CMMC Preparation Timeline: How Long It Really Takes
DoD estimates 12–18 months for typical contractors. In practice, most small businesses need 18–24 months from gap assessment to certified. Here's what happens in each phase.
The timeline to CMMC Level 2 certification is longer than most contractors expect. DoD's own cost analysis cites an average of 12–18 months — but that assumes contractors begin with reasonable existing security practices. Organizations starting from a low SPRS score baseline typically need 18–24 months from initial gap assessment to certified status.
| Phase | Duration | Key activities |
|---|---|---|
| 1. Gap assessment & scoping | Months 1–2 | Assess all 110 controls, calculate SPRS score, define CUI boundary, prioritize gaps |
| 2. SSP & documentation | Months 2–4 | Build or update SSP, develop required policies and procedures |
| 3. Technology remediation | Months 3–12 | Deploy MFA, SIEM, EDR, migrate to FedRAMP cloud, implement encryption, configure audit logging |
| 4. Policy & training | Months 4–9 | Develop security policies, conduct security awareness training, document evidence |
| 5. Pre-assessment review | Month 10–14 | Mock assessment, evidence package finalization, final gap closure |
| 6. C3PAO assessment | Months 14–20+ | Schedule C3PAO (6+ month lead times), conduct assessment, address findings |
| 7. Certification | Months 18–24+ | Receive certificate (full or conditional), begin annual affirmation cycle |
Start now
The CMMC Ready Now gap assessment delivers a prioritized roadmap with realistic timeline estimates based on your specific gaps.
Ready to start your CMMC journey?
Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.
More in Planning
