Six to eighteen months, and two clocks
Readiness is the clock you control. The assessor queue is the one you do not, which is exactly why starting early beats starting perfect.
Most companies pursuing CMMC Level 2 certification take 6 to 18 months from the day they start to the day they pass assessment, based on the range widely reported across the compliance industry (Huntress). CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense framework that verifies a contractor has real, working security controls in place, not a policy binder nobody follows. Companies that already have basic access controls, logging, and an asset inventory land toward the front of that range. Companies running on shared logins and no formal IT policy land toward the back. Simpatico runs a structured 90-day methodology to compress the readiness work inside that window, but readiness and the actual third-party assessment are two different clocks right now, and the second one has gotten more complicated. More on that below.
Key Takeaways
- Most companies pursuing CMMC Level 2 take 6 to 18 months from start to passed assessment, per ranges widely reported across the compliance industry (Huntress).
- Where you land in the range depends on your starting point: existing access controls, logging, and asset inventory pull you forward; shared logins and no formal IT policy push you back.
- Readiness and the third-party assessment are two different clocks, and the assessor queue is the one you cannot compress.
- Shrinking scope with a bounded enclave is the biggest structural accelerator available to a small contractor.
How long does CMMC certification take on average?
Across the industry, CMMC Level 2 runs 6 to 18 months from kickoff to a passed assessment. Most sources put the typical mid-market path at 6 to 12 months for a company with some existing IT foundation, stretching to 12 to 18 months for a company with a more complex environment or real gaps to close (Huntress). Almost none of that time is the assessment itself. Most of it goes into building the System Security Plan (SSP, the document that describes exactly how you meet each required control), closing gaps against the 110 controls tied to NIST SP 800-171, and generating evidence an assessor can actually check. Simpatico’s 90-day methodology exists because that timeline is compressible when scoping, remediation, and documentation run together instead of one after another.
What makes your CMMC timeline faster or slower?
Three things move your specific timeline more than anything else: your starting security maturity, how much of your business touches CUI (Controlled Unclassified Information, the sensitive but unclassified data CMMC exists to protect) or FCI (Federal Contract Information, a lighter category covered at CMMC Level 1), and how organized your documentation is from day one. A company with basic access controls and asset tracking already in place starts closer to the finish line than one with none of that. Scope matters just as much. CUI flowing through five systems is a smaller job than CUI flowing through fifty. And companies that try to build all their documentation during assessment prep, instead of as they go, consistently lose months to rework. The order these steps actually go in matters more than most contractors expect going in.
What are the four phases of a CMMC certification timeline?
Every CMMC path, fast or slow, moves through the same four phases. Scoping defines exactly which systems, people, and processes touch FCI or CUI, since nothing outside that boundary needs to be assessed. Gap assessment compares your current controls against what CMMC Level 2 requires. Remediation closes those gaps: new access controls, better logging, updated vendor agreements, sometimes a rebuilt network segmentation plan. Assessment prep packages the evidence a C3PAO (a CMMC Third-Party Assessment Organization, the independent firm that actually runs your Level 2 assessment) will need to see. Companies that stretch toward 18 months usually have a long, disconnected remediation phase where fixes trickle in one at a time instead of running as one coordinated project.
Why is the assessor shortage making CMMC take even longer right now?
Because passing your assessment and getting an assessor to show up are two separate problems. DoD’s own chief information officer, Kirsten Davies, put a number on it in July 2026: more than 100,000 defense industrial base companies will eventually need third-party assessment, and only around 100 C3PAOs are approved to do it (DefenseScoop). Her line on it: “the math just simply doesn’t math” for small and midsize businesses to get compliant on the original schedule. The Small Business Administration separately flagged compliance costs approaching $600,000 per certification for a small firm requiring third-party assessment (SBA), and DoD estimated the aggregate could top $7 billion a year across the small business base (DefenseScoop). What this means for your timeline: even a company that finishes readiness work in 90 days can sit in a queue waiting for an assessment slot. Starting early is what buys you a place in that queue. It does not make your own readiness work move any faster once you’re in it.
Where does a CMMC enclave fit into a faster timeline?
Scope is the single biggest lever on your timeline, and an enclave is fundamentally a scope decision. An enclave is a separate, tightly controlled environment where CUI lives, walled off from the rest of your systems, so the share of your business that never touches CUI, often most of it, stays out of the assessment boundary entirely. Less scope means less to document, less to remediate, and less for an assessor to examine, which is the difference between a gap assessment that takes weeks and one that drags for months. Simpatico partners with a hosted enclave provider specifically because a pre-built enclave is typically the fastest of the available paths to stand up when assessment capacity is this scarce.
What just happened with CMMC Phase 2, and does it change your timeline?
The CMMC 48 CFR final rule took effect November 10, 2025, opening Phase 1: DoD contracting officers can now require CMMC Level 1 or Level 2 self-assessments as a condition of contract award. Phase 2, which would have required independent third-party C3PAO assessment for contracts involving CUI, was set to begin November 10, 2026. On July 13, 2026, DoD suspended Phase 2 and the phases after it, pending a 60-day review by a newly formed CMMC Reform Task Force, with public comments accepted through August 14, 2026 (Holland & Knight; DefenseScoop). Phase 1 self-assessment requirements were not touched and remain in effect. What that means for your planning: the mandatory third-party assessment date is under review, not canceled, and primes are already asking subcontractors for proof of certification or a credible path to it ahead of any hard deadline. A pause in the phase-in schedule is not a reason to pause your own readiness work.
What should you do this quarter?
Start with the difference between being ready and being compliant. Readiness and compliance are not the same milestone, and confusing them is how companies think they’re further along than they are. Get a real scoping conversation on the calendar, understand what CMMC Level 2 actually costs for a company your size, and decide whether an enclave narrows your scope enough to matter. We are a compliance consulting partner for defense contractors through the whole CMMC journey, scoping, gap work, documentation, and assessment prep, and Simpatico Systems is a Registered Provider Organization (RPO) with the CMMC accreditation body, so that guidance comes from inside the process, not from someone advising it at a distance. The C3PAO that runs your final assessment is always an independent third party. We get you ready for them.
What should you do next?
Don’t wait for the CMMC Reform Task Force to tell you when to start. Schedule a strategy session and we’ll map your real timeline against where your CUI actually lives.
If your prime asked for proof of certification tomorrow, how many months of runway would you actually need?
Frequently Asked Questions
How long does a CMMC assessment take, separate from getting ready for one?
Can you get CMMC certified fast?
How long is CMMC certification valid?
Do subcontractors need CMMC certification too?
What happens if you fail your CMMC assessment?
Start the clock you control
The readiness work needs no assessor and can start today; the queue rewards whoever is prepared first.
- Gap assessment this quarter
- Structured 90-day readiness path
- In line before a contract forces it
30 Minutes · No Pressure · No Obligation