Skip to main content
← Insights
Analysis· 5 min read

CMMC Phase 2 readiness — a 90-day plan (updated: Phase 2 now suspended pending review)

Phase 1 self-assessment rules have appeared in DoD solicitations since November 2025. DoD suspended the Phase 2 C3PAO requirement on July 13, 2026 pending a 60-day review — the self-assessment and SPRS score requirement is unchanged.

Update, July 13, 2026: DoD suspended CMMC Phase 2 (the third-party C3PAO-assessment requirement, previously set for November 10, 2026) pending a 60-day review — see the current status for what changed and what still applies. The plan below remains the right sequence: it front-loads the self-assessment, SSP, and POA&M work that stays required today regardless of when (or whether) third-party assessment resumes.

The CMMC rollout is no longer theoretical. Under the CMMC Program rule (32 CFR 170), Phase 1 has been live since November 10, 2025 — contracting officers can include the self-assessment and affirmation requirements in new solicitations. Phase 2 — a C3PAO-assessed Level 2 certificate as the default condition of award for contracts involving CUI — was scheduled to begin November 10, 2026, but is now suspended pending the review above.

The math was already unforgiving before the suspension: C3PAO assessment waitlists run 6–9 months and growing, and only about 1,391 of the roughly 80,000 contractors who need Level 2 had been certified as of the May 2026 Cyber AB town hall. If CUI touches your contracts, this work still matters — primes can require certification on their own timeline independent of the federal rollout, and DIBCAC continues auditing self-assessed SPRS scores. The only part you control is whether you start before the assessor calendars fill.

Here is a 90-day plan that front-loads the work that gates everything else.

Days 1–7: Know your real number

You cannot plan against a score you are guessing at. Run the free Muster Score self-assessment under the DoD Assessment Methodology to see where you stand across all 110 NIST SP 800-171 requirements, with the weighted 5/3/1-point deductions applied. There is no signup, and you describe your environment rather than uploading its contents, so no CUI enters the tool.

Days 8–30: Triage every gap

Sort your gaps into two buckets: POA&M-eligible versus must-fix-first. Most 1-point items can sit on a Plan of Action & Milestones for up to 180 days, and a short list of requirements never can. The full POA&M eligibility rules cover the 88-point conditional minimum, the six never-eligible requirements, and the 3.13.11 exception, and they decide what you can defer and what you must close before an assessment.

Days 31–60: Draft the SSP and close must-fix gaps

Requirement 3.12.4 is the gate: without a current System Security Plan, no assessment can be completed at all, and it can never sit on a POA&M. Start your System Security Plan now, because it is the single longest-lead artifact, and close the must-fix gaps your triage surfaced.

Days 61–90: Get in the queue

Book your C3PAO while there is still calendar in 2026–2027, and finalize a POA&M that closes every remaining open item inside the 180-day window. See the full Phase 2 timeline for the per-phase detail.

One caveat runs through all of this: what you produce are drafts you review, approve, and attest to. Muster doesn't certify you, and doesn't attest for you — the judgment stays yours, which is what keeps you clear of False Claims Act trouble.

Know your real SPRS score. Free, no signup.

Get your free Muster Score