+91 98804 42758

How Long Does CMMC Certification Take

Level 1 is weeks. Level 2 is 6 to 12 months. Here's why, phase by phase

Sudhakar Varma Delivery Head, Avantcert
August 13, 2026 9 min read

The Short Answer

CMMC Level 1 self-assessment can be completed in a few weeks. CMMC Level 2 with a C3PAO-led assessment typically takes 6 to 12 months, driven by how mature your NIST 800-171 controls, SSP, and POA&M already are. Which of these two very different timelines applies depends on which level your contracts require.

This page assumes you know the CMMC level structure. See our CMMC 2.0 guide or our CMMC certification cost breakdown for the budget side.


Level 2 Timeline, Phase by Phase

PhaseTypical durationWhat happens
Scoping the CUI boundary1 – 3 weeksDeciding what's in scope drives everything downstream
Gap analysis against NIST 800-1712 – 4 weeksCurrent state assessed against all 110 controls
SSP & POA&M development3 – 6 weeksSystem Security Plan documented, remaining gaps logged with a closure plan
Control remediation8 – 20 weeksThe largest and most variable phase, driven by starting maturity
C3PAO booking & scheduling4 – 8 weeksRuns in parallel with remediation if started early enough
C3PAO assessment1 – 3 weeksFormal fieldwork and evidence review

Booking the C3PAO in parallel with remediation, rather than waiting until you're fully ready, is what keeps the total closer to 6 months than 12. Contractors who wait to book until remediation is complete routinely lose 4 to 8 weeks to assessor availability alone.

Level 1: A Much Shorter Path

Level 1 covers 17 basic safeguarding practices tied to Federal Contract Information and is self-attested, with no external assessment to schedule. For a contractor already meeting most of the practices, closing remaining gaps and submitting the affirmation can realistically happen in 2 to 4 weeks. The entire timeline is internal, which is the structural reason it's so much faster than Level 2.

What Drives the Level 2 Timeline Most

  • CUI scope, not company size. A tightly scoped enclave with CUI isolated from the rest of the network moves faster through every phase than a broad, unscoped environment.
  • Starting maturity against NIST 800-171. Contractors with mature access control and logging already in place spend less time in the remediation phase, by far the largest variable.
  • C3PAO availability. Assessor capacity has been a genuine industry-wide constraint, part of why the 2026 Phase 2 rollout was paused for review.
  • POA&M eligibility. Lower-weighted controls that can remain open on a POA&M reduce pre-assessment remediation time, but high-weighted controls like multi-factor authentication generally must be fully implemented first.

Need a realistic timeline against a contract deadline?

We'll map your CUI scope and current maturity to tell you honestly what's achievable and how to sequence it.

Get a Free Quote

Book the C3PAO Early

The single highest-leverage timeline move for Level 2 is booking a C3PAO as soon as a realistic readiness date is in view, not after remediation is finished. Given documented capacity constraints across the assessor market, waiting until you're fully ready before scheduling routinely adds 4 to 8 weeks that could have run in parallel with your own remediation work instead.

Preparing for a Level 2 assessment on a deadline?

We coordinate readiness and C3PAO scheduling together so assessor availability isn't the bottleneck.

Talk to an Avantcert Expert

Frequently asked questions about CMMC certification timelines

Why does CMMC Level 2 take so much longer than Level 1?

Level 1 covers 17 basic practices and is self-assessed, no external scheduling required. Level 2 covers all 110 NIST 800-171 controls and, for most contractors handling CUI, requires a scheduled third-party assessment with a C3PAO, whose calendar availability alone can add weeks beyond your own readiness timeline.

How long does building a System Security Plan and POA&M take?

Typically 3 to 6 weeks for a first-time SSP covering a well-scoped CUI environment, longer if CUI touches multiple systems or business units that each need documenting separately. The POA&M, listing any controls not yet fully implemented with a closure plan, is usually drafted alongside it.

How far in advance should a C3PAO be booked?

4 to 8 weeks minimum, longer given the assessor capacity constraints that contributed to the 2026 Phase 2 rollout pause. Booking as soon as a realistic readiness date is in view, rather than waiting until remediation is fully finished, is the single highest-leverage scheduling move available.

Does tightly scoping the CUI boundary actually shorten the timeline?

Yes, substantially. A tightly scoped enclave means fewer systems to remediate, document, and present to the assessor. Contractors that let CUI touch their whole network face a materially longer readiness and assessment timeline than those who isolate it to a dedicated environment first.

Can Level 1 certification realistically be completed in under a month?

Yes, for a contractor already meeting most of the 17 basic safeguarding practices. Since Level 1 is self-attested with no external audit scheduling, the timeline is almost entirely internal, remaining gaps can often be closed and the affirmation submitted within 2 to 4 weeks.

Does the 2026 Phase 2 pause affect how long certification takes right now?

Not for contractors with a level already required in a signed contract, that timeline pressure remains unchanged. For others, C3PAO capacity has been a genuine constraint, so building in extra scheduling buffer for third-party assessment booking is prudent regardless of the pause's outcome.

About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through CMMC readiness, NIST 800-171 remediation, and C3PAO assessment preparation. See our CMMC certification service or request a free quote.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.