Preparing for a CMMC Level 2 assessment typically takes 6 to 18 months, a planning estimate rather than a regulated duration. Remediation consumes most of that window, from about 2 months for contractors with a mature NIST SP 800-171 Revision 2 program to 12 months or more for those starting below 40 SPRS points. The C3PAO assessment itself usually takes several days of assessor work, on-site or remote. After it, 32 CFR Part 170 allows up to 10 business days to re-evaluate NOT MET requirements and 180 days to close POA&M items, and Department of War guidance permits only one finalized closeout. As of September 2026, the Department of War has suspended the move to CMMC Phase 2, so contracts may designate only Level 1 (Self) or Level 2 (Self), while C3PAO certification remains available voluntarily.
How long does CMMC Level 2 take?
It depends on your starting score and how complex your environment is. It also depends on which parts of the process run on a clock set by regulation.
Most of the durations on this page are planning estimates based on common patterns. No DoD rule and no Cyber AB procedure sets how long preparation, C3PAO scheduling or the assessment itself should take. What 32 CFR Part 170 does fix are the windows after the assessment, and the table in the next section separates the two.
The deadline question changed in July 2026, when the Department of War (DoW) suspended the move to CMMC Phase 2. What hasn’t changed is the work to meet NIST SP 800-171. For what to check in a specific solicitation or contract, see what to check during the CMMC pause.
Regulated Windows and Planning Estimates
Keep regulated windows and planning estimates apart in a CMMC Level 2 plan. That way you won’t treat an estimate as a deadline, or miss a window the rule enforces.
| Step | Fixed by rule or procedure | Planning estimate |
|---|---|---|
| Preparation (scoping, remediation, documentation, readiness review) | No duration set | 6 to 18 months in total |
| Scheduling a C3PAO | No duration set. The C3PAO and the contractor agree on an estimate of “the approximate duration and timing for the assessment” (CAP) | No official lead-time data. Ask two or three C3PAOs for dates in writing |
| The assessment (CAP Phases 1 to 3) | No duration set. DoD’s 2024 cost model priced 120 hours of C3PAO engagement (3-person team) for a small entity and 200 hours (5-person team) otherwise | Several days of active assessor work, on-site or remote |
| Re-evaluating NOT MET requirements | Up to 10 business days after the active assessment, before the findings report is delivered (32 CFR 170.17(c)(2)) | |
| Out-brief when re-evaluation is requested | No sooner than 10 business days after evaluative activity ends (CAP 3.10) | |
| Appeal to the Cyber AB | Within 15 business days of receiving the C3PAO’s written decision on the appeal (CAP 3.28) | |
| POA&M closeout | Within 180 days of the Conditional status date, finalized in CMMC eMASS one time (32 CFR 170.17; DoW CIO FAQ) | |
| Status validity | 3 years from the CMMC Status Date. After a Conditional status, that date stays the Conditional date and does not reset at Final (32 CFR 170.4, 170.17(a)(1)) | |
| Affirmation | After every assessment, including the POA&M closeout, and annually thereafter (32 CFR 170.22) |
The End-to-End Timeline
A realistic CMMC Level 2 timeline breaks into five stages. Total elapsed time depends on how many stages overlap and how much remediation your organization needs. The stages and their durations are planning estimates. They are separate from the four phases of the C3PAO’s CMMC Assessment Process and from the CMMC implementation phases.
Stage 1: Scoping and Gap Assessment (4-8 Weeks)
What happens: You define your CUI boundary, identify in-scope assets and map data flows. From there, you evaluate your current implementation against all 110 NIST SP 800-171 Revision 2 security requirements at the assessment-objective level. The result is a calculated score using the method in 32 CFR 170.24. Each requirement is worth 5, 3 or 1 point, and the score can go negative.
What determines duration: Environment complexity. A small contractor with a contained CUI enclave and a single location can scope and assess in 4 weeks. A mid-size organization with multiple locations, distributed systems and several external service providers needs 6 to 8 weeks.
Common delays: CUI turns up in systems nobody anticipated. Data flow mapping reveals undocumented connections. MSP relationships need a customer responsibility matrix. These delays matter later. In the C3PAO’s process, scope and external providers are hard gates. Scope disagreements must be resolved before the assessment proceeds to its Phase 2. An in-scope external service provider must supply a customer responsibility matrix and have staff present. Guidance: CUI boundary scoping and the customer responsibility matrix.
Milestone: A completed gap assessment with a calculated score, a prioritized list of NOT MET requirements, and a remediation roadmap.
Stage 2: Remediation (2-12 Months)
What happens: You close the gaps identified in Stage 1. This includes implementing technical controls, writing policies and procedures, configuring security tools, deploying new capabilities where needed, and training personnel.
What determines duration: How far you are from the baseline. An organization with a reasonable existing program, with MFA in place, encryption configured and basic policies written, might need 8 to 12 weeks of focused remediation. Starting below 40 points with large control gaps? Plan for 12 months or more.
Common delays:
Procurement cycles. New security tools (SIEM, vulnerability scanners, endpoint protection, backup) require evaluation, budgeting and approval, purchase, deployment, configuration and testing. Each tool adds weeks.
Policy development. Policies and procedures must describe how the NIST SP 800-171 requirements are implemented in your environment. Many teams organize that documentation by the 14 control families. Assessors compare it with how the environment runs in practice.
Training. Security awareness training must reach the managers, system administrators and users of in-scope systems (NIST SP 800-171 3.2.1), and the training records become assessment evidence. Role-based training for staff with security duties (3.2.2) takes additional time.
Then there’s MSP coordination. If your MSP implements controls assigned to it in the customer responsibility matrix, its timeline becomes yours. In Deep Fathom’s view, this is the delay contractors most often underestimate, because MSP remediation work competes with the provider’s other clients.
Milestone: Enough of the 110 requirements are implemented to support a Conditional status. Under 32 CFR 170.21 that means a score of at least 88 out of 110, with only 1-point requirements left for a POA&M. The one exception is SC.L2-3.13.11 (CUI encryption). When encryption is employed but not FIPS-validated, it scores 3 points and may still go on a POA&M. Six requirements can never be on the POA&M that supports a Conditional status: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4 and PE.L2-3.10.5. Under 32 CFR 170.24, every NOT MET requirement still needs a POA&M entry.
Stage 3: Documentation and Evidence (4-8 Weeks, Overlapping with Stage 2)
What happens: You build or update your System Security Plan, finalize policies and procedures, and collect evidence for every requirement. Capture evidence as controls are implemented during Stage 2. Consolidation, organization and quality review happen here.
What determines duration: Whether evidence was collected along the way or has to be assembled after the fact. Organizations that implement first and document later should add 4 to 8 weeks of dedicated effort.
Common delays: SSP completeness. Writing environment-specific implementation descriptions for 110 requirements is labor-intensive, and each description must match the technical reality. The SSP requirement (CA.L2-3.12.4) can’t be on the POA&M that supports a Conditional status. According to the DoW CIO FAQ, marking it NOT MET produces a “No Score” in SPRS. See how to write a CMMC System Security Plan.
Evidence gaps. A control is implemented, but nobody captured the configuration. Training happened, but attendance wasn’t recorded. Reconstructing decisions that nobody documented at the time is slower than capturing them as work happens.
Milestone: A finished SSP, finalized policies, and an organized evidence repository mapped to assessment objectives.
Stage 4: Readiness Review and Mock Assessment (2-4 Weeks)
What happens: You run an internal readiness review or engage a Registered Provider Organization for a mock assessment. You test evidence retrieval, verify SSP accuracy, rehearse staff interviews, and fix findings before the formal assessment. The DoW CIO FAQ gives the same order: self-assess, correct the gaps, then initiate an assessment. For the steps in detail, see how to prepare for your CMMC assessment.
What determines duration: The quality of Stages 2 and 3. Thorough work means a confirmatory review of about 2 weeks. Major gaps add remediation loops.
Plan for independence: A consultant who prepared you for a CMMC assessment cannot take part in your certification assessment for 3 years. During the assessment, the C3PAO can’t advise you on fixing gaps. If you aren’t ready, it can recommend suspending the assessment.
Milestone: Confirmed readiness for the formal assessment: requirements implemented, evidence retrievable, staff prepared for interviews and an SSP that matches the environment.
Stage 5: C3PAO Assessment (3 Days to a Week or More, Plus Scheduling)
What happens: An authorized or accredited C3PAO runs the assessment under the CMMC Assessment Process (CAP). Its phases are a pre-assessment phase, the conformity assessment, reporting of results, and certificate issuance with any POA&M closeout. At minimum, the team includes a Lead CMMC Certified Assessor and one other assessor. They examine documentation, interview personnel and test controls. By mutual agreement, much of the evidence work can run remotely.
What determines duration: Assessment scope, the number of in-scope systems, and team size. A small contractor with a contained enclave might finish the active assessment in 3 to 4 days. A larger organization with a complex boundary could need a week or more. These are estimates.
Scheduling: There’s no official data on current C3PAO lead times. On July 15, 2026, the Cyber AB reported 110 authorized C3PAOs and more than 1,000 CMMC Certified Assessors. Ask two or three C3PAOs for a written estimate of duration and timing before you fix a target date. The Cyber AB Marketplace lists authorized and accredited C3PAOs.
Milestone: A Conditional or Final Level 2 (C3PAO) status recorded in CMMC eMASS, followed by an affirmation in SPRS.
From Assessment to Certificate: The Regulated Windows
After the assessment, 32 CFR Part 170 and the CAP set the CMMC Level 2 timeline.
The 10-business-day re-evaluation window
Assessors may re-evaluate NOT MET requirements during the assessment and for 10 business days after the active assessment period ends. That applies only when additional evidence already exists, the change does not affect requirements already scored MET, and the findings report has not been delivered. For how this interacts with the POA&M, see re-evaluation and POA&M under CMMC.
Results, quality assurance and the certificate
Before the C3PAO submits results into CMMC eMASS, a quality assurance reviewer reviews the package. That reviewer must be a CMMC Certified Assessor outside the assessment team. eMASS transmits the results to SPRS. CMMC eMASS then returns the status (Final or Conditional), a unique identifier and the CMMC Status Date to the C3PAO, which issues the Certificate of CMMC Status. No rule sets how many days this takes. Ask your C3PAO for its usual turnaround.
Conditional status and the one-time POA&M closeout
A Conditional Level 2 (C3PAO) status lasts up to 180 days from the CMMC Status Date. Within that window, a C3PAO must perform a POA&M closeout assessment of the open requirements and post the results in eMASS. The DoW CIO FAQ adds that the closeout “can only be finalized in the CMMC Enterprise Mission Assurance Support System (eMASS) one time.” If any requirement is still NOT MET when it is finalized, the Conditional status ends and a new assessment is required.
So the 180 days aren’t all remediation time. Subtract the time to schedule the closeout, run it, complete quality assurance and post the results. A different C3PAO from the one that ran the original assessment can perform the closeout. See how the 180-day POA&M closeout works and what happens if you fail a CMMC assessment.
After a Conditional status, the three-year clock starts at the Conditional date
When an assessment ends in Conditional status, the CMMC Status Date is the date the Conditional results are submitted. A successful closeout doesn’t set a new date (32 CFR 170.4). So a contractor that closes its POA&M on day 170 holds Final status for about two and a half years before recertification is due. That’s 3 years from the Conditional date.
Is Six Months Enough to Prepare for CMMC Level 2?
As a planning estimate, six months from decision to assessment is achievable when the starting point is strong. Use these checks before committing to the date:
| Check | Why it matters | Where it comes from |
|---|---|---|
| Current score of at least 88 out of 110, or a credible path to it within about 3 months | Below 88, no Conditional status is possible | 32 CFR 170.21 (88-point threshold), planning estimate (3 months) |
| No open 5-point or 3-point requirements, apart from SC.L2-3.13.11 when encryption is employed but not FIPS-validated | Only 1-point requirements can be on the POA&M behind a Conditional status | 32 CFR 170.21 |
| None of the six excluded requirements open, including the SSP (CA.L2-3.12.4) | These can never be on the POA&M behind a Conditional status. A missing SSP produces “No Score” | 32 CFR 170.21 and DoW CIO FAQ |
| Scope agreed and any external service provider’s customer responsibility matrix ready | Both are gates in the C3PAO’s process | CAP 1.4 and 1.6 |
| New tools purchased or procurement under way | Procurement adds weeks per tool | Planning estimate |
| A C3PAO’s written estimate of dates and duration | No official lead-time data exists | CAP |
If most checks fail, plan for 9 to 18 months (a planning estimate). If they pass, six months is realistic, provided the remaining work is documentation, evidence and readiness review.
Total Timeline Summary
| Starting point | Typical time from decision to completed assessment (planning estimate) |
|---|---|
| Minimal existing program (score below 40, limited controls) | 12 to 18 months or longer |
| Moderate program (some controls in place, partial documentation) | 9 to 14 months |
| Strong NIST SP 800-171 program (score above 70, current SSP) | 6 to 9 months |
These ranges include time to schedule a C3PAO, but lead times vary by assessor and no official figure exists. Any POA&M window comes after the assessment and adds up to 180 days.
Delay Drivers and How to Shorten Them
Scope. Scoping reveals CUI in unexpected places, which expands the boundary and every later stage. In Deep Fathom’s view, narrowing the CUI boundary does more than any other step to shorten all five stages. A defined CUI enclave reduces what you need to secure and document.
Evidence captured in real time. Every time you implement or verify a control, capture the evidence: the configuration export, the access control list, the training record.
External service providers. Start the customer responsibility matrix during Stage 1. An MSP that hasn’t prepared becomes a bottleneck for every client.
Procurement is its own delay. Run purchases in parallel where you can.
Staff turnover. When the person leading the program leaves mid-preparation, knowledge leaves too. Keep requirements, owners, decisions and evidence in a shared record so the program survives the handoff.
A shared record of the work. Deep Fathom organizes each requirement, its assigned owner and its evidence in one record, so gaps and stalled work are visible before the assessment. The C3PAO assesses the implementation and determines your status.
How the July 2026 Suspension Changes the Timeline
As of September 2026:
- What changed. On July 13, 2026, the Department of War suspended the November 2026 transition to CMMC Phase 2. The DoW CIO’s memo of the same date held all later implementation milestones in abeyance. The implementing memo allows contracts to designate only CMMC Level 1 (Self) or Level 2 (Self). It directs removal of Level 2 (C3PAO) and Level 3 designations from active solicitations as soon as practicable, and from existing contracts before the next option is exercised or at the next scheduled administrative modification. During the suspension, no new DoW solicitation or contract may designate a Level 2 (C3PAO) or Level 3 requirement.
- What didn’t change. DFARS 252.204-7012 has required implementation of NIST SP 800-171 since December 31, 2017, and it still applies. A Level 2 (Self) requirement means a self-assessment with results in SPRS, an affirmation, and a 180-day window to close a Conditional self-assessment’s POA&M. The preparation stages above apply to either path.
- C3PAO certification is voluntary for new DoW requirements. The Cyber AB stated on July 15, 2026 that all CMMC program elements, including C3PAO Level 2 certification assessments, “remain operational and available.” A Level 2 (C3PAO) status also satisfies Level 1 (Self) and Level 2 (Self) for the same assessment scope, and a prime can still ask for one as a term of its subcontract. A contract or solicitation that hasn’t yet been modified can still carry a Level 2 (C3PAO) requirement, so check the document itself before scheduling or cancelling an assessment.
What happens next isn’t settled. A CMMC Reform Task Force was set up for a 60-day review. That review ended around September 11, 2026, and as of September 24, 2026, no report or decision had been published. If DoW restores the third-party requirement under the current rule, the stages and windows on this page apply as written. If 32 CFR Part 170 or the DFARS is amended, the amended text will set the windows and any deadline. And if contracts stay limited to self-assessment, Level 2 (Self) and the preparation stages above are the work.
Next Step
Tell us your current score, which systems handle CUI, and what your contract or prime requires. Our team will review it and reply within one business day with the stages likely to run long and what to fix first. Send it to our team, see how Deep Fathom organizes CMMC work, or create a free workspace to track the work yourself.
References · 6 official sources
| Source | What it covers in this article | Type |
|---|---|---|
| 32 CFR Part 170 (CMMC Program Rule) | Scoring method, Conditional status and POA&M limits, the 10-business-day re-evaluation window, the 180-day closeout, the CMMC Status Date and affirmations | Regulation |
| CMMC Assessment Process (CAP) v2.0, The Cyber AB | The C3PAO’s four assessment phases, scope and external-provider gates, out-brief timing, appeals and certificate issuance | Guidance |
| DoW CIO CMMC Frequently Asked Questions (July 2026) | The one-time POA&M closeout, “No Score” for a missing SSP, and DoW’s preparation advice | Guidance |
| USW(A&S) memo implementing the CMMC Phase II suspension (July 13, 2026) | The designations contracts may use during the suspension, and how existing requirements are removed | Guidance |
| The Cyber AB statement on the Phase II suspension (July 15, 2026) | Continued availability of C3PAO assessments and the size of the assessor ecosystem | Press |
| NIST SP 800-171 Rev 2 | The 110 security requirements that preparation must implement (withdrawn by NIST in 2024 and still the CMMC and DFARS 252.204-7012 baseline) | Standard |