CMMC Level 2 Readiness: A Practical 90-Day Roadmap for Tier 2 and Tier 3 Contractors

CMMC Level 2 readiness is within reach for Tier 2 and Tier 3 defense contractors—but only if you follow a structured 90-day roadmap. This guide breaks down key controls, evidence requirements, and realistic timelines.

A workable CMMC Level 2 readiness 90-day plan is the difference between a self-assessment your leadership can defend and a score that sits in SPRS as a liability — and, when third-party assessments return, between passing on the first attempt and paying $15K–$30K to fail. The companies that pass on the first attempt didn’t have bigger budgets or larger IT teams. They had a structured sequence, started early, and treated evidence as a product — not an afterthought. 90 days is the realistic minimum you need. Here’s exactly how I structure that window with my clients.

Why 90 Days Is the Realistic Minimum

CMMC Level 2 measures your implementation of the 110 security practices from NIST SP 800-171. But here’s what most contractors miss: the assessment doesn’t just check whether controls exist. It checks whether they operate consistently over time. A quarterly access review documented once proves nothing. Two review cycles with dated logs and signatures prove a working process.

That time dimension is why you can’t compress readiness into three weeks. Certain evidence — review cycles, change logs, audit records — only accumulates on the calendar. Ninety days gives you enough runway to remediate gaps and generate at least one full cycle of operating evidence for your highest-risk controls. Less than that, and you’re presenting policies instead of proof.

The cost of getting this wrong is concrete. Today, with third-party assessments paused since July 2026, the document carrying the risk is your self-assessment: an inaccurate score sitting in SPRS is a standing liability with your primes and under the False Claims Act. And when C3PAO assessments return — at $15,000 to $30,000 for a typical mid-size contractor, pass/fail, not diagnostic — showing up unprepared means paying full price to learn what a readiness review would have told you for a fraction of the cost.

Phase 1 (Days 1–20): Gap Analysis and Scoping

Everything starts with scope. Before you assess a single control, define where controlled unclassified information (CUI) actually lives in your environment. I’ve watched contractors spend six figures securing systems that never touch CUI while the file server that actually stores contract drawings sat unhardened. Draw the boundary first: which systems store, process, or transmit CUI? Which users touch it? Which vendors can reach those systems?

With scope defined, baseline yourself against all 110 practices of NIST SP 800-171. Be brutally honest. For each practice, ask three questions: Is it implemented? Is it documented? Can I prove it operated during the last 90 days? A control that fails any of the three goes on your remediation list. Score the result using the DoD methodology and submit it to SPRS — your contracts already require that, and primes check.

  • Deliverable: A scored gap report, a prioritized remediation list, and a Plan of Action & Milestones (POA&M)
  • Typical finding: Most contractors with decent IT hygiene score between 40% and 60% compliant on the first pass
  • Common trap: Overscoping. Every system you include in the boundary is a system you must defend during assessment

Phase 2 (Days 21–50): Remediation That Prioritizes Failure Points

You cannot fix everything in 30 days, so fix what fails assessments. In my experience, four domains account for the majority of first-attempt failures: access control, configuration management, incident response, and audit logging. Start there.

For access control, that means a documented policy, a role-based access matrix, multi-factor authentication on every system that touches CUI, and a working termination checklist. For configuration management, document baselines for your critical systems and stand up a change request process — even a simple ticketing workflow beats email approvals scattered across inboxes. For incident response, you need a plan people have actually rehearsed. For logging, confirm your systems capture who accessed what, and that someone reviews those logs on a schedule.

Update your System Security Plan (SSP) as you go, not at the end. The SSP is the first document your assessor reads, and it must describe your environment as it actually is. An SSP that references tools you decommissioned last year tells the assessor everything they need to know about your documentation discipline.

Phase 3 (Days 51–75): Evidence Collection on a Schedule

This is the phase most contractors skip, and it’s where assessments are won. Evidence answers one question: can you show the control happened, on schedule, more than once? A policy that says “we review access quarterly” is not evidence. A dated log showing the review happened, signed by the reviewer, with the exceptions that were found and fixed — that’s evidence.

During these 25 days, run your processes deliberately and capture the output. Conduct an access review and document it. Push changes through your new change process and keep the tickets. Run a tabletop incident response exercise with a realistic scenario — a phishing email that reached a CUI user works well — and write it up like a real incident, signatures included. That tabletop counts as evidence, and it’s the fastest way to prove your IR process without waiting for an actual breach.

Then index everything. Build a simple evidence matrix: practice number, control description, evidence artifact, location, date. When your assessor asks for proof of practice 3.1.7, you want to produce it in ninety seconds, not ninety minutes. Assessors form impressions early, and an organized evidence library signals a mature program before they’ve read a single artifact.

CMMC Level 2 readiness 90 day plan infographic with four phases and key controls
The CMMC 90-day roadmap: four phases from gap analysis to assessment-ready

Phase 4 (Days 76–90): The Mock Assessment

Spend the final two weeks assessing yourself the way a C3PAO will assess you. Pick controls at random and demand the evidence. Interview your own staff — assessors will ask your system administrator how account provisioning works, and the answer needs to match what the SSP says. Test controls live: attempt to access CUI from an unauthorized account, and confirm the attempt is blocked and logged.

Gaps you find in this window are cheap to fix. Gaps an assessor finds cost you the assessment. When my clients complete a mock assessment without surprises, they walk into the real one already knowing the outcome — and that’s precisely the point. If your team can’t answer a question in rehearsal, you’ve found next week’s priority.

Making Your CMMC Level 2 Readiness 90 Day Plan Stick

Three practical rules keep the plan on track. First, assign one owner. Readiness efforts stall when responsibility is distributed across “the IT team.” One person owns the plan, tracks the milestones, and escalates blockers. Second, don’t treat the July 2026 assessment pause as permission to stall. The DoD’s Reform Task Force reports back in fall 2026, and every signal it has given keeps NIST SP 800-171 at the core — the evidence you build now carries straight into whatever the program becomes, while contractors who paused will restart from zero with less runway. Third, protect the evidence habit after day 90. The reviews, logs, and audits you built are not a one-time sprint — the annual self-assessment and affirmation cycle comes around faster than you think, and so will the reformed program’s requirements.

For Tier 2 and Tier 3 contractors in Mexico’s aerospace and defense supply chain, the stakes are contract survival. Your prime doesn’t have discretion here: DFARS flow-downs still bind them, which means they still have to verify you — and with certification paused, your self-assessment and SPRS score are exactly what they check. No defensible compliance posture, no CUI flow-down, no work. If you want to see where your organization stands before committing to the full 90-day push, start with a CMMC readiness gap assessment — it turns the unknown into a plan you can budget.

Where to Start This Week

A CMMC Level 2 readiness 90 day plan only works if day one actually happens. This week, do three things: define your CUI boundary on paper, pull your current SPRS score (or calculate it for the first time), and pick the executive who owns the outcome. Those three actions cost nothing and surface the decisions everything else depends on.

If you’d rather compress the learning curve, I do this work with contractors every week — Schedule a discovery call and let’s map your 90 days.

2 Comments

  1. […] That number is your real readiness score — not your ISO certificate, not your policy count. And it points directly at the fix: for every practice that failed the test, either the control isn’t actually operating on a schedule (a process problem) or it operates but leaves no trail (an evidence problem). Process problems need remediation. Evidence problems need capture discipline: dated logs, named reviewers, stored artifacts. Both are solvable in a structured 90-day push — I’ve laid out that sequence in my CMMC Level 2 90-day roadmap. […]

Comments are closed.