Process · CMMC Guide

How to Prepare for a CMMC Level 2 Assessment: A 12-Week Plan

A twelve-week plan for a contractor that already has a reasonable security baseline, with the work front-loaded into documentation and remediation.

ProcessCMMC Level 2

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 19, 2026 · 6 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

This is a twelve-week plan for a defense contractor that already has a reasonable security baseline and is preparing for a CMMC Level 2 assessment. If you are starting from scratch, expect longer. If you have been maintaining compliance with NIST SP 800-171 and have a current SSP, you might compress it. Treat the timeline as directional, not a guarantee.

This plan assumes you have already identified your CUI boundary, have basic security infrastructure in place, and are now preparing specifically for the C3PAO assessment. It is a week-by-week action plan with clear deliverables at each stage. For what the assessment itself looks like, see the step-by-step assessment walkthrough.

Status note, September 2026. On July 13, 2026 the Department of War suspended the November 2026 Phase 2 transition. During the suspension, solicitations may designate only CMMC Level 1 (Self) or Level 2 (Self), and Level 2 (C3PAO) requirements are to be removed from active solicitations and existing contracts (DoW CIO memorandum, Attachment 1, cleared for open publication July 13, 2026). This plan describes the Level 2 (C3PAO) path as written in 32 CFR Part 170; the same preparation applies to a Level 2 self-assessment. See what the suspension changed and what still applies.

Weeks 1-2: Baseline and Gap Assessment

Objective: Know exactly where you stand against all 110 controls.

Conduct a thorough self-assessment against NIST SP 800-171. Score each requirement MET, NOT MET, or NOT APPLICABLE, the CMMC finding types (32 CFR 170.24), and document the specific deficiency for every requirement that is NOT MET. This is not the time for optimistic scoring. Every control you mark MET will be validated by the C3PAO, and an inaccurate self-assessment creates problems during the real assessment.

Deliverables: a completed self-assessment scorecard, a prioritized gap list, and an updated SPRS score. If you use an AaaS platform during this phase, it can shorten the baseline: the Enclave AI Level 2 Readiness Snapshot returns a PDF within minutes of intake, with measured findings for the requirements your connected sources can show and intake-based analysis for the rest.

Weeks 3-4: Documentation Sprint

Objective: Get every policy, procedure, and plan current and complete.

Your System Security Plan is the single most important document. It must accurately describe your CUI environment, how each control is implemented, and who is responsible for each control area. Update your SSP to reflect your current environment, not the environment you had when it was last written. In parallel, update or create all supporting documentation: access control policies, incident response plans, media protection procedures, configuration management plans, and any other procedures your SSP relies on. Each must align with the SSP and with what your systems actually do.

Weeks 5-7: Technical Remediation

Objective: Close the gaps identified in Weeks 1-2.

This is the most resource-intensive phase. Prioritize on two factors: which controls are not POA&M-eligible (a Conditional or Final Level 2 status needs these MET at the assessment), and which controls take the most time to implement. Address long-lead-time items first, such as deploying new security tools, reconfiguring network architecture, or establishing processes that require staff training. Activities can include deploying or configuring SIEM and log management, implementing MFA across all CUI-touching systems, establishing encrypted channels for CUI transmission, configuring endpoint detection and response, setting up automated vulnerability scanning, and strengthening network segmentation around CUI enclaves.

Before week one, get an honest read on how far your environment sits from the 110 controls. Start the free 10-question gap check →

Weeks 8-9: Evidence Collection and Organization

Objective: Build an evidence package assessors can validate efficiently.

For each of the 110 controls, compile evidence that demonstrates implementation and effectiveness: system screenshots showing configurations, policy documents with approval signatures, training records with dates and attendees, audit logs showing monitoring activity, vulnerability scan reports showing remediation, and incident response test results. Organize evidence by control family and control number so assessors can find what they need.

Week 10: Internal Readiness Review

Objective: Simulate the assessment before the real thing.

Conduct a mock assessment. Walk through every control as if the C3PAO were evaluating you. Test your documentation against your technical implementation, interview key personnel to confirm they can articulate their responsibilities, and address any remaining gaps immediately. An AaaS platform can help here: Enclave AI re-scans your connected sources about every seven days and re-issues the readiness package on your tier’s cycle, so the measured requirements reflect a recent scan rather than an old screenshot. Requirements no connected source can show still need your team’s own check.

Week 11: Personnel Preparation

Objective: Make sure everyone who interacts with assessors is ready.

Interview is one of the three assessment methods, with examine and test (NIST SP 800-171A), so expect the C3PAO to talk to the people who run the controls. System administrators need to explain technical implementations, managers need to articulate oversight processes, and end users need to demonstrate awareness of security practices. Prepare your team by reviewing what assessors will ask for each control area, running practice interviews, and confirming everyone knows the CUI boundary and their role within it.

Week 12: Final Validation and Assessment-Week Logistics

Objective: Eliminate last-minute surprises.

Run a final comprehensive check. Verify all evidence is current, all systems are configured as documented, all personnel are scheduled and available, and all physical access requirements are arranged. Confirm logistics with your C3PAO: schedule, participants needed each day, conference room and network access for assessors, and any documentation they want to review in advance.

Common Mistakes That Derail Preparation

These are the patterns to avoid. Underestimating documentation effort produces a rushed SSP that does not match reality. Ignoring the CUI boundary definition causes scope creep that inflates cost and complexity. Skipping practice interviews means the real interviews can reveal gaps that cannot be fixed in time. Treating POA&Ms as a safety net rather than a last resort leads to a Conditional status with a 180-day closeout clock (32 CFR 170.21).

A System, Not a Project

A twelve-week project gets you to one assessment. A system that re-measures on a stated schedule gives the next one a current starting point. Enclave AI re-scans connected sources about every seven days and delivers the readiness package on your tier’s cycle, so preparation starts from a current record rather than a scramble. The platform carries repetitive documentation work; your Affirming Official decides what is affirmed. Start with the $999 CMMC Level 2 Readiness Snapshot (one-time; if you start a Level 2 subscription with the same billing email within 30 days of receiving the Level 2 Readiness Snapshot PDF, the $999 is credited against your first Level 2 subscription payment, with any remainder applied to later invoices, per the refund policy), or read how to get CMMC certified for the full path.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read from 10 questions. The CMMC Level 2 Readiness Snapshot checks your intake, and the read-only configuration of any cloud you connect, against the 110-control NIST 800-171 baseline and returns a PDF within minutes of intake, for $999 one time. Your framework target is your choice: NIST SP 800-171 Rev. 2 (110 requirements, 320 assessment objectives; required and scored) by default, or NIST SP 800-171 Rev. 3 (97 requirements, 422 assessment objectives; emerging, no DoD score exists), selected at intake or from your workspace. CMMC Level 2 is bound to NIST SP 800-171 Rev. 2 today: 32 CFR 170.14(c)(3) states that the CMMC Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Readiness subscriptions are billed annually, with a month-to-month option on every tier.

Run the free 10-question gap check See the $999 Level 2 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures are the DoD's published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost.

Enclave AI™ is AI-native Agent-as-a-Service (AaaS) for CMMC Level 1 and Level 2 readiness and compliance operations. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee CMMC certification; certification assessments are conducted by an authorized C3PAO (Level 2) or DCMA DIBCAC (Level 3). The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.