HomeBlogCMMC
CMMC2026-07-12SecReadyNow

How to Get CMMC Level 2 Certified: A Step-by-Step Guide

CMMC certification is not a sprint - it is an 8-step process that takes most organizations 12 to 24 months. Here is the right sequence, what happens at each step, and the most common places organizations lose time and money.

Getting CMMC Level 2 certified is a multi-step process that typically takes 12 to 24 months from decision to certificate. Rushing it - skipping documentation or jumping to an assessment before controls are fully implemented - is expensive and demoralizing. This guide walks through the correct sequence.

Step 1: Scope Your CUI Environment

1

Define What Is In Scope

Identify every system, network, location, and person that processes, stores, or transmits CUI. This is your CMMC boundary. Smaller boundaries mean smaller assessment scopes and lower costs - but scoping too narrowly creates legal risk if CUI flows outside the defined boundary.

Your scope should document: network segments that touch CUI, cloud services that store or process CUI, endpoints used by personnel with CUI access, physical locations where CUI is handled, and third-party services that process CUI on your behalf.

Step 2: Conduct a Gap Assessment

2

Assess Your Current State Against All 110 Practices

Go through each of the 110 NIST 800-171 practices and determine: is this fully implemented, partially implemented, or not implemented? Document your findings. This gap assessment becomes the foundation for your POA&M and remediation plan.

Use NIST SP 800-171A as your assessment guide - it describes exactly what assessors look for in each practice. Your gap assessment findings feed directly into your Plan of Action and Milestones (POA&M).

Step 3: Submit Your SPRS Score

3

Calculate and Submit Your Self-Assessment Score

While preparing for your C3PAO assessment, you are required to submit a self-assessed SPRS score to the Supplier Performance Risk System. The score ranges from -203 to 110. It reflects your current implementation status, not your aspirational state. Do not inflate it.

SPRS submission requires an authorized representative to sign an affirmation statement. False SPRS submissions carry significant legal risk under the False Claims Act. Submit your accurate current-state score, then update it as your remediation progresses.

Step 4: Build Your Documentation

4

Create the SSP, POA&M, and Domain Policies

The System Security Plan (SSP) is the central document - it describes how each of the 110 practices is implemented in your environment. The POA&M documents gaps with remediation timelines. Domain policies (one per domain, 12 total) provide the written policy framework that the SSP implementation references.

Assessors read the SSP before the assessment begins. A well-written, complete SSP sets expectations that your technical controls then validate. A thin or vague SSP signals that implementation may be thin too.

Step 5: Implement Remediation

5

Close the Gaps Identified in Your Assessment

Work through your POA&M. Prioritize the five highest-impact domains: IA (MFA), AU (logging and monitoring), CM (configuration baselines), SC (encryption and segmentation), and AC (least privilege and access reviews). These produce the most NOT MET findings.

Give yourself time to let controls mature. An MFA deployment that went in last week will not have audit logs, configuration records, or a demonstrated operational history. Assessors look for evidence of sustained implementation, not just installation.

Step 6: Select a C3PAO and Schedule Your Assessment

6

Find and Engage a Certified Assessment Organization

C3PAOs are listed on the Cyber AB marketplace at cyberab.org. Get quotes from multiple organizations - assessment pricing varies considerably. Typical assessments for small organizations run $25,000 to $60,000 for the assessment alone (not including remediation, consultant fees, or documentation prep).

When engaging a C3PAO, they will typically request your SSP, network diagrams, and system boundary documentation in advance of the assessment. Some C3PAOs offer pre-assessment readiness reviews, which can help identify issues before the formal assessment clock starts.

Step 7: Complete the Assessment

7

Work Through the 3 to 5 Day Assessment Process

The assessment involves document review, interviews with key personnel (IT staff, CISO, system owners, HR), and technical verification (log review, configuration checks, active testing). Have your evidence package organized and accessible. Know who owns each domain so the right person is available for interviews.

Practices found NOT MET during the assessment either need immediate remediation (if possible within the assessment window) or a POA&M entry. Some POA&M items can be accepted for conditional certification; others - particularly foundational controls - typically cannot.

Step 8: Receive Your Certificate

8

C3PAO Submits Results and Certificate Is Issued

After the assessment, the C3PAO submits results to the CMMC database. If all practices are MET (or deferrable gaps are documented in an accepted POA&M), a 3-year certificate is issued. You then submit annual affirmations during the certificate period.

Don't Start the SSP From Scratch

The CMMC Level 2 Complete Certification Kit includes the SSP template (all 110 practices pre-populated), POA&M, and all 12 domain policies. Start from a professional foundation instead of a blank page.

View the Certification Kit - $299

Frequently Asked Questions

A subset of CMMC Level 2 contracts allow annual self-assessment with affirmation by a senior company official. Whether your specific contract allows self-assessment or requires a C3PAO is determined at the contract level by the DoD program office. Check your solicitation for the specific CMMC requirement tier, or ask your contracting officer.
Total costs vary widely. C3PAO assessment fees for small organizations typically run $25,000 to $60,000. Pre-assessment preparation (documentation, remediation, consultant fees) often adds another $50,000 to $150,000 depending on how mature your security posture is before you start. Organizations starting from a weak baseline spend more on remediation.
There is no formal pass/fail determination during the assessment. Practices found NOT MET either require immediate remediation (closing the finding before the assessment concludes) or entry into a POA&M with an accepted remediation timeline. Some conditional certifications are issued with open POA&M items; others require full remediation before certification. The C3PAO and DoD program office determine acceptability.
Yes. Registered Practitioners (RPs) and Registered Provider Organizations (RPOs) listed on the Cyber AB marketplace can help with gap assessments, documentation, and remediation. However, they cannot conduct the assessment - that must be done by a separate, independent C3PAO. Using the same organization to both consult and assess is a conflict of interest prohibited by CMMC rules.
A C3PAO (Certified Third-Party Assessment Organization) is authorized to conduct official CMMC assessments and issue findings. An RPO (Registered Provider Organization) can provide advisory, consulting, and implementation services but cannot conduct formal CMMC assessments. Use an RPO to help you prepare; use a C3PAO for the actual assessment.

Related Resources

Keep going - these are worth reading next.

🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, no spam.