- July 9, 2026
-
CMMC Level 2 Certification: Requirements, Process & Timeline
7 min read · CMMC Compliance
Most DoD contractors will now need to achieve the new baseline of CMMC Level 2 certification to process Controlled Unclassified Information (CUI) in order to continue to work on DoD contracts.
With the CMMC Program rule in place, most DoD’s Defense Industrial Base will no longer be able to use a self-attestation. This Level 2 Guide provides details on the requirements of the Level 2 and how the assessment process was carried out and how long it usually takes to become certified.
The Baseline
What does CMMC Level 2 Certification mean?
There are three levels of Cybersecurity Maturity Model Certification (CMMC) framework. Basic Safeguarding of Federal Contract Information is covered in Level 1 (Foundational). Level 2 (Advanced) is based directly on NIST SP 800-171 and is applicable to all contractors working with CUI, regardless of whether they are storing, processing or transmitting CUI. Level 3 (Expert) introduces essentials from NIST SP 800-172 for the highest priority programs.
CMMC Level 2 certification helps you ensure that your organization has implemented all security requirements in NIST SP 800-171 Revision 2. That’s the largest change the program mandates: for most contracts that involve CUI, that verification is not a self-assessment by the contracting party, but rather, an independent, third-party assessment.
The Requirements
For CMMC Level 2 (L2), 110 Controls are required
The 110 CMMC Level 2 requirements are grouped under 14 control families which cover the life cycle of protecting sensitive data:
Each Level 2 program is based on a pair of documents. Your system security plan (SSP) from your CMMC assesses how each control is applied throughout your environment. Gaps will be noted in your Plan of Action and Milestones (POA&M) and per the CMMC, only a few less weighted controls will remain on the POA&M at the time of assessment with 180 days to address the noted controls.
The 110 NIST SP 800-171 controls span 14 families
The Process
The steps of the CMMC Level 2 Certification Process
The certification process is a clearly-defined process. If you build your program based on these steps, the ultimate result will not be a scramble:
The most successful method for achieving a clean result is a good readiness review and gap analysis. The official control set is published in NIST SP 800-171 and information about the program is maintained on the DoD CMMC site.
A C3PAO conducts the official CMMC Level 2 assessment
The Timeline
How much time does it take to get CMMC Level 2 Certification?
The timeline will vary according to the starting point, but most contractors could expect to take 6 to 12 months from start to pass. It may be faster for organisations that have already got an IT practice in place, and slower for those without any existing documentation or controls to implement; plan accordingly. Preparing early (preparing for CMMC compliance) is important as the two largest time consuming activities are remediation and evidence collection.
It is not a one-time process to get certified. As you’re required to maintain your controls and monitor continuously, make sure it is part of your plan from day one and that you submit the annual affirmation. Contractors that believe certification is the ultimate goal are in a rush to re-certify; contractors that have monitoring and documentation as a habit can breeze through re-certification with much less work and cost.
Mapping a realistic CMMC Level 2 certification timeline
Answers
Frequently Asked Questions
What is the meaning of CMMC Level 2?
It is an independent review to ensure that a contractor has the 110 controls specified in NIST SP 800-171 to protect CUI on DoD contracts.
Do all contractors need to have a third party assessment?
The majority of contracts that cover CUI mandate a C3PAO assessment every three years. Self-assessment may be offered for select programs, as outlined in each contract.
How do the two CMMC levels differ?
Level 1 is the basic level of protection for Federal Contract Information (FCI) and it requires 15 requirements and a self-assessment annually. Level 2 is meant for CUI, and includes all 110 of the NIST 800-171 controls and generally requires third party certification.
How much does it cost to get CMMC Level 2 certified?
The costs vary by the size of the environment and the current maturity and range from the readiness assessment costs, remediation costs, C3PAO assessment fee and maintenance costs.
Get CMMC Level 2 Certified with Confidence
From readiness review to your C3PAO assessment, Solvere One guides DoD contractors through every NIST SP 800-171 control on the path to CMMC Level 2 certification.