When the 32 CFR Part 170 took effect on November 10, 2025, a mid-sized Registered Provider Organization (RPO) supporting defense contractors in aerospace and electronics faced an immediate challenge: 40 active clients, each at different readiness stages, suddenly subject to contractual enforcement timelines they hadn't fully internalized.
By June 2026, seven months into Phase 1, the firm had guided 23 contractors through gap assessments and helped 11 achieve their first CMMC certification. The remaining 17 were still remediating controls. What they learned during that sprint offers a blueprint for any contractor still preparing for the phased rollout.
The Challenge
The RPO's clients spanned the Defense Industrial Base: prime contractors, Tier 2 subcontractors, and small specialty manufacturers. Most handled Controlled Unclassified Information (CUI) and needed Level 2 certification. A few worked only with Federal Contract Information and could self-assess at Level 1.
The issue wasn't awareness. By late 2025, every contractor knew CMMC was coming. The problem was prioritization. Leadership teams treated CMMC as a future obligation, not an immediate constraint. Procurement hadn't updated subcontract templates. IT hadn't scoped assessment boundaries. Compliance officers were waiting for "clearer guidance" before committing budget.
Then solicitations started appearing with CMMC clauses. Contracting officers exercised their Phase 1 discretion to require Level 2 certifications as conditions of award. Three clients discovered CMMC requirements in active bids they'd already submitted. One lost a renewal because they couldn't provide a CMMC Unique Identifier for SPRS tracking.
The firm realized they were managing a coordination failure, not a technical one. Contractors had the budget and intent but lacked a forcing function to align stakeholders and commit resources.
The Environment and Constraints
The RPO operated under several constraints that shaped their approach:
Timeline pressure: Phase 1 runs through November 2026, but Phase 2 begins immediately after, expanding third-party certification requirements. Contractors delaying past mid-2026 faced a compressed window before Phase 2 obligations hit their contract base.
Resource variability: Small contractors (under 50 employees) typically lacked dedicated compliance staff. Mid-sized firms had IT teams but no experience translating NIST SP 800-171 controls into operational practice. Large primes had compliance programs but struggled with assessment scope definition across multiple enclaves.
Subcontractor cascades: Prime contractors couldn't certify until their subcontractors handling CUI also certified. This created dependency chains the RPO had to map and sequence.
SPRS integration: Every contractor needed a CMMC Unique Identifier submitted to the Supplier Performance Risk System before responding to solicitations with CMMC clauses. The 10-character code only gets assigned after an assessment submission, meaning contractors couldn't wait until contract award to start the process.
The Approach Taken
The RPO built a three-track engagement model based on client readiness:
Track 1: Emergency certification for contractors facing imminent bid deadlines. These engagements prioritized assessment scope definition and rapid gap closure on the subset of NIST SP 800-171 controls most commonly deficient: AC-3 (access enforcement), AU-2 (audit logging), CM-7 (least functionality), IA-2 (identification and authentication), and SC-7 (boundary protection). The goal was a passing assessment within 90 days.
Track 2: Structured remediation for contractors with 6-12 months before anticipated CMMC requirements. These clients completed full gap assessments, built remediation roadmaps, and implemented continuous monitoring processes before scheduling formal assessments. This track had the highest pass rate.
Track 3: Subcontractor alignment for primes managing CUI flow-down. The RPO helped primes inventory which subcontractors handled CUI, communicate CMMC obligations, and coordinate assessment timelines to avoid bottlenecks.
Across all tracks, the RPO standardized four internal checkpoints:
- Stakeholder kickoff: Legal, procurement, IT, and compliance in one room, walking through contract obligations and resource commitments.
- Scope validation: Defining assessment boundaries before starting gap work to avoid scope creep during formal assessments.
- SPRS registration: Submitting assessment results and obtaining the CMMC Unique Identifier before the contractor needed it for a proposal.
- Annual affirmation planning: Establishing logging, incident response, and documentation update processes to sustain compliance year-round.
The firm also built a solicitation monitoring service. They tracked Department of Defense contract opportunities for CMMC clause language and alerted clients when relevant solicitations appeared, giving procurement teams advance notice to update proposals.
Results and Metrics
By June 2026, the RPO's client outcomes were:
- 11 contractors achieved CMMC certification and obtained CMMC Unique Identifiers registered in SPRS.
- 23 contractors completed gap assessments and entered active remediation.
- 17 contractors were still closing control gaps, with assessments scheduled for late 2026.
- 3 contractors lost contract opportunities due to missing CMMC status at proposal submission.
The 11 certified contractors reported a consistent pattern: certification took 4-6 months from kickoff to SPRS registration. The longest delays occurred in access control remediation (implementing Role-Based Access Control across legacy systems) and audit logging (configuring centralized log collection for distributed environments).
Contractors who started Track 2 engagements in late 2025 had the smoothest path. Those who waited until they saw a CMMC clause in a solicitation faced compressed timelines and higher remediation costs.
What They Would Do Differently
The RPO identified three operational missteps:
Underestimating subcontractor coordination: Prime contractors consistently underestimated how long it would take subcontractors to achieve certification. The firm now advises primes to begin subcontractor outreach 12 months before they anticipate needing certification, not 6 months.
Delaying SPRS registration: Several contractors completed assessments but delayed submitting results to SPRS because they weren't actively bidding contracts. When solicitations appeared, they scrambled to register and obtain their CMMC Unique Identifier. The firm now treats SPRS registration as part of the assessment deliverable, not a post-assessment task.
Treating continuous monitoring as optional: Contractors who viewed CMMC as a point-in-time certification struggled with annual affirmation planning. The firm now embeds continuous monitoring design into every engagement, ensuring clients have logging, incident response, and documentation update processes operational before their first assessment.
Takeaways for Your Team
If you're still preparing for CMMC certification, here's what this case reveals:
Don't wait for a solicitation. Phase 1 gives contracting officers discretion to include CMMC requirements in any solicitation. You won't get advance notice. If you're bidding Department of Defense contracts in 2026, assume you'll need certification before Phase 2 begins in November 2026.
Scope your assessment now. The longest delays in this case came from contractors who hadn't defined assessment boundaries before starting gap work. Identify which systems handle CUI, map data flows, and document your assessment scope before you engage an assessor.
Treat SPRS registration as a deliverable. You can't respond to solicitations with CMMC clauses until you have a CMMC Unique Identifier registered in SPRS. Don't treat this as administrative paperwork. Build it into your project timeline.
Plan for annual affirmation from day one. CMMC isn't a one-time certification. You'll affirm continuous compliance annually. If you don't have logging, incident response, and documentation update processes in place, you're setting yourself up for a failed affirmation. Design those processes during your first certification cycle.
Coordinate subcontractors early. If you're a prime handling CUI, your certification depends on your subcontractors' certification. Start that coordination now. Don't assume subcontractors are tracking CMMC timelines as closely as you are.
The contractors who succeeded in this case didn't have better technical postures. They had better coordination. They aligned stakeholders, committed resources, and treated CMMC as an operational priority before it became a contract blocker. That's the pattern to replicate.


