's cycle, measured where a connected source can observe a control and answered from your recorded evidence where not. It does not remediate your systems, and it does not perform your assessment. The assessor still assesses. Your designated executive can approve or disapprove each delivered document, and your Affirming Official makes the affirmation decision. Start at step 2 with the $999 CMMC Level 2 Readiness Snapshot, a one-time readiness report that ranks your top control gaps; each subscription tier also offers a month-to-month option.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot compares your connected cloud and identity configuration against all 110 NIST 800-171 controls, measuring the controls those sources can show (intake-based if you connect none), and returns a PDF within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. Each subscription tier also offers a month-to-month option.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures attributed to the DoD are its published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost; $999 is Enclave AI's own price for the CMMC Level 2 Readiness Snapshot.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee any CMMC status or certification. A Level 2 certification assessment is conducted by an authorized or accredited C3PAO (32 CFR 170.17). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.