Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

90 Days to CMMC Compliance: What Is Really Possible

You have 90 days to CMMC compliance, and that is enough time to become a defensible, documented, honestly scored supplier. It is not enough time to become a fully implemented one unless your environment is unusually small and unusually clean. Both of those statements are true at once, and the gap between them is where companies waste the quarter.

The variable that decides your outcome is scope, not effort. A company that decides in week one to keep controlled information inside a small, defined boundary will finish. A company that tries to bring its entire network up to standard will spend the ninety days discovering how large its network is. Everything below assumes you make the scoping decision early. This article sits under Something Just Happened and You Need CMMC: A Triage Guide.

Decide what 90 days to CMMC compliance has to mean for you

Ninety day deadlines arrive attached to a specific ask. Read the ask carefully, because the three common versions require very different work.

What was asked forAchievable in 90 days?What it takes
A current SPRS score postedComfortably, if you have PIEE accessAn SSP, an honest scoring pass, and a senior official to affirm it
A score above a stated thresholdUsually, with focused work on the high value requirementsThe above, plus real implementation on the controls carrying the most points
Full implementation of all 110 requirements with evidenceRarely, unless the boundary is smallTechnical change, policy, training and a body of evidence per requirement

If you have not established which of these is being asked of you, stop and find out. It changes the plan completely, and the person who sent the deadline can answer the question in a sentence.

Weeks one and two: scope and access

Two things start now because they have external dependencies and everything else waits on them.

Get PIEE access sorted. Somebody at your company needs the SPRS Cyber Vendor role. If nobody currently holds it, the request can take anywhere from a day to two weeks depending on your PIEE administrator. This single item misses more deadlines than any technical control. Start it on day one even though you will not use it until week ten.

Find the controlled information. Not in theory, in fact. Where do the drawings, specifications and statements of work actually live today. Email, a file server, a shared drive, an engineer’s laptop, a supplier portal, a machine controller on the shop floor. Walk it physically and ask people. The answer is always wider than the org chart suggests.

If the answer is that everything sits in an ordinary Microsoft 365 tenant, read your CUI is sitting in commercial Microsoft 365 before you commit to a destination, because that decision drives the calendar.

Then draw the boundary. You are choosing, deliberately, which systems will hold controlled information going forward. Keeping that set small is the highest leverage decision available to you in this entire project, and it is free. Everything inside the boundary must meet the standard. Everything outside it must be genuinely outside it, which means the data has to move.

Weeks three through six: the plan and the honest baseline

Write the System Security Plan. This is not a formality and it is not a template with your logo on it. The DoD Assessment Methodology assigns no point value to requirement 3.12.4 precisely because its absence stops the assessment altogether. Without a plan describing your real environment, you do not have a low score. You have no valid score at all.

A workable SSP for a small contractor describes the boundary, the systems inside it, who administers them, how controlled information enters and leaves, and how each of the 110 requirements is met or not met. Twenty to forty pages is normal. Two hundred pages means somebody sold you a template. How to Write a CMMC System Security Plan walks the structure.

Then score yourself against all 110 requirements without flattering the results. Score what is true today, not what will be true in November. The scoring pass typically takes four to sixteen hours the first time, and the number that comes out of it is the input to every decision in the second half of the quarter. If you inflate it, you are planning against fiction. The mechanics are in How to Calculate Your SPRS Score.

Weeks seven through ten: fix what moves the number

Not all requirements are worth the same. The methodology weights them, and in a compressed timeline you work the weighted list from the top. In most small environments the same items surface, and most of them are configuration rather than capital.

  • Multifactor authentication on remote access and on privileged accounts. Often already licensed and simply not enabled.
  • FIPS validated encryption for controlled information at rest and in transit. Note that FIPS 140-2 certificates move to historical status on September 21, 2026, so confirm what your vendor is actually validated under before you rely on a claim.
  • Account management and least privilege. Removing the shared administrator account that four people use is a morning of work and it is worth points and real risk reduction.
  • Audit logging that is turned on, retained and reviewed by a named person. Retention with nobody reading it satisfies nothing.
  • Media and mobile device handling, which for most shops means a decision about USB drives and personal phones.
  • Incident response, including the practical detail that reporting a cyber incident to DIBNet within 72 hours requires a DoD medium assurance certificate you cannot obtain on the day you need it. Get it now. The requirements are covered in 72-Hour DoD Breach Notification: DFARS Reporting Requirements.

Write a Plan of Action and Milestones for everything you will not finish, following POA&M Best Practices for CMMC. Each open item gets an owner by name and a completion date. A POA&M is not an admission of failure. It is the normal and expected way a supplier documents work in progress, and it is what a buyer or a contracting officer wants to see.

Weeks eleven and twelve: post, affirm and communicate

Enter the score in SPRS. The mechanical submission takes under an hour. Book the senior official affirmation on somebody’s calendar in advance, because that signature carries legal weight and the person providing it deserves more than a hallway conversation about what they are signing.

Then tell whoever set the deadline what you did. If that person is a prime and the request arrives as a spreadsheet, your prime just sent you a cybersecurity questionnaire covers the response. A short note with the assessment date, the score, the boundary you scoped and the top three items on your POA&M is worth more to that relationship than any certificate you could have chased. Suppliers who communicate are kept.

What genuinely does not fit inside 90 days to CMMC compliance

Being straight about this saves you from promising something you will miss.

A migration to a government community cloud tenant with mailboxes, files and identity moved over is a three to six month project for most companies, and the calendar is driven by the vendor and your own users rather than by your effort. Twelve months of accumulated audit evidence cannot be manufactured; if a requirement asks you to demonstrate that reviews happen, you can start the reviews now and you cannot backdate them. Deep organizational habits like consistent labeling of controlled information take a year of reinforcement. And a third party certification assessment is not available at all while CMMC Phase 2 assessments remain suspended.

None of that prevents you from being compliant with what is actually in force today, which is DFARS 252.204-7012, NIST SP 800-171, a current SPRS score and an annual affirmation. That is the bar you can clear this quarter.

Frequently asked

Questions about this topic

Can a small company really get compliant in 90 days?
A small company can produce a System Security Plan, an honest SPRS score, an affirmation and a documented Plan of Action and Milestones in 90 days. Full implementation of all 110 requirements with supporting evidence usually takes six to eighteen months. Which outcome you need depends on what the person who set the deadline actually asked for.
What is the biggest time risk in a plan for 90 days to CMMC compliance?
Obtaining the PIEE account with the SPRS Cyber Vendor role, and discovering late that no usable System Security Plan exists. Both are administrative rather than technical, and both routinely cost more calendar time than the entire scoring effort.
Should we narrow our scope to a smaller boundary?
Almost always, yes. Restricting controlled information to a defined enclave rather than your whole network reduces the number of systems that must meet the standard and is the difference between finishing and not. The trade is that data must genuinely stay inside that boundary, which requires process discipline, not just technology.
Is it acceptable to post a score with open items?
Yes. Most contractors do. The methodology anticipates it, which is why the Plan of Action and Milestones exists. What matters is that the score reflects your real state and that the open items carry owners and dates.
Do we need consultants to hit 90 days?
Not necessarily. Companies with capable internal IT and an executive willing to make scoping decisions quickly often do better alone than with a firm learning their environment. Outside help is most valuable for the System Security Plan and for a second opinion on the scoring, which are the two places self assessment tends to drift.
What happens if we miss the deadline?
That depends entirely on who set it. A prime’s supplier deadline is usually a business conversation and is often extended for a supplier showing documented progress. A solicitation deadline is not negotiable, and a missing current assessment affects eligibility for award under DFARS 252.204-7019. Find out which kind you are facing before you decide how hard to push.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents