CMMC Roadmap: Your Ultimate Guide for CMMC 2.0 Compliance

The CMMC 2.0 Roadmap: Getting From Where You Are to Certified

Most defense contractors don’t fail CMMC 2.0 because they misunderstand the framework. They fail because they treat it as a single deadline instead of a sequence of stages, each with its own deliverables, and try to do everything at once under pressure instead of working through it in order.

This is that sequence — five stages, in the order they actually happen, from your first honest look at where you stand today to the ongoing work of staying certified. Some of these stages have a lot of detail underneath them; where that’s true, we’ve linked out to the deeper guide rather than repeating it here. This page is the map. The linked guides are the terrain.

Note: CMMC Phase 2 third-party certification requirements were suspended by the Department of War in July 2026, pending a program review. Self-assessment requirements and your underlying NIST SP 800-171 obligations are unaffected. See our post CMMC Phase II Is Suspended. Your DFARS Obligations Are Not. for the current program status.

Executive Summary

Main Idea: CMMC 2.0 certification is a five-stage journey — determine your required level, assess your current gaps, remediate and document, verify through self-assessment or third-party certification, and maintain compliance on an ongoing basis. Contractors who try to shortcut or reorder these stages typically end up redoing work.

Why You Should Care: CMMC compliance isn’t optional for any organization that wants to bid on contracts involving Controlled Unclassified Information — it’s a prerequisite. But the path to certification is long enough that starting without a clear sequence wastes both time and budget. Knowing the stages in order lets you plan realistically instead of scrambling against a deadline.


Stage 1: Determine Your Required CMMC Level

Before you can build a roadmap, you need to know your destination. CMMC level is determined by the type of data you handle, not by your organization’s size or how sensitive you consider your own operations to be.

If you handle only Federal Contract Information (FCI), you need Level 1 — verified by annual self-assessment against 17 basic safeguarding practices. If you handle Controlled Unclassified Information (CUI), you need Level 2 — verified by self-assessment or third-party certification against all 110 NIST SP 800-171 controls, depending on the specific contract. A small number of the highest-priority programs require Level 3, adding enhanced controls from NIST SP 800-172.

Check your contract language and your prime contractor’s flow-down requirements directly — this is usually specified, not something you have to guess at. For the full breakdown of what each level requires, see our CMMC compliance guide.

Stage 2: Assess Your Current Gaps

With your target level established, the next step is an honest gap assessment: where does your current environment stand against the specific controls your level requires, and what’s missing?

This means inventorying every system that touches CUI or FCI — not just the obvious ones. CUI moves through email, file sharing, managed file transfer, web forms submitted by partners, and increasingly through AI tools employees may be using without formal approval. A gap assessment that only looks at your primary systems and misses these secondary channels will produce a compliance plan with holes in it from the start.

The output of this stage should be a realistic picture of where you stand against each required control family — Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Media Protection, System and Communications Protection, and the rest — not a vague sense of “mostly compliant.” For a detailed checklist to work through this systematically, see our CMMC Compliance Checklist.

Stage 3: Remediate and Document

This is where most of the actual work happens, and it’s typically the longest stage. For every gap identified in Stage 2, you need either an implemented control or a documented Plan of Action and Milestones (POA&M) with a realistic remediation timeline.

Two documents anchor this stage. Your System Security Plan (SSP) describes, control by control, how your organization implements each required safeguard — this is the document a C3PAO assessor reviews line by line, and it needs to reflect what you actually do, not an aspirational description. Your POA&M tracks every control not yet fully implemented, with specific remediation steps and dates. An SSP that overstates your actual posture is a bigger liability than an honest one with a documented remediation plan, particularly given the DoJ’s Civil Cyber-Fraud Initiative’s focus on contractors who misrepresent their compliance status.

For contractors with resource or technical constraints — smaller teams, limited security budget, no dedicated compliance staff — this is often the stage where a unified platform that consolidates policy enforcement and produces audit-ready documentation across every channel makes the difference between a manageable project and an overwhelming one. For guidance specific to small and mid-sized contractors, see Best CMMC Compliance Software for Small Defense Contractors.

Stage 4: Verify Through Assessment

Once controls are implemented and documented, verification confirms it. How this happens depends on your level and, for Level 2, on your specific program’s criticality.

Level 1 is verified annually through self-assessment, with results affirmed by a senior company official. Level 2 is verified either through self-assessment (for nonprioritized programs) or third-party assessment by an accredited C3PAO (for prioritized programs involving the most critical national security information) — though the C3PAO requirement is currently suspended pending the Department of War’s program review, discussed above. Level 3 requires government-led assessment.

Whichever path applies, your SPRS score — posted to the Supplier Performance Risk System — needs to be current and accurate regardless of assessment type, since prime contractors and contracting officers reference it directly when evaluating subcontractors.

Stage 5: Maintain Compliance on an Ongoing Basis

Certification is not a one-time achievement. CMMC compliance is a continuous state, not a project with an end date — controls need to keep working, documentation needs to stay current, and recertification comes around on a triennial cycle for Level 2 and Level 3.

Build recertification into your roadmap from the start rather than treating it as a future problem: assign clear ownership for maintaining your SSP and POA&M as your environment changes, schedule periodic internal reviews rather than waiting for the recertification deadline to discover drift, and keep your audit trail continuously current so that evidence of compliance is available at any point, not just reconstructed right before an assessment.

Organizations that treat Stage 5 seriously generally find recertification far less disruptive than organizations that let their SSP and POA&M go stale between assessments and have to rebuild their compliance picture from scratch every three years.

How Kiteworks Supports Every Stage of the CMMC Roadmap

Kiteworks is built around the specific technical requirements NIST SP 800-171 imposes on organizations handling CUI, supporting nearly 90% of CMMC Level 2 requirements out of the box.

For Stage 2 and 3, Kiteworks consolidates CUI-handling channels — secure email, secure file sharing, managed file transfer, SFTP, and secure data forms — onto a unified policy engine, replacing the fragmented tools and inconsistent policies that make gap assessment and remediation harder than they need to be. AES-256 encryption with FIPS 140-3 validated cryptographic modules and customer-owned encryption keys addresses the System and Communications Protection control family directly.

For Stage 4, a single, consolidated, immutable audit trail across every channel gives assessors — whether self-assessment or C3PAO review — the evidence they need without requiring you to manually assemble logs from disconnected systems.

For Stage 5, that same consolidated audit trail stays continuously current, so recertification becomes a matter of reviewing existing evidence rather than reconstructing your compliance posture from scratch every three years. Kiteworks also holds FedRAMP Moderate Authorization, giving contractors documented control inheritance that compresses assessment scope at every stage of this roadmap.

To see how Kiteworks supports your organization’s specific stage of the CMMC roadmap, schedule a custom demo.

Frequently Asked Questions

Five stages, in sequence: determine your required CMMC level based on the type of data you handle (FCI or CUI); conduct a gap assessment across every system that touches that data; remediate identified gaps and document your security posture in a System Security Plan and Plan of Action and Milestones; verify your compliance through self-assessment or third-party C3PAO certification, depending on your level and program; and maintain compliance on an ongoing basis, including triennial recertification for Level 2 and Level 3. Contractors who work through these stages in order generally have a smoother path than those who try to shortcut gap assessment or documentation under deadline pressure.

Timelines vary significantly based on an organization’s starting security posture, size, and the CMMC level required. Organizations with mature security programs and good documentation practices may complete the process in a few months. Organizations starting with fragmented tools, inconsistent policies, and no formal documentation often need a year or more, particularly for Level 2 certification requiring all 110 NIST SP 800-171 controls. The gap assessment and remediation stages typically consume the most time, since they involve both implementing missing controls and producing documentation an assessor can review.

A System Security Plan (SSP) documents how your organization implements each required security control — it’s a description of your current security posture, control by control, and is the primary document a C3PAO assessor reviews during certification. A Plan of Action and Milestones (POA&M) documents controls that aren’t yet fully implemented, along with specific remediation steps and target dates. Both documents need to be accurate and current; an SSP that describes controls you don’t actually have implemented creates legal exposure under the DoJ’s Civil Cyber-Fraud Initiative, which pursues False Claims Act cases against contractors who misrepresent their compliance posture.

No. CMMC compliance is an ongoing state, not a project with a fixed end date. Level 2 and Level 3 certifications require triennial recertification, and the underlying security controls need to remain implemented and effective between assessments, not just at the moment of certification. Organizations that maintain current documentation, ongoing monitoring, and a continuously updated audit trail throughout the certification cycle generally find recertification significantly easier than organizations that let their compliance posture drift and have to reconstruct it before each assessment.

  • Blog Post CMMC Compliance for Small Businesses: Challenges and Solutions
  • Blog Post CMMC Compliance Guide for DIB Suppliers
  • Blog Post CMMC Audit Requirements: What Assessors Need to See When Gauging Your CMMC Readiness
  • Guide CMMC 2.0 Compliance Mapping for Sensitive Content Communications
  • Blog Post The True Cost of CMMC Compliance: What Defense Contractors Need to Budget For
  • Get started.

    It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

    Table of Content
    Share
    Tweet
    Share
    Explore Kiteworks