Getting CMMC certified is not mysterious. It is a defined sequence with a defined finish line. What trips contractors up is not knowing the steps, it is underestimating how much documentation and evidence each step demands. Here is the full path to Level 2, in order.
Status note, September 2026. On July 13, 2026 the Department of War suspended the November 2026 Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and Level 2 (C3PAO) requirements are to be removed from active solicitations and existing contracts (DoW CIO memorandum, Attachment 1, cleared for open publication July 13, 2026). This guide describes the Level 2 (C3PAO) path as written in 32 CFR Part 170. See what the suspension changed and what still applies.
Before you start: which level applies to you
CMMC has tiers, and you need to know yours before you spend a dollar. Level 1 covers Federal Contract Information and rests on the 15 basic safeguarding requirements of FAR 52.204-21, verified by an annual self-assessment (32 CFR 170.15). Level 2 covers Controlled Unclassified Information and rests on the 110 requirements in NIST SP 800-171 Rev 2. Depending on the solicitation, Level 2 is met either by self-assessment or by a C3PAO certification assessment (32 CFR 170.16 and 170.17).
Your contract language and the sensitivity of the data you handle determine the level. Confirm it before you scope anything, because building for the wrong level wastes effort. The full comparison is in CMMC Level 1 vs Level 2.
The seven steps to CMMC Level 2 certification
- Define your scope. Identify every asset, system, and person that processes, stores, or transmits CUI. Segment aggressively, because everything in scope gets assessed.
- Run a gap assessment. Measure your current environment against all 110 NIST SP 800-171 requirements and find what is missing, incomplete, or undocumented.
- Write the System Security Plan (SSP). Document how each of the 110 controls is implemented. The SSP is the spine of your entire certification.
- Remediate gaps and build the POA&M. Fix what you can, and document a Plan of Action and Milestones for anything not yet implemented. At assessment, only the requirements 32 CFR 170.21 allows can stay on a POA&M, and it must close within 180 days.
- Collect and organize evidence. For each control, assemble the artifacts that prove it is real: configurations, policies, logs, screenshots, and records.
- Engage an authorized C3PAO. Select a CMMC Third-Party Assessment Organization, schedule the assessment, and submit your scope and documentation.
- Complete the assessment and maintain certification. The C3PAO enters the result in CMMC eMASS, your Affirming Official affirms and re-affirms annually, and the environment has to stay compliant through the three-year cycle (32 CFR 170.17 and 170.22).
Where the time goes
How long it takes to get ready depends mostly on remediation and documentation, which are in your hands. The single biggest variable is how far your current environment sits from the 110 requirements. A contractor already running MFA, logging, access control, and configuration management is well ahead of one starting from a flat network and a folder of Word docs. The 12-week preparation plan shows how to sequence the work.
Mistakes to avoid
- Skipping scoping and assessing the whole company by accident.
- Treating the SSP as a checkbox instead of an accurate, maintained description of reality.
- Collecting evidence the week before the assessment instead of as you go.
- Letting the environment drift after certification, then paying to rebuild it before reassessment.
Where AaaS fits in the process
Steps two through five, the gap analysis, SSP, POA&M, and evidence, are the documentation-heavy steps, and they are the work the ai4cmmc.ai AaaS platform takes on. It re-scans the read-only configuration of the sources you connect about every seven days, measures the requirements those sources can show, takes the rest from your team’s attestations and evidence, and re-issues your SSP and POA&M on your tier’s cycle. It does not change your environment; remediation stays with your team. Your Affirming Official decides what is affirmed. Start with the $999 CMMC Level 2 Readiness Snapshot, a one-time purchase, and see your readiness picture before you commit a dollar to a C3PAO.