
CMMC Certification Timeline for First-Time Contractors
How Early Should You Start?
For a first-time defense contractor, the hardest part of CMMC timing is not the assessment itself. It is discovering six weeks before a proposal deadline that the environment, evidence, cloud services, System Security Plan, or assessment scope was never ready to be examined.
There is also an important 2026 wrinkle. CMMC Phase 1 began on November 10, 2025, but the department suspended the planned transition to Phase II on July 13, 2026. Phase I self-assessment requirements remain in place, so the suspension should not be read as permission to stop preparing.
The practical question is therefore not simply, “When does CMMC start?” It is: What CMMC status could your next solicitation require, how much remediation separates you from that status, and when must the result exist in SPRS?
Work backward from procurement requirements, not a generic rollout date.
Scope, technical gaps, evidence and service providers usually control the schedule.
Know when DIY readiness work ends and independent assessment work begins.
Planning rule: if CUI may enter your environment, begin the readiness clock months before you expect to need a formal status, not when the solicitation lands. 🛡️
Snapshot
This guide is for first-time U.S. defense contractors and subcontractors trying to estimate how long CMMC readiness and assessment may take. You will learn how the 2026 Phase II suspension affects planning, how Level 1 and Level 2 schedules differ, what commonly causes delays, and how to build a realistic date backward from a future procurement.
Table of Contents
- What Is the CMMC Timeline as of August 2026?
- Which CMMC Level Determines Your Deadline?
- A Practical First-Time CMMC Timeline
- What Changes the Timeline Most?
- What Must Be Ready Before an Assessment?
- DIY, Software or Professional Help?
- When Should You Schedule a C3PAO?
- CMMC Timeline Mistakes That Cost Months
- FAQ
- Your 15-Minute CMMC Timeline Check

What Is the CMMC Timeline as of August 2026?
There is currently no single certification date that every first-time contractor should place on a calendar.
Phase 1 began on November 10, 2025. On July 13, 2026, the department suspended the transition to Phase II, which had been scheduled to begin on November 10, 2026. The official CMMC site states that implementation is paused in Phase 1 and that Phase I self-assessment requirements remain in place.
That makes procurement-specific language more important than the old phase calendar. A solicitation containing an applicable CMMC requirement can require the necessary status before award, with the relevant status and affirmation recorded in SPRS.
Before You Act
CMMC obligations can differ by solicitation, subcontract, information type, assessment scope and contract clause. This guide is a planning resource, not individualized legal or contracting advice. Confirm material bid and compliance decisions against the current solicitation, contract flowdowns, 32 CFR Part 170, applicable DFARS clauses and qualified advisers where necessary.
The old November 2026 assumption is no longer safe
Before the suspension, the published four-phase implementation model called for Phase 2 to begin on November 10, 2026, with Level 2 certification requirements appearing where applicable. That transition has now been suspended. The earlier roadmap remains useful historical context, but it should not be treated as a current guaranteed deadline.
Phase 1 does not mean “nothing to do”
The department has said that Phase I self-assessment requirements remain and that it will continue enforcing NIST SP 800-171 Revision 2 compliance through self-assessments and select government-led assessments during the review period.
For a company planning to enter the Defense Industrial Base, this is valuable breathing room only if you use it to reduce uncertainty. Scope the environment, identify whether FCI or CUI is involved, establish evidence, close major control gaps and understand what your likely contracts will demand.
Key takeaway: build your internal readiness schedule around the date you want to be eligible for an award. Government-wide phase dates are secondary to the requirement actually written into the procurement.

Which CMMC Level Determines Your Deadline?
The word “certification” is often used loosely. CMMC includes self-assessment statuses as well as third-party and government certification assessments. That distinction can change your timeline dramatically.
| Possible Requirement | Assessment Method | Maintenance Cycle | Planning Consequence |
|---|---|---|---|
| Level 1 | Self-assessment | Annual self-assessment and affirmation | No C3PAO scheduling, but every applicable requirement must be MET |
| Level 2 Self | Organization self-assessment | Assessment every three years plus annual affirmation | More evidence and technical depth, but no third-party certification engagement |
| Level 2 C3PAO | Authorized or accredited C3PAO | Certification assessment every three years plus annual affirmation | Add assessor selection, contracting, scheduling and formal evidence review |
| Level 3 | DCMA DIBCAC | Three-year assessment cycle plus annual affirmation | Requires Final Level 2 C3PAO status first and substantially more planning |
Under 32 CFR Part 170, Level 1 requires an annual self-assessment and does not permit POA&Ms. Level 2 self-assessments and Level 2 C3PAO certification assessments operate on three-year assessment cycles, with annual affirmations.
If you handle only FCI
Level 1 scope centers on contractor information systems that process, store or transmit Federal Contract Information. Identifying those systems accurately can keep an otherwise small environment from becoming a sprawling compliance project.
If you will handle CUI
Level 2 planning is more demanding because the assessment scope can include CUI assets, security protection assets, contractor risk managed assets and certain service-provider relationships. CUI Assets are assessed against the Level 2 security requirements, while other asset categories receive treatment defined by the scoping rules.
Do not assume that merely handling CUI tells you whether your procurement will call for Level 2 Self or Level 2 C3PAO. The solicitation or contractual requirement is the document that matters for your award decision.
If the contract requires Level 2 C3PAO
The formal assessment must be performed by an authorized or accredited C3PAO, and the results are submitted through the CMMC process for transmission to SPRS. A required Level 2 C3PAO status must exist before award when the solicitation makes that status a condition of eligibility.
The answer changes when: your information moves from FCI to CUI, your procurement changes from self-assessment to C3PAO certification, your CUI footprint expands, or an external provider becomes part of the assessment scope.
A Practical First-Time CMMC Timeline
No regulation promises that a new contractor can become assessment-ready in a fixed number of weeks. A company with a tightly isolated CUI enclave and mature controls may move much faster than a business trying to retrofit CMMC across years of unmanaged systems.
The following planning bands are therefore editorial planning ranges, not government deadlines. They are useful for building a project schedule before you know the precise remediation workload.
First-Time CMMC Readiness Sequence
Identify FCI, CUI, systems, users, facilities and providers.
Assess requirements and document current implementation.
Close technical, process and documentation gaps.
Stabilize evidence and test whether practices actually operate.
Complete the required self, C3PAO or government assessment.
Weeks 0 to 2: establish scope before buying anything
Start with contracts and data, not products. Determine what information you expect to receive, where it will live, who will access it, which endpoints touch it, which identity systems protect it and which external providers support the environment.
- Identify likely FCI and CUI flows.
- List in-scope users, endpoints, servers and cloud services.
- Map security protection services such as identity, logging, backup and endpoint security.
- Identify external service providers and cloud providers.
- Decide whether a smaller controlled enclave is feasible.
A week spent correcting scope can save months of implementing controls on systems that never needed to be included.
Weeks 2 to 6: baseline the environment and build the evidence map
Evaluate each applicable requirement against what actually exists. Separate three conditions: implemented and provable, implemented but poorly evidenced, and not adequately implemented.
This is also when the SSP becomes a living representation of the environment rather than a document written in isolation. Your policies, technical settings, screenshots, logs, tickets, account records, diagrams and procedures should tell the same story.
Month 2 onward: remediation controls the schedule
A relatively mature contractor may spend only a few months closing targeted gaps. A company redesigning identity, separating CUI, migrating cloud workloads, establishing logging, formalizing access reviews and replacing unsupported systems may need substantially longer.
For an organization that expects a future Level 2 C3PAO requirement but has never built against NIST SP 800-171, roughly four to twelve months or more is a sensible planning envelope for the entire readiness project. Treat that as contingency planning, not an official estimate. Your own gap assessment should replace it as soon as possible.
Decision rule: if the gap assessment shows architecture changes, cloud migration or identity redesign, measure your CMMC schedule in months. If the environment already satisfies the requirements and the problem is mainly evidence quality, the schedule can be considerably shorter.
What Changes the Timeline Most?
Employee count is not the best predictor of CMMC preparation time. A 15-person engineering company with CUI scattered across personal laptops, ordinary SaaS tools and several managed providers can be harder to prepare than a much larger company with a tightly controlled enclave.
| Timeline Driver | Faster Situation | Slower Situation |
|---|---|---|
| CUI scope | Small isolated enclave | CUI distributed across the corporate environment |
| Identity | Centralized managed identities | Multiple directories, shared accounts or weak administration |
| Cloud | Known compliant architecture with clear responsibilities | Unclear service eligibility or fragmented SaaS use |
| Documentation | Current SSP, policies and diagrams | Policies written after the technology or copied from templates |
| Evidence | Repeatable logs, tickets and records | Controls exist but leave little evidence |
| Providers | Roles and responsibility matrices are clear | MSP, MSSP or cloud responsibilities are ambiguous |
1. Scope size
Scope is the first multiplier. Every extra endpoint, administrative path, service and network segment can create more configuration, documentation and evidence work.
2. Architecture changes
Changing a policy takes minutes. Rebuilding authentication, segmentation, logging, backup architecture or cloud hosting can take months. Treat architecture gaps as the critical path unless proven otherwise.
3. External providers
Level 2 rules explicitly address cloud service providers and external service providers. An ESP performing security functions or handling relevant information may affect assessment scope and evidence responsibilities. Cloud services that process, store or transmit CUI are subject to specific requirements under the CMMC rule and related DoD policy.
4. Your remediation backlog
Do not count controls. Weight them. Five difficult deficiencies involving architecture can consume more calendar time than twenty documentation problems.
If budgeting is becoming the next question, the separate CMMC compliance cost guide breaks the project into assessment, remediation, technology, consulting and recurring cost components.
What Must Be Ready Before an Assessment?
Passing a readiness review is not the same as having a stack of policies. An assessor needs to determine whether requirements are implemented within the defined scope and whether the evidence supports that conclusion.
Build an evidence map, not a document mountain
For each requirement or assessment objective, record the responsible owner, implementation location, technical mechanism, governing document and evidence source.
| Evidence Question | What You Should Be Able to Show |
|---|---|
| Where is the requirement implemented? | System, service, procedure or technical control |
| Who owns it? | Named role with operational responsibility |
| How does it work? | Configuration, process and expected behavior |
| How do you know it operates? | Logs, tickets, reports, records or other artifacts |
| Where is it documented? | SSP, policy, procedure, diagram or provider documentation |
| What changed recently? | Change record plus updated evidence where necessary |
Your SSP must describe the real environment
For Level 2 certification assessments, the CMMC rule requires information including the SSP name, date and version as part of the submitted assessment record. The assessment also evaluates the defined CMMC Assessment Scope.
A beautifully formatted SSP that describes last quarter’s architecture is worse than a modest document that accurately reflects today’s systems, boundaries and responsibilities.
Evidence retention matters after the assessment
Level 1 and Level 2 assessment artifacts are subject to six-year retention requirements under 32 CFR Part 170. For Level 2 C3PAO assessments, hashed artifacts used as evidence must be retained, with artifact integrity information provided through the assessment process.
DIY, Software or Professional Help?
Your schedule can become expensive when outside help is purchased before the scope is understood. The opposite mistake is waiting until the procurement clock is already ticking to discover that internal staff cannot independently prepare the environment.
| Approach | Best Fit | What It Can Speed Up | What It Cannot Replace |
|---|---|---|---|
| DIY | Small, technically mature team with time and clear scope | Initial scoping, gap tracking, policies, evidence organization | Required C3PAO certification assessment |
| Compliance software | Teams managing many controls, owners and artifacts | Workflow, evidence collection, reminders and status tracking | Correct architecture or genuine implementation |
| Readiness professional | First-time contractor with major uncertainty | Scoping, interpretation, gap prioritization and mock-assessment discipline | Ownership of your controls |
| C3PAO | Organization with an actual Level 2 certification requirement | Formal independent assessment | Readiness remediation performed at the last minute |
Do it internally when the problem is organization
You do not necessarily need a platform or consultant to create an asset inventory, identify data flows, gather contracts, establish owners or compare your current implementation with the applicable requirements.
Pay for software when repeatability becomes the bottleneck
A governance, risk and compliance tool can become useful when dozens of owners, recurring evidence requests, multiple systems and annual affirmation duties are difficult to manage manually. Software earns its keep when it removes coordination work, not when it simply turns your spreadsheet into a dashboard.
Pay for specialist help when uncertainty threatens the deadline
Professional readiness support can be worth considering when CUI scope is unclear, cloud responsibilities are disputed, your SSP does not match reality, major technical controls remain unresolved or management needs independent confidence before committing to a certification assessment.
Good / Better / Best scheduling logic: Good is knowing your required level and scope. Better is proving each control before the procurement deadline appears. Best is maintaining an evidence-ready environment so the next contract does not trigger a compliance rebuild.
When Should You Schedule a C3PAO?
The 2026 Phase II suspension changes urgency for many contractors, but it does not make speculative certification spending automatically wise or automatically unnecessary.
If your upcoming opportunity only requires a self-assessment status under the current Phase I environment, paying for a C3PAO assessment simply because November 10, 2026 once appeared on the roadmap may be premature. If a specific solicitation, subcontract or customer pipeline requires Level 2 C3PAO status, the calculation changes.
Ask these questions before requesting quotes
- Do we have a procurement that specifically requires Level 2 C3PAO status?
- What systems and CAGE codes are expected to fall inside the assessment scope?
- Is our SSP current?
- Have we completed a rigorous Level 2 readiness assessment?
- Which requirements remain NOT MET?
- Are any unresolved items ineligible for POA&M treatment?
- Do our cloud and external provider responsibilities match the rule?
- How much scheduling lead time does the C3PAO currently require?
Separate booking lead time from assessment duration
A provider’s next available assessment date and the time spent performing the assessment are different variables. Ask both questions explicitly. A short active assessment does not help if the first available slot falls after your proposal or award schedule.
Understand Conditional status before relying on it
Level 2 can permit Conditional status only under the POA&M rules. When Conditional Level 2 C3PAO status is achieved, applicable NOT MET requirements must be remediated and the POA&M closeout certification assessment completed within 180 days. If it is not successfully closed within that period, the Conditional status expires.
That 180-day window is a remediation deadline, not a six-month permission slip to postpone core preparation. Some requirements cannot be placed on a POA&M at all.
Buyer warning: do not sign an assessment statement of work until you understand what happens if your environment is not ready, how rescheduling works, what POA&M closeout costs, what travel or retesting is excluded, and which systems the quote assumes are in scope.
CMMC Timeline Mistakes That Cost Months
Mistake 1: starting with a tool purchase
Buying a “CMMC-ready” product before deciding what systems belong in scope can solve the wrong problem beautifully.
Start with data boundaries, architecture and contract requirements. Then determine which controls genuinely require new technology.
Mistake 2: writing policies that nobody follows
A policy is not evidence that a practice operates. If the procedure says inactive accounts are reviewed periodically, there should be a repeatable process and records showing that the review actually occurs.
Mistake 3: treating the MSP as a compliance black box
Outsourcing IT does not outsource accountability. If a managed provider operates identity, endpoint security, logging, backup or other security functions for the CUI environment, document who does what and what evidence each party can provide.
Mistake 4: waiting for a certification deadline announcement
This is especially risky in August 2026. Phase II is suspended while the program is under review, so the future implementation calendar may change. Current Phase I obligations and existing contract requirements still matter.
The durable strategy is to become technically capable of protecting FCI or CUI and to maintain credible evidence. That work remains useful even when an administrative milestone moves.

FAQ
Does the 2026 Phase II suspension mean CMMC has been cancelled?
No. The department states that implementation is paused in Phase 1, not cancelled, and that Phase I self-assessment requirements remain in place while the program is reviewed.
Should I still prepare for Level 2 certification?
Prepare the underlying Level 2 security capability if your business strategy involves handling CUI. Whether you should pay for a C3PAO certification assessment immediately is a separate decision. Base that decision on specific procurement demand, customer requirements, readiness and current program guidance.
Can a company become CMMC-ready in 90 days?
Possibly, but only when the starting point is already strong. Ninety days can be enough to document, tighten and prove an existing mature environment. It is a poor assumption for a company that must redesign its CUI boundary, replace major systems, fix identity architecture or migrate cloud services.
How long does a CMMC Level 2 status remain current?
Under the current rule, Final Level 2 Self and Final Level 2 C3PAO assessment statuses operate on a three-year assessment cycle, while an affirmation of continuous compliance is required annually.
Can I use a POA&M to fix everything after the assessment?
No. POA&M use is limited by the CMMC rules, certain requirements cannot be deferred, and eligible Conditional Level 2 items must be successfully closed within 180 days.
When should a subcontractor start preparing?
Start when you know FCI or CUI is likely to flow down, not after receiving the subcontract. Current DFARS provisions address flowdown and require an appropriate current CMMC status before a prime contractor awards a subcontract where the applicable clause and information requirements trigger it.
Your 15-Minute CMMC Timeline Check
Do not start your CMMC project today by shopping for a platform or requesting a certification quote.
Spend fifteen minutes creating a three-line timeline brief:
- Target opportunity: write down the contract, subcontract or customer opportunity you actually want to pursue and its expected solicitation or award window.
- Likely information: write down whether you expect FCI, CUI or neither to enter your systems.
- Current readiness: record whether you already have a defined assessment scope, current SSP and completed requirement-by-requirement gap review.
If you cannot confidently complete all three lines, your immediate milestone is scope discovery, not certification.
If you can complete them and your likely requirement is Level 2 C3PAO, work backward from the date the status may be required and add separate blocks for remediation, evidence stabilization, provider selection and scheduling. That turns “How long does CMMC take?” from a foggy question into a project you can manage.
The useful deadline is not the date on a CMMC roadmap.
It is the earliest date at which a real procurement could ask you to prove the required status. Build backward from that date, and give remediation the time it deserves.
Last reviewed: 2026-09