If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
90 Days to CMMC Compliance: What Is Really Possible
You have 90 days to CMMC compliance, and that is enough time to become a defensible, documented, honestly scored supplier. It is not enough time to become a fully implemented one unless your environment is unusually small and unusually clean. Both of those statements are true at once, and the gap between them is where companies waste the quarter.
The variable that decides your outcome is scope, not effort. A company that decides in week one to keep controlled information inside a small, defined boundary will finish. A company that tries to bring its entire network up to standard will spend the ninety days discovering how large its network is. Everything below assumes you make the scoping decision early. This article sits under Something Just Happened and You Need CMMC: A Triage Guide.
Decide what 90 days to CMMC compliance has to mean for you
Ninety day deadlines arrive attached to a specific ask. Read the ask carefully, because the three common versions require very different work.
| What was asked for | Achievable in 90 days? | What it takes |
|---|---|---|
| A current SPRS score posted | Comfortably, if you have PIEE access | An SSP, an honest scoring pass, and a senior official to affirm it |
| A score above a stated threshold | Usually, with focused work on the high value requirements | The above, plus real implementation on the controls carrying the most points |
| Full implementation of all 110 requirements with evidence | Rarely, unless the boundary is small | Technical change, policy, training and a body of evidence per requirement |
If you have not established which of these is being asked of you, stop and find out. It changes the plan completely, and the person who sent the deadline can answer the question in a sentence.
Weeks one and two: scope and access
Two things start now because they have external dependencies and everything else waits on them.
Get PIEE access sorted. Somebody at your company needs the SPRS Cyber Vendor role. If nobody currently holds it, the request can take anywhere from a day to two weeks depending on your PIEE administrator. This single item misses more deadlines than any technical control. Start it on day one even though you will not use it until week ten.
Find the controlled information. Not in theory, in fact. Where do the drawings, specifications and statements of work actually live today. Email, a file server, a shared drive, an engineer’s laptop, a supplier portal, a machine controller on the shop floor. Walk it physically and ask people. The answer is always wider than the org chart suggests.
If the answer is that everything sits in an ordinary Microsoft 365 tenant, read your CUI is sitting in commercial Microsoft 365 before you commit to a destination, because that decision drives the calendar.
Then draw the boundary. You are choosing, deliberately, which systems will hold controlled information going forward. Keeping that set small is the highest leverage decision available to you in this entire project, and it is free. Everything inside the boundary must meet the standard. Everything outside it must be genuinely outside it, which means the data has to move.
Weeks three through six: the plan and the honest baseline
Write the System Security Plan. This is not a formality and it is not a template with your logo on it. The DoD Assessment Methodology assigns no point value to requirement 3.12.4 precisely because its absence stops the assessment altogether. Without a plan describing your real environment, you do not have a low score. You have no valid score at all.
A workable SSP for a small contractor describes the boundary, the systems inside it, who administers them, how controlled information enters and leaves, and how each of the 110 requirements is met or not met. Twenty to forty pages is normal. Two hundred pages means somebody sold you a template. How to Write a CMMC System Security Plan walks the structure.
Then score yourself against all 110 requirements without flattering the results. Score what is true today, not what will be true in November. The scoring pass typically takes four to sixteen hours the first time, and the number that comes out of it is the input to every decision in the second half of the quarter. If you inflate it, you are planning against fiction. The mechanics are in How to Calculate Your SPRS Score.
Weeks seven through ten: fix what moves the number
Not all requirements are worth the same. The methodology weights them, and in a compressed timeline you work the weighted list from the top. In most small environments the same items surface, and most of them are configuration rather than capital.
- Multifactor authentication on remote access and on privileged accounts. Often already licensed and simply not enabled.
- FIPS validated encryption for controlled information at rest and in transit. Note that FIPS 140-2 certificates move to historical status on September 21, 2026, so confirm what your vendor is actually validated under before you rely on a claim.
- Account management and least privilege. Removing the shared administrator account that four people use is a morning of work and it is worth points and real risk reduction.
- Audit logging that is turned on, retained and reviewed by a named person. Retention with nobody reading it satisfies nothing.
- Media and mobile device handling, which for most shops means a decision about USB drives and personal phones.
- Incident response, including the practical detail that reporting a cyber incident to DIBNet within 72 hours requires a DoD medium assurance certificate you cannot obtain on the day you need it. Get it now. The requirements are covered in 72-Hour DoD Breach Notification: DFARS Reporting Requirements.
Write a Plan of Action and Milestones for everything you will not finish, following POA&M Best Practices for CMMC. Each open item gets an owner by name and a completion date. A POA&M is not an admission of failure. It is the normal and expected way a supplier documents work in progress, and it is what a buyer or a contracting officer wants to see.
Weeks eleven and twelve: post, affirm and communicate
Enter the score in SPRS. The mechanical submission takes under an hour. Book the senior official affirmation on somebody’s calendar in advance, because that signature carries legal weight and the person providing it deserves more than a hallway conversation about what they are signing.
Then tell whoever set the deadline what you did. If that person is a prime and the request arrives as a spreadsheet, your prime just sent you a cybersecurity questionnaire covers the response. A short note with the assessment date, the score, the boundary you scoped and the top three items on your POA&M is worth more to that relationship than any certificate you could have chased. Suppliers who communicate are kept.
What genuinely does not fit inside 90 days to CMMC compliance
Being straight about this saves you from promising something you will miss.
A migration to a government community cloud tenant with mailboxes, files and identity moved over is a three to six month project for most companies, and the calendar is driven by the vendor and your own users rather than by your effort. Twelve months of accumulated audit evidence cannot be manufactured; if a requirement asks you to demonstrate that reviews happen, you can start the reviews now and you cannot backdate them. Deep organizational habits like consistent labeling of controlled information take a year of reinforcement. And a third party certification assessment is not available at all while CMMC Phase 2 assessments remain suspended.
None of that prevents you from being compliant with what is actually in force today, which is DFARS 252.204-7012, NIST SP 800-171, a current SPRS score and an annual affirmation. That is the bar you can clear this quarter.
Frequently asked
Questions about this topic
Can a small company really get compliant in 90 days?
What is the biggest time risk in a plan for 90 days to CMMC compliance?
Should we narrow our scope to a smaller boundary?
Is it acceptable to post a score with open items?
Do we need consultants to hit 90 days?
What happens if we miss the deadline?
Keep reading
More in Trigger Events & Urgent Situations
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5