How long does CMMC Level 2 take? For a 5 to 50 person defense subcontractor with no security staff, plan on a week to your first honest score, a month to clear the cheap administrative gaps, a quarter for the technical fixes, and three to six months before your evidence, system security plan and plan of action are in final form. That is CMMC Map's planning guidance from walking small shops through the 110 requirements, not a survey statistic. Where you land depends on how much Controlled Unclassified Information (CUI) you handle.
The path contracts can require right now, CMMC Level 2 (Self), has no assessor on the critical path. You do the assessment, post the result in the Supplier Performance Risk System (SPRS), and affirm it. There is exactly one hard clock: if you post a conditional status with a plan of action, you have 180 days to close it.
The short version. Level 2 (Self) is a self-assessment of all 110 NIST SP 800-171 Revision 2 requirements against the NIST SP 800-171A objectives, posted in SPRS under 32 CFR 170.16. Since the July 13, 2026 suspension of CMMC Phase 2, new solicitations may require only the self-assessed levels, so there is no third-party assessor to book. Details in what the Phase 2 suspension changes.
How long does CMMC Level 2 take: the phase table
The durations assume one person owns the project part time and an outside IT provider does the hands-on work. A one-office, one-tenant shop sits at the short end; shop-floor machines or CUI in email push you toward the long end.
| Phase | Realistic duration | What done looks like |
|---|---|---|
| Week 1: scope and first score | 3 to 5 working days | CUI systems, people and locations named, all 110 requirements marked honestly, a first score you would defend to a prime |
| Month 1: identification and paperwork | 2 to 4 weeks | Signed user list, asset inventory and service account list; policies approved, dated and versioned; an owner for every open item |
| Quarter 1: technical fixes | 6 to 12 weeks | Multifactor authentication everywhere including local admin, logs collected and reviewed, FIPS-validated encryption for CUI at rest and in transit, backups encrypted and restore tested |
| Months 3 to 6: evidence and final documents | 4 to 12 weeks | SSP and plan of action in final form, evidence filed per objective, result posted in SPRS, affirmation submitted, any open items scheduled inside the 180-day window |
| Ongoing | Yearly and every three years | Annual affirmation, Level 2 self-assessment repeated within three years, artifacts kept six years |
Week 1: scope, an honest first pass, and a first score
Start with the boundary, not the controls. 32 CFR 170.16 requires the self-assessment to follow the scoping rules in 32 CFR 170.19, so the first job is a list: which laptops, servers, cloud tenants, shop-floor machines and people ever touch CUI. Everything off that list needs no evidence.
Then take one honest pass through all 110 requirements. The rule judges each against the NIST SP 800-171A assessment objectives, which turn 110 requirements into 320 questions, and a requirement is met only when every applicable objective is satisfied by evidence. No evidence, mark it not met. Our guide to the 800-171A objectives explains the split.
Finish the week with a number. The scoring method in 32 CFR 170.24 starts at 110 and subtracts 1, 3 or 5 points per requirement not met, and it can go negative. Run it without an account on the free SPRS calculator. A low first number is not a verdict. It is a to-do list with weights on it.
Month 1: the cheap identification objectives
Most requirements bundle an administrative act with a technical one: identify something, then enforce something about it. Small shops usually have the enforcement half and lack the identification half.
- Authorized users. Every account tied to a real person, reconciled against payroll, leavers removed.
- Devices. An asset inventory of everything inside the week 1 boundary, each with an owner.
- Service accounts and processes. Scheduled tasks, integrations, vendor logins, each with an owner.
- Privileged accounts. Who has admin and why; this list feeds next quarter's multifactor authentication work.
Month 1 is also when the policies get signed. 32 CFR 170.24 counts evidence only in final form and rules out drafts and unapproved policies, so approve, date and version them now. Give every open item an owner and a target date; that list is the start of the plan of action requirement 3.12.2 asks you to develop. Pick your Affirming Official too: 32 CFR 170.22 makes that the senior person with authority to affirm continuing compliance.
Quarter 1: the technical fixes that move the score
Four projects account for most of the missing points, and each has vendor lead time, a change window and users to retrain, which is why this phase is a quarter, not a week.
- Multifactor authentication everywhere, including local admin. Requirement 3.5.3 in NIST SP 800-171 Rev 2 covers local and network access to privileged accounts and network access for everyone else. The usual miss is the console of the server in the closet. Under 32 CFR 170.24, no multifactor authentication costs 5 points; covering only remote and privileged users still costs 3.
- Logging you can use. Requirement 3.3.1 asks for audit logs sufficient to monitor, analyze, investigate and report unauthorized activity, worth 5 points. Collect them in one place and put a review on the calendar.
- FIPS-validated encryption in transit and at rest. Requirements 3.13.8 (transmission), 3.13.16 (at rest) and 3.13.11 (FIPS-validated cryptography) work together. 32 CFR 170.24 subtracts 5 points if CUI is not encrypted and 3 if the encryption is not FIPS-validated. Check each product on the NIST Cryptographic Module Validation Program list before you buy.
- Backups, protected and proven. Requirement 3.8.9 protects the confidentiality of backup CUI. Encrypt the backups, restore a file, keep the screenshot.
Months 3 to 6: evidence, the SSP, and the 180-day POA&M clock
The last stretch turns work into evidence: for each objective, record what satisfies it and where the artifact lives. Then finish the two documents that matter most. The system security plan (SSP, requirement 3.12.4) must exist at assessment time: 32 CFR 170.24 says without an up-to-date SSP the finding is that an assessment could not be completed, and 3.12.4 can never sit on a plan of action.
The plan of action and milestones (POA&M) is where the timeline gets a legal edge. Under 32 CFR 170.21 you may post a Conditional Level 2 (Self) status only if your score is at least 0.8 of the total, which is 88 of 110, only 1-point requirements are open (3.13.11 may be open at 3 points if encryption exists but is not FIPS-validated), and none of 3.1.20, 3.1.22, 3.12.4, 3.10.3, 3.10.4 or 3.10.5 is on the list. Then the clock starts: remediate, perform a closeout self-assessment, and post the result in SPRS within 180 days of the Conditional CMMC Status Date, or the status expires. If it expires during a contract, 32 CFR 170.16 says standard contractual remedies apply, with no new Level 2 (Self) awards until you earn a new status.
The planning lesson: the 180 days start when you post, so do not post conditional until the remaining fixes are scheduled. One extra month to post a Final status beats racing the clock. After a closeout you affirm again under 32 CFR 170.22. The mechanics are in our POA&M explainer. Your DoD Assessment score under DFARS 252.204-7020 is a separate SPRS posting and asks for the date you expect to reach 110; give it a date your plan supports.
Ongoing: the calendar after you post
- Every year: the Affirming Official affirms in SPRS (32 CFR 170.22) that you have implemented and will maintain every requirement.
- Every three years: repeat the Level 2 self-assessment within three years of the status date (32 CFR 170.16). Separately, DFARS 252.204-7019 requires a current assessment, not more than three years old unless the solicitation says less, and 252.204-7020 bars primes from awarding a subcontract without one.
- Six years: keep the evidence artifacts for six years from the CMMC Status Date (32 CFR 170.16).
- Every quarter or so: access reviews, log reviews, restore tests, offboarding checks, training records.
If you only handle Federal Contract Information, 32 CFR 170.15 makes Level 1 (Self) an annual self-assessment with no plan of action permitted at any time. The free Level 1 checklist covers it.
If a C3PAO assessment comes back
Requiring activities may designate only the self-assessed levels today, and the Reform Task Force review that ended September 11 has produced nothing public, so we do not predict what comes next. But the rule for a third-party assessment already exists in 32 CFR 170.17, and it changes the timeline in three ways.
First, an authorized or accredited CMMC Third-Party Assessment Organization (C3PAO), listed on the Cyber AB marketplace, performs the assessment, so the assessor's availability becomes a wait you do not control. Second, you want a readiness check before the real assessment, ideally by someone who did not build your environment, because a requirement found NOT MET can be re-evaluated only during the assessment and for 10 business days after. Third, a plan of action after a certification assessment is closed out by the C3PAO inside the same 180 days, and artifacts must be hashed and kept six years. Add the booking wait and the readiness pass to the front of the table.
Two things that add months. Posting a conditional status before the remaining fixes are scheduled, because the 180-day clock in 32 CFR 170.21 starts on the status date, and treating drafts as done, because 32 CFR 170.24 counts only evidence in final form.
What to do this week
- Draw the boundary. List every system, person and location that stores, processes or transmits CUI.
- Take the honest first pass. Mark all 110 requirements against the objectives and get a score on the free SPRS calculator.
- Write the four lists. Users, devices, service accounts, privileged accounts.
- Book the quarter with your IT provider. Multifactor authentication including local admin, central logging, FIPS-validated encryption, encrypted and tested backups.
- Pick the Affirming Official and set a posting date. Put the SPRS submission and the first annual affirmation on a calendar someone owns.
CMMC Map, CMMC compliance software for small defense contractors, walks the 110 requirements objective by objective and keeps the live score and the evidence pointer next to each item. The assessment and the score are free forever. The generated system security plan, plan of action, policies and readiness report are the one paid plan at $149 a month.
This is explanatory content about contractual requirements, not legal advice. Your contract clauses and your prime's flowdown letter govern.
Get your first honest score this week
The CMMC Map assessment walks all 110 requirements with a live SPRS score, free, with no credit card, so week one of this timeline costs you an afternoon and nothing else.
Start free in CMMC Map