Ask how long CMMC Level 2 takes and the industry answers in unison: six to eighteen months. That number is real for the way most firms run the work. It is not a law of physics. This post is the honest account of where those months actually go, and the week-by-week mechanism we use to get a defense contractor scoped, deployed, remediated, and packaged for a C3PAO in 2-5 weeks, depending on environment size.
The claim, precisely: assessment-ready in 2-5 weeks: scoped, designed, deployed, remediated, evidence collected, and packaged for your C3PAO. The certification event itself belongs to the assessor. Anyone who promises you a certification date is selling something they do not control.
Where the 6-18 months actually goes
The conventional timeline is not padding. It is the natural result of running five workstreams in series, by hand:
- Gap assessment (4-8 weeks). Interviews, spreadsheet walkthroughs of 110 requirements, and a report that is stale the day it ships.
- Design (4-8 weeks). CUI enclave architecture, identity design, boundary documentation, usually sequential with the assessment because findings shape the design.
- Remediation (8-26 weeks). The bottleneck. Every finding becomes a ticket, the ticket waits for an engineer, the fix waits for a change window, the verification waits for another scan. Industry median time-to-remediate a single finding through a manual workflow is measured in weeks.
- Documentation (6-12 weeks). SSP written from templates, POA&M maintained in spreadsheets, policies adapted to an environment that keeps changing underneath the author.
- Evidence assembly (4-10 weeks). Screenshots, config exports, and log samples collected by hand and mapped to 320 assessment objectives, again, after remediation, because evidence gathered earlier no longer matches the environment.
Serial execution plus manual labor on the two longest phases. That is the entire trick behind 6-18 months. Remove those two properties and the timeline collapses.
The 2-5 week model
We run the same workstreams in parallel and automate the two that consume the most calendar time. Remediation is executed by PolicyCortex against your cloud environment, deterministic findings are fixed in minutes, with every action validated against its inverse before execution. Evidence is not assembled after the fact; it is generated as a byproduct of enforcement, so the package describes the environment as it actually exists, not as it existed at the last screenshot.
Week 1: Scope and baseline
CUI boundary definition, asset and data-flow inventory, current SPRS baseline, external service provider inventory, and the design decisions only you can make , front-loaded into structured sessions instead of drifting across months of email. You leave week one with a fixed scope and a committed calendar.
Weeks 2-3: Deploy and remediate
Enclave and identity architecture deployed, PolicyCortex enforcing against the full NIST SP 800-171 control set. Findings that are deterministic, encryption configuration, logging coverage, access policy drift, are remediated automatically and logged as evidence. Findings that require human judgment go to you as a short, decision-ready list, not a ticket queue.
Weeks 3-5: Evidence and package
SSP written against the real, running environment. POA&M for residual gaps with closure dates. Evidence mapped to all 320 NIST SP 800-171A assessment objectives, collected continuously rather than reconstructed. Validated SPRS score. The package your C3PAO receives is complete on the first submission, which is what keeps the assessment itself to days instead of weeks of re-tests.
What decides 2 weeks versus 5
Environment size and complexity, nothing else. We commit to a specific number after the week-one scope, never before it:
| Environment | Typical profile | Timeline |
|---|---|---|
| Small | Single CUI enclave, one cloud tenant, small user base | ~2 weeks |
| Mid | Multiple workloads, several ESPs, mixed cloud and SaaS | 3-4 weeks |
| Large | Multi-tenant or multi-site, legacy on-premise in scope | ~5 weeks |
What is outside anyone's control
The C3PAO assessment itself, typically 3-5 assessment days plus their scheduling lead time, belongs to the assessor, and authorized C3PAOs are a constrained resource. What you control is how the assessment goes once scheduled. A complete, defensible package is the difference between a first-pass assessment and months of follow-up findings, re-tests, and a second engagement fee. Assessors do not certify effort; they certify evidence.
Why do this during the Phase II pause
The July 2026 suspension paused Phase II implementation milestones. It did not suspend DFARS 252.204-7012, NIST SP 800-171, or the obligation to hold an accurate SPRS score. The review period is the cheapest preparation window the DIB will get: assessor calendars are open, remediation resources are not bid up by a deadline scramble, and a defensible posture now means you are scheduling from strength when milestones resume, whenever and however they resume.
The bottom line
Six to eighteen months is the cost of doing this by hand, in series. Two to five weeks is the cost of doing it in parallel, with automation on the phases where humans are slow and judgment on the phases where they are not. If you want the week-one scope for your environment, book a working session. You will leave with a fixed timeline, not an estimate.
Frequently asked questions
How can CMMC Level 2 be done in 2-5 weeks when most firms quote 6-18 months?
+
The 6-18 month figure comes from running scope, design, remediation, documentation, and evidence collection as serial, manual projects. We run them in parallel and automate the two longest phases: technical remediation (PolicyCortex remediates deterministic findings in minutes, not weeks) and evidence collection (evidence is generated as a byproduct of enforcement, not assembled by hand afterward). The work that remains, decisions only the client can make, is front-loaded into structured week-one scoping.
Does 2-5 weeks include the C3PAO certification itself?
+
No, and any firm that promises a certification date is overselling. The C3PAO assessment, typically 3-5 assessment days plus their scheduling lead time, is outside any contractor's control. What we control is everything up to that point: you arrive at scheduling with a complete, defensible evidence package, which is what determines whether the assessment finishes on the first pass or drags into re-tests and follow-up engagements.
What determines whether it is 2 weeks or 5 weeks?
+
Environment size and complexity. A single CUI enclave with one cloud tenant and a small user base is typically a 2-week engagement. Multi-tenant or multi-site environments, legacy on-premise systems in scope, or heavy external service provider dependencies push toward 5 weeks. We commit to a specific number after the week-one scope, not before it.
What is actually in the C3PAO evidence package?
+
A scoped CUI boundary definition, a System Security Plan written against your real environment rather than a template, a POA&M for any residual gaps with closure dates, evidence mapped to all 320 NIST SP 800-171A assessment objectives, and a validated SPRS score. Evidence is collected continuously by the platform as controls are enforced, so the package reflects the live environment rather than a point-in-time snapshot.
Does the CMMC Phase II pause change any of this?
+
The July 2026 suspension paused Phase II implementation milestones, not the underlying obligations. DFARS 252.204-7012, NIST SP 800-171, and accurate SPRS scoring remain contractually in force, and the review period is the cheapest time to prepare: assessor availability improves, and you are not competing with the entire Defense Industrial Base for remediation resources at the deadline.