How long does it take to get CMMC Level 2 compliant?

Short answer

CMMC Level 2 takes as long as it takes your company to implement and evidence all 110 NIST SP 800-171 Rev 2 requirements, and DoD publishes no fixed duration. Companies with a documented SSP and mature Microsoft 365 controls move far faster than those starting from scratch or migrating CUI to a new environment. The rule's fixed clocks are 180-day POA&M closeout and three-year validity.

Why there is no standard timeline

Neither the 32 CFR Part 170 rule nor the DoD CMMC program sets a time to compliance. The duration is driven by your gap: how many of the 110 requirements are already in place, whether you can prove it, and whether CUI has to move to a new environment first.

DoD's own cost analysis in the final rule assumes the security requirements are already implemented before an assessment begins. Implementation is the long pole, and assessment is the short one.

The phases your project will go through

  • Scoping: find where CUI lives and define the assessment boundary, including any external service providers.
  • Gap assessment: score yourself against the 110 requirements using the DoD methodology.
  • Documentation: write or update the System Security Plan and the POA&M.
  • Remediation: technical controls such as multifactor authentication, logging, encryption and endpoint management, plus policies and training.
  • Evidence and assessment: collect artifacts, complete the self-assessment, post to SPRS and have a senior official affirm.

What makes it take longer

The biggest delays are usually an unclear CUI boundary, a migration to a FedRAMP Moderate-equivalent cloud such as Microsoft 365 GCC High, unmanaged shop-floor or engineering systems, and policies that exist on paper but are not followed. Each one adds work before you can honestly affirm a score.

Clocks the rule does set

Once assessed, a conditional Level 2 status with a POA&M requires open items to be closed within 180 days. Assessments are valid for three years, and a senior official must affirm compliance every year.

Contract timing also matters. Phase 1 began November 10, 2025. The Phase 2 C3PAO requirement originally scheduled for November 10, 2026 was suspended on July 13, 2026 pending a Department of War review, so new solicitations currently call only for self-assessments. Use that window to finish implementation rather than to wait.

How to shorten the path

Shrink the scope first. Keeping CUI in a defined enclave, used by only the people who need it, reduces the number of systems to fix and evidence. Then work the highest-weighted requirements first, because those cannot be carried on a POA&M, and assign a named owner and due date to every open item so progress is visible to leadership.

Common follow-up questions

Can I get a POA&M to buy more time?

Only within limits. You need a score of at least 80 percent of the 110 points, items on the POA&M must be lower-weighted, certain requirements such as the SSP are never allowed, and everything must close within 180 days.

How often do I have to repeat CMMC Level 2?

Under 32 CFR Part 170 a Level 2 assessment is valid for three years, and a senior official must submit an affirmation of continued compliance in SPRS every year in between.

Does the Phase 2 suspension change my timeline?

It changes when third-party certification may be required, not your obligations. DFARS 252.204-7012 and Level 2 self-assessments remain in effect, and DoD has said further guidance will follow its 60-day review.

Need help with this?

LAN Service Group runs CMMC and NIST SP 800-171 programs led by a certified Information System Security Officer (ISSO), covering readiness, SSP and POA&M development, remediation and assessment preparation.

Talk to LAN Service Group (888) 281-7243

Sources