CMMC Final Audit Costs for Primes: What to Budget for Remediation and Certification

CMMC Level 2 compliance costs between $150,000 and $400,000 over three years for mid-sized contractors. The assessment itself represents only 15-30 percent of total costs. The majority goes toward gap remediation and technology upgrades. CMMC requirements now appear in new DoD contracts, and this makes precise budgeting critical to maintain contract eligibility. We’ll break down the true costs of CMMC certification in this piece. We’ll explore budgeting strategies for your CMMC audit and help you build a three-year forecast to achieve and maintain CMMC compliance. Breaking Down CMMC Certification Costs by Component CMMC certification expenses divide into three distinct categories: formal assessment fees, upfront remediation investments, and recurring maintenance costs. Contractors who understand each component can build accurate budgets and avoid surprises during implementation. Assessment Fees: Level 2 vs Level 3 for Primes C3PAO assessment fees for Level 2 certification range from $30,000 to $75,000, though actual costs vary based on organizational complexity and scope. Small organizations with fewer than 50 employees often pay between $30,000 and $50,000. Mid-sized contractors with 51-150 employees face fees of $50,000 to $80,000. Organizations exceeding 500 employees should budget $120,000 to $150,000 or more. The DoD’s official cost projections paint a broader picture. Level 2 third-party certification costs $105,000 to $118,000 over a three-year cycle. This figure has the triennial assessment and two annual affirmations required between full certifications. Assessment duration spans one to four weeks depending on organizational size. The actual evaluation takes three to five days for most contractors. Level 3 certification adds substantial expense. Organizations pursuing this highest certification level face Level 2 costs plus an additional $41,000 for implementing and assessing the 24 advanced controls from NIST SP 800-172. Total Level 3 assessment costs reach $146,000 to $159,000 every three years. Remediation Investment Ranges Most contractors spend their CMMC budget on remediation. Implementation costs range from $20,000 to $150,000 based on current security posture. Organizations with mature security programs and existing controls aligned to NIST SP 800-171 fall toward the lower end. Contractors starting from fragmented or outdated systems face higher investments. Small businesses budget $10,000 to $50,000 for remediation. Larger or more complex organizations require $50,000 to $100,000 or more. Documentation and System Security Plan development add $12,000 to $70,000 to total costs. Technology upgrades form a significant portion of remediation expenses. Required tools like endpoint protection, SIEM logging, encryption and vulnerability scanning cost $10,000 to $50,000 each year. Organizations needing CUI enclave setup should budget $300 to $400 per user monthly, or $3,000 to $4,000 monthly for managed environments. Ongoing Compliance and Maintenance Costs CMMC compliance demands continuous investment beyond the certification you get at first. Annual maintenance costs range from $5,000 to $40,000 depending on organizational size and complexity. These recurring expenses have security license renewals at $5,000 to $20,000 each year, continuous monitoring and internal audits starting between $1,000 and $3,000 monthly, and mandatory security awareness training at $1,000 to $5,000 yearly. Organizations should also establish a triennial recertification reserve and set aside funds to cover the next C3PAO assessment in three years. Level 2 contractors should expect ongoing costs between $20,000 and $80,000 each year. This has software renewals, managed security services, documentation maintenance and monitoring capabilities. Recertification every three years involves similar assessment costs to the certification you get at first. Budgeting for Gap Remediation Before Your CMMC Audit Gap remediation represents the most variable and substantial expense in your CMMC experience. Unlike fixed assessment fees, remediation costs depend on your starting point and how you address identified gaps strategically. Organizations that wait until contract deadlines approach face 20-30% higher total costs due to compressed timelines, rushed implementation, and limited expert availability. Conducting a Complete Readiness Assessment Your readiness assessment functions as a dress rehearsal before the formal C3PAO evaluation. This evaluation compares your current environment against all 110 requirements in NIST SP 800-171 Rev 2 and identifies where you stand and what remediation effort lies ahead. Gap assessment costs range from $3,500 to $25,000 depending on organizational size and complexity. Small to medium companies complete assessments within 4-6 weeks. Larger organizations with complex IT infrastructure require 8-12 weeks or more. Assessment timelines extend when documentation maturity is low, system complexity is high, or the core team remains unavailable for evidence review sessions. The assessment should assess current policies, processes, and technical controls against NIST 800-171, then score your compliance to identify deficiencies in both documentation and technical safeguards. Assessments often go wrong when they focus too heavily on policy documents rather than actual implementation. Auditors care about doing what you say and saying the right things equally. Prioritizing High-Impact Control Gaps After identifying gaps, prioritize based on certification effect and risk severity. Focus first on “showstopper requirements” like multi-factor authentication, FIPS-validated encryption, vulnerability patching, and incident response capabilities. These critical controls support other requirements and block certification if not implemented properly. Organizations need a minimum score of 88 out of 110 points (80%) to qualify for conditional certification. Controls like MFA and encryption cannot remain open at assessment time and should be treated as immediate remediation priorities rather than items to carry forward on timelines. Technology Upgrades: Endpoint Protection and Network Security Closing gaps requires investments in endpoint protection and monitoring tools, multi-factor authentication solutions, and secure configuration management. Technology purchases and deployments for organizations with low initial maturity cost between $20,000 and $150,000. Defense-grade technologies like endpoint protection, identity and access management, SIEM logging, monitoring, and secure enclave design all fall under this category. Policy Updates and SSP Documentation Costs System Security Plan development ranges from $5,000 to $35,000 based on organizational complexity. Policy creation and updates represent an important yet variable cost, though organizations must demonstrate ground adherence to these policies, not just create them. Documentation has policies broken down by practice family, standard operating procedures with step-by-step instructions, and Plan of Action and Milestones for tracking remediation. Estimated Remediation Timelines and Cost Implications CMMC Level 2 compliance requires 12-24 months for most contractors, depending on starting point and available
AI Framework for CMMC: What Defense Contractors Must Know

An AI framework for CMMC is coming, directed by the National Defense Authorization Act for Fiscal Year 2026, and it will layer AI-specific security requirements onto the compliance obligations defense contractors already carry. The framework targets a gap that traditional cybersecurity controls do not close well: the distinct ways artificial intelligence and machine learning systems can be attacked, from poisoned training data to manipulated inputs. This guide explains what the AI framework for CMMC covers, who must comply, the AI-specific controls it points to, and the current status, which has shifted since the framework was first announced. The central thing to understand is that this is an extension of CMMC, not a separate regime. Contractors already working toward or holding CMMC certification will face additional, AI-specific obligations when AI or machine learning enters the scope of their work with controlled unclassified information, on top of the requirements that already apply. Reading the framework this way, as added layers rather than a parallel program, is what makes preparing for it manageable. What the AI Framework for CMMC Covers The AI framework for CMMC originates in the National Defense Authorization Act for Fiscal Year 2026, which directs the Department of War to develop a framework addressing both the cybersecurity and the physical security of the artificial intelligence and machine learning technologies the department acquires. Rather than standing alone, the NDAA instructs that the framework be implemented as an extension of existing departmental cybersecurity requirements and CMMC, so contractors face heightened obligations layered onto current ones, not a second compliance system. The framework’s scope is defined around “covered AI/ML,” which encompasses the AI and machine learning the department acquires along with its associated components, such as source code, model weights, algorithms, training data, and the software used to develop it. It targets the security risks specific to these systems, three of which recur throughout the framework’s rationale. Data poisoning contaminates the datasets a model trains on, so the model misclassifies information or embeds hidden flaws. Adversarial tampering deliberately compromises the hardware, software, data, or processes behind an AI system. Unintentional data exposure discloses sensitive information through configuration or handling mistakes. The specific statutory provisions and definitions here are drawn from the NDAA and should be confirmed against the current text before relying on them, since the framework itself is still being developed. Who Must Comply The obligations reach “covered entities,” meaning organizations that contract with the Department of War for the development, deployment, storage, or hosting of covered AI/ML. That definition captures a broad slice of the defense industrial base, because it turns on the function an organization performs rather than its size. An organization must expect to comply if it develops AI models for defense applications, deploys AI systems in defense environments, or stores and hosts AI services for defense operations. The reach extends through the supply chain as well. Subcontractors that handle AI or machine learning for prime contractors fall within the same obligations, so a prime cannot treat the framework as its concern alone. For organizations already subject to CMMC Level 2, the practical effect is additive: the 110 security requirements drawn from NIST SP 800-171 that Level 2 already demands remain in place, with the AI-specific requirements added on top once the framework is finalized and incorporated into contracts. The Core Requirements The AI framework for CMMC organizes into a set of core requirement areas that extend an organization’s existing compliance program rather than replacing it. The table summarizes them and what each involves. Requirement area What it involves AI inventory and classification A complete catalog of AI systems that touch CUI, with purpose, data sources, and oversight model AI risk assessment Continuous, AI-specific risk evaluation across the model lifecycle AI-specific security controls Input validation, model access controls, output monitoring, and adversarial-attack prevention Documentation Updated System Security Plan, policies, and Plans of Action and Milestones covering AI Third-party AI tools Cloud AI that handles CUI must meet the FedRAMP Moderate baseline or equivalent The connecting logic across these areas is that AI expands the boundary of what a CMMC assessment covers. Every dataset, model, and AI-generated output that touches CUI becomes part of the assessed environment, which is why the first move is always to know what AI is in use. The following sections take the areas that carry the most weight in turn. AI Inventory and Classification A complete AI inventory is the foundation, because an organization cannot secure or document systems it has not identified. The inventory should catalog every AI system that processes, stores, or interacts with CUI, recording each system’s purpose, its data sources, whether it operates autonomously or under human oversight, and whether it was built in house, purchased, or accessed as a cloud service. The most common assessment finding related to AI is undocumented usage, where employees use AI services for CUI-related tasks without the organization’s knowledge, so the inventory is also the primary defense against the single most likely deficiency. Classification follows inventory, because different AI systems carry different risk. A rule-based tool, a machine learning model, and a system that makes autonomous decisions about CUI each warrant different controls, and mapping them by risk determines where to concentrate effort. Keeping the inventory current is mandatory rather than optional, since new tools appear and old ones retire, and an assessor will look for exactly the undocumented system the inventory is meant to surface. AI-Specific Security Controls The framework points to four categories of technical control that address vulnerabilities traditional cybersecurity measures do not cover. Input validation and sanitization defends against prompt injection and similar attacks by filtering inputs before they reach a model and constraining what the model returns, which matters acutely when a model has access to CUI in its context. Model access controls apply least-privilege, role-based access and multi-factor authentication to the models themselves, so not every user can reach every model or capability, and access is tied to role rather than individual. The remaining two categories govern what
CMMC 2.0 Certification: How to Engage a C3PAO for Your DoD Assessment

CMMC 2.0 certification is becoming mandatory for defense contractors. The DoD estimates that as many as 300,000+ contractors will need certification. CMMC requirements will appear in all contracts starting in fiscal year 2026. Self-attestation is no longer an option, especially when you have CMMC Level 2. Organizations must involve a Cyber AB-authorized C3PAO to become CMMC compliant. In this piece, we’ll walk you through how to get CMMC certification by selecting the right CMMC C3PAO and understanding DoD CMMC requirements. You’ll also learn to navigate the CMMC certification process successfully. Understanding C3PAO Requirements for CMMC 2.0 What Is a C3PAO and Why It Matters A C3PAO (CMMC Third-Party Assessor Organization) holds exclusive authority to conduct formal CMMC assessments and issue CMMC 2.0 certification. These organizations demonstrate to the Cyber AB, the governing body overseeing CMMC accreditations, that they have become skilled at security processes and practices required under the CMMC framework. C3PAOs use Certified CMMC Assessors (CCAs) to conduct assessments. Certified CMMC Professionals (CCPs) support them. The CCP exam spans three-and-a-half hours with 170 multi-choice questions. Candidates must score 500-plus to pass. CCPs in good standing can provide consultancy services to support organizations seeking to implement CMMC Level 1 and Level 2, but the same C3PAO cannot provide consultation and conduct an assessment for the same organization. CMMC Level 2 vs Level 1: Assessment Differences CMMC Level 1 focuses on simple cyber hygiene with 17 practices designed to safeguard Federal Contract Information (FCI). FCI is information provided by or generated for the government under contract, not intended for public release. Organizations handling only FCI can perform annual self-assessments and report findings through the Supplier Performance Risk System (SPRS). CMMC Level 2 addresses intermediate cyber hygiene with 110 practices that align with NIST SP 800-171. Level 2 protects Controlled Unclassified Information (CUI), which requires safeguarding controls pursuant to laws, regulations, and government-wide policies. The assessment methodology for Level 2 follows the CMMC Assessment Process (CAP): plan and prepare, assess, report, and address Plan of Action and Milestones if needed. DoD CMMC Requirements for Defense Contractors The DoD determines which CMMC level appears in contract solicitations based on information sensitivity. The assessment type depends on whether CUI is included in the National Archive’s CUI Registry Defense Organizational Indexing for Level 2. Contracts with critical national security relevance require third-party C3PAO audits. Organizations must demonstrate full compliance with all 110 NIST SP 800-171A security controls at the time they pursue C3PAO assessment for Level 2 certification. The Federal Register CMMC Final Rule states that organizations not meeting all 110 requirements but achieving a minimum passing score of 80% and meeting all critical controls may get Conditional Level 2 status. All unmet requirements must be addressed in a POA&M and validated within 180 days via a closeout assessment. Level 1 does not permit POA&Ms. Self-Assessment vs C3PAO Certification Both self-assessment and C3PAO certification pathways require organizations to conduct annual self-assessments. C3PAO-certified organizations must still complete annual self-assessments between the three-year certification cycles. Certification does not eliminate this requirement. CMMC Level 2 assessments are valid for three years from the certification date. Organizations must maintain compliance through annual self-assessments, SPRS submissions, and senior official affirmations. Certification renewal failures and contractual non-compliance may result from failure to conduct annual self-assessments or document system changes. C3PAO assessment is mandatory only for contracts that require CMMC Level 2 (Certified). The Department of Defense determines this designation based on programmatic risk. C3PAO certification will be required for all contracts designated as CMMC Level 2 once Phase 3 of CMMC implementation is complete. When to Engage a C3PAO for Your DoD Assessment Timing Your C3PAO Engagement You need to plan months ahead to secure assessment capacity. C3PAO lead times range from three to six months, and backlogs for many organizations stretch into 2026. Most organizations need about six to twelve months to reach Level 2 compliance. This means you must start preparation well before contract deadlines. Organizations should begin preparations at least six months before their CMMC audit. Starting earlier makes sense if no cybersecurity program exists. Early engagement provides scheduling certainty during periods of peak demand and early identification of gaps that can be resolved without driving costs. You also get a smoother assessment experience with ample time to compile and organize evidence. Phase 1 runs from November 10, 2025, through November 9, 2026, focusing on CMMC Level 1 and Level 2 self-assessments. Organizations should achieve audit-readiness and book a C3PAO engagement 8-12 weeks before their deadline to avoid major delays. Readiness Indicators Before Engaging a C3PAO Scheduling too early can lead to assessment failures. Scheduling too late can delay contract eligibility. Organizations should pursue a C3PAO assessment only after completing readiness activities to be done, finalizing documentation, and demonstrating implemented security controls. Before engaging a C3PAO, organizations need a complete System Security Plan detailing implementation status for all 110 practices and 320 assessment objectives. A formal gap analysis using NIST 800-171A as reference helps uncover compliance shortfalls. Security controls must be visible on systems through monitoring and logging. If documentation remains incomplete or controls lack proper implementation, Book a Readiness Call with a Registered Practitioner Organization to conduct a mock assessment and identify blind spots before scheduling your formal C3PAO evaluation. Contract Timeline and Assessment Scheduling The assessment itself spans four to six weeks. This includes pre-assessment review, evidence validation, the interview period, reporting, and any required POA&M closeout. The formal assessment process breaks down into four phases: plan and prepare, assess, report, and address POA&M if needed. During the planning phase, C3PAOs identify the core team contacts, finalize scope, complete pre-assessment documentation, and conduct readiness analysis. This phase can vary from a few weeks to months based on organization size and scope. JSVAP vs Official CMMC Assessment The Joint Surveillance Voluntary Assessment Program (JSVAP) allows defense contractors to undergo collaborative evaluations by both C3PAO and DIBCAC before CMMC 2.0 becomes mandatory. JSVAs will convert to CMMC Level 2 certification if performed under the JSVAP program, achieving
CMMC Level 2 Final Review: Expert Guide to Meeting DoD Compliance Standards

CMMC Level 2 certification is expected to apply to about 80,000 contractors within the defense supply chain. CMMC requirements appear in active DoD solicitations. Organizations must meet the specified certification level at contract award. Compliance is no longer optional for defense contractors handling Controlled Unclassified Information (CUI). The CMMC final rule introduces most important changes to how defense contractors demonstrate security compliance. CMMC Level 2 requires implementation of all 110 security controls outlined in NIST SP 800-171a Rev 2. CMMC 2.0 Level 2 mandates third-party C3PAO assessments every three years and moves beyond self-attestation to validated verification. This piece walks you through the CMMC Level 2 requirements, implementation timeline and preparation steps your organization needs to achieve certification. Understanding CMMC Level 2 Final Rule Requirements What CMMC Level 2 Certification Covers CMMC Level 2 certification covers two distinct pathways based on contract prioritization. Organizations with non-prioritized CUI contracts conduct annual self-assessments to demonstrate compliance with all 110 controls from NIST SP 800-171 Rev 2. Prioritized CUI contracts require third-party assessments conducted by a Certified Third-Party Assessment Organization (C3PAO), selected from the CMMC-AB Marketplace. Both pathways mandate implementation of the same 110 security requirements specified in NIST SP 800-171 Rev 2. These controls represent a fully developed cybersecurity program that is documented, repeatable and applied with consistency. A mature Level 2 environment has written policies, procedures and plans covering all 14 NIST control families. It also has technical safeguards designed to prevent, detect and respond to cyber threats. Documentation demonstrates consistent security practices. The organization commits to training, continuous monitoring and ongoing improvement. Level 2 certification assessments provide increased assurance to the DoD that contractors can protect CUI adequately at a level matching the adversarial risk. This accounts for information flow with subcontractors in a multi-tier supply chain. Key Differences Between CMMC Level 1 and Level 2 Level 1 focuses on simple protections for Federal Contract Information. Level 2 constitutes a fully developed cybersecurity program designed to protect Controlled Unclassified Information and often requires third-party validation. The most striking difference lies in the number of practices required. CMMC Level 1 consists of 17 practices, while CMMC Level 2 requires 110 practices. The certification approach is very different between levels. CMMC Level 1 certification comes through annual self-assessments. CMMC Level 2 compliance requires triennial third-party assessments for prioritized contracts, with annual self-assessments permitted for select non-prioritized programs. Level 2 certification remains valid for three years, coupled with an annual reassessment required to confirm continued compliance. Achieving Level 2 takes 6 to 18 months. This period covers gap analysis, remediation, documentation, training and preparation for assessment. How to Know If Your Organization Needs Level 2 Level 2 is usually required if your organization handles Controlled Unclassified Information in any form. Start by identifying the type of information your organization handles. Look for these indicators: presence of Defense Federal Acquisition Regulation Supplement clauses such as 252.204-7012, 252.204-7019, 252.204-7020, or 252.204-7021; work with technical data, specifications, diagrams, engineering information, or mission-related data; or confirmation from your contracting officer that CUI requirements apply. Your DoD contract will specify the required CMMC level, with details about the sensitivity of the information you’ll manage and the associated security expectations. Controlled Unclassified Information (CUI) Handling Requirements Controlled Unclassified Information means sensitive information that the government creates or possesses, or that a contractor handles or creates on the government’s behalf. This information must be protected according to laws, regulations, or government-wide policies. While not classified, CUI requires specific safeguarding and limited sharing. CUI Basic is the most common category for contractors. It means information that requires safeguarding under laws, regulations, or government-wide policies, but where these authorities do not specify handling controls different from baseline CUI controls. CUI Specified is a subset subject to enhanced handling requirements, where the governing authority states how to protect the information and who can access it. Data controlled under International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) often falls under CUI Specified, to cite an instance. CMMC Level 2 Security Controls and NIST 800-171 Alignment The 110 Security Controls in 14 Domains CMMC Level 2 maps to all 110 security requirements in NIST SP 800-171 Rev 2. These requirements are organized in 14 control families. The distribution varies substantially by domain. Access Control contains 22 requirements and System and Communications Protection has 16. Identification and Authentication covers 11. Configuration Management has 9 requirements, and Audit and Accountability also has 9. Media Protection and Maintenance include 9 and 6 requirements. Physical Protection has 6 requirements, System and Information Integrity has 7, and Incident Response has 3. The remaining families have Security Assessment (4), Awareness and Training (3), Risk Assessment (3), and Personnel Security (2). Each domain addresses specific security concerns. These range from limiting system access to safeguarding data that travels through networks. NIST SP 800-171 Rev 2 Compliance Standards The protection of Controlled Unclassified Information in nonfederal systems affects the federal government’s knowing how to conduct critical missions and functions. NIST SP 800-171 Rev 2 provides security requirements to protect CUI confidentiality when information resides in nonfederal systems and organizations. These requirements apply to all components of nonfederal systems that process, store, or transmit CUI. CMMC assessments follow the procedure described in NIST SP 800-171A. This procedure consists of assessment objectives and potential assessment methods. Assessment objectives are provided for each requirement and are based on existing criteria from NIST SP 800-171A. Certified assessors verify that contractors have implemented practices properly through documentation, computer configuration, network configuration, or training records. Conditional Certification and POA&M Requirements CMMC Level 2 compliance operates on a points-based system. Each of the 110 controls carries a criticality value of 1, 3, or 5 points. Organizations that seek certification start with 110 compliance points, and scoring is applied subtractively. An 80% score qualifies for conditional certification. This means a minimum of 88 points with only approved 1-point controls missing. Organizations must close out all POA&Ms within 180 days from the conditional CMMC status date. The closeout
CMMC Audit vs Internal Assessment: Cost Breakdown and Timeline Comparison for 2026

Understanding the difference between a CMMC audit and an internal assessment is significant for defense contractors navigating 2026 compliance requirements. Around 8,350 medium and large entities will be required to meet CMMC Level 2 third-party assessment requirements. The cost difference is notable: internal assessments range from $4,000-$50,000, while Level 2 certification assessments cost $105,000-$118,000. We’ll break down the timeline differences and cost considerations. This will help you determine which assessment path arranges with your contract requirements and budget constraints. Understanding CMMC Audit vs Internal Assessment What is a CMMC Audit (C3PAO Assessment) A Certified Third-Party Assessment Organization (C3PAO) performs a Level 2 certification assessment to review the CMMC level of an Organization Seeking Certification (OSC). The C3PAO employs Certified CMMC Assessors who use assessment methods defined in NIST SP 800-171A, along with supplemental guidance, to conduct these reviews. The assessment team has at least two CMMC Certified Assessors: a Lead Assessor who determines which assessment methods will best review your environment and a Secondary Assessor who supports the lead. Assessors rely on three main methods: getting into documents, interviewing staff, and testing systems. They determine the level of effort needed to support the determination that a CUI requirement has been satisfied. The assessment team drafts a report filed into e-MASS that explains in-scope assets, testing methodology, and assessment findings for each CMMC practice upon completion. The C3PAO can issue two certification types. Conditional Level 2 (C3PAO) is achieved when a Plan of Action & Milestones (POA&M) exists upon completion and meets all Level 2 POA&M requirements, with the OSC having 180 days to remediate unmet controls. Final Level 2 (C3PAO) is achieved upon implementation of all security requirements. Level 2 certification assessments provide increased assurance to the DoD that an OSA can protect CUI at a level commensurate with adversarial risk, which has protecting information flow with subcontractors in a multi-tier supply chain. What is an Internal Assessment (Self-Assessment) An entity performs a self-assessment to review its own CMMC Level, as applied to Level 1 and some Level 2 contracts. OSAs conducting self-assessments under 32 CFR 170.16 are expected to review their compliance with CMMC requirements using the same criteria established in NIST SP 800-171A and the assessment guide used for third-party assessments. Organizations must assess against 110 NIST SP 800-171 requirements for Level 2 self-assessments and produce a scored result used for SPRS and contract eligibility. The OSA must complete a self-assessment and submit results and scores in SPRS every three years and the executive affirmation annually to maintain this status. Completing a self-assessment alone is not enough to achieve a valid CMMC status that makes your organization eligible for contract awards with a Level 1 (Self) or Level 2 (Self) requirement. You must also submit your results every three years and affirm compliance every year in the SPRS. The DoD and prime contractors use these self-assessment results and scores to inform their decision-making when acquiring or maintaining relationships with vendors and suppliers. Key Differences Between Audit and Internal Assessment The contractor does a CMMC self-assessment internally and leadership affirms it, while a C3PAO performs a third-party assessment with independent evidence testing and higher scrutiny. Self-assessments must be updated annually, with results submitted into SPRS and supported by documented evidence. Contractors handling CUI for prioritized contracts require a third-party assessment by an authorized C3PAO every three years for Level 2. But if you handle CUI for non-prioritized contracts, you may be allowed to complete an annual self-assessment instead. Contract requirements and DoD determinations decide whether you qualify for self-assessment. CMMC Level 2 Certification Requirements in 2026 CMMC Level 2 applies to contractors that handle Controlled Unclassified Information and has 110 security requirements aligned to NIST SP 800-171, Rev. 2. These requirements are hosted across 14 security domains and cover areas such as configuration management, risk assessment, and system and information integrity. Requirements emphasize institutionalized security practices at this level. Contractors must demonstrate not only that controls exist but also that they are applied, monitored, and documented consistently. You need to maintain a current System Security Plan, retain objective evidence, and make sure that technical controls match documented policies and procedures. Timeline Comparison: CMMC Audit vs Internal Assessment Timeline expectations differ substantially between self-assessments and third-party certifications. Preparation phases consume more time than the actual evaluation process. Internal Assessment Timeline Breakdown (30-90 Days) Most organizations need 30 to 90 days for Level 1 self-assessments. The timeline is condensed because the scope is limited: you only need to verify 15 controls based on FAR 52.204-21. Organizations that already maintain baseline security posture spend most of this period formalizing existing practices and compiling documentation such as System Security Plans and policies. This includes unique user accounts and anti-virus software. Plans of Action & Milestones are not permitted for Level 1. You must verify that all 15 controls are implemented before you submit your affirmation in SPRS. The self-assessment process takes 1-2 weeks, and submission requires an additional day. Level 2 self-assessments require more extensive timelines. The self-assessment process spans 2-4 weeks and covers all 110 NIST SP 800-171 requirements with detailed documentation and evidence. You must submit results to SPRS after completion. CMMC Audit Timeline Breakdown (3-6 Months) The assessment phase for CMMC Level 2 certification extends 3-6 months. The actual assessment week lasts about one week, but scheduling constraints and preparation activities extend the duration. Your scoping call with the C3PAO occurs shortly after the original meetings and lasts ninety minutes. Assessors verify your asset categorization during this session and review your System Security Plan, network diagrams, data flow diagrams, policies, procedures, and CRMs. Weekly meetings begin after the scoping call for Assessment Plan development. The plan describes assessment logistics, assessor identities, on-site locations, and scheduling details. C3PAOs arrange travel about one month before the assessment to secure discounted fares if on-site travel is needed. You must finalize and upload documentation 7 days before the assessment begins. The Assessment Plan needs finalization 2 weeks prior. The assessment week involves documentation
CMMC 2.0 Certification for DoD Contractors: What You Need to Know Before 2026 Deadlines

CMMC 2.0 certification requirements began appearing in Department of War (DoW) and Department of Defense (DoD) contracts in November 2025, changing how defense contractors validate their security posture. The Defense Industrial Base has an estimated 350,000 suppliers competing for a limited number of authorized assessors. Compliance may take 6 to 12 months to achieve, so preparation matters. This guide walks defense contractors through the CMMC 2.0 certification requirements and the certification process, covering Level 2 assessment specifics and how to reach certification ahead of the 2026 deadline that determines contract eligibility. What CMMC 2.0 Means for DoW/DoD Contractors Moving from Self-Attestation to Third-Party Verification The DoW/DoD introduced the Cybersecurity Maturity Model Certification (CMMC) in 2020 to address the biggest problem in the defense supply chain: contractors were self-attesting compliance with cybersecurity requirements without independent verification. Before CMMC, contractors claimed they met NIST SP 800-171 standards, often with inaccuracies that left sensitive information vulnerable. Many overstated their compliance under this self-reporting system while cyber incidents among defense suppliers continued to rise. CMMC 2.0 changes this approach. The DoW/DoD published the final DFARS rule on September 10, 2025, formally integrating CMMC 2.0 into defense contracts through the DFARS 252.204-7021 clause. The rule took effect on November 10, 2025, and introduced a phased implementation over three years. Contractors must now undergo assessment by a Certified Third-Party Assessment Organization (C3PAO) every three years for Level 2 contracts that handle Controlled Unclassified Information (CUI). They must also affirm continuous compliance annually. The DoW/DoD estimates that approximately 80,000 contractors in the Defense Industrial Base will need Level 2 certification through a C3PAO assessment. Some Level 2 contracts tied to non-prioritized acquisitions may permit self-assessment, but most contractors who handle CUI critical to national security will require third-party verification. NIST SP 800-171 and 800-172 Alignment CMMC 2.0 aligns directly with NIST standards rather than creating an entirely new framework. Level 2 incorporates all 110 security requirements from NIST SP 800-171 Rev. 2, distributed across 14 control families. This alignment gives contractors proven cybersecurity practices already required by DFARS clause 252.204-7012. The scoring system uses a point-based methodology with a maximum score of 110 points. Contractors must achieve a minimum score of 88 out of 110 to obtain a conditional assessment, then have 180 days to mitigate all findings. That threshold represents 80 percent compliance with NIST SP 800-171 controls. Security requirements are valued at 1, 3, or 5 points, with deductions for unmet requirements. Partial credit is allowed for multi-factor authentication and FIPS cryptography implementation. Level 3 certification adds 24 enhanced security requirements from NIST SP 800-172 that defend against Advanced Persistent Threats (APTs). These enhanced requirements supplement the Level 2 controls and apply when contractors handle CUI associated with breakthrough technology or systems where an attack would create widespread DoW/DoD vulnerability. Mandatory Requirements vs Voluntary Adoption The existing 48 Code of Federal Regulations (CFR) rule was modified to align with the 32 CFR rule for CMMC, and compliance became mandatory rather than voluntary. Contracting officers now use the Supplier Performance Risk System (SPRS) to verify a contractor’s CMMC compliance status before awarding contracts and before executing contract extensions. The phased implementation began November 10, 2025. Phase 1 requires CMMC Level 1 and Level 2 self-assessments in applicable solicitations. Phase 2 starts November 10, 2026, and brings mandatory C3PAO certification requirements for Level 2 contracts. By November 2028, CMMC compliance becomes mandatory for all contracts that require the handling of Federal Contract Information (FCI) or CUI. Effect on Contract Eligibility and Revenue Contractors cannot be awarded DoW/DoD contracts, or maintain existing contracts when option periods require compliance verification, without proper CMMC 2.0 certification. Contracting officers shall not award a contract, task order, or delivery order to an offeror that does not meet the CMMC requirements identified in the solicitation. Non-compliant subcontractors cannot be awarded work, and awarding work to a subcontractor who lacks proper certification can place prime contracts at risk. The government can terminate contracts for non-compliance, and organizations could face serious consequences under the False Claims Act if compliance is misrepresented. Prime contractors must flow down CMMC requirements to all lower-tier subcontractors that store, process, or transmit FCI or CUI on unclassified contractor information systems. CMMC Level 2 Requirements and Assessment Guide 110 Security Practices in 14 Control Families Level 2 certification requires full implementation of 110 security controls specified in NIST SP 800-171 Revision 2. These practices address CUI protection across 14 distinct control families, and each family governs specific aspects of a cybersecurity program. Access Control represents the largest domain with 22 requirements. System and Communications Protection follows with 16 requirements. The remaining families range from 2 to 11 requirements each, covering everything from personnel security to risk assessment. Each security requirement maps to specific assessment objectives. Organizations must demonstrate compliance with 320 assessment objectives defined in NIST SP 800-171A. Assessors use three methods to evaluate these objectives: examine (reviewing documentation and configurations), interview (discussions with personnel), and test (exercising controls under specified conditions). The assessment methodology applies the same way regardless of contractor size or complexity. Technical Controls: Access Control and Authentication Access Control and Identification and Authentication together comprise 33 of the 110 total requirements, making them the most substantial technical domains. Requirement AC.L2-3.1.1 mandates limiting system access to authorized users, processes, and devices. Assessors verify role-based access control implementation, documented authorization procedures, and session timeout configurations during examination. The Identification and Authentication domain contains 11 requirements drawn from NIST SP 800-171 section 3.5. Requirement IA.L2-3.5.3 stands out as especially critical: multi-factor authentication for local and network access to privileged accounts, and for network access to non-privileged accounts. Organizations choose how to meet this requirement, and common approaches include authenticator apps, hardware tokens, or FIDO2 security keys. Password requirements under IA.L2-3.5.7 through IA.L2-3.5.9 are organizationally defined. They call for a minimum password complexity, restrictions on reuse across a defined number of generations, and immediate replacement of temporary credentials. NIST SP 800-171 sets these as organization-defined parameters rather than fixed values, so each contractor documents the specific thresholds in its policy. Administrative Controls: Training
Choosing a C3PAO: Your CMMC Audit Readiness Review Guide

Fewer than 85 certified assessors handle CMMC audit requirements for more than 80,000 organizations seeking compliance. This major gap creates challenges for defense contractors who must meet CMMC 2.0 requirements, which are now mandatory for all entities doing business with the DoD. Choosing the right CMMC C3PAO becomes critical. Failed assessments disqualify you from DoD contracts, and misrepresenting compliance can result in fines up to $10,000 per control. We’ve created this complete guide to help you select a qualified C3PAO and develop your CMMC audit preparation strategy. C3PAO Selection Framework for Defense Contractors Selecting a C3PAO shapes the whole assessment experience and determines the quality of your final report. Building a systematic framework helps you assess potential assessors objectively and avoid costly mistakes. Confirming Cyber AB Marketplace Listing Your first action must be verifying that any prospective C3PAO appears on the official Cyber AB Marketplace. All organizations seeking C3PAO designation undergo a rigorous, multi-step approval process that proves their impartiality, integrity, and cybersecurity competencies through Cyber AB accreditation. The Cyber AB serves as the official governing body with C3PAO oversight to determine eligibility, authorization, and accreditation. Never rely on what an assessor claims alone. Verify their Cyber AB accreditation status before moving forward with any discussions. Only C3PAOs listed on the Cyber AB marketplace are authorized to conduct CMMC Level 2 assessments. This verification ensures their legitimacy and adherence to program requirements. Ask how long they’ve held their C3PAO approval when you first speak with them. Some assessors secured early accreditation and have already completed CMMC assessments under the 2.0 framework. This early experience provides valuable insights into the actual assessment process versus theoretical knowledge. Evaluating Federal Compliance Experience Federal compliance experience extends beyond CMMC. Ask prospective C3PAOs about their broader federal assessment portfolio. How many federal clients do they serve? How many federal audits and assessments have they completed? Their answers reveal whether they understand the unique demands of government contracting. Experience with other federal assessments matters substantially. C3PAOs demonstrating competency in FedRAMP or ISO 27001 assessments show depth of expertise. These certifications serve as proof that the organization understands complex compliance frameworks. Ask about their assessor team structure as well. How many CMMC Certified Assessors (CCAs) and CMMC Certified Professionals (CCPs) do they employ? Are these professionals full-time employees or contractors? Full-time staff provides more consistency and availability than contract-based teams. NIST 800-171 Assessment Background NIST 800-171 assessment experience translates to CMMC competency. Ask whether they’ve performed NIST 800-171 assessments. This experience demonstrates their familiarity with CMMC compliance requirements since NIST SP 800-171 is the foundation of CMMC Level 2. Joint Surveillance Voluntary Assessments (JSVAs) represent another strong indicator of expertise. JSVAs allowed defense contractors to undergo collaborative evaluations by both third-party assessors and the DIBCAC before CMMC 2.0 became mandatory. C3PAOs who conducted JSVAs possess practical experience identifying and addressing cybersecurity gaps in real defense contractor environments. Client References and Case Studies Request references from organizations similar to yours in size and scope. Finding a C3PAO who has assessed similar organizations shows they know how to handle your environment and helps streamline the audit process. Small manufacturers working on weapons systems contracts need assessors experienced with that particular combination of size and complexity. Reputable C3PAOs provide case studies, client testimonials, or documented past assessment experience to demonstrate credibility. A lack of references serves as a warning sign. Compare at least three C3PAOs around costs, experience, methods, and staffing before making your decision. Red Flags and Warning Signs to Avoid “No C3PAO can promise certification, as assessments are based strictly on compliance with CMMC requirements.” — ISI Defense, CMMC compliance and cybersecurity advisory firm Understanding what to avoid proves just as significant as knowing what to seek. The CMMC audit process involves complex requirements that unscrupulous or inexperienced assessors might misrepresent. These warning signs protect your organization from wasted resources, failed assessments and potential legal risks when you recognize them. Below-Market Pricing Promises Pricing varies based on your organization’s cybersecurity maturity, size, required CMMC level and scope of work. Be that as it may, quotes that seem suspiciously low warrant scrutiny. A C3PAO that fails to ask detailed questions about your System Security Plan, documentation maturity and scope cannot estimate the work involved with any accuracy. Underbidding leads to frustrated assessors. The quality and integrity of your CMMC compliance audit suffers as a result. At the opposite end, excessively high fees without clear justification signal another problem. Request a detailed breakdown of all services included in the assessment cost. A reputable C3PAO explains what you’re paying for and provides transparent pricing structures. Costs that appear outrageous, whether thousands or millions of dollars, deserve additional scrutiny and comparison against industry guidelines. Guaranteed Certification Claims No assessor controls what they cannot guarantee. Promises like “we will have you done in 10 days” or “we guarantee you’ll be at the front of the assessment queue” sound appealing but mean nothing. C3PAOs cannot determine how long assessments take or which order the Department of Defense selects organizations to evaluate. What is more, Level 1 organizations need several months to verify all controls. Level 2 organizations require 15-18 months to prepare for an audit when starting from scratch. Anyone promising quick certification lacks understanding of the process. The final decision rests with assessors who evaluate whether your processes and controls meet CMMC standards. This process leads to missed requirements, failed certification and money wasted on C3PAO fees when you rush it since they must audit your organization again if you don’t pass. Conflict of Interest Violations A legitimate C3PAO does not provide CMMC readiness services to organizations it may assess. These restrictions protect the independence and integrity of the certification process. The objectivity of the assessment becomes compromised when an assessor also acts as an advisor. The Department of Defense and Cyber AB prohibit this conflict of interest. A C3PAO can offer both assessments and consulting services, but they cannot provide both to the same organization. Choose a C3PAO you have not
CMMC Town Hall Reveals Critical Level 2 Updates for Defense Contractors

CMMC is moving from talking about readiness to measuring throughput. In the February 2026 CMMC Town Hall, the program shared updated counts for CMMC Level 2 certifications, a snapshot of ecosystem capacity (C3PAOs, CCAs, CCPs), and clarified two topics that materially affect how organizations should prepare. First, a new Class Deviation intended to synchronize CUI safeguarding, NIST SP 800 171 assessments, and CMMC into a consolidated FAR and DFARS structure. Second, the ethics and limits of C3PAO led mock assessments (non-certification assessments), including what they must not include to protect impartiality. If you want help translating these updates into an execution plan for your environment, Book a Readiness Call to pressure test your scope, evidence, and assessment timeline. CMMC Level 2 certifications (February 2026 snapshot) The Town Hall shared the current status of CMMC Level 2 certifications and active assessments. Metric Count Certificates of CMMC Status Final 896 Certificates of CMMC Status Conditional 36 CMMC Level 2 Assessments In progress 110 What this means: Final certifications are increasing, conditional certifications remain a smaller subset, and there is an active pipeline of Level 2 assessments underway. If you are planning around assessment availability, this pipeline matters for scheduling and resourcing. Not sure how these numbers affect your timeline or assessor availability? Book a Readiness Call and we will map realistic lead times and readiness gates based on your current posture. CMMC ecosystem capacity: C3PAOs, assessors, practitioners The Town Hall also provided ecosystem counts across C3PAOs, assessors, and practitioners. Category Count Authorized C3PAOs 98 Applicant C3PAOs 547 CCAs 748 CCPs 1,494 Lead CCAs 452 Registered Practitioners 1,954 Registered Practitioners Advanced 255 Registered Practitioner Organizations 378 Approved Training Providers 47 Approved Publishing Partners 12 Why this matters for CMMC planning: There is a large applicant pool for C3PAOs and a growing base of practitioners, but the number of authorized C3PAOs is still comparatively limited, so readiness scheduling remains a real constraint for many organizations. What the new Class Deviation is A major topic was the new Class Deviation and its intended impact. The purpose The deviation is meant to synchronize CMMC, CUI safeguarding, and NIST SP 800 171 assessments into one consolidated document structure. The goal is to reduce fragmentation and align contracting language across overlapping requirements. What it temporarily replaces This deviation temporarily replaces existing FAR and DFARS text requiring contracting officers to use: Revised FAR Part 40 New DFARS Part 240 New DFARS PGI 240 What gets consolidated under DFARS Part 240 The discussion described consolidation of information and supply chain security under DFARS Part 240, including: CUI safeguarding NIST 800 171 assessments CMMC Supply chain risk authorities Telecom prohibitions Satellite prohibitions If your contracts or primes start using new references and your internal crosswalk is not updated, you can lose time fast. Book a Readiness Call to validate your clause to control mapping and avoid evidence rework. Clause renumbering: what changed vs what did not The Town Hall provided a clause mapping summary showing what was renumbered under the deviation and what remains unchanged. Old Clause Subject New RFO Clause (Deviation) FAR 52.204.21 Basic Safeguarding FAR 52.240 93 DFARS 252.204 7012 Safeguarding Covered Defense Information Not changed DFARS 252.204 7019 Retired DFARS 252.204 7020 NIST SP 800 171 Assessments DFARS 252.240 7997 DFARS 252.204 7021 CMMC Requirements Not changed Operational takeaway: Even when requirements are familiar, the clause references in contracting language may appear different. Update your internal clause mapping and any evidence tracker fields tied to clause IDs so your readiness work does not drift from what your contracts actually require. Before you update internal policies and evidence trackers, Book a Readiness Call to confirm the right clause crosswalk for your specific contracting context. Mock assessments: what a C3PAO can do and what they cannot do Another practical discussion focused on the ethics around mock assessments. Mock assessments are permitted, but only as non certification assessments A C3PAO can perform a non certification assessment for organizations seeking certification. The key constraints (Section 3.4) Section 3.4 addresses Non Certification Assessments (mock assessments). This is a cybersecurity conformity assessment, in full or in part, that does not result in issuance or denial of a certification. It can involve CMMC or other cybersecurity standards. To avoid impartiality risk, the mock assessment must A mock assessment must: Be conducted formally and in accordance with the CAP or other established cybersecurity conformity standards Not include any recommendations, advice, or consultative information to the organization seeking assessment Produce a deliverable documenting the official results Important: mock assessments do not equal CMMC status Mock assessments do not convey any standing or status within the CMMC program. If you want remediation guidance, not just a results only deliverable, Book a Readiness Call to design a readiness program that actually closes gaps before your formal assessment. Why you might not want your C3PAO to perform your mock assessment This was the most practical question raised in the discussion. If a C3PAO led mock assessment cannot provide recommendations or advice, then its value depends on what you are buying it for. When a C3PAO mock assessment can be valuable You need a formal CAP style rehearsal to see how your evidence reads under assessment discipline You believe you are already ready and want a neutral results artifact You want to stress test scoping, sampling, and evidence traceability without consulting When it can be a poor fit, or a premature spend Your biggest blocker is what to fix next You need help interpreting gaps, prioritizing remediation, or building an evidence plan You want how do we become compliant faster, which the mock assessment format is not allowed to answer Practical CMMC readiness strategy: many organizations benefit from a readiness partner that can advise and remediate, then engage the C3PAO for the official assessment once the program is truly evidence ready. This avoids paying for a results only dry run while still needing a separate engagement to translate results into fixes. ISACA transition: CAICO and certification administration The Town Hall
Financial Planning for CMMC Level 2 Readiness & Gap Closure

The numbers are striking – only 200 companies have completed CMMC Level 2 assessments out of 80,000 organizations that need certification. Defense Industrial Base contractors face mounting pressure as the December 16, 2024 deadline approaches faster. They must achieve compliance or risk losing valuable DoD contracts. Your organization needs to meet 110 practices arranged with NIST SP 800-171 standards for CMMC Level 2 compliance. The readiness process usually takes 12 to 24 months based on your starting point. Your certification costs could jump 20-30% if you delay compliance planning. Limited assessor availability and compressed timelines drive these increased costs. Most organizations need 6-12 months to prepare properly and avoid missing revenue opportunities. This complete guide breaks down CMMC Level 2 readiness costs, including certification expenses and hidden fees. You’ll learn budget-friendly ways to plan your investment. We’ll get into both direct and indirect compliance costs and share practical strategies to maximize your spending. This piece will help you guide your financial planning for successful CMMC Level 2 implementation, whether you’re a prime contractor, subcontractor, or service provider handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Understanding CMMC Level 2 Readiness and Scope Image Source: ECURON CMMC Level 2 helps organizations that handle sensitive government data in the Defense Industrial Base. You need to know the requirements, controls, and how to set the right scope before spending money on implementation. This will help control costs and stop the project from growing too big. CMMC Level 2 requirements and NIST 800-171 alignment CMMC Level 2 works hand in hand with NIST Special Publication 800-171. This gives a standard way to protect Controlled Unclassified Information (CUI). The DoD created CMMC Level 2 because many contractors weren’t following NIST 800-171 requirements properly. The Department of Defense came up with CMMC after seeing that defense suppliers weren’t consistently following NIST 800-171 standards. CMMC Level 2 doesn’t add new requirements – it just takes all the security controls from NIST 800-171 Rev 2, making both frameworks similar. CMMC Level 2 certification shows that your organization can protect CUI well enough to handle potential threats. This protection extends to information shared with subcontractors throughout supply chains. How many controls in CMMC Level 2 and what they cover CMMC Level 2 has all 110 security controls from NIST SP 800-171, hosted in 14 different security domains. These controls give detailed protection requirements for CUI throughout its lifecycle. The 14 security domains has: Access Control (AC) – Limits system access to authorized users only Awareness and Training (AT) – Helps staff spot security risks Audit and Accountability (AU) – Tracks and checks logs for incidents Configuration Management (CM) – Keeps systems configured securely Identification and Authentication (IA) – Checks user identity before giving access Incident Response (IR) – Sets up ways to spot and handle incidents Maintenance (MA) – Keeps systems secure during maintenance Media Protection (MP) – Protects physical and digital media with sensitive data Personnel Security (PS) – Makes sure system users have proper vetting Physical Protection (PE) – Controls who can enter facilities with CUI Risk Assessment (RA) – Reviews possible threats and weak points Security Assessment (CA) – Confirms if security controls work well System and Communications Protection (SC) – Keeps data safe during transmission System and Information Integrity (SI) – Fixes system flaws and stops malware Assessors look at 320 assessment objectives for these 110 controls during certification. Your organization must implement all these objectives fully to get CMMC Level 2 certification. CMMC Level 2 scoping guide: defining your CUI boundary Getting the scope right matters a lot for CMMC Level 2 compliance because it affects how much your assessment will cost. The CMMC Assessment Scope tells you which parts of your setup need checking. Level 2 assessment scope works differently from Level 3. The official CMMC Scoping Guide splits assets into five groups: CUI Assets – Systems that work directly with CUI. These need full assessment against all relevant controls and must appear in your asset inventory and System Security Plan (SSP). Security Protection Assets – Tools that keep CUI assets safe (like firewalls and SIEMs). These only need assessment for controls that match their security job. Contractor Risk Managed Assets – Systems that could handle CUI but aren’t meant to. These need documentation but less assessment. Specialized Assets – Things like IoT devices, operational technology, or government equipment that might handle CUI but can’t support all controls. These need special risk documentation. Out-of-Scope Assets – Systems completely cut off from CUI through physical or logical separation. These stay outside the assessment. A good CUI boundary definition focuses on finding where CUI exists in your setup and creating proper separation between CUI and non-CUI assets. This approach can cut compliance costs by a lot because you’ll only need to assess systems that truly need protection. Cost Breakdown for CMMC Level 2 Compliance Image Source: Info-Tech CMMC Level 2 certification requires a major financial commitment. Small to mid-sized contractors should expect to spend $70,000 to $250,000. Organizations need this cost breakdown to plan their budget throughout their compliance experience. Readiness assessment and gap analysis costs A full gap assessment reveals security shortcomings and serves as the first compliance step. Companies pay between $5,000 and $40,000 based on their size and complexity. Small and medium-sized businesses typically invest $10,000-$20,000 for a CMMC Level 2 gap analysis. Several factors affect this cost: Company’s size and current cybersecurity maturity IT complexity and number of locations Scope of systems handling CUI Need help getting started? Book a Readiness Call with a specialized consultant to understand your assessment requirements. Policy development and documentation expenses Your compliance program’s foundation rests on documentation that costs between $10,000 and $50,000. The breakdown includes: System Security Plan (SSP): $5,000-$20,000 Security policies and procedures: $3,000-$15,000[163] Standard Operating Procedures (SOPs): $2,000-$10,000[163] Plan of Action & Milestones (POA&M): $1,000-$5,000[163] Technology upgrades: MFA, SIEM, endpoint protection Technology investments vary widely from $20,000 to $250,000+ based on your current infrastructure. Key implementations include: Endpoint protection
CMMC Compliance Checklist for the Level 2 Self-Assessment

This CMMC compliance checklist is built for the requirement in front of you right now: the Level 2 self-assessment. In July 2026 the Department of War paused third-party CMMC assessment, which means most contractors handling Controlled Unclassified Information are currently accountable for a self-assessment they score and attest to themselves. The checklist below walks that from the 110 controls through the CUI-handling workflows and the documentation an assessor reads, so you can work it top to bottom and know where you stand. The standard did not change when the assessment path did. Level 2 still means all 110 requirements of NIST SP 800-171 Revision 2, and a self-attestation you cannot support is still a false statement to the government. Treat this as the same bar it always was, now with your signature on the result. Before the Checklist: What Level 2 Now Requires Level 2 applies to organizations that process, store, or transmit CUI, and it requires implementing all 110 NIST SP 800-171 Rev 2 requirements across 320 assessment objectives. The suspension changed who confirms your implementation, not what you have to implement. For the detail of what is paused and what stays in force, see the breakdown of the CMMC Level 2 suspension; for the end-to-end assessment mechanics, see the CMMC Level 2 assessment guide. Three obligations survive the suspension and are the reason the checklist still matters: DFARS 252.204-7012 still requires the 110 controls, the requirements themselves are unchanged, and a false self-attestation carries False Claims Act exposure. Work the checklist as if an assessor will read it, because the version of you that attests is standing in for the assessor who is currently paused. The CMMC Compliance Checklist for Level 2 Each item below is a checkpoint, not a one-time task. Work them in order, because each depends on the one before it. Confirm your level and your contract clauses. Verify whether your contracts carry DFARS 252.204-7012, which points to Level 2 for CUI, versus FAR 52.204-21 for FCI-only work at Level 1. The clauses in your contracts, not your assumptions, set the level. Settle and document your scope. Identify every asset that processes, stores, or transmits CUI and everything that protects those systems. Scope drives the size of the assessment, so this checkpoint carries the most cost leverage. Inventory and categorize assets. Place every in-scope asset into its category and give every out-of-scope asset a documented reason it cannot reach CUI. Assess against all 110 requirements. Run a gap assessment using the NIST SP 800-171A objectives, the same criteria an assessor uses, and rank what is missing. Score with the DoD Assessment Methodology. Build your Supplier Performance Risk System score from the official weighted methodology, not an estimate. Write the System Security Plan and POA&M. Document how each control is implemented and track every open gap with an owner and a close-out date. Submit and maintain. Submit the score to SPRS, close POA&M items within their window, and keep the documentation current as the environment changes. The rest of this guide expands the checkpoints that carry the most risk: the 110 controls, the CUI-handling workflows, and the documentation. The 110 Controls: What the CMMC Controls List Covers The CMMC Level 2 controls list is the 110 requirements of NIST SP 800-171 Revision 2, organized into 14 families. Knowing the families is how you turn an abstract number into a work plan, because each family is a distinct body of work with its own owner. Control family group Examples of what it covers Access and identity Access control, identification and authentication, limiting who reaches CUI and proving who they are Operations and monitoring Audit and accountability, configuration management, maintenance, system and information integrity People and response Awareness and training, personnel security, incident response Protection Media protection, physical protection, system and communications protection, risk and security assessment The table groups the 14 families so the list is workable, but the assessment scores all 110 requirements individually against 320 assessment objectives, which is the deeper number that matters. Each requirement can have several objectives, and every objective has to be met and evidenced. A control that is half-implemented is a partial or failed objective, not a rounding error, so the controls list is best treated as 320 things to prove rather than 110 things to install. CUI Workflows That Keep Scope Under Control The fastest way to lose control of a CMMC assessment is to let CUI move in ways your workflows do not account for, because every path CUI takes pulls the systems on that path into scope. Building the handling workflows deliberately is what keeps the boundary you scoped from quietly expanding. Start by following the data. Trace where CUI enters, where it is processed and stored, and where it leaves, and turn that into a data flow diagram that becomes assessment evidence. The workflows that matter most are the everyday ones: how CUI is received from the government or a prime, how it is stored and who can reach it, how it is transmitted to subcontractors, and how it is disposed of. Each of those is a workflow you define and enforce, not an accident you discover during assessment. The workflows also decide how tightly you can separate CUI from everything else. Logical separation, using segmentation and access controls, keeps CUI-handling systems apart while they stay connected, and it is the common approach. Physical separation removes the connections entirely for the most sensitive cases. The point of both is the same: the smaller and better-defined the set of systems and people that touch CUI, the smaller the assessment. The mechanics of drawing that line are covered in the CMMC environment scoping guide, and the specific question of where CUI stops is covered in defining the CUI boundary. Documentation the Checklist Produces The checklist is not finished until it has produced the documents an assessment runs on, because implemented controls that are not documented cannot be verified. Three artifacts carry the weight. The System Security Plan