- CMMC Certification: How to Get Your Organization Certified
- What Is CMMC Certification?
- Who Needs CMMC Certification
- The Three CMMC Certification Levels
- How to Get CMMC Certified
- How Long CMMC Certification Takes, How Long It Lasts, and Its 2026 Status
- Getting Help: Certification Services, C3PAOs, and Consultants
- How to Simplify CMMC Certification
- Key Takeaways
- CMMC Certification FAQs
CMMC Certification: How to Get Your Organization Certified
CMMC certification is the formal determination that a U.S. Department of Defense (DoD) contractor has implemented the cybersecurity controls required for its assigned CMMC level. CMMC stands for Cybersecurity Maturity Model Certification, a DoD program codified in 32 CFR Part 170, a final rule effective December 16, 2024.
- CMMC Level 1 uses an annual self-assessment.
- CMMC Level 2 can be self-assessed or assessed by an accredited third party called a CMMC Third-Party Assessment Organization (C3PAO).
- CMMC Level 3 is assessed by the government’s DIBCAC, the Defense Contract Management Agency’s assessment center.
However, as of mid-2026, the third-party certification path remains paused. On July 13, 2026, the Department of Defense suspended the phase that would have required accredited third-party assessments, and the interim rule asks contractors for self-assessments instead.
This guide explains what CMMC certification is, who needs it, the levels an organization can be certified at, the steps to get there, and how long it takes and lasts. For the full program overview, see the complete guide to CMMC.
What Is CMMC Certification?
CMMC certification is how the Department of Defense confirms that a contractor has met its contractual cybersecurity requirements. The Cybersecurity Maturity Model Certification (CMMC) program ties each contract to one of three levels. Each DoD contractor must reach the required level before it can win or keep that work.
What is CMMC certification? It is the proof a defense contractor shows the Department of Defense that its systems meet the cybersecurity rules for the kind of government information it handles. Contractors check themselves at Level 1, and an outside assessor or the government checks the higher levels.
CMMC sits inside the Department of Defense’s acquisition process. When a contract involves sensitive but unclassified government information, the solicitation names a required CMMC level, and a contractor has to show it meets that level’s controls to be eligible for the award. The certification is the record of that demonstration, scoped to the exact requirements the level carries.
The name covers two different things. The Cybersecurity Maturity Model Certification is the program and model the DoD publishes; a CMMC certification is the individual determination that one organization meets its assigned level. That determination is either self-attested by the contractor or issued by an accredited assessor, recorded so a contracting officer can verify it, and kept current over time through annual affirmations.
When scoping a CMMC assessment, many teams can reuse the compliance work they already have. The CMMC Multi-Framework Crosswalk maps CMMC and NIST SP 800-171 controls to NIST 800-53 and other common frameworks.
Who Needs CMMC Certification
CMMC certification applies to Department of Defense contractors and subcontractors across the Defense Industrial Base (DIB) that handle sensitive government information. The DIB is the network of companies that supply the U.S. military, one of the nation’s 16 critical infrastructure sectors. Providers of commercial off-the-shelf (COTS) products are excepted.
Two data types decide who needs certification and at what level. Federal Contract Information (FCI) is information not intended for public release that the government provides, or that is generated for the government under a contract. Controlled Unclassified Information (CUI) is information a law, regulation, or government-wide policy requires to be safeguarded, as the National Archives explains.
The required level follows the data in the contract. FCI maps to Level 1, CUI maps to Level 2, and the most sensitive CUI programs map to Level 3.
External service providers (ESPs) can also fall inside the assessment. An ESP that stores, processes, or transmits a contractor’s CUI or Security Protection Data is part of that contractor’s assessment scope under 32 CFR §170.19(c).
The Three CMMC Certification Levels
CMMC has three certification levels, and what an organization gets certified against changes at each one. The levels are cumulative, so each builds on the requirements below it, as the DoD’s official CMMC Model Overview lays out across the program’s 14 security domains.
| Level | Protects | Control basis | How it’s assessed |
|---|---|---|---|
| Level 1 | FCI | 15 basic safeguarding requirements from FAR 52.204-21 | Annual self-assessment |
| Level 2 | CUI | 110 requirements of NIST SP 800-171 Rev 2 | Self-assessment or C3PAO assessment |
| Level 3 | Highest-priority CUI programs | Selected NIST SP 800-172 enhanced requirements | Government assessment (DIBCAC) |
Level 1 relies on an annual self-assessment against 15 safeguarding requirements drawn from the Federal Acquisition Regulation clause FAR 52.204-21. Level 2 covers CUI and maps to the 110 requirements of NIST SP 800-171 Rev 2, which a contract can require be met through a self-assessment or an accredited C3PAO assessment. Level 3 is reserved for the highest-priority programs, adding selected enhanced requirements from NIST SP 800-172 on top of the Level 2 baseline, and is assessed by the government’s DIBCAC.
CMMC pins Level 2 to NIST SP 800-171 Rev 2, even though NIST withdrew Rev 2 on May 14, 2024 and replaced it with Rev 3. The correct term is “NIST SP 800-171 Rev 2.” Building to Rev 3 does not satisfy CMMC Level 2, which 32 CFR §170.14 pins to Rev 2. Level 3’s enhanced requirements follow the same logic: NIST finalized SP 800-172 Rev 3 on May 13, 2026, but a program tracks the version the CMMC rule names rather than the newest NIST edition.
Organizational CMMC certification differs from individual credentials such as the Certified CMMC Professional (CCP) and Certified CMMC Assessor (CCA), which are held by the people who staff assessments.
How to Get CMMC Certified
Getting CMMC certified follows an ordered path from scoping to affirmation.
- Determine the required level. Read the contract to see whether it involves FCI or CUI, which sets the level the organization must reach.
- Define the CMMC Assessment Scope. Identify every asset, user, and system that handles FCI or CUI, because scope decides what the assessment covers.
- Gap-assess against the level’s requirements. Measure the current state against the applicable control set for the target level.
- Remediate and document. Close the gaps, then record the environment in a System Security Plan (SSP) and track open items in a Plan of Action and Milestones (POA&M).
- Submit a score to SPRS. Post the self-assessment score to the Supplier Performance Risk System (SPRS), the DoD database of contractor scores, per [DFARS 252.204-7021].
- Complete the assessment. Run a self-assessment for Level 1 and Level 2 (Self), engage a C3PAO for Level 2 (Third-Party), or work with DIBCAC for Level 3.
- Maintain the status with an annual affirmation. File the annual affirmation of continuous compliance and keep the evidence current.
Level 2 allows a conditional result. A contractor that scores at least 88 of 110, or 80 percent, can pass conditionally with the open items recorded on a POA&M, which must close within 180 days. Whether a self-assessment suffices or a C3PAO assessment is required depends on the CUI the contract involves.
A crosswalk speeds up the gap assessment in step 3. The CMMC Multi-Framework Crosswalk lines up CMMC, NIST SP 800-171, and NIST 800-53 requirements side by side, so teams can see which existing controls already satisfy CMMC.
How Long CMMC Certification Takes, How Long It Lasts, and Its 2026 Status
How long CMMC certification takes depends on an organization’s starting security posture and its level, so the honest answer is a range. Common planning ranges look like this:
- Level 1: roughly 30 days to 4 months.
- Level 2: commonly 6 to 12 months of readiness work.
- Level 3: 18 to 24 months or more, after Level 2 is in place.
The largest variable is the remediation needed to close gaps against the controls. Level 2 and Level 3 certifications are valid for three years. Between assessments, a contractor files an annual affirmation in SPRS confirming continued compliance with the NIST SP 800-171 requirements. Level 1 is an annual self-assessment plus an annual affirmation.
On July 13, 2026, the Department of Defense suspended CMMC Phase II, the phase that would have required C3PAO third-party assessments and was previously slated for November 10, 2026. The suspension opened a 60-day reform review. The C3PAO Level 2 third-party designations and the DIBCAC Level 3 designations are paused. In the interim, the DoD requires only Level 1 and Level 2 self-assessments as a condition of a new award, not a C3PAO certification.
Three assessment paths sit behind these rules. A self-assessment is run by the contractor. A C3PAO certification is issued by an accredited third party. A DIBCAC assessment is run by the government. During the suspension, the third-party and government paths are paused, and the self-assessment carries the interim obligation.
The suspension did not remove the underlying requirement. Contractors handling CUI must still implement NIST SP 800-171 Rev 2 under the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which remains in force. The pre-suspension pace was slow: as of October 2025, only 431 organizations held a final Level 2 status. In its report on the CMMC final rule, the Government Accountability Office cited DoD’s own estimate that the program would cost the Defense Industrial Base roughly $4.0 to $4.2 billion a year.
Getting Help: Certification Services, C3PAOs, and Consultants
Several kinds of organizations help contractors get certified, and the differences between them matter. Only an accredited C3PAO can conduct a Level 2 certification assessment and issue the result through the government’s Enterprise Mission Assurance Support Service (eMASS), following the four-phase CMMC Assessment Process (CAP) that the Cyber AB maintains for C3PAOs. An independence rule under 32 CFR Part 170 blocks a C3PAO from assessing an organization it also consulted for.
A consultant, often a Cyber AB Registered Provider Organization (RPO) staffed with Registered Practitioners (RPs), helps a contractor prepare. That work covers scoping, authoring the SSP, running a gap assessment, remediation, and packaging evidence. A consultant cannot issue a Certificate of CMMC Status. The common pattern follows from those rules: engage an RPO or consultant to get ready, then bring in a separate C3PAO to assess.
How to Simplify CMMC Certification
Simplifying CMMC certification comes down to keeping the readiness work in one connected system. The self-assessment, the evidence behind each answer, and the open gaps are the same underlying data, so holding them in one workspace makes each annual affirmation and audit-ready package repeatable.
With Isora GRC, the GRC Assessment Platform™, security teams get one workspace to run the full readiness process. Use Questionnaires & Surveys to complete a framework-aligned CMMC self-assessment and attach evidence directly to each answer — no separate spreadsheet, no reassembly at audit time. Use Risk Management to turn each gap into a tracked item with full context already attached, so the Plan of Action and Milestones builds as the work progresses.
See how Isora GRC supports CMMC readiness →
Key Takeaways
CMMC certification is the DoD’s formal determination that a contractor has implemented the controls required for its level, and how it is granted depends on that level. As of July 2026, Phase I self-assessment is active while the C3PAO and DIBCAC certification paths are paused pending a reform review. For now, the next move is to build and hold the NIST SP 800-171 Rev 2 posture and the evidence behind it.
Which level applies follows the information in the contract: FCI maps to Level 1, CUI to Level 2, and the most sensitive CUI programs to Level 3. The requirement to protect that information under DFARS 252.204-7012 remains in force through the suspension, so the contractors that keep their scoping, self-assessment, and evidence current are the ones ready to move when the third-party path resumes.
See the GRC Assessment Platform™ in action →
CMMC Certification FAQs
What Is CMMC Certification?
CMMC certification is a formal determination that a Department of Defense contractor has implemented the cybersecurity controls required for its CMMC level. It is part of the Cybersecurity Maturity Model Certification program, codified in 32 CFR Part 170 (effective December 16, 2024). How the determination is made depends on the organization’s level: Level 1 uses an annual self-assessment, while Level 2 and Level 3 are assessed by an accredited third party (a C3PAO) or the government (DIBCAC).
How to Get CMMC Certified?
An organization determines the level its contracts require, defines its assessment scope, gap-assesses against that level’s requirements, then remediates and documents the results in a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M). It submits a score to the Supplier Performance Risk System (SPRS) and completes the assessment — a self-assessment for Level 1 and Level 2 (Self), or a C3PAO assessment for Level 2 (Third-Party). It then keeps the status current with an annual affirmation.
Who Needs CMMC Certification?
CMMC applies to Department of Defense contractors and subcontractors across the Defense Industrial Base that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI); providers of commercial off-the-shelf (COTS) products are excepted. The level an organization needs is set by the type of information its contract involves — FCI maps to Level 1, CUI to Level 2, and the most sensitive CUI programs to Level 3. External service providers that handle a contractor’s CUI can fall within its assessment scope.
How Long Does CMMC Certification Take?
It depends on an organization’s starting security posture and level, so it is best expressed as a range. Organizations often plan roughly 30 days to 4 months for Level 1, 6 to 12 months of readiness work for Level 2, and 18 to 24 months or more for Level 3 (which requires reaching Level 2 first). The largest variable is the remediation work needed to close gaps against the controls.
How Long Is a CMMC Certification Valid?
Level 2 and Level 3 certifications are valid for three years. In between, contractors must submit an annual affirmation in SPRS confirming continued compliance with the NIST SP 800-171 requirements. Level 1 is an annual self-assessment plus an annual affirmation.
Is CMMC Certification Still Required in 2026?
The rollout changed in 2026. On July 13, 2026, the Department of Defense suspended CMMC Phase II and paused C3PAO (Level 2 third-party) and DIBCAC (Level 3) certification designations while a 60-day reform review runs. In the interim, the DoD requires only Level 1 and Level 2 self-assessments as a condition of a new award — but the underlying requirement to implement NIST SP 800-171 Rev 2 under DFARS 252.204-7012 remains in force.
What Is the Difference Between a CMMC Self-Assessment and a CMMC Certification?
A self-assessment is when an organization evaluates its own controls and submits the score to SPRS; a certification (for Level 2 Third-Party or Level 3) is a determination made by an accredited C3PAO or by the government (DIBCAC). Level 1 and, in some cases, Level 2 allow self-assessment; higher-sensitivity CUI programs require a third-party or government assessment. During the 2026 Phase II suspension, only self-assessments are required for new awards.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.