Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

Understanding the CMMC Certification Lifecycle

The CMMC certification lifecycle is the complete process your organization goes through from initial assessment to renewal. Understanding this lifecycle is essential for defense contractors who need to maintain continuous eligibility for Department of Defense (DoD) contracts.

Lifecycle means the complete series of stages something goes through from beginning to end, including renewal or replacement.

Unlike a one-time compliance check, the CMMC certification lifecycle requires ongoing maintenance, annual affirmations, and periodic recertification to ensure your organization continuously protects government information.

This guide explains every stage of the CMMC certification lifecycle, including how long certifications last, what happens if they expire, and how to maintain your status throughout the three-year certification period.

Overview of the CMMC Certification Lifecycle

The CMMC certification lifecycle consists of five critical stages:

  1. Initial Assessment – Your first evaluation against CMMC requirements
  2. Conditional or Final Certification – Achieving CMMC status based on assessment results
  3. POA&M Closeout (if applicable) – Addressing deficiencies within 180 days
  4. Annual Affirmations – Yearly attestations that you maintain compliance
  5. Recertification – New assessment every 1-3 years depending on your level

The specific timeline and requirements for your CMMC certification lifecycle depend on which CMMC level you need: Level 1, Level 2, or Level 3.

Stage 1: Initial Assessment in the CMMC Certification Lifecycle

The CMMC certification lifecycle begins when you conduct your initial assessment. How this works depends on your required CMMC level.

CMMC Level 1 Initial Self-Assessment

For CMMC Level 1, the certification lifecycle starts with an annual self-assessment where your organization evaluates itself against the 15 security requirements in FAR clause 52.204-21.

FAR stands for Federal Acquisition Regulation—the primary set of rules governing all federal government purchases.

According to 32 CFR 170.15, you must:

  • Conduct the self-assessment yourself (no third-party required)
  • Score yourself using the CMMC Scoring Methodology
  • Achieve a “MET” result for ALL 15 requirements (no exceptions allowed)
  • Submit results to SPRS
  • Retain all assessment evidence for 6 years

SPRS stands for Supplier Performance Risk System—the DoD’s online database where contractors report their cybersecurity assessment scores and CMMC status.

Important: Level 1 does NOT allow Plans of Action and Milestones (POA&Ms). You must fully implement all 15 requirements before achieving CMMC Status.

CMMC Level 2 Initial Assessment

For CMMC Level 2, the CMMC certification lifecycle involves either a self-assessment or third-party certification assessment against all 110 security requirements from NIST SP 800-171 Revision 2.

NIST SP 800-171 stands for National Institute of Standards and Technology Special Publication 800-171—the federal standard for “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.”

Level 2 Self-Assessment
According to 32 CFR 170.16, you conduct your own assessment and:

  • Evaluate all 110 security requirements
  • Score yourself using the CMMC Scoring Methodology
  • Submit results to SPRS
  • Can use a POA&M for certain requirements if you score at least 80%

Level 2 Certification Assessment (C3PAO)
According to 32 CFR 170.17, a certified third-party assessor evaluates your organization:

  • A C3PAO conducts an independent assessment
  • Assessment follows NIST SP 800-171A procedures
  • Results uploaded to CMMC eMASS (automatically transfers to SPRS)
  • You receive a CMMC Assessment Findings Report
  • Can use a POA&M for certain requirements if you score at least 80%

C3PAO stands for CMMC Third-Party Assessment Organization—companies authorized by the CMMC Accreditation Body to conduct Level 2 certifications. eMASS stands for Enterprise Mission Assurance Support Service—a government system for tracking assessment results.

CMMC Level 3 Initial Certification

For CMMC Level 3, the certification lifecycle requires a government-led assessment by DCMA DIBCAC against 24 additional security requirements from NIST SP 800-172.

DCMA DIBCAC stands for Defense Contract Management Agency Defense Industrial Base Cybersecurity Assessment Center—the DoD organization that conducts all Level 3 assessments.

According to 32 CFR 170.18:

  • You must FIRST achieve Final Level 2 (C3PAO) status
  • You initiate the process by emailing DCMA DIBCAC
  • DCMA DIBCAC validates your Level 2 status and schedules assessment
  • Assessment covers all 24 Level 3 requirements
  • Can use a POA&M for certain requirements if you score at least 80%

Stage 2: Conditional vs Final Certification Status

A critical part of the CMMC certification lifecycle is understanding the difference between Conditional and Final certification status.

Final CMMC Status

Final CMMC Status means you achieved a perfect score on your assessment—all requirements fully met with no POA&M.

For Final Status:

  • Level 1: All 15 requirements MET (score of 15/15)
  • Level 2: All 110 requirements MET (score of 110/110)
  • Level 3: All 24 Level 3 requirements MET (score of 24/24)

Achieving Final Status immediately makes you eligible for contract award and starts your three-year certification period (except Level 1, which is annual).

Conditional CMMC Status

Conditional CMMC Status means you met the minimum 80% threshold but have some requirements documented in a Plan of Action and Milestones (POA&M).

Plan of Action and Milestones (POA&M) is a formal document that identifies security requirements you haven’t fully implemented yet and describes your plan to fix them, including specific milestones and target completion dates.

According to 32 CFR 170.21, for Conditional Status:

  • Minimum score: 80% of maximum points (88/110 for Level 2)
  • Certain critical requirements: MUST be fully met (cannot be in POA&M)
  • Timeline: You have 180 days to close out all POA&M items
  • Contract eligibility: You CAN win contracts with Conditional Status

Critical Point: Conditional Status is NOT inferior to Final Status for contract awards. Both statuses make you eligible to win DoD contracts.

Stage 3: POA&M Closeout in the CMMC Certification Lifecycle

If you achieve Conditional Status, the POA&M closeout becomes a critical stage in your CMMC certification lifecycle.

The 180-Day POA&M Closeout Window

According to official regulations:

  • You have exactly 180 days from your Conditional CMMC Status Date
  • You must remediate (fix) ALL requirements marked as “NOT MET”
  • You must undergo a POA&M closeout assessment to verify fixes
  • Assessment results must be posted within the 180-day window

Remediate means to fix or correct a security deficiency by implementing the required controls.

What Happens During POA&M Closeout

For Level 2 Self-Assessment:

  • You conduct your own POA&M closeout self-assessment
  • You verify all NOT MET requirements are now MET
  • You post updated results to SPRS
  • Your status changes from Conditional to Final

For Level 2 or Level 3 Certification:

  • Your C3PAO or DCMA DIBCAC conducts the closeout assessment
  • They verify all POA&M items are properly remediated
  • Results uploaded to eMASS and transferred to SPRS
  • Your status changes from Conditional to Final

What Happens If POA&M Isn’t Closed Within 180 Days

This is critical: If you don’t successfully close your POA&M within 180 days, your Conditional CMMC Status expires.

According to 32 CFR 170.17:

  • Your Conditional Status becomes invalid
  • You become ineligible for new contract awards requiring that CMMC level
  • If you have an active contract, “standard contractual remedies” apply (potential termination or cure periods)
  • You must undergo a completely new assessment to regain CMMC Status

Stage 4: CMMC Certification Validity Periods

A key aspect of the CMMC certification lifecycle is understanding how long your certification lasts.

CMMC Level 1 Certification Lifecycle Timeline

Duration: 1 year (annual)

CMMC Level 1 has the shortest certification lifecycle:

  • Self-assessment required annually (every year)
  • No three-year period—you reassess every 12 months
  • Annual affirmation required after each assessment
  • Must maintain continuous compliance

According to 32 CFR 170.15, Level 1 requires annual self-assessments to maintain eligibility.

CMMC Level 2 Certification Lifecycle Timeline

Duration: 3 years

CMMC Level 2 follows a three-year certification lifecycle:

  • Assessment (self or C3PAO) every three years
  • Annual affirmations in years 2 and 3
  • Three-year period starts from your CMMC Status Date
  • If you had a POA&M, the three years starts from your Conditional Status Date (not Final)

CMMC Status Date means the official date your CMMC Status was established, as recorded in SPRS.

This means if you achieve Conditional Level 2 status on January 1, 2026, your next full assessment is due by December 31, 2028—regardless of when you closed your POA&M.

CMMC Level 3 Certification Lifecycle Timeline

Duration: 3 years (but requires TWO separate assessments)

CMMC Level 3 has the most complex certification lifecycle:

  • Level 2 (C3PAO) assessment every three years
  • Level 3 (DIBCAC) assessment every three years
  • Both must be maintained simultaneously
  • Annual affirmations for BOTH Level 2 AND Level 3

According to 32 CFR 170.18, maintaining Level 3 Status requires:

“A Level 2 (C3PAO) certification assessment must also be conducted every three years to maintain CMMC Level 3 (DIBCAC) status.”

This means Level 3 contractors must undergo two separate assessments every three years to maintain their status.

Stage 5: Annual Affirmations in the CMMC Certification Lifecycle

Annual affirmations are a required maintenance activity throughout your CMMC certification lifecycle.

What is a CMMC Affirmation?

A CMMC affirmation is a formal attestation by your Affirming Official that your organization continues to comply with all security requirements for your CMMC level.

Affirming Official means a senior-level representative from your organization who has the authority to attest to your company’s continuing compliance with CMMC requirements.

According to 32 CFR 170.22, affirmations must be submitted in SPRS and include attestation that you maintain continuous compliance.

When Affirmations Are Required

Level 1 Affirmations:

  • After completing each annual self-assessment
  • Every year (annual basis)

Level 2 Affirmations:

  • Immediately after initial assessment
  • At POA&M closeout (if applicable)
  • Annually following your Final CMMC Status Date
  • Must continue for all three years of certification

Level 3 Affirmations:

  • Immediately after initial Level 3 assessment
  • At POA&M closeout (if applicable)
  • Annually for BOTH Level 2 AND Level 3 Status
  • Must maintain both affirmations for three years

Example: If you achieve Final Level 2 status on March 15, 2026, you must submit affirmations on or before:

  • March 15, 2027 (Year 2)
  • March 15, 2028 (Year 3)
  • March 15, 2029 (New assessment due)

What Happens If You Miss an Affirmation

Missing your annual affirmation has serious consequences:

  • Your CMMC Status may become invalid
  • You may be ineligible for new contract awards
  • Contracting officers verify affirmation status before awards
  • Could trigger contract compliance issues

The affirmation is not just a formality—it’s a legal attestation that your Affirming Official is personally certifying your organization’s compliance. False affirmations could result in False Claims Act liability.

False Claims Act is a federal law that imposes liability on individuals and companies who knowingly submit false claims to the government or make false statements material to those claims.

Stage 6: Recertification in the CMMC Certification Lifecycle

The final stage of the CMMC certification lifecycle is recertification—the process of renewing your CMMC Status for another period.

CMMC Level 1 Recertification

Frequency: Annual

Level 1 recertification is straightforward:

  • Conduct a new self-assessment every year
  • Submit results to SPRS
  • Submit new affirmation
  • Essentially repeats the initial assessment process annually

CMMC Level 2 Recertification

Frequency: Every 3 years

Level 2 recertification occurs three years after your CMMC Status Date:

  • Schedule new assessment (self or C3PAO as required)
  • Complete full reassessment of all 110 requirements
  • Can again use POA&M if needed (Conditional Status)
  • Submit new affirmation
  • Starts a new three-year cycle

Important: Your recertification date is based on your original CMMC Status Date, NOT when you closed your POA&M. This ensures consistent three-year cycles.

CMMC Level 3 Recertification

Frequency: Every 3 years (TWO assessments)

Level 3 recertification is the most complex:

  • First, complete Level 2 (C3PAO) recertification
  • Then, schedule Level 3 (DIBCAC) recertification with DCMA DIBCAC
  • Must maintain both certifications simultaneously
  • Must affirm both levels annually

According to the regulations, you cannot maintain Level 3 Status without also maintaining a current Level 2 (C3PAO) certification.

Maintaining Compliance Throughout the CMMC Certification Lifecycle

Achieving CMMC certification is just the beginning. Maintaining your status requires continuous effort:

Daily Security Practices

  • Implement and maintain all required security controls
  • Monitor systems for security incidents
  • Keep security policies and procedures current
  • Train employees on security requirements
  • Document changes to your environment

Ongoing Documentation

  • Maintain System Security Plans (SSPs)
  • Update POA&Ms as needed
  • Retain assessment artifacts for 6 years
  • Document system changes
  • Track security incidents and responses

System Security Plan (SSP) is a formal document that describes how your organization implements security requirements and protects information systems.

Continuous Monitoring

  • Monitor compliance with security requirements
  • Conduct internal audits
  • Review and update security controls
  • Address new vulnerabilities
  • Prepare for annual affirmations

System Changes and CMMC UIDs

If you make significant changes to your information systems during your certification period:

  • New systems may need new CMMC UIDs
  • You must report changes to contracting officers
  • Significant changes may require reassessment
  • Always maintain documentation of changes

CMMC UID stands for CMMC Unique Identifier—a 10-character alphanumeric code assigned to each assessed information system and tracked in SPRS.

What Happens When CMMC Certifications Expire

Understanding expiration is critical to managing your CMMC certification lifecycle.

Level 1 Expiration

Level 1 Status expires if you:

  • Fail to conduct your annual self-assessment
  • Miss your annual affirmation
  • Fail to achieve all 15 requirements MET

Result: You’re ineligible for new contracts requiring Level 1 until you complete a new assessment.

Level 2 Expiration

Level 2 Status expires if you:

  • Fail to complete recertification within three years of CMMC Status Date
  • Fail to submit annual affirmations
  • Don’t close POA&M within 180 days (for Conditional Status)
  • Experience major security incidents that compromise compliance

Result: You’re ineligible for new contracts requiring Level 2 and may face contractual remedies on existing contracts.

Level 3 Expiration

Level 3 Status expires if you:

  • Fail to maintain Level 2 (C3PAO) certification
  • Fail to complete Level 3 recertification within three years
  • Fail to submit annual affirmations for both Level 2 and Level 3
  • Don’t close POA&M within 180 days

Result: You’re ineligible for new contracts requiring Level 3.

CMMC Certification Lifecycle Best Practices

To successfully navigate your CMMC certification lifecycle:

1. Plan Ahead

  • Start preparation 6-12 months before needed
  • Budget for initial certification and ongoing maintenance
  • Schedule recertification before expiration

2. Use a Compliance Calendar

  • Track your CMMC Status Date
  • Set reminders for annual affirmations
  • Note recertification deadlines
  • Plan for POA&M closeout milestones

3. Consider a CMMC Registered Provider Organization (RPO)

  • RPOs help prepare for assessments
  • Provide ongoing compliance support
  • Help maintain documentation
  • Assist with recertification planning

CMMC Registered Provider Organization (RPO) is a company authorized to provide CMMC preparation and advisory services to help contractors achieve certification.

4. Maintain Continuous Documentation

  • Don’t wait until assessment time
  • Keep evidence current throughout the lifecycle
  • Document all security controls and processes
  • Retain artifacts for 6 years minimum

5. Treat Affirmations Seriously

  • Review compliance before affirming
  • Ensure your Affirming Official understands the responsibility
  • Document the basis for affirmation
  • Address any gaps before affirming

Key Takeaway: Mastering Your CMMC Certification Lifecycle

The CMMC certification lifecycle is not a one-time event but an ongoing process requiring continuous attention and maintenance. Understanding each stage—from initial assessment through conditional or final certification, POA&M closeout, annual affirmations, and recertification—is essential for maintaining your eligibility to win and keep DoD contracts.

Remember these critical lifecycle facts:

✓ Level 1 certifications last 1 year (annual)
✓ Level 2 and 3 certifications last 3 years
✓ POA&M must be closed within 180 days or Conditional Status expires
✓ Annual affirmations are mandatory to maintain eligibility
✓ Recertification is required at the end of each validity period
✓ Missing deadlines results in loss of contract eligibility

Start planning your CMMC certification lifecycle strategy now. Success requires understanding not just how to achieve certification, but how to maintain it year after year.


Related Articles:

Official Sources: This article is based on 32 CFR Part 170 “Cybersecurity Maturity Model Certification Program” (effective December 16, 2024), specifically sections 170.15-170.18 (assessment requirements), 170.21 (POA&M requirements), and 170.22 (affirmation requirements), published by the Department of Defense.

Table of Contents