Process · CMMC Guide

How to Get CMMC Certified: The Level 2 Process, Step by Step

Getting certified is not mysterious, it is a defined sequence with a defined finish line, and the documentation is what trips contractors up.

ProcessCMMC Level 2

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 24, 2026 · 5 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Getting CMMC certified is not mysterious. It is a defined sequence with a defined finish line. What trips contractors up is not knowing the steps, it is underestimating how much documentation and evidence each step demands. Here is the full path to Level 2, in order.

Status note, September 2026. On July 13, 2026 the Department of War suspended the November 2026 Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and Level 2 (C3PAO) requirements are to be removed from active solicitations and existing contracts (DoW CIO memorandum, Attachment 1, cleared for open publication July 13, 2026). This guide describes the Level 2 (C3PAO) path as written in 32 CFR Part 170. See what the suspension changed and what still applies.

Before you start: which level applies to you

CMMC has tiers, and you need to know yours before you spend a dollar. Level 1 covers Federal Contract Information and rests on the 15 basic safeguarding requirements of FAR 52.204-21, verified by an annual self-assessment (32 CFR 170.15). Level 2 covers Controlled Unclassified Information and rests on the 110 requirements in NIST SP 800-171 Rev 2. Depending on the solicitation, Level 2 is met either by self-assessment or by a C3PAO certification assessment (32 CFR 170.16 and 170.17).

Your contract language and the sensitivity of the data you handle determine the level. Confirm it before you scope anything, because building for the wrong level wastes effort. The full comparison is in CMMC Level 1 vs Level 2.

The seven steps to CMMC Level 2 certification

  1. Define your scope. Identify every asset, system, and person that processes, stores, or transmits CUI. Segment aggressively, because everything in scope gets assessed.
  2. Run a gap assessment. Measure your current environment against all 110 NIST SP 800-171 requirements and find what is missing, incomplete, or undocumented.
  3. Write the System Security Plan (SSP). Document how each of the 110 controls is implemented. The SSP is the spine of your entire certification.
  4. Remediate gaps and build the POA&M. Fix what you can, and document a Plan of Action and Milestones for anything not yet implemented. At assessment, only the requirements 32 CFR 170.21 allows can stay on a POA&M, and it must close within 180 days.
  5. Collect and organize evidence. For each control, assemble the artifacts that prove it is real: configurations, policies, logs, screenshots, and records.
  6. Engage an authorized C3PAO. Select a CMMC Third-Party Assessment Organization, schedule the assessment, and submit your scope and documentation.
  7. Complete the assessment and maintain certification. The C3PAO enters the result in CMMC eMASS, your Affirming Official affirms and re-affirms annually, and the environment has to stay compliant through the three-year cycle (32 CFR 170.17 and 170.22).
Not sure which controls you are missing? Find out before you book an assessor. Start the free 10-question gap check →

Where the time goes

How long it takes to get ready depends mostly on remediation and documentation, which are in your hands. The single biggest variable is how far your current environment sits from the 110 requirements. A contractor already running MFA, logging, access control, and configuration management is well ahead of one starting from a flat network and a folder of Word docs. The 12-week preparation plan shows how to sequence the work.

Mistakes to avoid

Where AaaS fits in the process

Steps two through five, the gap analysis, SSP, POA&M, and evidence, are the documentation-heavy steps, and they are the work the ai4cmmc.ai AaaS platform takes on. It re-scans the read-only configuration of the sources you connect about every seven days, measures the requirements those sources can show, takes the rest from your team’s attestations and evidence, and re-issues your SSP and POA&M on your tier’s cycle. It does not change your environment; remediation stays with your team. Your Affirming Official decides what is affirmed. Start with the $999 CMMC Level 2 Readiness Snapshot, a one-time purchase, and see your readiness picture before you commit a dollar to a C3PAO.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-control NIST 800-171 baseline and returns a PDF within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Readiness subscriptions are billed annually, with a month-to-month option on every tier.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures are the DoD's published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee CMMC certification; certification assessments are conducted by an authorized C3PAO (Level 2) or DCMA DIBCAC (Level 3). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.