Process · CMMC Guide

The CMMC Level 2 Certification Process: Every Step, In Order

CMMC Level 2 is not opaque, it is just long, and the contractors who struggle are almost always the ones who do the steps out of order.

ProcessCMMC Level 2

By Enclave AI™ on ai4cmmc.ai · ElasticD3M, LLC · Patent Pending
Published June 10, 2026 · 6 min read · CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

CMMC Level 2 certification has a reputation for being opaque. It is not. It is just long. There are nine steps between "we should probably deal with this" and a certificate in SPRS, and the contractors who struggle are almost always the ones who did them out of order.

Here is the full sequence, what each step actually involves, and where the time and money go.

Step 1: Confirm your level and define your scope

If you only handle Federal Contract Information (FCI), Level 1 self-assessment may be all you need. If you handle Controlled Unclassified Information (CUI), such as drawings, specs, and technical data marked or identified as CUI, you are in Level 2 territory. Then define the assessment scope: which systems, networks, and people touch CUI. A well-designed CUI enclave can dramatically shrink everything that follows. For the dividing line, see CMMC Level 1 vs Level 2.

Step 2: Run a gap assessment against NIST SP 800-171

Level 2 is the 110 security requirements of NIST SP 800-171, assessed against the objectives in NIST SP 800-171A. The gap assessment tells you which controls you meet, which you partially meet, and which are missing. This is where automation pays off first. A control-by-control analysis that takes a consultant weeks can be produced and kept current continuously by an AaaS platform, with your team validating findings rather than generating them.

Step 3: Post your self-assessment score to SPRS

DoD requires a current NIST 800-171 self-assessment score in the Supplier Performance Risk System (SPRS). Primes check it. An honest score with a credible improvement plan beats an inflated one, and false claims can carry legal exposure, so keep the score accurate.

Get the control-by-control gap picture the whole process is built on. Start the free 2-minute gap check →

Step 4: Remediate the gaps

Close the missing controls: access management, encryption, logging, incident response, and the rest. Prioritize by assessment weight and implementation lead time. Some controls take an afternoon, some take a procurement cycle.

Step 5: Build the documentation

Your System Security Plan (SSP) is the central artifact of the entire assessment, and assessors work from it. Add the policies and procedures behind each control and a Plan of Action and Milestones (POA&M) for anything unfinished. Only certain lower-weighted controls may sit on a POA&M at assessment time, you must hit the minimum score, and POA&M items must be closed within the regulatory window. Documentation is the largest labor sink in the whole process, and the most automatable.

Step 6: Book your C3PAO early

Certified Third-Party Assessment Organizations are the only bodies that can issue Level 2 certifications, and they have been booking out well in advance as the Phase 2 date approaches. Book before you feel ready. The backlog does not care about your readiness. (We are not a C3PAO and do not issue certifications; we provide the readiness software that gets you to the assessment in good shape.)

Step 7: The assessment itself

The C3PAO reviews your SSP, examines evidence, interviews staff, and tests controls against the 800-171A objectives. Strong evidence hygiene, meaning organized, current, and mapped to controls, is the difference between a smooth assessment and a painful one. Our step-by-step walkthrough of the assessment covers what each day looks like.

Step 8: Conditional vs. final certification

Meet every requirement and you receive final certification. Hit the minimum score with allowable POA&M items and you can receive conditional status, with a hard deadline to close out the remaining items and verify closure. Miss that window and you are back in the queue.

Step 9: Maintain it

Certification runs on a three-year cycle with annual affirmations of continuing compliance in between. The affirmation is a signed, on-the-record statement, so treat it accordingly. Continuous monitoring is not a nice-to-have, it is the operating model.

The Pattern Behind Every Step

Look at where the effort concentrates: analysis, documentation, evidence, and upkeep. That is systematic work, which is why the process is being transformed by AI-as-a-Service. ai4cmmc.ai runs steps 2, 5, and the evidence side of 7 and 9 as a continuous automated system, with every output reviewed and approved by your people. The assessor still assesses. Your authorizing official still decides. The grind disappears. Start at step 2 with the $799 CMMC Readiness Snapshot and you get the control-by-control gap picture the entire process is built on, month-to-month, no long-term contract.

Know where you stand before you spend a dollar on remediation

The free gap check gives you a directional read in about 2 minutes. The CMMC Readiness Snapshot measures your environment against all 110 NIST 800-171 controls and returns a PDF within minutes of intake, for $799 one time. Month-to-month plans available, no long-term contract.

Run the free 2-minute gap check See the $799 Readiness Snapshot
CMMC Level 2 Compliance. AI-Native. At the Speed of Thought.

Disclaimer. This article is general information about CMMC, not legal, compliance, financial, or assessment advice, and it does not create any advisory or contractual relationship. CMMC regulations and figures change; nothing here is a representation, warranty, or guarantee of any outcome, score, cost, timeline, or certification. Verify current requirements with your own qualified counsel and an authorized C3PAO before making decisions. Dollar figures are the DoD's published estimates from the CMMC Program Regulatory Impact Analysis, not quotes or predictions of your cost.

Enclave AI™ builds AI-driven CMMC Level 1 and Level 2 readiness software. We are not a C3PAO and we will not seek C3PAO authorization, that separation is permanent. We do not issue, grant, or guarantee CMMC certification, only an authorized C3PAO can. The free gap check is a directional self-assessment and is not an official SPRS score. Patent Pending. ElasticD3M, LLC, Texas. All third-party names and frameworks are referenced for identification only and remain the property of their respective owners.