If you are a defense contractor handling Controlled Unclassified Information (CUI), the window to prepare for your CMMC assessment is closing fast. Phase 2 of the CMMC rollout takes effect on November 10, 2026, and it makes third-party certification by a Certified Third-Party Assessment Organization (C3PAO) mandatory for most contracts involving CUI. The CMMC Final Rule under 32 CFR Part 170 took effect on December 16, 2024, and the complementary DFARS acquisition rule went into effect on November 10, 2025. New DoD solicitations are already including CMMC requirements as a condition of contract award.
As someone who has conducted CMMC Level 2 certification assessments and seen organizations both succeed and fail, I can tell you that the difference almost always comes down to preparation. This guide walks you through exactly how to prepare for a CMMC assessment—from understanding which level applies to you, all the way through assessment day and beyond.

1. Understand Which CMMC Level You Need
Before anything else, determine the CMMC level your organization requires. The framework established by the DoD CIO CMMC Program has three levels, each tied to the sensitivity of the data you handle.
CMMC Level 1 applies to contractors that only handle Federal Contract Information (FCI). It involves 17 basic safeguarding practices aligned with FAR 52.204-21 and requires an annual self-assessment. There are no POA&Ms allowed at this level—every practice must be fully implemented.
CMMC Level 2 is where most defense contractors land. If your contracts involve CUI, you almost certainly need Level 2 compliance. This level aligns with all 110 security requirements in NIST SP 800-171 Revision 2 and requires either a self-assessment or a third-party certification assessment conducted by a C3PAO, depending on contract language. Check your solicitation for the DFARS 252.204-7021 clause—it will specify “CMMC Level 2 (Self)” or “CMMC Level 2 (C3PAO).”
CMMC Level 3 is reserved for high-priority DoD programs and adds selected requirements from NIST SP 800-172. Government assessors from DCMA DIBCAC conduct these assessments. Most contractors will never need Level 3.

If you handle CUI and your contracts contain DFARS 252.204-7012 (Safeguarding Covered Defense Information), plan for Level 2 C3PAO certification. That is the safest assumption heading into Phase 2.
2. Define Your CMMC Assessment Scope
Scoping is one of the most consequential decisions you will make, and it is where I see organizations get into trouble most often during assessments. Your CMMC assessment scope—as defined in 32 CFR § 170.19—defines which systems, networks, people, and facilities will be evaluated against the 110 NIST SP 800-171 security requirements.
Start by identifying every system that processes, stores, or transmits CUI. Map how CUI flows through your organization—from the moment it enters your network to where it is stored, shared, and eventually disposed of. Every asset that touches CUI falls within scope.
You must also classify your assets into the categories defined by the CMMC scoping guidance: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. The DoD CIO publishes detailed scoping guidance on the CMMC Resources & Documentation page. This classification directly determines what the C3PAO will evaluate.

A common mistake is scoping too broadly, which inflates costs and complexity. Another equally dangerous mistake is scoping too narrowly, which leads to assessment failures when the C3PAO discovers unassessed systems handling CUI. The goal is an accurate, defensible boundary. Consider establishing a CUI enclave—a segmented portion of your network dedicated to CUI processing—to reduce your assessment footprint while maintaining compliance.
3. Conduct a Thorough Gap Assessment
Once your scope is defined, perform a gap assessment against all 110 NIST SP 800-171 security requirements and their 320 assessment objectives as defined in NIST SP 800-171A. This is non-negotiable. You need to know exactly where your gaps are before you engage a C3PAO.
A proper gap assessment evaluates each security requirement across three assessment methods: examining documentation and artifacts, interviewing personnel responsible for implementation, and testing technical controls on live systems. If you only review documentation without testing controls in practice, you will have blind spots that a C3PAO assessment team will find.
Document your current SPRS score based on the DoD’s scoring methodology. Each of the 110 requirements carries a point value of 1, 3, or 5 points, and your score starts at 110 and decreases for every unmet requirement. Your SPRS score must be entered into the Supplier Performance Risk System (SPRS) and is a prerequisite for contract eligibility.

The gap assessment gives you a remediation roadmap. Prioritize closing gaps on the higher-weighted 5-point and 3-point requirements first, as these have the greatest impact on your score.
4. Build and Refine Your Core Documentation
Documentation failures are the single most common cause of “false starts” in CMMC assessments. I have seen organizations that implemented security controls properly but could not demonstrate it because their documentation was incomplete, inconsistent, or outdated. Here are the documents you must have ready.
System Security Plan (SSP): This is the most critical document your C3PAO will review. Your SSP must describe how your organization implements each of the 110 NIST SP 800-171 security requirements within your defined assessment scope. It should include your network architecture diagrams, data flow diagrams, system boundaries, and a description of every component within scope. A vague or generic SSP will raise red flags with any experienced assessor.
Plan of Action and Milestones (POA&M): Under CMMC, you can achieve Conditional Level 2 certification with a POA&M for certain unmet requirements. However, you must still meet at least 80% of requirements (88 out of 110) as fully implemented. Per 32 CFR § 170.21, certain foundational requirements aligned with FAR 52.204-21 and DFARS 252.204-7012 cannot be placed on a POA&M at all. If you receive a conditional certification, you have exactly 180 days to close all POA&M items and pass a closeout assessment, or your certification expires.
Policies and Procedures: You need written cybersecurity policies covering all 14 NIST SP 800-171 control families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Each policy should define organizational responsibilities, enforcement mechanisms, and review cycles.
Customer Responsibility Matrices (CRMs): If you rely on cloud service providers, managed service providers, or any external service for meeting CMMC security requirements, you need CRMs from each provider documenting which controls they satisfy and which remain your responsibility. Cloud service providers handling CUI must meet FedRAMP Moderate baseline equivalency. Missing CRMs are a frequent cause of assessment delays.

5. Implement and Test Your Security Controls
With gaps identified and documentation underway, the next phase is to implement and harden your technical and operational controls. This is where your CMMC compliance becomes real.
Ensure that multi-factor authentication (MFA) is enforced for all CUI access—both local and remote. Configure your systems with FIPS-validated encryption for CUI at rest and in transit. Implement robust audit logging that captures user actions on CUI systems and retain those logs in accordance with your policy requirements. Lock down your access controls so that CUI access follows the principle of least privilege.
Beyond technical controls, train your workforce. Every employee who accesses CUI systems must receive security awareness training, and personnel in security-significant roles must receive role-based training. The assessor will interview your staff during the assessment, and their answers need to reflect a genuine understanding of their responsibilities under your organization’s cybersecurity policies.

Once controls are in place, test them rigorously. Run vulnerability scans, verify that your SIEM is capturing the right events, test your incident response plan with a tabletop exercise, and confirm that your configuration baselines match what is documented in your SSP. Do not wait for the C3PAO to find discrepancies between your documentation and your live environment.
6. Select and Engage Your C3PAO Early
This is not optional advice—it is a strategic imperative. There are approximately 80 authorized C3PAOs serving an estimated 76,000-plus organizations that need Level 2 certification. Assessment capacity is severely constrained, and scheduling lead times currently range from three to six months. By late 2026, wait times could exceed 18 months.
Only engage a C3PAO that is authorized by the Cyber AB. Verify their status on the Cyber AB Marketplace. Ask about their assessment methodology, their team’s experience, and their availability. Get pricing in writing—assessment fees currently range from roughly $31,000 to $150,000, depending on organizational complexity, and costs are expected to rise significantly as demand outstrips supply.
Do not schedule your C3PAO assessment until your organization is genuinely ready. Scheduling too early leads to assessment failures, which wastes your budget and delays your certification. Plan to book your assessment slot 8 to 12 weeks before your contract deadline, and only after you have completed your gap remediation, finalized your SSP, and verified your controls through internal testing.
7. Know What to Expect During Assessment Week
A CMMC Level 2 C3PAO assessment typically spans about one week of intensive activity, preceded by roughly three months of pre-assessment coordination. The CMMC Assessment Process (CAP) is the official procedural guide used by C3PAOs and their CMMC Certified Assessors (CCAs) to ensure consistency and integrity across all assessments.
During the pre-assessment phase, the C3PAO validates your readiness. You will upload your SSP, network diagrams, data flow diagrams, policies, procedures, and CRMs for review. A scoping call (typically about 90 minutes) lets the assessment team confirm your assessment boundary, asset categorization, and whether on-site evaluation is required.
The assessment phase begins with an in-brief meeting where the lead CCA aligns on scope, schedule, and procedures. The assessment team then evaluates your controls through documentation review, personnel interviews, and technical testing. They meet with your team daily to track progress and address questions. Every security requirement is scored against its assessment objectives.
In the post-assessment phase, an independent quality assurance review is conducted by a CCA outside the assessment team. Results are finalized and presented to your organization in an out-brief before being submitted to the CMMC system of record in SPRS.

Your outcome will be one of three results: Final Level 2 (C3PAO) certification if all 110 requirements are met, Conditional Level 2 (C3PAO) certification if you meet at least 88 requirements with a valid POA&M for the rest, or no CMMC status if you fall below the 80% threshold.
8. Maintain Compliance After Certification
CMMC certification is not a one-time event. Your Level 2 certification is valid for three years, but you must submit annual affirmations to maintain your status. If your affirmation lapses, so does your certification and your contract eligibility.
Treat CMMC compliance as a continuous program. Monitor your controls, update your SSP when systems change, conduct periodic internal assessments, and keep your workforce training up to date. Build a relationship with your C3PAO for your triennial reassessment. The DoD also retains the right to conduct its own assessment of your organization under DFARS 252.204-7020, and if their findings show non-compliance, their determination takes precedence over your existing certification.
9. Understand the Subcontractor Flowdown Requirements
One area that catches many organizations off guard is subcontractor flowdown. Under 32 CFR § 170.23, CMMC requirements must be flowed down to every tier of the supply chain. If your prime contract requires Level 2 C3PAO certification, every subcontractor that processes, stores, or transmits CUI on your behalf must also hold Level 2 certification. Subcontractors that only handle FCI need Level 1 at a minimum.

Prime contractors such as Lockheed Martin, Boeing, and Raytheon are already screening their supply chains for CMMC-ready suppliers. If you are a subcontractor, do not wait for your prime to push the requirement onto you. If you are a prime, begin mapping your subcontractor compliance status now; a single non-compliant subcontractor can jeopardize your entire contract.
10. Start Now—The Clock Is Ticking
As of early 2026, fewer than 2% of organizations in the Defense Industrial Base have achieved Level 2 C3PAO certification. The November 2026 Phase 2 deadline will bring a surge in demand that current assessor capacity simply cannot absorb. DoD projections from the 32 CFR Final Rule show C3PAO assessment capacity ramping from 517 assessments in Year 1 to 2,599 in Year 2 and 8,666 in Year 3—but demand will substantially outpace that capacity well into the Phase 2 window.

Organizations that begin preparation now will secure C3PAO availability, control costs, and position themselves as preferred partners for prime contractors who are already building CMMC-certified supply chains. Your CMMC assessment preparation is not just a compliance exercise—it is a business survival strategy.
Define your scope. Close your gaps. Perfect your documentation. Engage a C3PAO before the window closes. The contractors who certify first will win contracts. The rest will be left behind.
CMMC Assessment Guide (cmmcassessmentguide.com) provides expert guidance on CMMC compliance, assessment preparation, and cybersecurity best practices for the Defense Industrial Base.


