CMMC Level 2 is a process, not a product. You cannot buy your way to certification. You have to execute a defined sequence, generate the right evidence, pass a third-party audit, and keep the controls operating between assessments. This guide walks the sequence end-to-end, in the order you should actually run it.
The Seven-Step Process at a Glance
- Scope CUI: identify every system, person, and process that touches Controlled Unclassified Information.
- Gap assessment: measure current state against the 110 NIST 800-171 controls.
- Build the SSP and POA&M: document how each control is met or how you will meet it.
- Remediate: implement the missing controls and close the gaps.
- Internal pre-assessment: score yourself before the C3PAO does.
- C3PAO assessment: the third-party Level 2 certification audit.
- Continuous compliance: keep the controls operating between assessments.
A common reason a first C3PAO assessment does not go well is that they ran these steps out of order, usually by starting the SSP before scoping CUI. Sequence matters.
Step 1: Scope CUI
Before you touch a single control, map every place CUI lives, moves, and is processed: email, file shares, ERP, engineering and CAD/CAM applications, mobile devices, and any vendor or subcontractor environment that touches your data. Output: a CUI data-flow diagram, a list of in-scope systems and users, and a decision between full-network and enclave architecture. Common mistake: assuming CUI lives only on the engineering file share. It travels in email replies, drafts on laptops, and backups. Scope wider than you think.
Step 2: Gap Assessment Against NIST 800-171
CMMC Level 2 maps to the 110 controls in NIST SP 800-171. A gap assessment scores your current state against each control as Met, Partially Met, or Not Met. Output: a control-by-control scorecard, a gap register, and a remediation backlog ranked by risk and effort. Common mistake: treating the gap assessment as a one-time event. Controls drift, so plan to re-score regularly.
Step 3: Build the SSP and POA&M
The System Security Plan documents how each of the 110 controls is implemented in your environment. The Plan of Action and Milestones documents the gaps you have not yet closed, with target dates and ownership, alongside the supporting policy set. This is where consultancies spend the most billable hours. Common mistake: writing an SSP that describes the controls you want instead of the ones you have. C3PAOs check evidence against SSP claims, and mismatches fail you.
Want Steps 1 through 3 as a starting picture before you commit? The free 2-minute gap check is a directional self-assessment, not an official SPRS score, but it shows you where to begin.
Run the free gap check →Step 4: Remediate and Implement Controls
Close the gaps from Step 2. For most small and mid-size contractors, the work concentrates in multi-factor authentication, FIPS-validated encryption at rest and in transit, centralized logging, endpoint detection and response, configuration management, and identity governance. Output: an environment where every in-scope control has supporting evidence. Common mistake: deploying tools without configuring evidence collection. A control that produces no auditable record does not pass.
Step 5: Internal Pre-Assessment
Score yourself against the DoD Assessment Methodology before the C3PAO does. The methodology assigns weighted point values to the 110 controls; the exact thresholds and weighting should be confirmed against the current published methodology version. Output: a scored self-assessment, an evidence library mapped to every control, and a go or no-go decision on engaging a C3PAO. Common mistake: using the same firm for both the pre-assessment and the remediation. Use independent eyes. For the path comparison, see self-assessment vs. C3PAO.
Step 6: C3PAO Assessment
Engage a Certified Third-Party Assessor Organization. The C3PAO reviews your SSP, POA&M, and evidence library and conducts interviews and technical validation. The outcome is Level 2 certification, a conditional status with a window to close residual gaps, or a fail. Output: a certification you can attach to contract bids. Common mistake: treating the C3PAO as adversarial. The assessors want to certify you if the evidence is there, so cooperate rather than litigate every finding.
Step 7: Continuous Compliance
Your certification has a fixed validity period, but you re-affirm annually and must operate the controls continuously. Material changes to scope, ownership, or environment can trigger reassessment. Output: ongoing monitoring, regular evidence refresh, annual self-affirmation, and change-triggered control reviews. Common mistake: filing the certificate and ignoring drift. Drift is what makes the next assessment expensive. See our Level 2 cost guide for budgeting the ongoing phase.
How AI Compresses the Timeline
Under the legacy consulting model this process drags, mostly because four steps are run by hand: gap assessment, SSP authoring, evidence collection, and continuous monitoring. An AI-as-a-Service (AaaS) platform collapses those four into a single continuous workflow. It connects to your environment, observes live control state, auto-generates the gap register, pre-populates the SSP and POA&M, builds the evidence library with provenance, and monitors drift continuously. Your authorizing official reviews and approves. This is operational leverage for your team, not a replacement for it. For the full ten-step view, see our CMMC certification process walkthrough.
What It Means for Sequencing
The practical takeaway is simple: scope first, document against reality, and treat evidence and monitoring as continuous capabilities rather than pre-audit scrambles. The contractors who sequence the process correctly spend less and pass sooner.