Editor’s note (updated July 16, 2026): On July 13, 2026, the Department of Defense suspended CMMC Phase 2, including the November 10, 2026 start date for third-party (C3PAO) assessments. A 60-day review is underway and all Phase 2 milestones are on hold until further notice. CMMC Phase 1 self-assessment stays in force. We updated this article to reflect the suspension. We will update it again when DoD announces the review’s outcome. For current status, check dodcio.defense.gov/CMMC.
The short answer: C3PAO (CMMC Third-Party Assessment Organization) wait times run about 4 to 6 months once you need an assessment. The November 2026 deadline that made this urgent is on hold as of July 13, 2026. If a current contract requires a Level 2 certification, the process below still applies to you. If not, you have time. Use it to raise your NIST 800-171 score, the self-assessment score for your required security controls.
CMMC stands for Cybersecurity Maturity Model Certification. It is the Department of Defense program that checks whether contractors protect sensitive information. This guide explains how a CMMC Level 2 C3PAO assessment works. It also covers how to find and vet a C3PAO, and what the process costs and takes. Phase 1, the self-assessment stage, started November 10, 2025, and stays active. Phase 2 would have added a required third-party C3PAO assessment for most Level 2 contracts starting November 10, 2026. DoD suspended that start date on July 13, 2026. Read the short answer above to see whether the steps below apply to you right now.
What a C3PAO Actually Does
For CMMC Level 2 contracts that require a third-party assessment, an accredited C3PAO is the only organization DoD authorizes to conduct it. CUI (Controlled Unclassified Information) is the sensitive government information these contracts protect. It is not classified, but it still needs protection under NIST SP 800-171 security rules.
Self-assessment is allowed for a small subset of Level 2 contracts that DoD designates as non-prioritized under 32 CFR 170.16. DFARS 252.204-7021 is the Defense Federal Acquisition Regulation Supplement clause that adds cybersecurity requirements to DoD contracts. If your contract includes that clause with a Level 2 requirement, assume you need a C3PAO. Check with your contracting officer if you are not sure.
You cannot hire a general IT firm, or even a well-known cybersecurity consultant, to run this assessment. Only an accredited C3PAO can do it.
Here is how the network works, start to finish:
- Cyber AB accredits the C3PAO. Cyber AB (the Cybersecurity Maturity Model Certification Accreditation Body) is the non-profit body DoD authorized to accredit assessor organizations. Without Cyber AB accreditation, an organization has no legal authority to assess. Cyber AB maintains the public list of accredited C3PAOs on its marketplace.
- The C3PAO assigns CCAs and CCPs to your assessment. CCAs (Certified CMMC Assessors) are the credentialed individuals who conduct your assessment. CCPs (Certified CMMC Professionals) support the process. A C3PAO is the organization. CCAs and CCPs are the people inside it who do the work.
- The assessment package goes back to Cyber AB. After your assessment is complete, the C3PAO submits the results to Cyber AB for validation. This step can add weeks to the timeline.
- Results post to SPRS. SPRS (Supplier Performance Risk System) is the DoD portal where your certification status is recorded. Contracting officers check SPRS to verify compliance on contracts that include DFARS 252.204-7021.
One more term to know: POA&M stands for Plan of Action and Milestones. It is a documented list of security controls you have not yet implemented, along with your plan to implement them. C3PAOs look at your POA&M as part of the assessment process.
The 80-vs-80,000 Problem
Cyber AB’s marketplace listed just over 100 accredited C3PAOs in mid-2026. Check the current count directly at cyberab.org, since new accreditations are added most months.
DoD’s own regulatory impact analysis for the 32 CFR Part 170 final rule estimates that more than 80,000 defense contractors handle CUI. All of them will eventually need CMMC Level 2 certification. That is a roughly 1,000-to-1 ratio of contractors to C3PAOs.
Not every C3PAO operates at national scale. Many focus on specific regions or industries. Some specialize in manufacturing, others in IT services. Each C3PAO can only schedule so many assessments per quarter, based on how many credentialed CCAs it has on staff.
This shortage is one reason DoD gave for suspending Phase 2 on July 13, 2026. The department pointed to the gap between the number of accredited assessors and the number of contractors who will eventually need certification. The 60-day task force review is looking at how to close that gap before Phase 2 resumes.
None of this changes the wait time itself. C3PAO wait times still run 4 to 6 months from initial RFQ (request for quote) to certification. What changed is the deadline that made the timing urgent. There is no live Phase 2 start date right now, so there is no fixed date to work backward from. If your contract already requires Level 2 certification, the 4 to 6 month wait time still applies. The same is true once DoD sets a new Phase 2 date. Plan around it.
How to Find C3PAOs Near You
The Cyber AB Marketplace is the authoritative source. Go to cyberab.org/Catalog/CMMC-Marketplace and follow these steps:
- Search by state. The marketplace includes a location filter. Start with your own state, then expand to neighboring states. Many C3PAOs conduct remote portions of assessments, so geography matters less than availability and price.
- Check active status. Look for C3PAOs listed as “Active” or “Accredited.” Some listings reflect organizations still in process. You want a fully accredited C3PAO with the authority to conduct assessments today.
- Review their capability description. Some C3PAOs specialize in certain sectors, such as defense manufacturing, software, or IT services. If your business is in a specific sector, look for assessors with relevant experience.
- Check CCA staffing. A C3PAO is only as capable as its credentialed assessors. Ask directly how many CCAs are on staff and their current availability. A C3PAO with two CCAs can only run so many assessments at once.
- Contact at least three C3PAOs. Pricing, timelines, and approach vary. Getting multiple quotes protects you from paying above market, and gives you options if one firm is fully booked.
Do not limit your search to the largest or most visible names. Smaller regional C3PAOs often have better availability and are more responsive to small business clients.
The RFQ Email: What to Send
Send this email to each C3PAO on your short list. Fill in the bracketed fields with your specifics. Keep it clean and factual. C3PAOs receive a lot of vague inquiries. The more specific your email, the faster they will respond with a real quote.
Subject: CMMC Level 2 Assessment RFQ for [Your Company Name] Hello, We are requesting a quote for a CMMC Level 2 assessment for [Company Name], a [state] company providing [brief description of services] to the Department of Defense under NAICS [your NAICS code(s)]. Key details: - Contract type: [Prime / Subcontractor] - Prime contractor(s): [Name if subcontractor] - CUI scope: We handle CUI in [describe: email, files, engineering drawings, etc.] - CMMC Level required: Level 2 (110 controls per NIST SP 800-171) - Approximate number of employees: [number] - IT environment: [Cloud-based / On-premise / Hybrid], [number] endpoints - External service providers (MSPs, cloud platforms): [list if any] - Current SPRS score: [score, or "not yet submitted"] - SSP status: [Complete / In progress / Not started] - POA&M items remaining: [number, or "none"] - Target certification date: [date your contract requires, or "flexible, no set date yet"] We are requesting: 1. Your available assessment windows for the next two quarters 2. Estimated total cost (assessment only) 3. Whether you offer a pre-assessment readiness review and at what cost 4. Your CCA staffing model for an engagement of our size We are contacting multiple C3PAOs and aim to select one within two weeks. Please reply to [your email] or call [phone number]. Thank you, [Your Name] [Title] [Company] [Phone]
Attach your SSP (System Security Plan) table of contents, or a one-page summary of your CUI environment if you have one ready. It signals that you are a serious prospect and speeds up the quoting process. Do not send your full SSP in the initial inquiry.
Five Questions to Ask Before Signing
Before you sign an engagement agreement with any C3PAO, get clear answers to these five questions. They separate prepared assessors from ones who will create problems later.
- How many CCAs will be assigned to our assessment, and what are their backgrounds? Ask for the specific people, not just the number. A CCA with a manufacturing background and a CCA with a software background bring different depth to different environments. You want someone who understands your work.
- How do you handle the eMASS submission step? After your assessment, the C3PAO enters your results into the CMMC instance of eMASS (Enterprise Mission Assurance Support Service). eMASS is the DoD system that records CMMC assessment results. From there your status flows to SPRS. A C3PAO that is not fluent in the current submission process can create delays at this step. Ask how they handle submission, and how long their recent submission-to-results timelines have run.
- What is included in the assessment fee, and what triggers additional charges? Some C3PAOs charge a flat fee. Others charge by day or by the number of assets assessed. Get a clear scope statement. Common add-ons include travel, additional interview sessions, and POA&M review. Know what you are buying.
- Do you offer a pre-assessment readiness review, and do you recommend it? A pre-assessment is an informal review that identifies gaps before the formal assessment starts. Not all C3PAOs offer it. For companies new to a Level 2 assessment, a pre-assessment often pays for itself. It reduces the number of deficiencies found during the formal assessment.
- What happens if we fail practices during the assessment? Ask about their process when a gap is found. Do they give you time to remediate during the assessment? What goes into the final report to Cyber AB? How do conditional certifications work? Understanding their process before you start prevents surprises mid-assessment.
Four Readiness Milestones C3PAOs Check Before Scheduling
Most C3PAOs will not schedule a formal assessment until your business clears four basic readiness milestones. Trying to schedule before you reach these is a common mistake that wastes time and money.
Milestone 1: All 110 controls implemented or documented in a POA&M. NIST SP 800-171 (National Institute of Standards and Technology Special Publication 800-171) lists 110 security requirements for protecting CUI. Each control must be fully implemented, or covered by a POA&M with a credible remediation date. A C3PAO will not assess what does not exist.
Milestone 2: A current SPRS self-assessment on file. Your SPRS score comes from your NIST 800-171 self-assessment. A score of 110 means all controls are implemented. A lower score is acceptable, but you need a documented self-assessment and a credible POA&M. C3PAOs want evidence that you have tracked your own posture honestly.
Milestone 3: A documented System Security Plan. Your SSP (System Security Plan) describes how your organization protects CUI. It covers your system boundary, hardware and software inventory, user roles, and how each control is implemented. The SSP is the first document a CCA reviews. If it is not complete, the assessment cannot begin.
Milestone 4: At least one internal readiness walk-through complete. Before the formal assessment, walk through your environment against the 110 controls at least once. This catches documentation gaps and scope boundary questions that are far cheaper to fix before assessment day than after. Your C3PAO may offer a formal pre-assessment review as a paid service.
Get to all four milestones before you schedule. An assessment you enter underprepared costs the same as one you enter ready. Your probability of passing does not.
C3PAO Wait Times: Cost and Duration
Assessment cost: The 32 CFR Part 170 final rule regulatory impact analysis provides cost estimates for CMMC assessments. For small businesses, third-party assessments are estimated at $40,000 to $80,000 (estimate). That range covers the formal assessment only. It excludes travel, pre-assessment reviews, and remediation support. Larger organizations with complex IT environments should expect quotes above this range.
Factors that drive quote variation:
- Number of assets in scope (endpoints, servers, cloud instances)
- Number of people who access CUI
- Whether your IT environment is entirely cloud-based or includes on-premise infrastructure
- Number of external service providers (MSPs, cloud platforms) that need to be assessed as part of your boundary
- Geographic location, and whether the assessors must travel to your site
Timeline: From the day you send your first RFQ to the day your certification posts in SPRS, plan for 4 to 6 months. That timeline breaks down roughly as follows:
- Weeks 1-3: RFQ sent, quotes received, C3PAO selected, engagement agreement signed
- Weeks 4-8: Pre-assessment readiness review (if conducted), SSP review, scope finalization
- Weeks 9-16: Formal assessment conducted (on-site and remote sessions)
- Weeks 17-24: Assessment package compiled, submitted to Cyber AB, Cyber AB review, results posted to SPRS
The Cyber AB submission-to-results step can add 4 to 8 weeks to the back end of the timeline. That step could take longer once Phase 2 resumes and submission volume rises across the industry. Build the buffer into your plan now, even without a fixed deadline.
Frequently Asked Questions
What is the difference between a C3PAO and a CCA?
A C3PAO (CMMC Third-Party Assessment Organization) is the company authorized to conduct CMMC assessments. A CCA (Certified CMMC Assessor) is the individual within that company who holds the credential to perform the assessment. You contract with the C3PAO. The C3PAO assigns CCAs to your engagement. Both the organization and the individuals must hold current Cyber AB credentials.
Can I do a CMMC Level 2 self-assessment instead of hiring a C3PAO?
Not if your contract requires Level 2 certification for CUI on a prioritized program. In that case, CMMC Level 2 requires a third-party assessment by an accredited C3PAO. Self-assessment is allowed only for CMMC Level 1 (15 practices drawn from FAR 52.204-21 basic safeguarding requirements). It is also allowed for a small subset of Level 2 contracts DoD designates as non-prioritized. As of July 13, 2026, DoD has suspended the broad Phase 2 rollout. That rollout would have added the third-party requirement to new solicitations by default. If your specific contract already names a Level 2 third-party requirement, that requirement still applies. If it does not, no new requirement is active right now.
How long is a CMMC Level 2 certification valid?
A CMMC Level 2 certification is valid for three years from the CMMC Status Date associated with the assessment. Under 32 CFR 170.17(a)(1), that is the date Cyber AB posts the results to SPRS. After three years, you must go through a full reassessment. Annual affirmations are required in years one and two to confirm your security posture has not materially changed since the initial assessment.
What happens if my SPRS score is below zero when I contact a C3PAO?
A negative SPRS score means your self-assessment found deficiencies against the 110 NIST 800-171 controls. That does not disqualify you from starting the assessment process, but it does mean you have remediation work ahead. Most C3PAOs will want to see a credible POA&M and evidence that you are actively working toward full implementation. They want this before they schedule your formal assessment. A score of zero or below at the time of the formal assessment will likely result in a conditional certification or a failed assessment. The outcome depends on the nature and number of gaps.
How does a C3PAO submit my assessment results?
After your assessment, the C3PAO enters your results into the CMMC instance of eMASS (Enterprise Mission Assurance Support Service). eMASS is the DoD system that records CMMC assessment results, using the CMMC assessment data standard. From eMASS, your status flows to SPRS, where contracting officers can verify it. Ask any C3PAO you evaluate how they handle this submission step, and what their recent submission-to-results turnaround has been. It affects your timeline.
Can a C3PAO also help me get ready for the assessment?
Some C3PAOs offer pre-assessment readiness consulting or gap analysis as a separate service from the formal assessment. Others keep a strict separation between consulting and assessment to avoid conflicts of interest. Ask each C3PAO you contact whether they offer readiness support. If not, ask whether they can recommend a CMMC Registered Practitioner Organization (RPO). RPOs are separate from C3PAOs, but also listed in the Cyber AB Marketplace.
Is there still a Phase 2 deadline?
No. DoD suspended the November 10, 2026 Phase 2 start date on July 13, 2026. A 60-day CMMC Reform Task Force review is underway. DoD has not announced a new date, and we do not know what the review will recommend. Check dodcio.defense.gov/CMMC for the current status before you make a scheduling decision.
New to CMMC? Start with CMMC Certification for Small Businesses for a full breakdown of what certification costs and requires. We are updating our companion CMMC Level 2 cost guide to reflect the Phase 2 suspension as well.