Twelve weeks is the minimum realistic timeline for a defense contractor with a reasonable security baseline to prepare for a CMMC Level 2 assessment. If you are starting from scratch, expect longer. If you have been maintaining compliance with NIST SP 800-171 and have a current SSP, you might compress it. Treat the timeline as directional, not a guarantee.
This plan assumes you have already identified your CUI boundary, have basic security infrastructure in place, and are now preparing specifically for the C3PAO assessment. It is a week-by-week action plan with clear deliverables at each stage. For what the assessment itself looks like, see the step-by-step assessment walkthrough.
Weeks 1-2: Baseline and Gap Assessment
Objective: Know exactly where you stand against all 110 controls.
Conduct a thorough self-assessment against NIST SP 800-171. Score each control as MET, NOT MET, or PARTIALLY MET, and document the specific deficiency for every control that is not fully MET. This is not the time for optimistic scoring. Every control you mark MET will be validated by the C3PAO, and an inaccurate self-assessment creates problems during the real assessment.
Deliverables: a completed self-assessment scorecard, a prioritized gap list, and an updated SPRS score. If you deploy an AaaS platform during this phase, the AI agents can complete the baseline assessment in days rather than weeks, giving you more runway for remediation.
Weeks 3-4: Documentation Sprint
Objective: Get every policy, procedure, and plan current and complete.
Your System Security Plan is the single most important document. It must accurately describe your CUI environment, how each control is implemented, and who is responsible for each control area. Update your SSP to reflect your current environment, not the environment you had when it was last written. In parallel, update or create all supporting documentation: access control policies, incident response plans, media protection procedures, configuration management plans, and the other policy documents the 14 control families require. Each must align with the SSP and with what your systems actually do.
Weeks 5-7: Technical Remediation
Objective: Close the gaps identified in Weeks 1-2.
This is the most resource-intensive phase. Prioritize on two factors: which controls are not POA&M-eligible (these must be MET before the assessment), and which controls take the most time to implement. Address long-lead-time items first, such as deploying new security tools, reconfiguring network architecture, or establishing processes that require staff training. Common activities include deploying or configuring SIEM and log management, implementing MFA across all CUI-touching systems, establishing encrypted channels for CUI transmission, configuring endpoint detection and response, setting up automated vulnerability scanning, and strengthening network segmentation around CUI enclaves.
Weeks 8-9: Evidence Collection and Organization
Objective: Build an evidence package assessors can validate efficiently.
For each of the 110 controls, compile evidence that demonstrates implementation and effectiveness: system screenshots showing configurations, policy documents with approval signatures, training records with dates and attendees, audit logs showing monitoring activity, vulnerability scan reports showing remediation, and incident response test results. Organize evidence by control family and control number so assessors can find what they need. A well-organized package signals maturity and reduces assessment time.
Week 10: Internal Readiness Review
Objective: Simulate the assessment before the real thing.
Conduct a mock assessment. Walk through every control as if the C3PAO were evaluating you. Test your documentation against your technical implementation, interview key personnel to confirm they can articulate their responsibilities, and address any remaining gaps immediately. This is where AaaS platforms add real value: AI agents can run a continuous readiness check against all 110 controls and flag discrepancies between your documentation and your actual environment before assessors arrive.
Week 11: Personnel Preparation
Objective: Make sure everyone who interacts with assessors is ready.
The C3PAO interviews personnel at multiple levels. System administrators need to explain technical implementations, managers need to articulate oversight processes, and end users need to demonstrate awareness of security practices. Prepare your team by reviewing what assessors will ask for each control area, running practice interviews, and confirming everyone knows the CUI boundary and their role within it.
Week 12: Final Validation and Assessment-Week Logistics
Objective: Eliminate last-minute surprises.
Run a final comprehensive check. Verify all evidence is current, all systems are configured as documented, all personnel are scheduled and available, and all physical access requirements are arranged. Confirm logistics with your C3PAO: schedule, participants needed each day, conference room and network access for assessors, and any documentation they want to review in advance.
Common Mistakes That Derail Preparation
The frequent failures follow predictable patterns. Underestimating documentation effort produces a rushed SSP that does not match reality. Ignoring the CUI boundary definition causes scope creep that inflates cost and complexity. Waiting until Week 10 to prepare personnel means interviews reveal gaps that cannot be fixed in time. Treating POA&Ms as a safety net rather than a last resort leads to conditional certifications that create ongoing obligations.
Why Systems Beat Projects
The contractors who pass on the first attempt are not the ones who run a 12-week project. They are the ones who built a compliance system that runs continuously. AaaS platforms enable that shift by automating gap assessment, documentation, and monitoring so that assessment preparation becomes a validation exercise rather than a scramble. AI carries the engineering and documentation work; your authorizing official reviews and approves every output. Start with the $799 CMMC Readiness Snapshot, month-to-month, no long-term contract, or read how to get CMMC certified for the full path.