The CMMC Certification Process, Step by Step
The Cybersecurity Maturity Model Certification (CMMC) program began phasing into defense contracts on November 10, 2025, when the Defense Federal Acquisition Regulation Supplement (DFARS) final rule took effect. The program was designed to require a Level 2 third-party assessment as a condition of contract award for roughly 8,350 medium and large defense contractors.
As of September 2026, that third-party assessment requirement is on hold. On July 13, 2026, the Department of Defense (DoD) suspended CMMC Phase 2, including the November 10, 2026 milestone that would have required assessments by a Certified Third-Party Assessment Organization (C3PAO), pending a 60-day Reform Task Force review.
The suspension pauses the assessment mechanism but does not lift the underlying obligations: Phase 1 self-assessment requirements and DFARS 252.204-7012 safeguarding duties remain in force. The pending Phase 3 and Phase 4 milestones are paused, along with Phase 2. Contractors still need to complete the underlying preparation, which carries over unchanged and positions them to move quickly once third-party assessment resumes.
Key Takeaways
- Three-stage process. Start with scope and self-assessment so remediation and the final assessment have the evidence they need.
- System Security Plan. An absent or inaccurate System Security Plan (SSP) halts the assessment entirely and cannot be deferred to a Plan of Action and Milestones (POA\&M).
- Assessment path. The assigned level determines the assessor type and reporting route.
- Infrastructure scope. Deploying inside an already-authorized Federal Risk and Authorization Management Program (FedRAMP) boundary shifts infrastructure-layer controls off your responsibility and narrows what a C3PAO assesses.
The CMMC Certification Process Verifies Cybersecurity Maturity Against a Defined Standard
CMMC certification is a structured path that verifies whether a contractor's information systems meet a defined cybersecurity standard before a contract is awarded. The standard depends on the level:
- Level 1 includes 15 Federal Contract Information requirements in the CMMC Level 1 Assessment Guide, Version 2, drawn from Federal Acquisition Regulation (FAR) 52.204-21.
- Level 2 maps to the National Institute of Standards and Technology (NIST) SP 800-171 Rev. 2, which contains 110 requirements.
- Level 3 maps to the 110 requirements plus 24 additional requirements selected from NIST SP 800-172.
The process starts by defining which assets fall in scope. Contractors then document and implement the required controls before a final assessment determines certification status.
Who performs that final assessment depends on the level and the contract. Level 1 and some Level 2 requirements are satisfied through self-assessment submitted in the Supplier Performance Risk System (SPRS). Prioritized Level 2 acquisitions involving Controlled Unclassified Information (CUI) require an authorized C3PAO assessment. The government assesses Level 3 exclusively through the Defense Contract Management Agency (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
With the standards and assessor roles established, the next question is how the work itself is sequenced.
The Certification Process Follows a Defined Sequence
The path to certification works best when treated as sequential. Each stage produces the inputs that the next stage depends on, so skipping ahead leaves documentation and evidence problems until late in the process.
1. Scope the Environment and Conduct a Self-Assessment
Scoping and self-assessment produce the foundational documentation that all subsequent steps depend on. Getting the boundary and current-state evaluation right the first time prevents rework during remediation and the formal assessment.
- Identify every asset that processes, stores, or transmits CUI, and categorize all assets into the five CMMC categories in the CMMC Level 2 Scoping Guide, Version 2: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets.
- Map current controls against the 110 NIST SP 800-171 requirements to determine which are MET and which are NOT MET, using the same NIST SP 800-171A objectives an assessor would apply.
- Document the SSP, including the system boundary and asset categories, a network diagram showing CUI flow, implementation status for each requirement, and a Customer Responsibility Matrix if a cloud provider is involved.
An accurate scope and honest self-assessment reveal exactly what remediation needs to address.
2. Remediate the Control Deficiencies
Remediation closes the distance between existing controls and the requirements the assessor will test. Prioritization matters here because not every deficiency carries the same weight.
- Prioritize deficiencies by risk and scoring weight, since the DoD Assessment Methodology, Version 1.2.1 (June 24, 2020), subtracts 1, 3, or 5 points for high-value controls that are missing or partially implemented.
- Update policies and procedures so they reflect actual operations, not aspirational language.
- Implement the technical controls, then record any permitted remaining items in a POA\&M with owners, milestones, and completion dates.
Once remediation is complete and the POA\&M reflects any residual work, the environment is ready for external review.
3. Complete the Third-Party or Government Assessment
The formal assessment validates the work done in the previous stages against the assigned CMMC level. Timing and reporting mechanics matter as much as the technical evidence. Because Phase 2 is currently suspended, a C3PAO assessment is not a present condition of award. These steps describe the process as designed, so a contractor stays ready for when the requirement resumes.
- Engage an authorized C3PAO from the Cyber AB Marketplace for the assessment.
- Plan for assessor capacity when the requirement resumes: the Federal Register projected C3PAO-led certification assessments to rise from 135 in Year 1 to 4,452 in Year 4, against roughly 8,350 medium and large entities in scope for Level 2. A limited pool of authorized C3PAOs was a stated reason for the Phase 2 pause.
- Complete the required reporting path: Level 2 C3PAO and Level 3 DIBCAC results are routed through CMMC eMASS and SPRS, and any conditional POA\&M items close within 180 days.
Results feed the SPRS and eMASS entries that determine certification status and award eligibility.
Common Weaknesses That Can Slow the Certification Process
Even contractors who follow the sequence correctly can lose time to a handful of predictable weaknesses that surface during the C3PAO review. Some are documentation issues that prevent the assessment from producing a finding. Others are technical implementations that look compliant on paper but fall short under the assessor's evaluation criteria.
Recognizing where these tend to appear helps focus remediation efforts on areas that actually change the outcome.
- Missing or outdated SSP. An absent or stale SSP halts the assessment, and CA.L2-3.12.4 cannot be placed on a POA\&M. The SSP must reflect how the environment actually operates.
- Encryption that is capable but not validated. FIPS 140-3 validation matters under 3.13.11. Confirm FIPS 140-3 mode is enabled and that validation applies to the module itself.
- Incomplete multifactor authentication. Control 3.5.3 requires MFA for local and network access to privileged accounts and network access to non-privileged accounts. Partial implementation still costs points.
- Control families requiring sustained operation. SC, AC, and CM require continuous enforcement and monitoring. Incident Response (IR) and Audit & Accountability (AU) require technical capability plus consistent day-to-day operation.
- Undocumented shared responsibility. When cloud responsibility is not captured in the SSP and the Customer Responsibility Matrix, assessors have no basis to treat a control as inherited.
The severity and applicability of these weaknesses depend on the CMMC level assigned by the contract.
The Assigned Level Determines the Assessment Path
The level named in the solicitation dictates who assesses you, how often, and what affirmation is required. The same underlying control evidence may support the work, but the route to a certified status changes by level.
- Level 1 uses a self-assessment path: Covering 15 Federal Contract Information requirements, contractors complete a recurring self-assessment, enter the results into SPRS, and affirm compliance. No third party is involved, and POA\&Ms are not permitted.
- Level 2 uses a C3PAO assessment path: covering the 110 requirements in NIST SP 800-171 for systems handling CUI, prioritized acquisitions require an accredited C3PAO to conduct the assessment (the milestone paused under the July 2026 suspension), with affirmation steps between assessment cycles.
- Level 3 uses a government-led assessment path: Adds 24 selected requirements from NIST SP 800-172 and is assessed exclusively by DCMA DIBCAC. A Level 2 C3PAO status for the same scope, with any Level 2 POA\&M closed out, is a prerequisite for the Level 3 assessment.
Whichever path applies, the volume of evidence required scales with the extent of the environment in scope.
Contractors With CUI in Multiple Systems Face a More Complex Assessment Scope
Every asset that processes, stores, or transmits CUI enters scope, along with supporting infrastructure such as firewalls, Security Information and Event Management (SIEM) systems, Virtual Private Network (VPN) services, and any external service provider whose services help meet a requirement.
When CUI runs through multiple applications or cloud environments, the number of assets to document, the controls to evidence, and the hours a C3PAO must spend all multiply. Segmentation, whether physical or logical, is the primary way to shrink that footprint, but it only works when the boundary is precisely defined and holds up under scrutiny.
The underlying hosting model largely determines how much of that boundary a contractor owns outright.
A Pre-Hardened Infrastructure Simplifies Every Stage of the Process
The more infrastructure a contractor owns from the physical layer up, the more controls they must implement, document, and defend during assessment. A pre-hardened environment with authorized infrastructure-layer controls shifts much of that work to the provider and shrinks the boundary a C3PAO must review.
Knox Systems is a FedRAMP-as-a-Service platform whose pre-authorized boundary lets SaaS vendors and subcontractors deploy inside an environment where infrastructure controls are already assessed and available to inherit.
- Authorization coverage: Currently supports FedRAMP Moderate, FedRAMP High, and Defense Information Systems Agency (DISA) IL-4. Impact Level 5 (IL-5) authorization is in process, with an estimated completion date of December 2026.
- Inherited controls: Infrastructure-layer controls are pre-authorized and available for the contractor's SSP.
- Documented responsibilities: Continuous monitoring keeps shared and inherited controls mapped for the SSP and Customer Responsibility Matrix.
Application-layer controls, policies, and operations still require assessment, but the surface an assessor must review is materially smaller.
Following the CMMC Certification Process Starts With Knowing Where You Stand
The gap between a self-assessed SPRS score and an independently reviewed score is where contractors can get caught. Knowing your true starting position is the first honest step in the process, because it shows how much scoping and remediation stand between you and an assessment you can pass.
Knox Systems is a FedRAMP-as-a-Service platform that narrows that distance at the infrastructure layer. By deploying within its pre-authorized boundary, SaaS vendors and prime-contractor subcontractors inherit a meaningful share of the technical controls that would otherwise sit on their own remediation roadmaps, with automated continuous monitoring that keeps inherited and shared responsibilities documented.
Knox delivers authorization in approximately 90 days at 90% lower cost than the traditional path, which costs $3.5M+ and takes 12 to 36 months. While the platform does not remove the C3PAO or DIBCAC assessment, a smaller inherited-control footprint means you have to build, harden, and prove less of the environment yourself.
If federal contracts are sitting in your pipeline behind a compliance requirement, book a meeting and map your CUI environment against what you can inherit.
FAQs about the CMMC Certification Process
How Long Does a Level 2 C3PAO Assessment Take?
Assessment length depends on scope size, SSP accuracy, evidence completeness, assessor availability, and POA\&M closeout work. A smaller, well-documented boundary is easier to schedule and support.
When Should I Engage a C3PAO?
With Phase 2 suspended, a mandatory C3PAO assessment is not a current condition of award, though voluntary assessments remain available. Engage an authorized C3PAO after the boundary, SSP, asset categories, and initial control evidence are ready for review. Schedule to account for the assessor's availability and any remaining remediation work when the requirement resumes.
What Happens if Scope Changes Before the Assessment?
A scope change can alter the asset inventory, network diagram, shared-responsibility documentation, and evidence package. Reconfirm the boundary before the assessment date so the review reflects the environment the contractor actually operates in.