The 48 CFR rule published on September 10, 2025, means CMMC requirements start appearing in DoD solicitations and contracts on November 10, 2025. You're not preparing for a future requirement anymore. You're preparing for contract language that determines whether you can bid next quarter.
This playbook walks you through the concrete steps to take between now and your first CMMC-gated solicitation. It's written for security engineers and compliance leads who need to execute, not theorize.
The Problem: Assessment Capacity Doesn't Match Contractor Volume
More than 300,000 contractors need certification. Fewer than 80 accredited C3PAOs exist to assess them. If you wait until a solicitation drops with CMMC 252.204-7021 in the contract clauses, you'll be competing for assessor slots with hundreds of other contractors hitting the same deadline.
The phased rollout (November 2025 through November 2028) doesn't buy you time. It compresses it. Programs can voluntarily include CMMC clauses starting November 10, 2025. Phase 2 begins November 10, 2026, when C3PAO assessments become common in solicitations. That's your real deadline for Level 2 (C3PAO) readiness, and it's 12-18 months away from contract award to certified status if you start from scratch.
What You Need Before Starting
Contractual intelligence:
- List of active DoD contracts and their renewal dates through 2027
- Data flow maps showing which systems touch FCI vs. CUI
- Subcontractor roster with data sensitivity assignments
Technical baseline:
- Current SPRS score (must be submitted within the last three years)
- NIST SP 800-171 Rev 2 SSP documenting your 110 controls
- Asset inventory for all systems processing CUI
Administrative access:
- Login credentials for SPRS
- Contract POC who can interpret data handling clauses in your agreements
- Budget authority for remediation and assessment costs (Level 2 C3PAO assessments typically run $25,000, $75,000 depending on scope)
Determine your required level:
- Level 1: You handle only FCI, basic contract performance data, no technical specs or proprietary information
- Level 2: You handle CUI, technical data packages, export-controlled information, proprietary contractor data marked CUI
- Level 3: Your contract explicitly calls out NIST SP 800-172 or you handle exceptionally sensitive CUI (rare; you'll know if this applies)
Most contractors handling anything beyond administrative contract data will need Level 2.
Step-by-Step Implementation
Step 1: Validate Your SPRS Submission (Week 1)
Log into SPRS and confirm:
- Your most recent self-assessment is dated within the last three years
- The score reflects your current environment (if you've made infrastructure changes, you need a new assessment)
- Each control has a valid POA&M if not fully implemented
If your SPRS score is below 110, document every gap with:
- Control identifier (e.g., 3.1.1, 3.5.2)
- Current implementation status
- Planned remediation date
- Estimated cost
Step 2: Conduct a Gap Assessment Against Your Required Level (Weeks 2-4)
For Level 1, map your practices to FAR 52.204-21 (15 basic safeguarding requirements). For Level 2, assess against all 110 NIST SP 800-171 Rev 2 controls.
Focus on common deficiencies first:
- 3.1.1 (Authorized Access): Do you have documented access authorization for every CUI system user?
- 3.3.1-3.3.9 (Audit Logging): Can you produce tamper-proof logs showing who accessed CUI, when, and what they did?
- 3.5.1-3.5.2 (Identification and Authentication): Are you enforcing multi-factor authentication for all remote access and local access to CUI?
- 3.13.1-3.13.11 (System and Communications Protection): Is CUI encrypted at rest using FIPS 140-2 validated modules?
Document findings in a remediation tracker:
Control | Status | Gap Description | Remediation Action | Owner | Target Date | Cost
3.5.2 | Partial | MFA enforced for VPN but not local workstation login | Deploy Duo or YubiKey for workstation auth | IT Lead | 2025-12-15 | $8K
Step 3: Prioritize and Execute Remediation (Weeks 5-12)
Tackle controls in this order:
Immediate (Weeks 5-6):
- Encrypt CUI storage (3.13.16): Enable BitLocker or LUKS on endpoints; verify encryption at rest on cloud storage
- Document access authorizations (3.1.1): Create a user access matrix with manager approvals
- Enable audit logging (3.3.1): Configure Windows Event Forwarding or deploy a SIEM to centralize logs
Short-term (Weeks 7-10):
- Deploy MFA (3.5.3): Roll out hardware tokens or authenticator apps for all users with CUI access
- Implement session controls (3.1.10): Configure 15-minute session lock on workstations and VDI
- Establish incident response capability (3.6.1): Draft an IR plan, assign roles, conduct a tabletop exercise
Medium-term (Weeks 11-12):
- Conduct vulnerability scanning (3.11.2): Deploy Tenable or Rapid7; schedule monthly authenticated scans
- Harden configurations (3.4.1-3.4.9): Apply STIGs or CIS benchmarks to Windows/Linux systems
- Document your SSP: Update NIST 800-171 SSP with implemented controls and evidence pointers
Step 4: Update SPRS with Remediated Controls (Week 13)
After remediation:
- Log back into SPRS
- Update each control's implementation status
- Attach or reference evidence (policies, configs, logs)
- Submit the updated assessment
Your new score should reflect closed gaps. If you're at 110/110, you're ready for C3PAO assessment. If not, document remaining POA&Ms with realistic completion dates.
Step 5: Engage a C3PAO (Week 14)
If you need Level 2 (C3PAO), contact assessors now. Ask:
- Current lead time for scheduling (expect 8-12 weeks minimum)
- Assessment scope (which facilities, systems, and enclaves)
- Pre-assessment readiness review availability
- Cost estimate and payment terms
Schedule your assessment for at least 60 days out to allow for pre-assessment prep and any last-minute fixes the C3PAO identifies during scoping.
Validation: How to Verify It Works
Before your C3PAO assessment, run these checks:
Access control validation:
- Attempt to log into a CUI system without MFA, it should fail
- Check user access list against HR roster, no orphaned accounts should exist
Audit log verification:
- Pull logs for the last 30 days
- Confirm you can identify: user, timestamp, action, system
- Verify logs are write-protected (test: attempt to delete a log entry as a standard user)
Encryption check:
- Run
manage-bde -statuson Windows orlsblkon Linux to confirm disk encryption - Verify FIPS 140-2 mode is enabled: check certificate numbers against NIST CMVP database
Incident response test:
- Simulate a Controlled Unclassified Information spill (e.g., email attachment sent to wrong recipient)
- Confirm your team follows the IR plan and reports to DoD within 72 hours per DFARS 252.204-7012
If any check fails, remediate before the C3PAO arrives.
Maintenance: Ongoing Tasks
CMMC isn't one-and-done. After certification:
Monthly:
- Review SPRS score; update if controls change
- Run vulnerability scans; remediate high/critical findings within 30 days
- Audit user access; remove terminated employees within 24 hours
Quarterly:
- Test incident response plan (tabletop or simulation)
- Review Audit Logging for anomalies
- Update SSP if systems or processes change
Annually:
- Renew Level 1 self-assessment (if applicable)
- Conduct Self-Assessment against NIST 800-171 to prepare for triennial C3PAO re-assessment
Trigger events:
- New contract with different CMMC level: re-scope and assess
- Subcontractor onboarding: verify their CMMC status before granting CUI access
- Significant system change (cloud migration, new enclave): update SSP and potentially re-assess affected controls
Track these tasks in a compliance calendar. Missing a renewal or letting your SPRS score lapse can disqualify you from bidding even if you were previously certified.
The November 10 effective date isn't theoretical. Solicitations with CMMC clauses are already in draft. If you start this playbook today, you'll have a defensible SPRS score, documented controls, and an assessment slot reserved before your competitors realize the queue is full.



