If your company does business with the Department of Defense, or wants to, CMMC certification is no longer optional paperwork. It’s the difference between staying eligible for contracts and getting quietly dropped from a bid list. This guide walks through exactly what it takes to get certified, from figuring out which level applies to you through passing your assessment and staying compliant afterward.
In This Guide
- 01
What Is CMMC Certification? - 02
Step 1: Determine Your Required CMMC Level - 03
Step 2: Scope Your CUI/FCI Environment - 04
Step 3: Conduct a Gap Assessment - 05
Step 4: Build Your Remediation and Implementation Plan - 06
Step 5: Develop Required CMMC Documentation - 07
Step 6: Run a Mock Assessment / Readiness Review - 08
Step 7: Choose Your Assessment Path - 09
Step 8: Undergo the CMMC Assessment - 10
Step 9: Address Findings and Close Out Your POA&M - 11
Step 10: Receive and Maintain Your CMMC Status - 12
How Much Does CMMC Certification Cost and How Long Does It Take? - 13
Common CMMC Certification Mistakes to Avoid - 14
How Nexeris Helps You Get CMMC Certified - 15
FAQs
What Is CMMC Certification?
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that contractors and subcontractors are actually protecting the sensitive information they handle, not just claiming to. It replaces the old system of self-attestation, where a company could simply state it met NIST SP 800-171 requirements with no outside verification. Under CMMC, that claim has to be backed by evidence, and in many cases, by an independent assessor. These obligations trace back to DFARS clause 252.204-7012, which has required safeguarding of covered defense information since 2017. CMMC adds the verification layer DoD felt was missing, formalized through the newer DFARS 252.204-7019, 252.204-7020, and 252.204-7021 clauses that govern SPRS reporting and CMMC assessment requirements.
Why CMMC Certification Matters for DoD Contract Eligibility
CMMC status isn’t a nice-to-have credential. It’s a gate. Once the requirement appears in a solicitation or contract, you cannot bid, win, or continue performing on that work without the appropriate CMMC level. Primes are also required to flow the requirement down to their subcontractors, so even companies several tiers removed from the government can find themselves needing certification to keep a contract. The financial stakes are real. Losing CMMC eligibility doesn’t just cost you the next contract. It can jeopardize existing revenue if a current contract’s requirements tighten mid-performance.
The DoD’s Phased CMMC Rollout (2025–2028)
CMMC was originally structured as a four-phase rollout from November 2025 through November 2028. However, the Department suspended the transition to Phase 2 in July 2026 while it reviews the structure and future direction of the program.
- Phase 1: November 10, 2025 to November 9, 2026. Contracting officers began including Level 1 and Level 2 self-assessment requirements in applicable solicitations and contracts. Selected Phase 1 procurements could also require Level 2 C3PAO certification. Phase 1 remains in effect.
- Phase 2: Originally scheduled to begin November 10, 2026. Level 2 C3PAO certification was expected to become a requirement for applicable solicitations and contracts, with Level 3 requirements potentially appearing in selected procurements. The transition to Phase 2 is currently suspended.
- Phase 3: Originally scheduled to begin November 10, 2027. Level 3 certification assessments conducted by DCMA DIBCAC were expected to become requirements for applicable solicitations and contracts. This milestone is also affected by the current suspension and review.
- Phase 4: Originally scheduled to begin November 10, 2028. Full implementation was expected to bring applicable CMMC requirements into all covered DoD solicitations and contracts. The timing of this phase may change depending on the outcome of the current review.
Important 2026 Update: CMMC Phase 2 Suspended
On July 13, 2026, the Department announced the immediate suspension of the transition to CMMC Phase 2, which had been scheduled to begin November 10, 2026. Phase 1 self-assessment requirements remain in effect, but pending and future CMMC implementation milestones have been suspended while the Department reassesses the program. The Department also launched a 60-day review focused on the future structure of CMMC, including ways to reduce compliance burdens and barriers for small, medium-sized, and non-traditional defense contractors while maintaining cybersecurity protections. Until new guidance is released, organizations should not interpret the suspension as eliminating their existing cybersecurity obligations. Requirements to protect covered defense information, including applicable NIST SP 800-171 requirements under DFARS 252.204-7012, remain in place.
CMMC 2.0 vs. Legacy Self-Attestation
Under the pre-CMMC system, a contractor could sign a document stating it met NIST 800-171 and move on, with no outside check, no standardized scoring, and no consequences beyond a potential audit years later. CMMC 2.0 changes that in three ways: it defines exactly which controls apply at each level, it requires documented evidence rather than a signature, and for many organizations handling CUI, it requires an independent third-party assessment rather than a self-assessment. The result is a system that’s harder to fake and easier for the DoD to verify at scale.
Step 1: Determine Your Required CMMC Level
Before anything else, you need to know which of the three CMMC levels applies to your organization. Guessing wrong here wastes months of preparation on the wrong set of controls.
Level 1 (Foundational): FCI Only
Level 1 applies to organizations that handle only Federal Contract Information: non-public information the government provides or generates as part of your contract, but that isn’t sensitive enough to be classified as CUI. Level 1 requires implementing 15 basic security practices and is verified through an annual self-assessment. No third-party assessor is required.
Level 2 (Advanced): CUI Handling
Level 2 is where most defense contractors land. If your system processes, stores, or transmits Controlled Unclassified Information, you need Level 2 at minimum. This level requires implementing all 110 security requirements from NIST SP 800-171, and depending on what your contract specifies, it may require either a self-assessment or a full third-party assessment conducted by a Certified Third-Party Assessment Organization (C3PAO).
Level 3 (Expert): Critical Programs
Level 3 is reserved for a small number of contractors supporting the DoD’s most sensitive programs, where the risk of advanced persistent threats is highest. It builds on Level 2 by adding 24 enhanced security requirements from NIST SP 800-172 and is assessed directly by the government’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not a commercial C3PAO.
Confirming Your Level Through Contract Language (DFARS 252.204-7021)
Don’t assume your level. Confirm it. Your contracts and solicitations will specify the required CMMC level through DFARS clause 252.204-7021, with the specific level identified in DFARS provision 252.204-7025. If the language is ambiguous or you’re unsure whether the information you handle counts as FCI or CUI, ask your contracting officer directly before you start preparing. Pursuing the wrong level wastes time, money, and credibility.
Step 2: Scope Your CUI/FCI Environment
Once you know your level, the next move is defining exactly which parts of your organization are actually subject to assessment. This step, known as scoping, has more influence on your total cost and timeline than almost anything else in the process.
Defining Your Assessment Boundary
Your assessment boundary is the documented perimeter around every system, process, and location that touches FCI or CUI. Everything inside that boundary gets assessed against the applicable security requirements; everything genuinely outside it doesn’t. Scoping isn’t a guess. It has to be backed by a network diagram and an asset inventory that an assessor can independently verify.
In-Scope Assets, People, Facilities and ESPs
Scope isn’t limited to servers and laptops. A complete scoping exercise accounts for:
- People who have access to CUI or FCI, including employees, contractors, and vendor personnel
- Facilities, including office locations, data centers, and any shared spaces like network operations centers
- Technology, from workstations and cloud instances to backup systems and email servers
- External Service Providers (ESPs), such as managed IT providers, cloud platforms, and security operations centers that touch or protect your CUI environment
Overlooking any one of these categories is one of the most common reasons scoping fails during an assessment.
Why Tight Scoping Reduces Cost and Risk
A narrow, well-documented boundary is almost always cheaper and faster to certify than a broad one. Many organizations reduce scope by building a dedicated CUI enclave, a logically or physically separated environment where all CUI-related work happens, so the rest of the corporate network stays out of the assessment entirely. Over-scoping means paying to secure and document systems that never needed to be included. Under-scoping means CUI ends up on systems that were never assessed or secured, leaving real gaps in protection and an affirmation that doesn’t reflect reality. That exposure may surface later through a breach, a DIBCAC audit, or a False Claims Act claim, rather than during the CMMC assessment itself.
Step 3: Conduct a Gap Assessment
With your scope defined, it’s time to find out how far you actually are from meeting the requirements.
Comparing Current Posture Against NIST SP 800-171
A gap assessment measures your current security controls against the 110 requirements in NIST SP 800-171, organized across 14 control families and broken down into 320 individual assessment objectives. These cover areas such as access control, audit and accountability, configuration management, incident response, and more. The output is a clear list of what’s already implemented, what’s partially in place, and what’s missing entirely.
Common Gaps Found in First-Time Assessments
Organizations going through this for the first time tend to hit the same walls repeatedly: multi-factor authentication not enforced consistently across all privileged accounts, audit logging that exists but isn’t centralized or reviewed, incident response plans that were written once and never tested, and a System Security Plan that doesn’t exist yet or is dangerously out of date.
Should You Use an RPO or Consultant?
Level 1 gap assessments are often manageable internally if you have the expertise. Level 2 is a different story. The scope, documentation burden, and technical depth typically require outside help from a Registered Provider Organization (RPO) or an experienced CMMC consultant. A good consulting partner brings pattern recognition from other engagements, catches gaps an internal team might miss, and can move faster because they’ve built the documentation before. If you’re weighing internal effort against outside help, working with a firm that offers dedicated CMMC compliance services can significantly shorten the timeline, reduce costs, and minimize time wasted on avoidable mistakes.
Step 4: Build Your Remediation and Implementation Plan
The gap assessment tells you what’s missing. This step is where you actually close those gaps.
Prioritizing Technical Controls (MFA, Encryption, Logging)
Start with the technical controls that carry the most weight in an assessment: multi-factor authentication across all privileged and remote access, FIPS-validated encryption for CUI at rest and in transit, centralized audit logging with active monitoring, and network segmentation that keeps your CUI environment isolated from the rest of your infrastructure.
Closing Policy and Procedural Gaps
Technical controls only get you halfway. Assessors also expect to see formal, written policies and procedures covering access control, incident response, configuration management, and change management, and they expect those documents to reflect what your organization actually does, not an aspirational future state.
Realistic Timelines by Level
Implementation timelines vary widely based on starting maturity. Level 1 organizations with reasonably mature IT practices can often close their gaps in a matter of months. Level 2 organizations should plan for a longer runway. Twelve to 18 months is typical for a moderately mature environment, and organizations starting from a low security baseline should budget closer to 18 to 24 months. Building in buffer time for unexpected complications is not optional; it’s standard practice.
Step 5: Develop Required CMMC Documentation
Documentation is not an afterthought in CMMC. It’s often the single largest body of work in the entire process, and it’s what assessors spend the most time reviewing.
System Security Plan (SSP)
Your System Security Plan is the authoritative document describing exactly how every applicable security control is implemented across your environment. For a mid-sized contractor, a complete SSP can easily run past 200 pages and take several months of dedicated work to produce. It needs to cover every in-scope system, who’s responsible for each control, how it’s tested, and where the supporting evidence lives.
Policies, Procedures and Standard Operating Procedures
Beyond the SSP, you’ll need formal policies and standard operating procedures covering every required domain: access control, incident response, configuration management, and more. Starting from free CMMC policy templates rather than a blank page can save significant time, as long as the templates are then tailored to reflect your actual environment rather than left generic.
Plan of Action & Milestones (POA&M)
Any gap you haven’t fully closed by the time of assessment needs to be tracked in a formal Plan of Action & Milestones, with a clear owner and target date for remediation. For Level 2 and Level 3, a limited number of open items can be acceptable at assessment time, but not all controls are POA&M-eligible, and the ones that are must be closed within a strict window after assessment.
Network Diagrams and CUI Data Flows
Assessors need to see, visually, how CUI moves through your environment: where it enters, where it’s stored, how it’s transmitted, and where the security boundary sits. A clear network diagram and CUI data flow map make it dramatically easier for an assessor to validate your scope and controls quickly.
Evidence Collection and Organization
Documentation without evidence is just a story. Start collecting proof early: configuration screenshots, training records, audit logs, vulnerability scan results, and access control lists. Organizations that keep this evidence organized as they go, rather than scrambling to assemble it right before assessment, consistently have smoother, faster assessments.
Step 6: Run a Mock Assessment / Readiness Review
Before you bring in a formal assessor, run your own dress rehearsal.
Why a Pre-Assessment Review Improves Pass Rates
A mock assessment, conducted internally or by a third party, tests your documentation, evidence, and staff readiness against the same methodology a real assessor will use. It’s the single most effective way to catch problems while they’re still cheap and easy to fix. Using a structured CMMC audit readiness checklist during this phase helps make sure nothing gets overlooked.
What to Test Before the Real Assessment
Focus your mock assessment on the areas that most commonly derail real ones: whether your SSP matches your actual environment, whether staff can speak confidently to the controls they’re responsible for, whether your evidence is current and in final (not draft) form, and whether your network diagram and asset inventory are consistent with each other.
Step 7: Choose Your Assessment Path
Once you’re confident in your readiness, it’s time to formally commit to an assessment path.
Level 1 & Eligible Level 2: Self-Assessment and SPRS Submission
If you’re pursuing Level 1, or a Level 2 contract that permits self-assessment, you’ll conduct the assessment internally against the applicable practices, document your findings, and submit the results to the DoD’s Supplier Performance Risk System (SPRS), along with an annual affirmation signed by a designated official.
Level 2 (C3PAO): Selecting a Certified Third-Party Assessor
If your contract requires Level 2 (C3PAO) certification, you’ll need to select a Certified Third-Party Assessment Organization from the Cyber AB Marketplace. Request proposals from a few candidates, check references, and confirm their experience with organizations similar in size and complexity to yours. Give yourself several weeks for this selection process, since demand for qualified assessors often outpaces availability.
Level 3: DIBCAC Government-Led Assessment
Level 3 assessments are conducted directly by the government through DIBCAC, not a commercial C3PAO, and require that you’ve already achieved Final Level 2 (C3PAO) status covering the same assessment scope.
Step 8: Undergo the CMMC Assessment
This is the moment all the preparation has been building toward.
The Examine, Interview, Test (EIT) Methodology
Assessors evaluate every applicable control using three methods: examining your documentation, mechanisms, and artifacts; interviewing staff at various levels to confirm they understand and actually perform the required practices; and testing controls directly, such as observing an authentication process or verifying a configuration setting functions as documented.
What Assessors Actually Look For
Beyond simple compliance, assessors are looking for evidence that your controls are consistently enforced, not just implemented on paper. They want to see that logging and monitoring are actively used, that staff can speak knowledgeably about their responsibilities without reciting a script, and that your SSP reflects current reality rather than a plan you intend to implement someday.
Assessment Scoring and Passing Thresholds
For Level 2, each of the 110 requirements is scored, and organizations need a minimum passing score to achieve certification. Requirements that aren’t fully met but are eligible for remediation can be tracked through a POA&M rather than causing an outright failure, but certain high-priority controls must be fully met with no exceptions.
Step 9: Address Findings and Close Out Your POA&M
Very few organizations pass every single requirement on the first attempt. What happens next depends on how significant the gaps are.
Conditional vs. Final CMMC Status
If you meet the minimum passing threshold but have a limited number of eligible open items, you’ll receive a Conditional CMMC Status rather than being denied outright. Meeting every applicable requirement outright earns Final status immediately.
The 180-Day POA&M Closeout Window
Conditional status comes with a strict deadline: all POA&M items must be fully closed out, verified, and confirmed through a formal closeout assessment within 180 days. Missing that window causes your conditional status to expire, which means losing eligibility until you re-assess.
Controls That Cannot Use POA&M
Not every unmet requirement is eligible for a POA&M. A small set of the highest-priority security controls must be fully implemented at the time of assessment with no deferral option. If you fail one of these, remediation and re-assessment are required before certification can be granted.
Step 10: Receive and Maintain Your CMMC Status
Getting certified is a milestone, not a finish line. Maintaining that status requires ongoing discipline.
Annual Affirmations
Every CMMC level requires an annual affirmation, a signed statement from a designated official confirming your organization continues to meet its applicable requirements. This isn’t a formality; it’s a legal attestation the government can hold you to.
Triennial Reassessment Cycle
Level 2 and Level 3 certifications are valid for three years, after which a full reassessment is required to maintain your status. Level 1 self-assessments must be renewed annually.
Continuous Monitoring Between Assessments
Between formal assessments, your environment doesn’t stand still. New tools get adopted, staff change roles, and configurations drift. Organizations that treat compliance as a one-time project rather than an ongoing program often find themselves scrambling to rebuild evidence and close new gaps before their next reassessment. It’s worth staying current on program developments, including the CMMC Phase 2 status, since rollout timelines and requirements have continued to shift.
How Much Does CMMC Certification Cost and How Long Does It Take?
Cost by Level (Implementation, Assessment, Maintenance)
Costs vary enormously based on organization size, current security maturity, and scope. As a general guide: Level 1 organizations typically spend in the range of a few thousand to tens of thousands of dollars in the first year, factoring in implementation and self-assessment support. Level 2 organizations should expect a considerably larger investment once gap assessment, remediation, documentation, and (if required) C3PAO assessment fees are included, often well into six figures for organizations starting from a lower security baseline. Level 3 costs are higher still, given the additional NIST SP 800-172 requirements and government-led assessment process. Ongoing annual maintenance costs apply at every level and should be budgeted as a permanent line item, not a one-time expense.
Timeline by Level (Gap Assessment Through Certification)
Level 1 organizations can often move from gap assessment to certification within several months. Level 2 organizations, particularly those with lower initial security maturity, should plan for a considerably longer timeline, commonly well over a year when accounting for gap assessment, remediation, documentation, and the assessment process itself. Level 3 adds additional time on top of an already-completed Level 2 certification. Starting early is the single best way to control both cost and timeline.
Common CMMC Certification Mistakes to Avoid
Waiting Until CMMC Appears in a Solicitation
Preparation, especially for Level 2, takes far longer than most organizations expect. Waiting until a solicitation explicitly requires CMMC status often means missing the bid entirely, since certification can’t be rushed to meet a submission deadline.
Incorrect or Overly Broad Scoping
Scoping mistakes are one of the most expensive errors in the entire process. Too broad, and you’re paying to secure and document systems that never needed to be in scope. Too narrow, and an assessor eventually finds CUI somewhere outside your documented boundary, a problem that can stall or fail an assessment outright.
Treating Certification as a One-Time Project
CMMC isn’t a certificate you earn once and forget about. Organizations that don’t build ongoing monitoring, periodic internal reviews, and change management into their operations tend to find themselves out of compliance well before their next reassessment is even due, sometimes without realizing it until an incident or audit exposes the gap.
How Nexeris Helps You Get CMMC Certified
Getting certified involves scoping, gap assessment, remediation, hundreds of pages of documentation, evidence collection, mock assessments, and formal assessor coordination, and most organizations don’t have the internal bandwidth or specialized expertise to run that process alone while still doing the work that pays the bills. That’s where working with an experienced CMMC compliance consulting partner makes the difference. As a dedicated CMMC consultant, Nexeris scopes your environment, closes technical and documentation gaps, Develops your SSP and supporting policies, runs a mock assessment before the real one, and represents you directly through the formal assessment process, so your team stays focused on delivering contract work instead of chasing compliance paperwork. Whether you’re just starting to evaluate your required level or you’re deep into remediation and need CMMC compliance services to get across the finish line, a dedicated CMMC compliance consultant can shorten your timeline and reduce the risk of a failed first attempt.
FAQs
How long does it take to get CMMC certified?
It depends heavily on your level and starting security maturity. Level 1 organizations can often certify within several months. Level 2 organizations should plan for a longer runway, commonly well over a year when accounting for gap assessment, remediation, documentation, and the formal assessment process, especially if starting from a lower security baseline.
How much does CMMC certification cost?
Costs scale with your level and current maturity. Level 1 is generally the least expensive, often in the low tens of thousands of dollars in the first year. Level 2 typically runs considerably higher once gap assessment, remediation, documentation, and C3PAO assessment fees are included, particularly for organizations with more ground to cover. Level 3 costs are higher still due to the additional enhanced requirements and government-led assessment.
Do I need a C3PAO, or can I self-assess?
It depends on your contract. Level 1 always permits self-assessment. Some Level 2 contracts allow a self-assessment path, while others explicitly require a third-party C3PAO assessment. Check your specific contract language or ask your contracting officer to confirm which applies to you.
What happens if I fail my CMMC assessment?
For Level 2 and Level 3, meeting the minimum passing score with a limited number of eligible open items results in a conditional status rather than an outright failure, giving you a defined window to close those items through a POA&M. If you don’t meet the minimum threshold, or if a required control that can’t use a POA&M isn’t met, you’ll need to remediate and undergo a new assessment.
How often do I need to renew CMMC certification?
Level 1 requires annual self-assessment renewal. Level 2 and Level 3 certifications are valid for three years, with annual affirmations required in between, followed by a full reassessment at the end of the three-year cycle.
Do subcontractors need their own CMMC certification?
Yes. Prime contractors are required to flow CMMC requirements down to subcontractors handling FCI or CUI. Subcontractors need to hold CMMC status at the level appropriate to the information they process, store, or transmit under the subcontract, regardless of how many tiers removed they are from the government.
