URGENT — ACTION REQUIRED

CMMC Phase 2 Deadline
November 10, 2026

C3PAO assessment slots are filling 3–6 months out. If you're handling CUI on DoD contracts, the real deadline to START is right now — not November.

NOV 102026
Phase 2 Enforcement — No Self-Attestation, No Extensions
80K+
Contractors need CMMC cert
<800
Currently certified
6
Months typical C3PAO wait
$0
Fines — but you lose contracts

The Deadline: What November 2026 Actually Means

CMMC Phase 2 enforcement begins November 10, 2026. This is not an estimate — it's the hard date in 32 CFR Part 170. After this date, DoD contracting officers must reject bids from contractors who don't hold a valid CMMC Level 2 certificate.

CMMC Level 2 requires third-party certification by an authorized C3PAO (Certified Third-Party Assessment Organization). Self-attestation is no longer accepted. You cannot buy your way past this. You cannot get a waiver by asking nicely. The only path to eligibility is a C3PAO assessment and a certificate in eMASS.

What changed at Phase 2

Phase 1 (now): Self-attestation for Level 1 and a subset of Level 2. Phase 2 (November 2026): C3PAO assessment required for all Level 2 contractors. Phase 3 (November 2027): Full CMMC Model 2.0 requirements, including all DOMAINs.

The CMMC Final Rule was published December 26, 2023 — the three-year phase-in window is already more than halfway through. DoD agencies are already embedding hard-gate CMMC Level 2 requirements into solicitations. NAVAIR, NAVFAC Southwest, and other major commands have added November 2026 gates to 2025–2026 contract actions. This is not theoretical.


The C3PAO Slot Crisis: Why "I'll Start in Fall" Is Already Too Late

There are approximately 70 authorized C3PAOs as of 2026. Demand has outstripped supply since the rule finalized — typical scheduling wait times are 3–6 months. Organizations with complex environments (multiple sites, regulated data, legacy systems) can wait 6–9 months just for the assessment phase to begin.

The math is brutal: if you start your readiness prep today (May 2026), you might finish in 3–4 months. But if you wait until July to book a C3PAO, you're looking at October or November before assessment even starts — past the enforcement date.

MAY 2026 — RIGHT NOW
Book your C3PAO assessment slot
C3PAOs are booking 3–6 months out. The window to book and complete assessment before November is open — barely.
JUN–JUL 2026
Begin gap assessment and remediation
Fix MFA, audit logging, SSP documentation, incident response plan, CUI data flows. This takes 6–10 weeks minimum.
AUG–SEP 2026
C3PAO pre-assessment review
Internal mock assessment against NIST 800-171 Rev 2. Identify and close remaining gaps before the real assessment.
OCT–NOV 2026
C3PAO official assessment
Assessors on-site (or remote). 2–8 week engagement. Results submitted to eMASS. Certificate issued.
Hard reality

If you haven't started your C3PAO booking process by July 2026, the math against the November 2026 deadline does not work. The assessment wait alone is 3–6 months. Start now or plan for a gap in DoD contract eligibility.


Your Status in 3 Minutes

The fastest way to understand where you stand is our free CMMC Level 2 Readiness Assessment. Ten questions covering your current security posture, CUI handling, SPRS score, and documentation status. You'll get an immediate score and a prioritized gap list.

CMMC Level 2 Readiness Assessment
10 questions · 3 minutes · Immediate results
Check My CMMC Readiness
No account required. Results stored locally.

After the assessment, you'll know your gaps vs. NIST 800-171 Rev 2 (the 110 practices that C3PAOs assess against). You'll also get a recommended path based on your SPRS score and organizational complexity.


What Happens If You Miss It

Missing the CMMC Level 2 deadline doesn't come with a fine. It comes with a three-pronged business crisis:

1. Contract Ineligibility

Contracting officers are required to verify CMMC certificate status before award for covered contracts. If you don't have a Level 2 certificate in eMASS by November 2026, your bid will be rejected. Full stop. This isn't a warning — it's a contract requirement in DFARS 252.204-7021.

2. Supply Chain Ejection

Prime contractors who flow CUI to subcontractors are responsible for verifying those subcontractors' CMMC status. Once Phase 2 enforcement is active, primes will not risk their own contract eligibility by sourcing from uncertified subs. Expect to be quietly removed from subcontractor rosters — or asked to produce a certificate before project award.

3. Revenue Gap with No Cure Period

There is no grace period or cure provision in the current rule. If you're not certified on November 10, 2026, you are ineligible until you are certified. DoD work that represented 40–100% of your revenue becomes inaccessible — and competitors who are certified will fill those contracts in your absence.

No cure period

Unlike some compliance frameworks that allow a remediation window after the deadline, CMMC Phase 2 enforcement has no cure provision in the current rule. You are either certified or you cannot bid. Plan accordingly.


The 5-Step Path From Today to Certified

Every contractor that achieves CMMC Level 2 follows this same five-step sequence. The timeline and cost vary by starting posture — but the steps don't change.

1

Gap Assessment

Inventory your environment against NIST 800-171 Rev 2's 110 practices. Identify what's in place, what's partial, what's missing. Produce a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M). Typically 2–6 weeks.

2

Policy Writing & Documentation

Write the policies and procedures your SSP describes. Access control, audit logging, media protection, incident response, personnel security — each control family needs documented practice. Typically 4–10 weeks for first-timers.

3

Technical Implementation

Deploy the technical controls: MFA for all users, FIPS 140-2 validated encryption, endpoint detection, audit log collection, network segmentation for CUI systems, patch management. Typically 3–8 months depending on your starting point.

4

C3PAO Pre-Audit

Engage a C3PAO for a pre-assessment or gap review (separate from the formal assessment). Identify what will fail before the real assessors arrive. Fix the findings. This step is optional but highly recommended — it catches showstoppers.

5

C3PAO Assessment & Certification

Official assessment by an authorized C3PAO. Assessors review your SSP, POA&M, evidence of controls, and interview staff. 2–8 week engagement. Results go to eMASS. Certificate issued for 3 years.

Average total timeline: 6–18 months from Day 1 to certificate. Average total cost for SMBs: $40,000–$120,000 including assessment fees, readiness work, and tools.

Contractors starting with a SPRS score above 80 and existing SSP documentation can significantly compress both timeline and cost. Contractors starting from scratch with no policies or technical controls should plan for the upper end of both ranges.

Tip

The most common mistake is starting with implementation before doing the gap assessment. You'll spend money on controls you don't need and miss ones you do. Run our 3-minute readiness assessment first — it gives you the prioritized gap list to focus your investment.


C3PAO Booking Guide: Find, Vet, and Book the Right Assessor

C3PAOs are authorized by the CMMC Accreditation Body (CMMC AB). You must use a registered C3PAO — a random cybersecurity firm or consultant cannot conduct your CMMC assessment. The CMMC AB Marketplace is the official registry of authorized C3PAOs.

How to Find a C3PAO

  1. Go to the CMMC AB Marketplace — this is the only official list
  2. Filter by your NAICS code and organization size to narrow results
  3. Contact 3–5 C3PAOs simultaneously — demand is high, availability varies widely
  4. Ask for a scoping call before booking — a quality C3PAO will discuss your environment before providing a quote

What C3PAO Assessment Costs

Organization Size Typical Assessment Cost Assessment Duration
Small (1–50 employees, simple scope) $25,000–$40,000 2–3 weeks
Mid-size (50–250 employees, multiple sites) $40,000–$65,000 3–5 weeks
Large (250+ employees, complex environment) $65,000–$100,000+ 5–8 weeks

Pre-assessment / gap review services (optional but recommended) typically add $5,000–$15,000. These are separate from the formal assessment fee.

What to Look for in a C3PAO

Watch out

Beware of C3PAOs who guarantee a pass. C3PAOs cannot guarantee outcomes — the assessment is independent. Anyone promising a guaranteed certificate is either lying or violating CMMC AB rules. A legitimate C3PAO will tell you your current posture, give you a gap list, and assess against the standard honestly.


Frequently Asked Questions

CMMC Phase 2 enforcement begins November 10, 2026. This is when DoD contract solicitations begin requiring CMMC Level 2 certification at award for contractors who handle Controlled Unclassified Information (CUI). The CMMC Final Rule (32 CFR Part 170) was published December 26, 2023, initiating a three-year phased rollout. Phase 1 (self-attestation) is already in effect. Phase 2 (November 10, 2026) requires third-party certification from an authorized C3PAO. Hard-gate enforcement has already appeared in agency solicitations — NAVAIR and NAVFAC Southwest embedded November 2026 CMMC Level 2 requirements in 2025. VERIFIED
CMMC Level 1 (self-attestation) applies to contractors who handle Federal Contract Information (FCI) but NOT Controlled Unclassified Information (CUI). CMMC Level 2 (third-party C3PAO assessment) applies to contractors who process, store, or transmit CUI on DoD contracts. If your contracts contain DFARS clause 252.204-7012 and involve CUI, you need Level 2. Most defense contractors handling drawings, specifications, PII, ITAR-controlled data, or any CUI require Level 2. The trigger is CUI handling, not company size. VERIFIED
The total timeline from starting prep to certificate is 6–18 months, depending on your current posture. Organizations with a SPRS score above 80 and existing System Security Plan can realistically complete in 6–9 months. Organizations starting from a low SPRS score (below 50) should plan 12–18 months. The C3PAO assessment itself takes 2–8 weeks. The critical bottleneck: C3PAO scheduling wait times are 3–6 months. The latest you can START and still have a certificate before November 2026 is approximately right now — May–June 2026. AI-GENERATED
CMMC Level 2 certification costs vary significantly by organization size and readiness posture. C3PAO assessment fees: $25,000–$75,000 depending on complexity, number of assessors, and organization size. Large organizations with complex environments can pay $100,000+. Readiness/preparation costs: $15,000–$80,000 for gap assessment, SSP documentation, policy writing, technical implementation, and remediation. Tools and infrastructure: MFA, SIEM, endpoint protection, patch management — $5,000–$30,000 for SMBs. Total cost range for most SMBs: $40,000–$120,000. VERIFIED
A C3PAO (Certified Third-Party Assessment Organization) is a private sector firm authorized by the CMMC Accreditation Body (CMMC AB) to conduct CMMC Level 2 assessments of defense contractors. C3PAOs are trained, certified, and registered with DoD. They send assessors to your facility to verify your compliance with NIST SP 800-171 Rev 2 (110 practices). You cannot choose a random cybersecurity firm — it must be a registered C3PAO. As of 2026, approximately 70 C3PAOs are authorized, but demand far exceeds supply — slots fill 3–6 months out. VERIFIED
No. Self-attestation for Level 2 ended with Phase 1. After November 10, 2026, CMMC Level 2 requires formal third-party assessment by an authorized C3PAO. There is no workaround. Some contractors ask about 'Plan of Action' waivers or conditional awards — these are extremely limited and require senior DoD approval. The requirement is unambiguous: Level 2 = C3PAO assessment. If you do not have a certificate, you are not eligible for new covered contracts. VERIFIED
Three cascading consequences: (1) Contract ineligibility — contracting officers must reject proposals from uncertified contractors for covered acquisitions. (2) Supply chain ejection — prime contractors cannot legally flow CUI to uncertified subcontractors. If your prime implements hard-gate requirements, you will be removed from their supply chain. (3) Revenue loss — for many contractors, DoD work represents 50–100% of revenue. Missing this deadline means losing the ability to bid on DoD contracts — with no grace period. VERIFIED
NIST SP 800-171 is the security framework — 110 practices across 14 domains for protecting CUI. CMMC is the certification program that verifies you are actually implementing 800-171. Think of it as: NIST 800-171 = what you need to do; CMMC = proof you did it, verified by a third party. CMMC Level 2 requires full compliance with NIST 800-171 Rev 2. You cannot achieve CMMC Level 2 without also being compliant with NIST 800-171. The DoD self-assessment (SPRS score) is based on NIST 800-171. CMMC is the third-party verification of the same controls. VERIFIED

The Deadline Is Fixed.
Your Readiness Is Not.

3 minutes to know your score. 5 steps to get certified. No excuse to miss November 2026.

Check My CMMC Readiness Get My RFP Match Report