CMMC Ready Now
Compliance Alert

Countdown to CMMC Phase 2: 5 Critical Moves to Make Before November 10, 2026

November 10, 2026 is not a soft target and it will not move. Contractors who act in July control their own timeline. Contractors who wait until fall will be negotiating with a queue.

CMMC Phase 2 arrives on November 10, 2026, and for thousands of defense contractors it will be the most consequential compliance date of the decade. On that day, contracting officers gain the authority to require a third-party CMMC Level 2 certification as a condition of contract award for work involving Controlled Unclassified Information (CUI). With four months left on the clock, the difference between winning and losing DoD work now comes down to preparation.

Here are the five moves every contractor should make before the deadline, in priority order.

What Changes When CMMC Phase 2 Begins

Under the phased rollout defined in 32 CFR Part 170, Phase 1 (which began November 10, 2025) required self-assessments and affirmations in SPRS. Phase 2 raises the bar: contracts involving CUI can now require a CMMC Level 2 certification performed by an authorized C3PAO before award.

That word “before” matters. Certification is becoming a prerequisite for award, not a promise you can fulfill after signing. If your certificate is not in place when a solicitation demands it, you are simply ineligible, no matter how good your proposal is. We covered the mechanics of the rule in our earlier post on CMMC Phase 2 requirements.

The scale of the change is worth pausing on. The Department of Defense estimates that tens of thousands of companies in the defense industrial base handle CUI and will eventually need Level 2 certification. As of this spring, only about 1,000 organizations held one. The contractors who close that gap early will spend late 2026 winning work; the rest will spend it explaining to primes why their certificate is still pending.

Move 1: Confirm Your CMMC Level and Assessment Scope

Start with the data. Do you create, receive, or store CUI? Which contracts carry DFARS 252.204-7012 or the new 7021 clause? Your answers determine whether you need Level 1 self-assessment or Level 2 certification, and they define your assessment boundary.

Scoping errors are among the most expensive mistakes in a CMMC program. A boundary drawn too wide inflates cost; drawn too narrow, it can invalidate your assessment. If you are unsure where to draw the line, our guide on what activates CMMC is the place to start.

Move 2: Update Your SPRS Self-Assessment and Affirmation

Primes and contracting officers are checking SPRS scores before they shortlist bidders. An outdated or missing score is a silent disqualifier. Refresh your NIST SP 800-171 self-assessment, submit the current score, and make sure a senior official has filed the required affirmation.

This step costs nothing and takes days, not months. There is no reason it should not be done this week.

Move 3: Close Your Remaining Gaps Now

Most contractors need 12 to 18 months to remediate a typical gap list — a reality we documented in why 18 months is not enough. With four months left, the honest question is no longer “can we close everything” but “what must be closed before assessment, and what can legitimately ride on a POA&M.”

Prioritize the high-weight controls first. Multi-factor authentication, access control, audit logging, and incident response procedures cannot be deferred — they are evaluated at assessment and must be fully implemented. POA&M accommodations exist for lower-weight gaps, but assessors and contracting officers are increasingly skeptical of programs that rely heavily on them.

Controls That Cannot Ride a POA&M

Access control (AC), multi-factor authentication (IA.3.083), audit logging (AU), and incident response (IR) are among the practices assessors require fully implemented before issuing a passing assessment. If any of these are on your gap list, they move to the front of your remediation queue.

Move 4: Get on a C3PAO Schedule Before the Queue Grows

Roughly 103 authorized C3PAOs are serving a defense industrial base of about 80,000 companies, and wait times are stretching past a year. Booking an assessment slot now — even a provisional one — is one of the cheapest insurance policies available. The Cyber AB Marketplace lists every authorized assessor.

A scheduled slot also creates a forcing function for your remediation plan. Teams that are accountable to an assessment date move faster than teams working against a general sense of urgency. The calendar pressure is real and it is useful — use it.

Move 5: Build Your Evidence Package Early

Assessors do not grade intentions — they grade evidence. Screenshots, configurations, policies, training records, and system security plan (SSP) detail should be organized against each of the 110 controls before the assessment team arrives. Contractors who assemble evidence during remediation, rather than after, consistently move through assessments faster.

A practical structure: one folder per control family, one evidence index that maps each artifact to the specific NIST SP 800-171A assessment objective it satisfies, and a named owner for keeping each artifact current. When an assessor asks how you enforce session lock, the answer should take ninety seconds, not a scavenger hunt.

The Bottom Line on CMMC Phase 2

November 10, 2026 is not a soft target and it will not move. Contractors who act in July control their own timeline; contractors who wait until fall will be negotiating with a queue. The good news: every move above is achievable in the time remaining if you start now.

Get a Straight Answer About Your Phase 2 Readiness

Not sure where you stand with four months to go? Book a free 30-minute call with Rick and get an honest read on your CMMC Phase 2 position, with no sales pitch. We never touch your CUI — your data stays exactly where it belongs.

Book a Free Call with Rick