APTSecurity Management

How Long Does CMMC Prep Take?

Cody D. Martin//Updated August 9, 2026

Level 1 preparation typically takes four to eight weeks. Level 2 typically takes nine to eighteen months from gap assessment to a defensible position, driven mostly by how much infrastructure work the gaps require rather than by company size.

The honest answer is that it depends more on what you already have than on how big you are. A well run twenty person company can be closer to compliant than a sprawling two hundred person one.

That said, planning needs numbers.

Level 1

Four to eight weeks, most of which is documentation rather than technical work.

Fifteen requirements, and most companies already meet ten of them without having written anything down. The work is confirming, fixing the two or three that are genuinely missing, and producing a record a company official can sign against.

The usual gaps are shared accounts, standing local administrator rights, and no written media disposal process.

Level 2

Nine to eighteen months from gap assessment to a position you would defend.

Phase Typical duration
Gap assessment 2 to 8 weeks
Quick wins and foundations 1 to 2 months
Infrastructure remediation 3 to 6 months
Documentation and process 2 to 3 months
Verification and evidence 1 to 2 months

Companies that come in under nine months usually had a mature IT function already. Companies that run past eighteen usually stalled on one infrastructure item that nobody owned.

What actually drives the variance

How much infrastructure work the gaps require. Deploying MFA across an organization with a single identity provider is a fortnight. Doing it across three disconnected directories and a set of legacy applications is a quarter.

Whether someone owns it. The single strongest predictor. A named person with allocated time beats a larger budget with the work distributed across people who have other jobs.

Cloud versus on premise. Cloud environments are usually faster to bring into compliance, because the controls are configuration rather than procurement.

Boundary size. Every system in scope is more work. Scoping properly at the start changes the size of the project more than any other decision, in both directions.

Legacy systems. One machine that cannot be patched, cannot be replaced and processes CUI will consume more time than the rest of the program combined.

Budget shape

Most of the cost is not consulting. It is:

  • Tooling you did not have, mostly MFA, EDR and log management
  • Infrastructure work, mostly segmentation
  • Internal time, which is the largest line and the one nobody budgets

Advisory is typically the smallest component and the one that determines whether the rest is spent well.

What the July 2026 suspension does to planning

It removed the external deadline and it did not remove the work.

Phase 2 was suspended, pausing third party assessment. DFARS 252.204-7012 was not suspended, so NIST SP 800-171 self assessment, the SSP, the POA&M, SPRS scoring and the annual affirmation all continue.

Two practical consequences for planning:

The urgency changed, the requirement did not. If you were racing a November 2026 date, you are not any more. If you were behind on 7012, you still are.

Do not disband the program. The task force is due to report on more scalable measures. A contractor who kept a program running adapts to whatever it recommends. One who disbanded starts again with less notice than the first time.

The most efficient plan right now is to keep the twelve month shape and drop the schedule pressure, rather than to stop.

  • CMMC
  • planning
  • NIST 800-171
  • budget

More on compliance