Built by Velocity Technologies for defense contractors, manufacturers, and subcontractors.
(602) 425-5630
Velocity CMMC Resource Center

How to get CMMC certified: a step-by-step roadmap for defense contractors

Use this roadmap to understand the CMMC certification sequence before you commit to tools, assessment timing, or remediation work.

Step 1: Identify the information and the contract path

Start by identifying whether the business is handling FCI, CUI, or both, and which solicitations, subcontracts, or customer expectations are driving the need. That determines whether the target is Level 1, Level 2, or in rare cases Level 3, and whether the likely path is self-assessment or a C3PAO assessment.

Step 2: Define the assessment scope

Use the official scoping approach before you start buying tools. Identify CUI assets, security protection assets, contractor risk managed assets, specialized assets, and true out-of-scope assets. Build the asset inventory and network diagram that the scoping guide expects.

Step 3: Perform a real readiness assessment

Assess the scoped environment against the applicable requirements. For Level 2, that means the 110 NIST SP 800-171 Rev. 2 requirements as currently used by CMMC. The readiness assessment should separate policy and documentation gaps from technical and operational gaps.

Step 4: Remediate and document

Close technical gaps, tighten the operating model, and build the documentation package. For most buyers that means SSP work, POA&M discipline where allowed, policy and procedure development, evidence organization, and mock-assessment preparation.

Step 5: Follow the right assessment path

If the requirement is self-assessment, complete the self-assessment, upload results to SPRS as required, and submit the affirmation. If the requirement is Level 2 C3PAO, engage the formal certification assessment path and prepare to support the assessor with scope, evidence, and interviews.

Step 6: Maintain current status

Do not treat CMMC as a one-time event. Track the current-status window, annual affirmations, evidence retention, and ongoing control operation. A company that reaches status and then stops operating the program creates avoidable contract risk later.

What a support partner should do

  • Run scoping workshops and document the boundary.
  • Perform readiness assessments tied to current official rules.
  • Support remediation and evidence gathering.
  • Build or refine the SSP and related documentation.
  • Prepare leadership and technical staff for interviews and evidence requests.
  • Help maintain readiness after the initial push.

Frequently asked questions

How do we get CMMC certified?

Identify the right level and assessment path, define the scope, perform readiness work, remediate gaps, complete the required assessment path, and maintain current status with affirmations and ongoing controls.

What is the first mistake companies make?

They skip scoping and start buying products or scheduling assessments before they know what the boundary really is.

Can a consultant certify us?

No. A consultant can prepare you. A Level 2 certification assessment is performed by a C3PAO when that assessment type is required.

Do we need the SSP before the assessment?

You need a serious documentation package and evidence trail before the assessment path becomes efficient. The SSP is a core part of that readiness work.

Should we wait until the customer asks?

No. Because current status matters at award, it is better to start readiness work before the customer or prime pushes the deadline.

Is CMMC a one-time project?

No. Assessments recur and annual affirmations are required, so the program has to be maintained.

Official sources reviewed

Use this guide to plan readiness and communicate clearly with buyers, primes, and internal stakeholders. Contract language, current regulations, and assessor guidance control.

Want help turning this into a real readiness plan?

Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.