# CMMC Phase 2: What to Expect and How to Prepare [2026]

> CMMC Phase 2 starts November 2026 with mandatory C3PAO assessments. Here's the timeline, what changes, the conditional certification rules, and how to prepare now.

canonical: https://secureframe.com/blog/cmmc-phase-2-preparation

**Editor's note: ***While the transition to CMMC Phase 2 is currently on hold, we've preserved the original post as a record of the program and DoW's implementation plan as described in the [32 CFR rule](https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program). The readiness guidance and checklist below is still sound: implementing the NIST SP 800-171 controls is required today under DFARS 7012 and CMMC Level 2 (Self) requirements remain in place so the work is the same. See [the Phase 2 pause update](https://secureframe.com/blog/cmmc-news-2026-phase-2-pause) for what changed and what to do now.*

Phase 2 of the CMMC rollout begins November 10, 2026, which will include third-party assessment requirements in more defense contracts.

Since most contracts involving [Controlled Unclassified Information (CUI)](https://secureframe.com/blog/controlled-unclassified-information-cui) will require Level 2 (C3PAO) certification as a condition of award, this is the phase that officially shifts [CMMC](https://secureframe.com/blog/cmmc) from largely self-assessed to independently verified. 

**Bottom line**: If you're a defense contractor handling CUI, Phase 2 is your real deadline for CMMC certification. Here’s what you need to know.

## What Phase 2 changes

## What Phase 2 changes 

The critical change of this phase of CMMC enforcement: 

- **In [Phase 1](https://secureframe.com/blog/cmmc-deadline-announcement)**, DoD contracting officers had the discretion to include C3PAO assessment requirements in certain Level 2 contracts that handled more sensitive CUI, but this phase largely focused on self-assessments for Level 2 contracts involving non-critical CUI (and [Level 1](https://secureframe.com/blog/cmmc-level-1-compliance) contracts involving FCI).
- **In Phase 2**, Level 2 (C3PAO) certification becomes the default for contracts involving CUI. 

Across the entire DIB (~220,000 organizations), the DoD estimates that 35% will need to complete Level 2 (C3PAO) certification. Here's how the numbers break down across the DIB, based on [DoD estimates published in the 32 CFR rule](https://www.federalregister.gov/d/2024-22905/p-1240):

Among organizations handling CUI specifically:

- 93% will require Level 2 (C3PAO) starting in Phase 2
- 5% will require Level 2 (Self)
- 2% will require [Level 3 (DIBCAC)](https://secureframe.com/blog/cmmc-level-3-compliance)

Among organizations with Level 2 requirements specifically:

- ~95% will require a C3PAO assessment for Phase 2
- Only ~5% handling non-critical CUI may qualify for a self-assessment

![DoD estimates of CMMC assessment level 2 and types](https://images.prismic.io/secureframe-com/aSciiWGnmrmGqW9E_DoD-estimates-of-CMMC-assessment-level-2-and-types.png?auto=format,compress)

*Image Source: [Impact and Cost Analysis of the Revised CMMC Program in 32 CFR rule](https://www.federalregister.gov/d/2024-22905/p-1239)*

In short, if your contract involves CUI and it's awarded after November 10, 2026, you'll almost certainly need a CMMC Level 2 (C3PAO) certification. A self-assessment isn’t enough; you’ll need to complete an assessment conducted by a [Certified Third-Party Assessor Organization](https://secureframe.com/hub/cmmc/c3pao).

```
<style>
#pen-testing-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
}
#pen-testing-table thead {
  background-color: #0CAB6B;
  color: #fff;
}
#pen-testing-table thead strong,
#pen-testing-table thead th,
#pen-testing-table thead tr {
  color: #fff;
  font-weight: bold;
}
#pen-testing-table thead tr th {
  font-family: Assistant, sans-serif;
}
#pen-testing-table td,
#pen-testing-table th {
  padding: 1rem;
}
#pen-testing-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}
#pen-testing-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}
#pen-testing-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}
#pen-testing-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}
#pen-testing-table tbody tr th,
#pen-testing-table tbody tr td {
  color: #091922;
}
</style>

<table id="pen-testing-table">
  <thead>
    <tr>
      <th></th>
      <th>Phase 1</th>
      <th>Phase 2</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><strong>Date</strong></td>
      <td>Began November 10, 2025</td>
      <td>Begins November 10, 2026</td>
    </tr>
    <tr>
      <td><strong>Focus</strong></td>
      <td>Level 1 and 2 (Self)</td>
      <td>Level 2 (C3PAO)</td>
    </tr>
    <tr>
      <td><strong>Types of data</strong></td>
      <td>FCI and non-critical CUI</td>
      <td>CUI</td>
    </tr>
    <tr>
      <td><strong>% of DIB affected</strong></td>
      <td>~65% (only 2% estimated for Level 2 (Self))</td>
      <td>~35%</td>
    </tr>
    <tr>
      <td><strong>Level 2 enforcement</strong></td>
      <td>Level 2 (Self) implemented in contracts handling less critical CUI, but C3PAO requirements could be included at DoD's discretion</td>
      <td>Level 2 (C3PAO) requirements included as default for DoD contracting officers</td>
    </tr>
    <tr>
      <td><strong>Level 3 enforcement</strong></td>
      <td>Not begun</td>
      <td>Level 3 requirements can be included at DoD's discretion</td>
    </tr>
  </tbody>
</table>
```

## Recommended reading

CMMC Self-Assessment Guide: Level 1 and Level 2 Process

## Who is affected by Phase 2?

## Who is affected by Phase 2?

Phase 2 primarily affects organizations that:

1. **Handle CUI under DoD contracts**: Most DIB organizations handling CUI will need Level 2 (C3PAO) certification—93% according to [DoD estimates](https://www.federalregister.gov/d/2024-22905/p-1239).
2. **Are subcontractors receiving CUI from primes**: [CMMC requirements flow down](https://secureframe.com/blog/cmmc-requirements-for-subcontractors) to every tier. So if a prime needs Level 2 (C3PAO) certification, then that’s the minimum requirement for any subcontractor that handles CUI on their behalf.
3. **Plan to bid on new DoD contracts after November 2026**: Starting on November 10, 2026, new solicitations and contracts involving CUI will most likely include Level 2 (C3PAO) requirements. 
4. **Previously relied on self-assessment**: Organizations that were self-reporting NIST 800-171 compliance via SPRS under DFARS 7019 will now need to prove NIST 800-171 compliance via C3PAO-led assessments under CMMC Level 2. 

**Who is NOT affected:**

- Contractors handling only FCI (CMMC Level 1 remains self-assessment)
- COTS suppliers (exempt from CMMC)
- Existing contracts awarded before Phase 2 (generally not retroactive, though re-competitions and option exercises may include CMMC)

## Recommended reading

How to Meet CMMC Level 2 Compliance Requirements + Checklist

## Understanding the C3PAO Assessment Process

## Understanding the C3PAO Assessment Process

A C3PAO is an independent organization authorized by the Cyber AB to conduct CMMC assessments. While the process and duration of a CMMC assessment varies based on the C3PAO and the size and complexity of the organization seeking certification (OSC), the process typically runs like this:

### Phase 1: Preparation (1-12 months)

- Define and document your system boundary in architecture diagrams and executive summaries
- Document how each of your controls are implemented in an [SSP](https://secureframe.com/blog/cmmc-ssp)
- Draft policies and procedures and distribute for employees to accept and review
- Collect and organize evidence for all requirements ideally using a GRC platform

This first part takes more than a year on average, according to [Redspin’s latest report on the State of DIB CMMC Readiness](https://redspin.com/press/new-redspin-report-finds-lagging-execution-despite-increased-cmmc-awareness-2/). The right tool can slash this timeline to a fraction, with [Secureframe Defense](https://secureframe.com/cmmc) reducing assessment readiness to as little as 4 weeks on average.

“One of the major pitfalls I see in Phase One is just poor or incomplete documentation. Your data flow diagrams are missing or overly complex. Policies are spread across too many sources. SSPs don't match. All these things can make assessments much more difficult than they need to be. So focusing on Phase one, getting your documentation in order, and getting ready to respond to questions…makes a huge difference in how smoothly these assessments go.” —Matt Graham, Vice President of US Federal Practices, Prescient Security

### Phase 2: The Actual Assessment 

#### 1. Scheduling the assessment (Start 3–6+ months before your target date)

Lead times for C3PAOs can stretch several months, so start reaching out proactively during your readiness phase. A C3PAO's availability is just one of several criteria you can use to select the right partner.

“Some folks are booking eight months out. Some folks are ready to go next week. If you're targeting specific quarters, for award cycles, you need to start engaging with those C3PAOs very early. Don't wait until your documentation is perfect before you start working on your C3PO relationship. A good C3PAO is going to help align your readiness milestones with their schedule, and that will help you develop your shortlist.”  —Matt Graham, Vice President of US Federal Practices, Prescient Security

#### 2. Pre-assessment (2-4 weeks)

Up to a month before the assessment, the C3PAO typically conducts a scoping call to: 

- Review architecture diagrams and CUI data flows
- Determine [assessment scope ](https://secureframe.com/blog/cmmc-scope)
- Schedule on-site/remote assessment activities
- Request your SSP, [POA&M](https://secureframe.com/blog/plan-of-action-and-milestones-poam), and supporting documentation in advance

#### 3. Assessment (1-2 weeks)

This is when your assessors verify that what's documented in your SSP is actually happening in practice.

- Assessors evaluate each of the 110 NIST 800-171 requirements and 320 assessment objectives
- Review of policies, procedures, and technical configurations
- Interviews with key personnel
- Testing of technical controls (scanning, verification)
- Evidence collection and validation

#### 3. Scoring, reporting, and results

Each requirement is scored as MET, NOT MET, or NOT APPLICABLE. There are three possible outcomes based on your total score:

1. **CMMC Level 2 Final Status** if all 110 requirements MET (valid 3 years)
2. **Conditional CMMC Status** if at least 80% MET (88/110) with qualifying POA&M items (must close within 180 days)
3. **No CMMC Status** if below 80% threshold or critical requirements not met that can’t be on POA&M

#### 4. Post-assessment

- **If conditional status**: 180-day window to close POA&M items, followed by a closeout assessment
- **If final status**: Annual affirmation required to maintain certification
- Full re-assessment every 3 years

## Recommended reading

SPRS Scoring: How to Get a Current CMMC Status and Stay Eligible for DoD Contracts

## Conditional CMMC Status

## Conditional CMMC Status: What Contractors Need to Know Before the Phase 2 Deadline

With the Phase 2 deadline of November 10, 2026 approaching, conditional CMMC status may be the most realistic path for organizations that can't achieve full Level 2 compliance in time. But the rules are strict. Here’s what you need to know:

### Requirements for conditional status:

- Must score at least 80% (88 of 110) requirements as MET
- Document permitted unmet requirements in a POA&M 
- Each POA&M item must be worth no more than 1 point in the scoring methodology
- All POA&M items must be closed within 180 days
- A C3PAO closeout assessment must verify remediation

If POA&M items are not closed out within 180 days, your conditional status expires and you become ineligible for contracts requiring Level 2.

### Requirements that CANNOT be on a POA&M (must be MET at assessment):

There are some 1-point requirements that the DoD deems fundamental to CUI protection and therefore must be fully implemented before the C3PAO assessment—not documented in a POA&M and remediated later.

These are either basic safeguarding requirements under FAR 52.204-21 or DFARS clause 252.204-7012, and explicitly listed as prohibited in [32 CFR 170.21(a)(2)(iii)](https://www.ecfr.gov/current/title-32/part-170/section-170.21#p-170.21(a)(2)(iii)).

```
<style>
#pen-testing-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
}
#pen-testing-table thead {
  background-color: #0CAB6B;
  color: #fff;
}
#pen-testing-table thead strong,
#pen-testing-table thead th,
#pen-testing-table thead tr {
  color: #fff;
  font-weight: bold;
}
#pen-testing-table thead tr th {
  font-family: Assistant, sans-serif;
}
#pen-testing-table td,
#pen-testing-table th {
  padding: 1rem;
}
#pen-testing-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}
#pen-testing-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}
#pen-testing-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}
#pen-testing-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}
#pen-testing-table tbody tr th,
#pen-testing-table tbody tr td {
  color: #091922;
}
</style>

<table id="pen-testing-table">
  <thead>
    <tr>
      <th>Requirement ID</th>
      <th>Requirement Name</th>
      <th>Requirement Description</th>
      <th>Required Under Existing Regulation</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>AC.L2-3.1.20</td>
      <td>External Connections (CUI Data)</td>
      <td>Verify and control/limit connections to and use of external systems.</td>
      <td>FAR clause 52.204-21</td>
    </tr>
    <tr>
      <td>AC.L2-3.1.22</td>
      <td>Control Public Information (CUI Data)</td>
      <td>Control CUI posted or processed on publicly accessible systems.</td>
      <td>FAR clause 52.204-21</td>
    </tr>
    <tr>
      <td>CA.L2-3.12.4</td>
      <td>System Security Plan</td>
      <td>Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.</td>
      <td>DFARS clause 252.204-7012</td>
    </tr>
    <tr>
      <td>PE.L2-3.10.3</td>
      <td>Escort Visitors (CUI Data)</td>
      <td>Escort visitors and monitor visitor activity.</td>
      <td>FAR clause 52.204-21</td>
    </tr>
    <tr>
      <td>PE.L2-3.10.4</td>
      <td>Physical Access Logs (CUI Data)</td>
      <td>Maintain audit logs of physical access.</td>
      <td>FAR clause 52.204-21</td>
    </tr>
    <tr>
      <td>PE.L2-3.10.5</td>
      <td>Manage Physical Access (CUI Data)</td>
      <td>Control and manage physical access devices.</td>
      <td>FAR clause 52.204-21</td>
    </tr>
  </tbody>
</table>
```

## C3PAO Availability: The Booking Crisis

## C3PAO Availability: The Booking Crisis

This is the most underappreciated risk for Phase 2. The number of authorized C3PAOs is growing, but still limited relative to the demand.

According to the [February 2026 Cyber AB Town Hall](https://www.cmmc.com/newsroom/cyber-ab-town-hall-02-2026), 

- There are 98 authorized C3PAOs
- 896 final Level 2 Certificates and 36 conditional certificates have been issued
- 110 Level 2 assessments currently in progress

Assuming the conditional certificates and current assessments turn into final certificates, that still means only 1,042 of the estimated 76,598 organizations have completed the expected certification. In other words: 99% of organizations still need to complete Level 2 (C3PAO) certification. 

These organizations are expected to perform these assessments gradually over the next decade, not all at once. [DoD projections from the 32 CFR rule](https://www.federalregister.gov/d/2024-22905/p-1410) show C3PAO assessment capacity ramping from 517 C3PAO in Year 1 to 2,599 in Year 2 and 8,666 in Year 3. Meaning, demand will substantially outpace current capacity well into the Phase 2 window.

![c3pao assessment count projections by DoD over decade](https://images.prismic.io/secureframe-com/aanhKFxvIZEnjYdl_c3pao-assessments-projections-over-decade.png?auto=format,compress)

Image source:  *[Impact and Cost Analysis of the Revised CMMC Program in 32 CFR rule](https://www.federalregister.gov/d/2024-22905/p-1410)*

As a result:

- C3PAOs are already reporting full calendars extending into late 2026
- Assessment timelines of 8-12 weeks from engagement to completion are typical
- As Phase 2 approaches, wait times will increase

**What this means**: If you wait until mid-2026 to begin your C3PAO process, you may not be able to schedule an assessment before the November deadline. Book your C3PAO engagement now, even if your assessment won't occur for months.

Find authorized C3PAOs at the [Cyber AB Marketplace](https://secureframe.com/hub/cmmc/c3pao-list) or search at[ cyberab.org/Catalog](https://cyberab.org/Catalog).

## Recommended reading

Secureframe Achieves CMMC Level 2 Certification, Continuing Its Lead in Federal Compliance & Innovation

## What if you're not ready by November 2026?

## What if you're not ready by November 2026?

You won't lose existing contracts overnight. Phase 2 applies to new solicitations and contracts after November 10, 2026. Existing contracts generally aren't retroactively modified.

But you will:

- Be unable to bid on new contracts requiring Level 2 (C3PAO)
- Risk losing re-competition or option exercise opportunities
- Potentially face subcontracting restrictions if primes require verified compliance
- Fall behind competitors who are certified

The pragmatic approach: Even if you can't complete a C3PAO assessment by November 2026, being in process ([gap analysis](https://secureframe.com/blog/cmmc-gap-analysis) complete, remediation underway, C3PAO booked) puts you in a vastly better position than having done nothing.

## Recommended reading

Measuring CMMC Readiness: How to Know You’re Fully Ready for a C3PAO Assessment [+ Checklist]

## Phase 2 preparation checklist

## Phase 2 preparation checklist

These timeline estimates reflect readiness efforts using manual processes or disparate tools or consultants. Secureframe Defense automates documentation, gap analysis, remediation tracking, and real-time SPRS scoring, compressing average readiness to as little as 4 weeks.

```
<style>
#cmmcPhase2Checklist .checkbox-group {
  margin-bottom: 40px;
}

#cmmcPhase2Checklist .column {
  display: flex;
  justify-content: center;
  align-items: center;
  width: 50px;
  min-height: 50px;
  padding: 8px;
}

#cmmcPhase2Checklist .column.column2 {
  justify-content: flex-start;
  font-weight: 500;
  width: 100%;
  padding-left: 15px;
}

#cmmcPhase2Checklist .column.column2.indented {
  padding-left: 45px;
}

#cmmcPhase2Checklist h2 {
  text-align: center;
  margin-bottom: 20px;
  font-weight: 600;
}

#cmmcPhase2Checklist .checklist-intro {
  text-align: center;
  margin-bottom: 50px;
  font-size: 16px;
  line-height: 1.5;
  color: #0e1952;
}

#cmmcPhase2Checklist h3 {
  position: relative;
  color: #fff;
  font-size: 24px;
  font-weight: 500;
  line-height: 1.25;
  min-height: 60px;
  align-items: center;
  text-align: center;
  width: 100%;
  padding: 17px;
}

#cmmcPhase2Checklist .sublabel {
  display: block;
  font-size: 13px;
  color: #555;
  margin-top: 4px;
  font-weight: 400;
}

#cmmcPhase2Checklist label {
  display: inline-block;
  color: #0e1952;
  font-size: 18px;
  line-height: 1.3333;
}

#cmmcPhase2Checklist input[type="checkbox"] {
  -webkit-appearance: none;
  appearance: none;
  background-color: transparent;
  margin: 0;
  font: inherit;
  color: #0e1952;
  width: 1.1em;
  height: 1.1em;
  border: 0.075em solid #0e1952;
  border-radius: 0;
  transform: translateY(-0.075em);
  display: grid;
  place-content: center;
  margin-top: 3.5px;
  cursor: pointer;
  flex-shrink: 0;
}

#cmmcPhase2Checklist input[type="checkbox"]::before {
  content: "";
  width: 0.65em;
  height: 0.65em;
  clip-path: polygon(14% 44%, 0 65%, 50% 100%, 100% 16%, 80% 0%, 43% 62%);
  transform: scale(0);
  transform-origin: bottom left;
  transition: 120ms transform ease-in-out;
  box-shadow: inset 1em 1em #0e1952;
}

#cmmcPhase2Checklist input[type="checkbox"]:checked::before {
  transform: scale(1);
}

#cmmcPhase2Checklist .input-group + h3 {
  margin-top: 30px;
}

#cmmcPhase2Checklist .input-group {
  display: flex;
  align-items: flex-start;
}

#cmmcPhase2Checklist .section-note {
  font-size: 13px;
  color: #555;
  padding: 8px 15px 8px 65px;
  font-style: italic;
  line-height: 1.4;
}

/* Color cycling: teal, purple, blue, orange */
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+1) h3 {
  background-color: #8ee1d0;
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+1) .column {
  border: 1px solid rgba(142, 225, 208, 0.75);
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+1) .input-group:nth-of-type(even) .column2 {
  background-color: rgba(142, 225, 208, 0.25);
}

#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+2) h3 {
  background-color: #ceb8f8;
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+2) .column {
  border: 1px solid rgba(206, 184, 248, 0.75);
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+2) .input-group:nth-of-type(even) .column2 {
  background-color: rgba(206, 184, 248, 0.25);
}

#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+3) h3 {
  background-color: rgb(123, 202, 246);
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+3) .column {
  border: 1px solid rgba(123, 202, 246, 0.75);
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+3) .input-group:nth-of-type(even) .column2 {
  background-color: rgba(123, 202, 246, 0.25);
}

#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+4) h3 {
  background-color: #f9c784;
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+4) .column {
  border: 1px solid rgba(249, 199, 132, 0.75);
}
#cmmcPhase2Checklist .checkbox-group:nth-of-type(4n+4) .input-group:nth-of-type(even) .column2 {
  background-color: rgba(249, 199, 132, 0.25);
}

@media(max-width: 766px) {
  #cmmcPhase2Checklist h3 { font-size: 20px; min-height: 40px; padding: 12px; }
  #cmmcPhase2Checklist .column { box-sizing: content-box; }
  #cmmcPhase2Checklist label { font-size: 16px; }
  #cmmcPhase2Checklist .column.column2.indented { padding-left: 30px; }
}
</style>

<div class="blog-details-content" id="cmmcPhase2Checklist">
  <h2>Phase 2 Preparation Checklist</h2>
  <p class="checklist-intro">These timeline estimates reflect readiness efforts using manual processes or disparate tools or consultants. Secureframe Defense automates documentation, gap analysis, remediation tracking, and real-time SPRS scoring, compressing average readiness to as little as 4 weeks.</p>

  <!-- Section 1: Start Immediately -->
  <div class="checkbox-group">
    <h3>Start Immediately (if you haven't already)</h3>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem1" id="cmmcItem1" />
      </div>
      <div class="column column2">
        <label for="cmmcItem1">Confirm your required CMMC level (check contract DFARS clauses)</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem2" id="cmmcItem2" />
      </div>
      <div class="column column2">
        <label for="cmmcItem2">Complete or update your gap analysis against NIST 800-171 Rev 2</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem3" id="cmmcItem3" />
      </div>
      <div class="column column2">
        <label for="cmmcItem3">Migrate to a FedRAMP-compliant cloud if processing CUI</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem4" id="cmmcItem4" />
      </div>
      <div class="column column2">
        <label for="cmmcItem4">Deploy MFA for all users accessing CUI systems <em>(cannot be on POA&amp;M)</em></label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem5" id="cmmcItem5" />
      </div>
      <div class="column column2">
        <label for="cmmcItem5">Implement FIPS 140-2 validated encryption for CUI at rest and in transit <em>(cannot be on POA&amp;M)</em>
          <span class="sublabel">*SC.L2-3.13.11 CUI Encryption may be included on a POA&amp;M if encryption is employed but not yet FIPS-validated (point value of 3).</span>
        </label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem6" id="cmmcItem6" />
      </div>
      <div class="column column2">
        <label for="cmmcItem6">Escort and monitor all visitors in areas where CUI is handled <em>(cannot be on POA&amp;M)</em></label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem7" id="cmmcItem7" />
      </div>
      <div class="column column2">
        <label for="cmmcItem7">Establish and maintain physical access logs <em>(cannot be on POA&amp;M)</em></label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem8" id="cmmcItem8" />
      </div>
      <div class="column column2">
        <label for="cmmcItem8">Control and manage physical access devices <em>(cannot be on POA&amp;M)</em></label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem9" id="cmmcItem9" />
      </div>
      <div class="column column2">
        <label for="cmmcItem9">Verify and control connections to external systems <em>(cannot be on POA&amp;M)</em></label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem10" id="cmmcItem10" />
      </div>
      <div class="column column2">
        <label for="cmmcItem10">Establish controls for CUI posted to publicly accessible systems <em>(cannot be on POA&amp;M)</em></label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem11" id="cmmcItem11" />
      </div>
      <div class="column column2">
        <label for="cmmcItem11">Have a documented System Security Plan (SSP) in place <em>(cannot be on POA&amp;M)</em></label>
      </div>
    </div>
  </div>

  <!-- Section 2: Within 90 Days -->
  <div class="checkbox-group">
    <h3>Complete Within 90 Days</h3>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem12" id="cmmcItem12" />
      </div>
      <div class="column column2">
        <label for="cmmcItem12">Create or update your Plan of Action &amp; Milestones (POA&amp;M)</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem13" id="cmmcItem13" />
      </div>
      <div class="column column2">
        <label for="cmmcItem13">Define and document your CUI boundary</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem14" id="cmmcItem14" />
      </div>
      <div class="column column2">
        <label for="cmmcItem14">Implement an incident response plan and conduct a tabletop exercise</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem15" id="cmmcItem15" />
      </div>
      <div class="column column2">
        <label for="cmmcItem15">Deploy audit logging and establish regular log review procedures</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem16" id="cmmcItem16" />
      </div>
      <div class="column column2">
        <label for="cmmcItem16">Conduct security awareness training for all CUI-handling staff</label>
      </div>
    </div>
  </div>

  <!-- Section 3: Within 6 Months -->
  <div class="checkbox-group">
    <h3>Complete Within 6 Months</h3>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem17" id="cmmcItem17" />
      </div>
      <div class="column column2">
        <label for="cmmcItem17">Remediate all critical gaps (focus on MFA, encryption, access controls, audit logging, incident response)</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem18" id="cmmcItem18" />
      </div>
      <div class="column column2">
        <label for="cmmcItem18">Update and finalize your System Security Plan (SSP)</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem19" id="cmmcItem19" />
      </div>
      <div class="column column2">
        <label for="cmmcItem19">Conduct a mock assessment or readiness review with an RPO</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem20" id="cmmcItem20" />
      </div>
      <div class="column column2">
        <label for="cmmcItem20">Calculate your SPRS score to confirm assessment readiness</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem21" id="cmmcItem21" />
      </div>
      <div class="column column2">
        <label for="cmmcItem21">Engage a C3PAO and schedule your assessment</label>
      </div>
    </div>
  </div>

  <!-- Section 4: Before November 2026 -->
  <div class="checkbox-group">
    <h3>Before November 2026</h3>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem22" id="cmmcItem22" />
      </div>
      <div class="column column2">
        <label for="cmmcItem22">Complete C3PAO assessment (or have it scheduled with a firm date)</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem23" id="cmmcItem23" />
      </div>
      <div class="column column2">
        <label for="cmmcItem23">Address any POA&amp;M items from conditional certification</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem24" id="cmmcItem24" />
      </div>
      <div class="column column2">
        <label for="cmmcItem24">Complete annual affirmation</label>
      </div>
    </div>

    <div class="input-group">
      <div class="column column1">
        <input type="checkbox" name="cmmcItem25" id="cmmcItem25" />
      </div>
      <div class="column column2">
        <label for="cmmcItem25">Ensure ongoing compliance monitoring is in place</label>
      </div>
    </div>
  </div>
</div>
```

## Go from zero to assessment-ready

## Go from zero to assessment-ready with Secureframe Defense

Don't wait for Phase 2 to start preparing. Secureframe Defense automates every step of the process, from infrastructure deployment to documentation to monitoring, so you can get assessment-ready in weeks, not months.

Why navigate the process alone when Secureframe will perform a gap analysis against NIST 800-171, document your controls, track your remediation progress, give you a real-time SPRS score—and so much more—so you know exactly where you stand before your C3PAO walks in for the assessment.

[Talk to an expert](https://secureframe.com/request-cmmc-demo) about fast-tracking your Level 2 (C3PAO) certification for Phase 2 before it’s too late.

### Can I still self-assess for Level 2 in Phase 2?

Yes, for some Level 2 contracts. The DoD may specify Level 2 (Self) instead of Level 2 (C3PAO) in certain solicitations that involve non-critical CUI. However, the DoD estimates that only about 5% of all Level 2 contracts—only 2% of the entire DIB—may qualify for Level 2 (Self). Level 2 (C3PAO) certification becomes the default for most CUI contracts starting in Phase 2.

### How much does a C3PAO assessment cost?

Industry estimates range from $35,000-$75,000 for the assessment fee alone, as confirmed by  Matt Graham, Vice President of US Federal Practices at Prescient Security, during a recent Secureframe webinar. The DoD's official total estimate is higher because it includes the triennial assessment plus two annual affirmations at $105,000-$118,000. Smaller organizations with well-defined enclaves tend toward the lower end, although the exact cost depends on the organization’s scope, complexity, and number of requirements and assessment objectives in play.

### Can I change C3PAOs between my initial assessment and my triennial re-assessment?

Yes. You're not locked into a specific C3PAO. You can use any authorized C3PAO for future assessments.

### What happens during the 180-day conditional period?

You can still be awarded contracts. Conditional CMMC Status is treated as valid for contracting purposes during the 180-day window. But you must close all POA&M items and pass the closeout assessment, or your status expires.

### Can a C3PAO conduct both a mock assessment and my official certification assessment?

Yes, but with strict conditions. Per the Cyber AB's Code of Professional Conduct, a mock assessment (formally called a non-certification assessment) must follow formal procedures aligned with the CMMC Assessment Process, cannot include consulting recommendations during the assessment itself, and must produce a formal deliverable. A mock assessment cannot simply be converted into an official certification mid-stream — the certification assessment must start as a clean, separate engagement.
