Levels, timelines, and the route to certification, mapped to how DoD contractors actually get assessed.
Book a readiness callUntil CMMC becomes a mandatory contract requirement (Nov 10, 2026).
Level 1, 2, and 3, scoped to the sensitivity of the data you handle.
The control set assessed for a Level 2 certification.
How often a C3PAO assessment must be renewed.
You have 124 days until CMMC becomes a standard contract clause. Contractors who wait for a solicitation to require it typically run out of runway.
Level 1 and select Level 2 contractors self-attest annually in SPRS.
C3PAO-certified Level 2 assessments start appearing in new contracts.
CMMC requirements cascade to subcontractors handling CUI further down the supply chain.
CMMC becomes a standard condition of contract award and renewal across the DIB.
Your level is set by what you handle: Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), not by company size.
FCI only. 17 basic safeguarding practices. Annual self-assessment.
CUI in scope. All 110 NIST SP 800-171 controls. Third-party (C3PAO) assessment for most contracts.
Highest-sensitivity CUI. Level 2 plus a further control set. Government-led assessment.
For Level 1 (FCI-only) and select Level 2 contractors, who can self-attest in SPRS without a third-party assessor.
Annual self-attestation in SPRS
Senior official affirmation required
Lower cost, faster to complete
No third-party assessor involved
Required for most Level 2 contracts and all of Level 3. An accredited third-party assessment organization conducts the assessment.
Assessed against all 110 controls
Certification valid for three years
POA&Ms allowed for a limited control set
Required to hold CUI on most DoD contracts
A program guide is only as good as the artifacts behind it. This is what we bring to the engagement.
Advisory and engineering under one roof, not handed off between vendors
SSPs written to match the environment as built, not as originally scoped
Assessor-grade dry runs before the real assessment starts
Secure Enclave and Microsoft Gov Cloud partner on staff for the CUI boundary itself
Yes, at Level 1. Any contractor processing Federal Contract Information under a covered contract needs an annual Level 1 self-assessment, even without CUI in scope.
Only a subset of Level 2 contracts allow self-assessment. Most Level 2 contracts, and all of Level 3, require a C3PAO-led third-party assessment.
Phase 2 makes CMMC certification a condition of contract award for in-scope solicitations issued on or after that date. Contractors without the required level are ineligible for those awards.
Most programs run 4 to 9 months from initial scoping through a passed C3PAO assessment, depending on how much remediation the environment needs.