Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

Steps to CMMC certification

What are the steps to CMMC Certification

Getting CMMC certified doesn’t happen by accident. It requires deliberate action, proper preparation, and a clear understanding of the process from start to finish.

This guide breaks down the steps to CMMC certification into a clear sequence you can follow. Whether you’re pursuing Level 1, Level 2, or Level 3, you’ll understand exactly what happens at each stage and what you need to do to succeed.

The CMMC Certification Process at a Glance

Before diving into details, here’s the high-level certification process:

Level 1 Certification:

  1. Implement 15 security practices
  2. Conduct self-assessment
  3. Submit score to SPRS
  4. Affirm compliance annually

Level 2 Certification:

  1. Implement 110 security requirements
  2. Develop System Security Plan and documentation
  3. Submit SPRS score
  4. Schedule C3PAO assessment (for most contractors)
  5. Complete third-party assessment
  6. Receive certification
  7. Maintain compliance and recertify every three years

Level 3 Certification:

  1. Achieve Level 2 certification first
  2. Implement enhanced NIST SP 800-172 requirements
  3. Complete DIBCAC government-led assessment
  4. Receive certification
  5. Maintain compliance and recertify every three years

Now let’s walk through each step in detail.

Step 1: Confirm Your Required CMMC Level

Your first step is confirming exactly which CMMC level you need. This determines everything else about your certification journey.

Check your contracts for DFARS clauses. Look for these specific clauses that indicate your requirements:

DFARS 252.204-7012 means you handle Controlled Unclassified Information and likely need Level 2.

DFARS 252.204-7021 explicitly states CMMC requirements and specifies the required level.

DFARS 252.204-7019 and 7020 address NIST SP 800-171 assessment requirements.

Contact your contracting officer. If contracts don’t clearly specify, ask directly. As CMMC enforcement expands through 2025, solicitations will explicitly state required levels.

Consider your prime contractor requirements. If you’re a subcontractor, your prime may require specific CMMC levels regardless of direct government contract language. Primes are responsible for ensuring their supply chain meets requirements.

Think about future contracts. What work do you want to pursue? If future opportunities involve CUI, prepare for Level 2 now rather than scrambling later.

Most contractors fall into these categories:

Contractors handling only Federal Contract Information need Level 1.

Contractors handling Controlled Unclassified Information need Level 2.

Contractors working on critical national security programs with the most sensitive CUI may need Level 3.

Step 2: Define Your Assessment Scope

Scope determines which systems, people, and locations your certification covers. Proper scoping is essential because it directly impacts your implementation effort, assessment cost, and ongoing maintenance burden.

Identify your information assets. Document where FCI and CUI exist in your organization:

  • File servers and network shares
  • Email systems
  • Cloud storage and applications
  • Workstations and laptops
  • Mobile devices
  • Paper files and physical storage
  • Backup systems

Map your data flows. Understand how protected information moves through your organization:

  • How does it enter (email, file transfer, portal access)?
  • Who processes it and on what systems?
  • Where is it stored?
  • How does it leave (deliverables, sharing with subs)?

Categorize your assets. The CMMC Level 2 Scoping Guidance defines asset categories:

CUI Assets directly handle CUI and are fully in scope.

Security Protection Assets provide security for CUI systems (firewalls, authentication systems, SIEM) and are in scope.

Contractor Risk Managed Assets could access CUI but aren’t intended to. You manage and document the risk.

Specialized Assets include IoT, OT, and constrained devices requiring special handling.

Out-of-Scope Assets have no connection to CUI processing.

Consider scope reduction strategies. Smaller scope means faster, cheaper certification:

  • Create a dedicated CUI enclave separate from general IT
  • Segment networks to isolate CUI processing
  • Limit personnel with CUI access
  • Use FedRAMP-authorized cloud services
  • Outsource CUI handling to compliant providers

Document your scope decisions thoroughly. Assessors will review your scoping methodology.

Step 3: Conduct a Gap Assessment

A gap assessment compares your current security posture against CMMC requirements. This step reveals exactly what work lies ahead.

For Level 1, assess the 15 practices across six domains:

  • Access Control (2 practices)
  • Identification and Authentication (2 practices)
  • Media Protection (1 practice)
  • Physical Protection (4 practices)
  • System and Communications Protection (2 practices)
  • System and Information Integrity (4 practices)

For Level 2, assess all 110 requirements from NIST SP 800-171 across 14 control families:

  • Access Control (22 requirements)
  • Awareness and Training (3 requirements)
  • Audit and Accountability (9 requirements)
  • Configuration Management (9 requirements)
  • Identification and Authentication (11 requirements)
  • Incident Response (3 requirements)
  • Maintenance (6 requirements)
  • Media Protection (9 requirements)
  • Personnel Security (2 requirements)
  • Physical Protection (6 requirements)
  • Risk Assessment (3 requirements)
  • Security Assessment (4 requirements)
  • System and Communications Protection (16 requirements)
  • System and Information Integrity (7 requirements)

Rate each requirement honestly:

MET means fully implemented with evidence available.

NOT MET means not implemented or only partially implemented.

Calculate your SPRS score. For Level 2, each unmet requirement reduces your score from the maximum of 110. Requirements are weighted at 1, 3, or 5 points based on their security impact.

Document gaps and remediation estimates. For each gap, note:

  • What’s missing or incomplete
  • What’s needed to close the gap
  • Estimated effort and resources required
  • Dependencies on other work

Your gap assessment becomes the foundation for your implementation plan.

Step 4: Develop Your System Security Plan

The System Security Plan (SSP) is your core compliance document. It describes your environment and how you implement each security requirement.

For Level 1, a detailed SSP isn’t required, but documenting your practices is still recommended for consistency and evidence.

For Level 2 and Level 3, the SSP is mandatory and will be reviewed during assessment.

Your SSP should include:

System description covering the purpose, architecture, and boundaries of your CUI environment.

System environment detailing hardware, software, network topology, and data flows.

Roles and responsibilities identifying who manages security functions.

Requirement implementation describing how each of the 110 requirements is satisfied in your specific environment.

Interconnections documenting connections to external systems and how they’re protected.

Use a structured format. Many organizations use NIST SP 800-171A as a framework for documenting implementation. Each requirement should have a clear implementation statement explaining what you do to satisfy it.

Keep it accurate and current. Your SSP must reflect your actual environment. Assessors will compare what you’ve documented against what you’ve implemented. Discrepancies create findings.

Update continuously. As you implement controls and change your environment, update the SSP. Don’t wait until assessment time to bring it current.

Step 5: Create Policies and Procedures

Policies and procedures provide the governance framework for your security program. They establish what you do, why you do it, and how it gets done.

Policies are high-level statements of intent and requirements. They explain what must happen and why. Example: “All users must use multi-factor authentication to access CUI systems.”

Procedures are detailed step-by-step instructions. They explain how to accomplish policy requirements. Example: “Steps to enroll a new user in the MFA system.”

Create policies for each control family:

  • Access Control Policy
  • Awareness and Training Policy
  • Audit and Accountability Policy
  • Configuration Management Policy
  • Identification and Authentication Policy
  • Incident Response Policy
  • Maintenance Policy
  • Media Protection Policy
  • Personnel Security Policy
  • Physical Protection Policy
  • Risk Assessment Policy
  • Security Assessment Policy
  • System and Communications Protection Policy
  • System and Information Integrity Policy

Make policies practical. Policies nobody follows are worse than no policies. Write policies your organization can actually implement and maintain.

Obtain management approval. Policies carry weight when leadership formally approves and signs them. This demonstrates organizational commitment.

Establish review cycles. Policies should be reviewed at least annually and updated when requirements or your environment changes.

Step 6: Implement Technical Controls

Technical controls are the security measures built into your systems. For most organizations, this step requires the most time and resources.

Access Control. Implement controls to limit system access:

  • Role-based access control
  • Least privilege principles
  • Privileged access management
  • Session timeouts and controls
  • Remote access protections

Identification and Authentication. Verify users are who they claim:

  • Multi-factor authentication
  • Strong password policies
  • Account lockout after failed attempts
  • Unique user identifiers

Audit and Accountability. Track what happens on your systems:

  • Centralized log management
  • Audit log protection
  • Log retention per requirements
  • Regular log review
  • Alerting for security events

Configuration Management. Maintain secure system configurations:

  • Baseline configurations
  • Change management processes
  • Software restrictions
  • Configuration monitoring

System and Communications Protection. Protect data and networks:

  • Network segmentation
  • Boundary protection (firewalls)
  • Encryption for data in transit
  • Encryption for data at rest
  • Wireless security

System and Information Integrity. Maintain system security:

  • Malware protection
  • Patch management
  • Vulnerability scanning
  • Security alert monitoring
  • Integrity monitoring

Physical Protection. Secure physical access:

  • Facility access controls
  • Visitor management
  • Physical access logs
  • Equipment protection

Prioritize based on your gap assessment. Address highest-risk gaps first. Focus on controls that affect multiple requirements to maximize impact.

Step 7: Implement Process Controls

Not all controls are technical. Many CMMC requirements involve people and processes.

Awareness and Training. Establish security training programs:

  • General security awareness for all personnel
  • Role-based training for specific responsibilities
  • Training on recognizing threats like phishing
  • Documentation of training completion

Incident Response. Prepare to handle security incidents:

  • Incident response plan
  • Defined roles and responsibilities
  • Response procedures
  • Reporting requirements (72-hour DoD notification)
  • Testing and exercises

Personnel Security. Manage personnel-related risks:

  • Screening before granting access
  • Access termination procedures
  • Transfer procedures when roles change

Maintenance. Control system maintenance:

  • Maintenance scheduling and approval
  • Remote maintenance controls
  • Maintenance tool controls
  • Maintenance record keeping

Risk Assessment. Continuously evaluate risks:

  • Regular risk assessments
  • Vulnerability scanning
  • Risk response procedures

Security Assessment. Evaluate your own controls:

  • Periodic self-assessments
  • Remediation tracking
  • Plan of Action and Milestones management

Step 8: Collect and Organize Evidence

Evidence proves you’ve implemented what you claim. Without proper evidence, even fully implemented controls may receive findings during assessment.

Types of evidence:

Configuration evidence includes screenshots, exports, and reports showing system settings match requirements.

Documentation evidence includes policies, procedures, plans, and diagrams.

Operational evidence includes logs, reports, and records showing controls function over time.

Interview evidence comes from personnel demonstrating knowledge of their responsibilities.

Organize evidence by requirement. Create a structure that maps evidence to specific CMMC requirements. When assessors ask for evidence of a specific control, you should find it immediately.

Keep evidence current. Evidence should reflect your current environment. A screenshot from six months ago doesn’t prove current implementation.

Collect evidence continuously. Build evidence collection into your regular operations rather than scrambling before assessment.

Maintain chain of custody. Store evidence securely with access controls. Assessors may question evidence integrity if it’s not properly protected.

Step 9: Submit Your SPRS Score

The Supplier Performance Risk System (SPRS) is the DoD database where contractors report their compliance status. Submitting your score is a required step before CMMC certification.

What you submit:

  • Your NIST SP 800-171 self-assessment score (for Level 2)
  • Date of assessment
  • Scope of assessment
  • System Security Plan details
  • Plan of Action and Milestones summary

Who can submit:

Only authorized representatives with SPRS access can submit scores. You’ll need a Medium Assurance Certificate and proper SPRS account access.

Accuracy matters.

Your SPRS score is a formal representation to the government. Submitting an inaccurate score can have serious consequences including False Claims Act liability.

Keep it updated.

As you close gaps and improve your score, update SPRS. Your score should reflect your current state.

Step 10: Complete Your Assessment

The assessment process differs by level.

Level 1: Self-Assessment

You conduct your own assessment using the CMMC Level 1 Self-Assessment Guide. Document your findings for each of the 15 practices, affirm compliance, and submit to SPRS.

Using Greypike’s Obolix platform, this entire process takes just one week. Obolix guides you through each practice with pre-built templates, automated evidence collection, and clear steps from implementation to SPRS submission. Instead of spending months figuring out requirements, you follow a structured workflow that keeps you moving forward.

Level 2: Third-Party Assessment (C3PAO)

Most Level 2 certifications require assessment by a Certified Third-Party Assessment Organization.

Schedule early. C3PAO availability is limited. Contact assessors months before you’re ready to secure your preferred timing.

Provide documentation. Assessors review your SSP and documentation before the on-site or virtual assessment.

Support the assessment. During assessment, you’ll provide evidence, answer questions, and demonstrate controls. Key personnel should be available and prepared.

Assessment phases include:

  1. Pre-assessment planning and document review
  2. Assessment execution (evidence review, interviews, testing)
  3. Preliminary findings discussion
  4. Final report

Address findings. If assessors identify gaps, you may need to remediate and demonstrate closure before receiving certification. Some findings may be addressed through a Plan of Action and Milestones (POA&M) with specific timeframes.

Level 2: Self-Assessment Option

Some Level 2 certifications allow self-assessment rather than C3PAO assessment. This applies to specific contract situations defined by the DoD. Even with self-assessment, you must meet all requirements and affirm compliance.

Level 3: Government Assessment (DIBCAC)

Level 3 requires assessment by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center. The government conducts this assessment directly.

You must hold Level 2 certification before pursuing Level 3. Coordinate with DIBCAC on timing and prepare for a thorough evaluation of your enhanced security controls.

Step 11: Receive Your Certification

Upon successful assessment completion, you receive your CMMC certification.

For Level 1, your certification is based on your self-assessment and affirmation in SPRS.

For Level 2 and Level 3, your C3PAO or DIBCAC submits results to the CMMC Enterprise Mission Assurance Support Service (eMASS), and your certification is recorded.

Your certification is valid for three years for Levels 2 and 3. Level 1 requires annual affirmation.

Certification is scope-specific. Your certification covers the environment and systems assessed. If you significantly change your environment or expand scope, you may need reassessment.

Step 12: Maintain Continuous Compliance

Certification isn’t the end. It’s the beginning of ongoing compliance.

Monitor your controls. Security controls can degrade over time. Regularly verify controls remain effective:

  • Review access permissions periodically
  • Monitor audit logs
  • Verify security tools function properly
  • Test incident response capabilities

Manage changes. When you change systems or processes, evaluate impact on compliance:

  • Update SSP for system changes
  • Modify policies and procedures as needed
  • Collect new evidence for changed controls
  • Document changes for next assessment

Conduct annual assessments. Even between certification cycles, assess your compliance regularly:

  • Level 1 requires annual self-assessment and affirmation
  • Levels 2 and 3 benefit from annual internal reviews

Address new requirements. CMMC requirements may evolve. The DoD has indicated NIST SP 800-171 Revision 3 may be adopted in the future. Stay informed and prepare for changes.

Train continuously. Security awareness isn’t a one-time event. Maintain ongoing training programs and update content for new threats.

Prepare for reassessment. Three years passes quickly. Begin reassessment preparation 6-12 months before certification expiration.

Steps to CMMC certification & Common Mistakes to Avoid

Starting too late. CMMC certification takes time. Contractors who wait until a contract requires certification often can’t achieve it in time.

Underestimating scope. Many contractors discover more CUI systems than initially identified. Thorough scoping prevents surprises.

Neglecting documentation. Implementing controls without documenting them creates assessment problems. Document as you implement.

Treating compliance as IT-only. CMMC involves HR, legal, facilities, and operations. Engage stakeholders across the organization.

Ignoring the supply chain. If your subcontractors handle CUI, they need CMMC certification too. Address supply chain requirements early.

Stopping at certification. Compliance requires ongoing effort. Organizations that neglect maintenance struggle at reassessment.

Timeline Summary

Here’s what to expect for each certification level:

Level 1

  • With Obolix: 1 week
  • Traditional approach: 1-3 months
  • Assessment type: Self-assessment
  • Renewal: Annual affirmation

Level 2

  • Well-prepared organizations: 6-9 months
  • Starting from scratch: 12-18 months
  • Assessment type: C3PAO or self-assessment
  • Renewal: Every 3 years

Level 3

  • Minimum timeline: 18-24 months (includes Level 2)
  • Assessment type: DIBCAC government assessment
  • Renewal: Every 3 years

Steps to CMMC certification Key Takeaways

Confirm your required level by reviewing contracts and talking to contracting officers.

Define scope carefully and consider reduction strategies to minimize burden.

Conduct honest gap assessment to understand your starting point and required work.

Develop your SSP early and keep it updated as you implement controls.

Create practical policies that your organization can actually follow.

Implement controls systematically addressing both technical and process requirements.

Collect evidence continuously rather than scrambling before assessment.

Submit accurate SPRS scores reflecting your true compliance state.

Prepare for assessment by organizing evidence and briefing personnel.

Maintain ongoing compliance after certification through monitoring and continuous improvement.

Sources and References

Ready to start your CMMC certification journey? Contact Greypike for expert guidance, or get started with Obolix to achieve Level 1 compliance in just one week.

Table of Contents