How Long Does CMMC Prep Take?
Cody D. Martin//Updated August 9, 2026
Level 1 preparation typically takes four to eight weeks. Level 2 typically takes nine to eighteen months from gap assessment to a defensible position, driven mostly by how much infrastructure work the gaps require rather than by company size.
The honest answer is that it depends more on what you already have than on how big you are. A well run twenty person company can be closer to compliant than a sprawling two hundred person one.
That said, planning needs numbers.
Level 1
Four to eight weeks, most of which is documentation rather than technical work.
Fifteen requirements, and most companies already meet ten of them without having written anything down. The work is confirming, fixing the two or three that are genuinely missing, and producing a record a company official can sign against.
The usual gaps are shared accounts, standing local administrator rights, and no written media disposal process.
Level 2
Nine to eighteen months from gap assessment to a position you would defend.
| Phase | Typical duration |
|---|---|
| Gap assessment | 2 to 8 weeks |
| Quick wins and foundations | 1 to 2 months |
| Infrastructure remediation | 3 to 6 months |
| Documentation and process | 2 to 3 months |
| Verification and evidence | 1 to 2 months |
Companies that come in under nine months usually had a mature IT function already. Companies that run past eighteen usually stalled on one infrastructure item that nobody owned.
What actually drives the variance
How much infrastructure work the gaps require. Deploying MFA across an organization with a single identity provider is a fortnight. Doing it across three disconnected directories and a set of legacy applications is a quarter.
Whether someone owns it. The single strongest predictor. A named person with allocated time beats a larger budget with the work distributed across people who have other jobs.
Cloud versus on premise. Cloud environments are usually faster to bring into compliance, because the controls are configuration rather than procurement.
Boundary size. Every system in scope is more work. Scoping properly at the start changes the size of the project more than any other decision, in both directions.
Legacy systems. One machine that cannot be patched, cannot be replaced and processes CUI will consume more time than the rest of the program combined.
Budget shape
Most of the cost is not consulting. It is:
- Tooling you did not have, mostly MFA, EDR and log management
- Infrastructure work, mostly segmentation
- Internal time, which is the largest line and the one nobody budgets
Advisory is typically the smallest component and the one that determines whether the rest is spent well.
What the July 2026 suspension does to planning
It removed the external deadline and it did not remove the work.
Phase 2 was suspended, pausing third party assessment. DFARS 252.204-7012 was not suspended, so NIST SP 800-171 self assessment, the SSP, the POA&M, SPRS scoring and the annual affirmation all continue.
Two practical consequences for planning:
The urgency changed, the requirement did not. If you were racing a November 2026 date, you are not any more. If you were behind on 7012, you still are.
Do not disband the program. The task force is due to report on more scalable measures. A contractor who kept a program running adapts to whatever it recommends. One who disbanded starts again with less notice than the first time.
The most efficient plan right now is to keep the twelve month shape and drop the schedule pressure, rather than to stop.
- CMMC
- planning
- NIST 800-171
- budget
More on compliance
