Skip to content
    August 22, 2026| Top Floor Team| 12 min read

    How Long Does CMMC Level 2 Take?

    Plan six to eighteen months from a standing start to assessment-ready at CMMC Level 2: around six months where you have capable IT and modest gaps, twelve to eighteen where the gaps are structural, internal IT is thin, or several sites are in scope. That range is our own observation across readiness programs rather than a published statistic, and the honest version comes with a caveat: with CMMC Phases 2 through 4 suspended since July 13, 2026, nobody can tell you the date a third-party assessor will be available. What can be said with a primary source behind it is the capacity arithmetic. The 32 CFR Part 170 final rule states that "the Department estimates 8350 medium and large entities will be required to meet CMMC Level 2 C3PAO assessment requirements as a condition of contract award", and that figure counts only medium and large entities, so it is a floor rather than a total.

    This article breaks the calendar into the phases it actually splits into, works the capacity arithmetic honestly, and says what the suspension does and does not buy you.

    Key takeaways

    • Six to eighteen months to assessment-ready is our observed range; the variance is driven by internal IT capability and by how many sites are in scope, not by company size.
    • Remediation is not the long pole. Evidence maturity is, because an assessor examines, interviews, and tests rather than reading a policy signed last week.
    • DoD's own final rule estimates 8350 medium and large entities will need a third-party Level 2 assessment, and that count excludes small entities.
    • A CMMC Status is valid for three years from the CMMC Status Date, with affirmation required annually, so this is a recurring calendar and not a project.
    • The suspension moved the assessment date, not the DFARS 252.204-7012 obligations underneath it.

    Where the calendar actually goes

    Programs that finish in six months and programs that take eighteen do the same five things. They differ in how long each takes and in how much runs in parallel.

    Scoping, two to eight weeks

    Establish what data you receive, where it lands, and how small the boundary can honestly be. This is short in calendar time and disproportionate in consequence: every subsequent estimate is a function of the scope decision, and scope decided badly is discovered late and expensively.

    Gap assessment against the assessment objectives, three to six weeks

    Not against the 110 requirement sentences, against the objectives an assessor actually works to. A gap assessment done at requirement level looks reassuring and misses most of the work.

    Remediation, two to nine months

    The widest band, and the one people plan around. Multifactor authentication, encryption of CUI in transit and at rest, boundary protection, and logging are where most of it lands.

    Documentation, running throughout, finishing last

    The system security plan is a Level 2 requirement in its own right, and under 32 CFR 170.21 it is one of the items that can never be deferred to a plan of action. Written afterwards it takes twice as long and describes an environment that has already moved.

    Evidence maturity, three to six months, mostly overlapping the above

    The step nobody schedules. More on it next.

    Add those up honestly and six months is achievable only with parallelism and a capable IT function. Sequenced by one overloaded person, the same content takes eighteen.

    Why evidence maturity is the long pole

    CMMC does not define an observation window the way a SOC 2 Type II report does. That absence misleads people into thinking a control implemented in the week before assessment counts the same as one that has been running for a year.

    In practice it does not, and the reason is in how an assessment is conducted. Assessors examine artifacts, interview the people who operate the control, and test that it behaves as described. A control switched on last Tuesday produces one artifact, an interviewee who has done it once, and a test that passes in a configuration nobody has yet had to maintain. A control running for two quarters produces a record series, staff who describe it consistently because they actually do it, and a history of exceptions handled.

    The practical rule we work to: whatever the last remediation item is, the calendar wants a further quarter of the control simply operating before anyone assesses it. That quarter is not padding. It is where access reviews get performed twice, where the log retention setting is proven by logs that are actually that old, and where the gap between the written procedure and the practice gets found by you rather than by an assessor.

    This is also the reason the current pause is more useful than it looks. Evidence maturity is the one input you cannot buy late.

    The capacity arithmetic, worked as a floor

    Take the two numbers that have sources.

    DoD's final rule estimates 8350 medium and large entities will be required to meet Level 2 third-party assessment requirements as a condition of contract award. That sentence is doing careful work: it excludes small entities, which are the large majority of the defense industrial base, so the real population needing third-party assessment is higher and this is a floor.

    On the supply side, Secureframe's analysis of the March 2026 Cyber AB town hall (a compliance platform vendor, so read their numbers accordingly) puts the ecosystem at roughly 103 authorized assessor organizations and 759 certified assessors. Counts in this ecosystem vary with the source: the same page's Cyber AB Marketplace snapshot lists 764 certified assessors where its town hall series says 759, so treat any single number as approximate and check the marketplace yourself at the time you need it.

    Now the arithmetic, and note what it does and does not support. Divide the floor population by the assessor organization count and each organization would carry roughly 81 assessments to clear the medium and large entities alone. Spread across the three-year cycle the same final rule sets, where "CMMC Status will be valid for three years from the CMMC Status Date" and an organization must "reaffirm in SPRS their compliance with CMMC Level 2 requirements annually but need only conduct a new assessment every three years", that is about 27 assessments per organization per year, before a single small entity is served and before renewals begin recurring.

    That is a demanding but not obviously impossible workload, and we are not going to inflate it into a crisis. The defensible conclusion is narrower and still useful: the supply side is thin enough that a surge in demand would show up as scheduling delay rather than as capacity, and the population it has to serve is larger than the number in that sentence. If third-party requirements return on a fixed date, the contractors who start after that date are competing for slots with everyone who did the same.

    What the suspension does and does not buy you

    It moved the assessment date. That is all it moved.

    DFARS 252.204-7012 is untouched, which means implementation of NIST SP 800-171 on covered systems, the 72-hour cyber incident report, media preservation, and flow-down to subcontractors are all owed today. Phase 1 self-assessment requirements, live since November 10, 2025, are untouched. The affirmation a senior official signs is still a representation to the government. We work through the full list of what survived in what the Phase 2 suspension did and did not change.

    What is genuinely uncertain is the assessment model itself. The CMMC Reform Task Force review was announced with recommendations due in roughly 60 days from July 13, 2026, which puts a report around mid-September 2026. It is possible the recommendations change which contracts require a third-party assessment rather than a self-assessment, or how the phases sequence. We will revise this article when the report lands, and until then any timeline advice that assumes the pre-July schedule is advice about a schedule that no longer exists.

    Planning under that uncertainty is not complicated. The readiness work is identical under every plausible outcome, because it is the 110 requirements either way. Only the date of the external event is unknown, and the correct response to an unknown date is to be ready before it rather than after.

    The three things that reliably add six months

    Scope discovered late. A CUI path nobody knew about (an engineer's laptop, a shared drive, a supplier portal) found during evidence collection rather than during scoping. This is the most common and the most expensive, and it is why the scoping weeks are worth taking seriously.

    One person carrying the program. Compliance work has a serialization problem: one capable person doing scoping, remediation, documentation, and evidence collection in sequence takes roughly the sum of those durations, while a program with a technical owner and a documentation owner takes roughly the maximum. Our piece on staffing versus outsourcing compliance work covers the arithmetic in more depth.

    Treating the plan of action as a plan. Under 32 CFR 170.21 only a narrow set of items can be deferred, the conditional status carries a 180-day closeout clock, and several requirements can never be deferred at all. We cover the rules in CMMC POA&M rules. A program built on the assumption that twenty percent can be finished later discovers the constraint at the worst possible moment.

    When to wait instead

    The against-interest section, because a readiness engagement is exactly what a firm like ours sells.

    If you have no defense contract, no subcontract, and no realistic pipeline into one, wait. The timeline for a company with no contract is not eighteen months, it is not started, and a readiness program bought on the strength of a prime's mailing list is a recurring cost with no counterparty.

    If you handle only Federal Contract Information, the Level 2 timeline is not your timeline. Level 1 is 15 requirements from FAR 52.204-21, self-assessed annually. That is a project measured in weeks.

    If your current contracts name no CMMC level and your pipeline is genuinely two or more years out, the honest advice is to implement the DFARS 7012 obligations you already owe and revisit assessment readiness when the task force reports. You will not have wasted anything, because that work is the same work.

    Where we would push back hard is on doing nothing at all because the phases are suspended. The controls are contractually owed today, and a pause is the cheapest window you will ever get to make an inaccurate SPRS score accurate.

    Where Top Floor fits

    Our CMMC practice runs the sequence above with the parallelism that makes six months possible: scoping first, gap assessment at objective level rather than requirement level, and the system security plan written as the environment changes rather than afterwards. The part clients are most often surprised by is how early we start evidence collection, and that is deliberate for the reasons in the evidence-maturity section.

    Where CMMC sits alongside commercial framework obligations, running one program instead of three is usually both faster and cheaper, which is what compliance as a service is for. For the DoD's own cost estimates, which are the only assessment figures this site publishes, see our CMMC 2.0 guide.

    We do not perform certification assessments, and an assessor cannot assess a client it consulted for, so nothing in our advice about when to book one is a booking we get to make.

    How to decide this week

    Write down your scope decision and the date you made it. If you cannot state your boundary in a paragraph, your timeline has not started yet, whatever the project plan says.

    Pick the four requirements that most first assessments stumble on (multifactor authentication, encryption of CUI at rest and in transit, boundary protection, logging) and get an honest status on each. Those four set the shape of your remediation band.

    Count the people who will actually do this work, not the people named on the org chart. Divide the task list among them. If the answer is one person, your realistic timeline is the sum of the phases, not the maximum.

    Then start the evidence clock on everything already implemented. Access reviews, log retention, and training records only become evidence with age, and age is the one input no budget accelerates.

    Frequently asked questions

    How long does CMMC Level 2 certification take?

    Plan six to eighteen months from a standing start to assessment-ready, based on what we observe across readiness programs rather than on a published statistic. Around six months is achievable with capable internal IT, modest gaps, and work running in parallel; twelve to eighteen is realistic where gaps are structural, IT is thin, or several sites are in scope. Since the July 13, 2026 suspension of CMMC Phases 2 through 4, the date by which a certification assessment becomes required is a separate unknown that no timeline can currently pin down. Assessor availability is a different question: if a current award or live solicitation already requires a certification assessment, C3PAOs will still quote you calendar dates, and you should be asking for them now.

    How long is a CMMC certification valid?

    Three years. The 32 CFR Part 170 final rule states that "CMMC Status will be valid for three years from the CMMC Status Date", and that organizations must "reaffirm in SPRS their compliance with CMMC Level 2 requirements annually but need only conduct a new assessment every three years". The regulation carries the assessment deadline in 32 CFR 170.17(a)(1), which says "the Level 2 certification assessment must be completed within three years of the CMMC Status Date associated with the Conditional Level 2 (C3PAO)", and the affirmation requirement in 170.17(a)(2), which applies "at the time of each assessment, and annually thereafter". That makes CMMC a recurring calendar rather than a one-time project: the control set has to keep operating, the system security plan has to keep describing reality, and a senior official has to be willing to sign the affirmation every year.

    Should we wait for the CMMC Reform Task Force report before starting?

    No, because the readiness work is the same under every plausible outcome. The task force review announced on July 13, 2026 carried a roughly 60-day timeline, which places a report around mid-September 2026, and it can plausibly reach the assessment model: which contracts need a third-party assessment, how the phases sequence, how the burden falls on small businesses. What it does not plausibly reach is DFARS 252.204-7012, which already obliges implementation of NIST SP 800-171 on covered systems. Implementing those controls is not a bet on the outcome.

    How far in advance should we book an assessor?

    Far enough that the answer is not a scheduling problem, and that is currently unanswerable with precision because Phases 2 through 4 are suspended. What the arithmetic supports is caution about the supply side: DoD's final rule estimates 8350 medium and large entities will need third-party Level 2 assessments as a condition of award, a figure that excludes small entities, while the assessor ecosystem was reported at roughly 103 authorized organizations as of March 2026. Thin supply against a larger population shows up as scheduling delay, which favours contractors who are ready before a date is set rather than after.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.