CMMC Remediation Services: How to Close Your Gaps Without Hiring the Wrong Provider
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance — not affiliated with, endorsed by, or acting on behalf of the Department of Defense, the Cyber AB, the CAICO, DCMA DIBCAC, NIST, or any U.S. government agency. This is educational content, not legal, contractual, cybersecurity, or compliance advice. Please don't submit CUI, contract numbers, system diagrams, vulnerability details, or any sensitive security information through any form on this site.
CMMC remediation servicesare the hands-on work of closing the gap between your current security posture and the cybersecurity your defense contracts actually require — implementing missing controls, writing your System Security Plan (SSP) and Plan of Action & Milestones (POA&M), standing up tools, and raising your score in the Supplier Performance Risk System (SPRS), the Department of Defense database that stores CMMC statuses and self-assessment results. If you handle Controlled Unclassified Information (CUI), you're in Level 2 territory: 110 requirements across 14 control families, verified by self-assessment or a third-party C3PAO assessment depending on your contracts.
The answer changes if you only handle Federal Contract Information (FCI) under Level 1(15 requirements from FAR 52.204-21, self-assessed annually, all requirements MET, no POA&Ms), or if you already score 88 or higher and simply need an assessor. Use the table below to find yourself fast.
Start here: find your situation
| If this is you | You probably need first | Don't start with | Your next move |
|---|---|---|---|
| You handle only FCI (Level 1) | An internal owner, light readiness help if any | A C3PAO | Confirm the 15 FAR 52.204-21 safeguards and file your annual affirmation |
| You handle CUI but have no real SSP | An RPO / readiness lead | A C3PAO | Lock scope, build the SSP, POA&M, and an evidence map |
| Your SPRS score is low, negative, or stale | A readiness lead + technical remediation | A certification assessor | Turn gaps into a prioritized, owner-assigned plan |
| Your MSP says "we do CMMC" but can't show evidence | A CMMC-capable MSP/MSSP + readiness lead | A software-only fix | Verify they map work to NIST 800-171 objectives |
| CUI is scattered across email, drives, endpoints | A scoping/enclave strategy | Migrating everything before scoping | Decide whether to shrink scope before you buy tools |
| You already score 88+ and are ready to certify | A separate, authorized C3PAO | The same consultant who prepped you | Run final independence and evidence checks |
Not sure which row you're in?
Tell us your level, scope, environment, and timeline — without submitting any CUI — and we'll match you with source-checked CMMC provider options that fit.
Find my remediation path →What are CMMC remediation services?
CMMC remediation services close the gaps that stand between your current environment and a passing CMMC status — bad scoping, missing NIST SP 800-171 controls, thin SSP and POA&M documentation, weak evidence, and the wrong environment for CUI. It's the doing phase. It sits between the gap assessment (which finds the problems) and the formal assessment (which verifies they're fixed). For Level 2, “done” means you've actually implemented the 110 NIST SP 800-171 Revision 2 requirements, documented them in an SSP, and produced evidence an assessor can verify.
Remediation is not one service. It's a sequence — scope, document, implement, prove, operate — and different parts of that sequence are best handled by different kinds of providers. Treating it as a single thing you buy from one vendor is how budgets blow up and certifications get delayed.
Where remediation fits in the CMMC process
| Phase | What happens | Who typically leads | What you walk away with |
|---|---|---|---|
| 1. Gap assessment | Map your CUI/FCI, score against NIST 800-171, identify findings | RPO / readiness consultant | A scored gap register and a baseline SPRS score |
| 2. Remediation | Fix the findings: controls, SSP, POA&M, tooling, evidence | RPO + MSP/MSSP / enclave / GRC | A defensible environment and an evidence package |
| 3. Assessment | Self-assessment, or a formal C3PAO assessment if required | You, or a separate C3PAO | A CMMC status posted in SPRS |
What a real remediation engagement includes
Remediation breaks into a handful of workstreams. A credible provider can tell you which ones they own, which ones they don't, and what proof each one produces.
| Workstream | Examples of the work | Evidence it produces | Best-fit provider |
|---|---|---|---|
| Scoping | CUI/FCI data-flow mapping, asset inventory, defining the boundary | Data-flow diagram, asset inventory, SSP scope | RPO / readiness lead |
| Documentation | SSP, POA&M, policies, procedures | Updated SSP, control narratives, POA&M | RPO / RP-led consultant |
| Technical controls | MFA, logging, EDR, configuration, vulnerability management | Configs, screenshots, log reports, tickets | MSP / MSSP |
| CUI environment | GCC High, AWS GovCloud, enclave, secure collaboration | Architecture, responsibility matrix, SSP updates | Enclave / cloud implementer |
| Evidence workflow | Evidence collection, owner tracking, recurring reviews | Evidence repository, task history, affirmation calendar | GRC / workflow software |
| Assessment readiness | Mock assessment, objective-by-objective review | Readiness findings, remediation punch list | RPO / readiness lead |
Do you actually need CMMC remediation right now?
You need CMMC remediation when a gap assessment, a low or stale SPRS score, a prime's flow-down, a solicitation clause, or an internal CUI review shows your environment doesn't meet the CMMC level your contracts require. Under the program rule — 32 CFR Part 170, effective December 16, 2024 — CMMC applies to any contractor information system that processes, stores, or transmits FCI or CUI, and the required level is written into the solicitation and the contract.
Here's the detail that surprises people, and the reason “we'll deal with it when our prime asks” is a dangerous plan: the eligibility decision happens before you're awarded anything. A solicitation provision called DFARS 252.204-7025 (“Notice of Cybersecurity Maturity Model Certification Level Requirements,” effective November 10, 2025)tells offerors which level the contract requires. Per 48 CFR 252.204-7025, if you don't have the current required CMMC status at the time of offer, you are ineligible for award — full stop. Remediation isn't something you do after you win; it's what determines whether you can compete.
Which DFARS clauses matter during remediation?
| Clause | What it does | Why it matters during remediation | Primary source |
|---|---|---|---|
| 252.204-7012 | Safeguarding covered defense information and cyber incident reporting; baseline obligation to implement NIST SP 800-171 | This is the underlying duty CMMC verifies; FedRAMP-equivalency for cloud handling CUI traces here | Acquisition.gov |
| 252.204-7019 | Requires a current (within 3 years) NIST SP 800-171 DoD Assessment posted in SPRS to be eligible for award | Your baseline SPRS score lives here; remediation raises it | Acquisition.gov |
| 252.204-7020 | Government access for higher-level assessments; flow-down of the assessment requirement to subcontractors | Sets up DoD/DIBCAC's right to verify your work | Acquisition.gov |
| 252.204-7021 | The CMMC contract clause: requires holding the required CMMC status and affirmation during performance, and flow-down | The ongoing obligation once you win | Acquisition.gov |
| 252.204-7025 | Solicitation provision notifying offerors of the required CMMC level; no current status = ineligible for award | The gate you must clear before award | Acquisition.gov / 48 CFR 252.204-7025 |
The timing math you can't argue with
Two dated facts make the urgency real, not manufactured:
- Phase 1 runs November 10, 2025 through November 9, 2026; Phase 2 begins November 10, 2026.That's the point in the phased rollout (defined at 32 CFR 170.3) when DoD intends to require a Level 2 third-party (C3PAO) certification as a condition of award for applicable contracts — not just a self-assessment — though DoD may delay that requirement to an option period at its discretion. Phase 1 (self-assessments) has been live since November 10, 2025.
- There aren't enough assessors yet. DoD estimates about 8,350 medium and large entities will be required to meet Level 2 C3PAO assessment requirements as a condition of contract award (per the program rulemaking in the Federal Register), and projected only about 135 C3PAO-led certification assessments in the first year, ramping to 4,452 by year four. Against that, a March 2026 analysis of the Cyber AB Marketplace counted roughly 103 authorized C3PAOs. (Re-verify the live count before relying on it; it changes monthly.)
Put those together with a 6-to-12-month remediation timeline, and the picture is simple: if you need a certified posture for a 2027 opportunity, mid-2026 is not early. It's about right — and possibly tight.
What just happened that sent you here
| Trigger | What it means | First remediation move |
|---|---|---|
| New solicitation with DFARS 252.204-7025 | The contracting officer has named a required level; no status = no award | Confirm the exact level and assessment type, then scope |
| Prime flowed down CMMC language | Your status now gates your subcontract | Get the required level and information type in writing |
| Low / negative / stale SPRS score | Your documented posture fails the threshold | Convert findings into a prioritized plan |
| Gap assessment delivered | You have a punch list, not a plan | Sequence the work and assign owners |
| You scheduled a C3PAO too soon | You may pay for an assessment you'll fail | Pause; build readiness first |
| You found CUI in email, drives, or endpoints | Your scope is bigger than you thought | Map data flows before buying anything |
One honest disqualifier
If you handle only FCI and your contracts require Level 1, you likely don't need a remediation program in the sense this page describes. Level 1 is 15 requirements from FAR 52.204-21, self-assessed annually with an affirmation, all of which must be MET — and POA&Ms aren't permitted at Level 1 at all. Confirm your basics, file your affirmation, and skip the six-figure conversation. See our CMMC Level 1 vs Level 2 guide if that's you.
Get matched before the queue tightens
If you handle CUI and have open gaps, the smart move is to start now. Send us the non-sensitive basics — level, scope, environment, timeline — and we'll point you to source-checked provider categories that fit, so you don't lose weeks guessing.
Find my remediation path →How much do CMMC remediation services cost in 2026?
For CMMC Level 2, remediation typically runs $10,000 to $150,000+, and it's the single largest and most variable cost in the whole effort. Your number depends on your starting SPRS score, the size of your CUI scope, your environment (commercial Microsoft 365 vs. GCC High vs. an enclave), and how much of the work you can do in-house. Small businesses generally land near $50,000–$130,000 all-in for Level 2; mid-size firms, $100,000–$200,000.
We'll be straight with you: there is no honest flat price for remediation. Anyone who quotes you a fixed number before mapping your CUI and scoring your gaps is guessing. The cost lives in what's broken, and nobody knows that until someone looks. That's not a dodge — it's the reason a gap assessment comes first.
What remediation actually costs, by component
DCR market-planning estimate, last verified June 3, 2026. Compiled from multiple 2026 cost analyses and DoD's own published estimates. Planning ranges, not quotes.
| Cost component | Typical 2026 range | Notes |
|---|---|---|
| Gap / readiness assessment | $3,500 – $40,000 | RPO small-business work often $5K–$10K; complex environments $15K–$25K+ |
| SSP + documentation | $5,000 – $60,000 | DIY $5K–$15K; consultant-built $15K–$40K; full packages higher |
| Control implementation (the labor) | $10,000 – $150,000+ | The big variable; some complex Level 2 efforts reach $250K |
| Tooling / licensing (MFA, SIEM, EDR, scanning, encryption) | $10,000 – $50,000+ /yr | Recurring, not one-time |
| CUI enclave / secure collaboration | $300–$400 /user/mo, or $3,000–$4,000+ /mo managed | Scales with users or managed scope |
| vCISO / fractional compliance lead (if used) | $250–$400 /hr; $50K–$300K full programs | Direction and accountability |
| Ongoing maintenance | ~15–30% of initial, annually | Affirmations, monitoring, renewals |
Level 3 is not a simple add-on
It requires reaching Final Level 2 (C3PAO) status first, then a government DIBCAC assessment against 24 additional requirements selected from NIST SP 800-172. Budget it as its own program, not a line item.
A few things that genuinely move your number, up or down:
- Scope drives cost more than headcount. A 20-person shop with CUI everywhere can cost more than a 100-person shop that isolated CUI into a small enclave. Reducing scope is the single biggest lever most companies have.
- Starting posture is everything. Organizations with mature security spend dramatically less on the labor line than those starting from a negative SPRS score.
- Inherited controls help. If your cloud is FedRAMP-authorized, you inherit some controls, which shrinks your documentation and implementation burden.
- Cheap can get expensive. A tool you bought before scoping, or a consultant who can't map work to assessment objectives, often becomes a re-do.
Free and lower-cost help for small businesses
Before you spend, check the free or lower-cost help that exists for the DIB: APEX Accelerators (DoD-funded procurement assistance), Project Spectrum (a DoD-sponsored cybersecurity readiness platform), and the NIST Manufacturing Extension Partnership (MEP) network support small-business cybersecurity readiness. See also our guide to CMMC for small defense contractors.
Request scoped quotes by category, not guesswork
Tell us what you already have — an SSP, a POA&M, your current environment, your provider, and your deadline — and we'll help you identify source-checked options in the right category so the quotes you collect are actually comparable.
Find my remediation path →Who should do your CMMC remediation: RPO, MSP/MSSP, vCISO, enclave, GRC software, or C3PAO?
The right provider depends on the bottleneck, not the marketing label. Scope and documentation problems need advisory help (an RPO or readiness lead). Missing technical controls need an implementer (a CMMC-capable MSP/MSSP). CUI spread everywhere may need an enclave strategy. Scattered evidence may need GRC software. And formal certification needs a separateC3PAO. Match the provider to the gap that's actually blocking you.
The CMMC Remediation Provider-Fit Matrix
DCR editorial conclusion based on verified regulatory facts — reflects how we'd sequence the work, not a regulatory ordering of providers.
| Your actual problem | Best first provider category | What they should produce | What they should not claim | How to verify |
|---|---|---|---|---|
| You don't know if your data is FCI, CUI, or both | Scoping-led RPO / readiness consultant | CUI/FCI data-flow map, asset inventory, boundary recommendation, SSP scope | "We can certify you" or "just buy this platform" | CMMC applies to systems handling FCI/CUI; the contract names the level (32 CFR Part 170) |
| You handle CUI and have no defensible SSP | RPO / readiness consultant | SSP, POA&M, gap register, evidence map, control-owner map | A formal certification assessment | NIST SP 800-171 Rev. 2 requires documented implementation; DFARS 7019/7020 govern SPRS scoring |
| Technical controls are missing or weak | CMMC-capable MSP/MSSP + a readiness lead | MFA, logging, EDR, configuration, vulnerability, backup, incident-response evidence | "Installing the tool means you're CMMC-ready" | Level 2 = 110 requirements across 14 families; evidence must map to objectives (NIST SP 800-171A) |
| CUI is sprawled across email, drives, endpoints, vendors | CUI enclave / GCC High / GovCloud provider + a scoping lead | Reduced-scope design, responsibility matrix, data-flow map, SSP updates | "An enclave is a shortcut to certification" | Level 2 scoping defines asset categories per 32 CFR §170.19 |
| Evidence is scattered and tasks slip | GRC / evidence software + a readiness owner | Evidence repository, POA&M workflow, owner accountability, affirmation calendar | "The software implements the controls for you" | Artifacts, SSP, POA&M, and affirmations must be supportable in SPRS |
| You already score 88+ and are assessment-ready | A separate authorized / accredited C3PAO | Formal Level 2 assessment, findings report, status in SPRS | Helping you prepare for the same assessment it will conduct | C3PAO must be current on the Cyber AB Marketplace |
| You hold Conditional Level 2 with an open POA&M | Your remediation owner + the applicable closeout path | Closed POA&M items, updated evidence, closeout package | "A POA&M can cover anything, indefinitely" | Conditional status requires POA&M closeout within 180 days (32 CFR 170.21) |
A quick tour of the categories
Registered Provider Organization (RPO)
A consultancy listed on the Cyber AB Marketplace whose people (Registered Practitioners, or RPs, and often Certified CMMC Professionals/Assessors) provide preparation and advisory services. RPOs are your scope, SSP, POA&M, and readiness leads. They cannot issue your certification. See our comparison of RPOs vs. C3PAOs.
CMMC-capable MSP / MSSP
A managed service or managed security provider that actually builds and runs the technical controls — identity, logging, endpoint protection, configuration. Important: an MSP that handles your CUI becomes an External Service Provider (ESP) in your scope, with documentation and assessment obligations. Evaluate MSPs by what they can access, not their marketing category.
vCISO / fractional compliance lead
Strategy, prioritization, and accountability when you have IT but lack direction. Often the cheapest way to keep a program from drifting.
GRC / compliance software
Tools that automate documentation, evidence collection, and POA&M tracking. A genuine help — and a genuine trap if you mistake it for the whole solution. Software doesn't implement controls or pass assessments.
CUI enclave / secure collaboration
GCC High, AWS GovCloud, or a purpose-built CMMC enclave — the most powerful scope-reduction lever available to most companies. Isolating CUI into a controlled environment can shrink what must be protected and assessed. It doesn't eliminate the need for an SSP, evidence, or control implementation.
C3PAO
A CMMC Third-Party Assessment Organization, authorized by the Cyber AB to conduct Level 2 certification assessments. This is the only entity that can certify you for a Level 2 (C3PAO) contract — and, as you'll see next, it generally cannot also be the firm that prepared you. See our guide to finding an authorized C3PAO.
Compare provider categories before you spend a dollar
Send only the non-sensitive basics — level, scope, current environment, timeline — and we'll point you to the remediation category that fits your bottleneck, so you're not paying a documentation specialist to fix firewalls.
Find my remediation path →Can one company handle both your remediation and your assessment?
Why the firewall exists
The logic is simple: a firm that assessed a client it had just consulted for would be grading its own homework. Impartiality is the whole point of a third-party certification. If the line blurs, the certification means nothing — and an assessment performed in a conflict can be challenged, which is far more expensive than doing it right the first time.
What this actually means for choosing a partner — and why it's good for you
The dream of “one vendor does everything” is exactly the wrong instinct here. Instead:
- Choose a remediation partner that hands you off cleanly and will document the separation between readiness and assessment.
- Treat any “we'll fix you andcertify you” pitch as a red flag.It signals either a misunderstanding of the rule or a willingness to bend it — and either way, your certification is what's at risk.
- Know the one compliant model: an RPO or MSP prepares you; a separate, authorized C3PAO assesses you. Some organizations hold multiple roles in the ecosystem, but the same firm and assessors can't prepare you and then sit on your Level 2 certification within that three-year window.
Separate readiness from assessment the right way
Want it handled end-to-end without tripping the conflict rule? We'll match you with a readiness partner to close your gaps and help you line up an independent C3PAO for the assessment — two clean engagements, one path.
Find my remediation path →What should a CMMC remediation plan look like?
A real CMMC remediation plan maps every gap to a specific requirement, the system it affects, an owner, the evidence that will prove it's fixed, a due date, and the consequence if it's not closed. It is not a wish list. A POA&M only counts under strict rules — Conditional Level 2 and Level 3 status depend on closing valid POA&M items within 180 days, and Level 1 doesn't permit POA&Ms at all (32 CFR 170.21). If your “plan” is a spreadsheet of vague intentions, it won't survive an assessment.
The difference between a punch list and a plan is ownership and evidence. Here's the structure we recommend, and what a few rows look like in practice.
Remediation plan template
| Gap | Requirement family | Affected system | Fix owner | Evidence needed | POA&M-eligible? | Closeout risk |
|---|---|---|---|---|---|---|
| MFA not enforced for privileged access | Access Control / Identification & Authentication | Identity provider | MSP/MSSP | Config screenshots, policy, user sample | Depends on the specific requirement and score | High |
| SSP missing a system boundary | Security Assessment | Whole CUI environment | RPO / readiness lead | SSP section, architecture diagram | No — the SSP itself cannot be deferred | High |
| Logs not centralized | Audit & Accountability | Servers / endpoints / cloud | MSP/MSSP | SIEM/log reports, retention settings | Depends on assessment status | Medium–High |
| CUI in unmanaged file shares | Media Protection / Access Control | File shares | Enclave/cloud + readiness | Data-flow map, migration evidence | Scope-dependent | High |
The sequence that works
1. Scope your CUI/FCI boundary first
Misjudging your CUI footprint is one of the most expensive mistakes in the entire program. Shrink before you fix. See our guide on the enclave-vs-enterprise decision.
2. Baseline your SPRS score
Know your real starting point before committing to a timeline or a provider.
3. Build the SSP
The document an assessor asks for first. CA.L2-3.12.4 (the SSP requirement) cannot go on a POA&M — it must be in place.
4. Prioritize the POA&M
Sequence around impact and the items you can't defer. The six prohibited requirements must be fully implemented; everything else flows from there.
5. Implement controls and deploy tools
Where most of the cost and time live. Match technical implementation to an MSP that can map work to NIST 800-171A evidence objectives.
6. Collect and organize evidence
Evidence that can't be produced at assessment time is evidence that doesn't exist. Build your evidence repository before you schedule the C3PAO.
The 6 requirements that can never go on a POA&M
Under 32 CFR §170.21(a)(2)(iii), these six Level 2 requirements must be fully implemented to achieve any CMMC status. Missing any one of them means no Conditional pass — just no status:
- AC.L2-3.1.20 — Verify and control all connections to external systems
- AC.L2-3.1.22 — Control CUI posted or processed on publicly accessible systems
- CA.L2-3.12.4 — The SSP itself — your environment description must exist
- PE.L2-3.10.3 — Escort visitors and monitor visitor activity
- PE.L2-3.10.4 — Maintain audit logs of physical access
- PE.L2-3.10.5 — Control and manage physical access devices
How we built this guide
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We built this guide by separating three kinds of claims: regulatory facts (cited to primary sources), market facts like cost and assessor capacity (cited and dated, because they change), and editorial judgmentslike which provider category fits a situation (clearly framed as our conclusions). We don't sell remediation. We route readers to the right category.
What we actually verified
- Program rule: 32 CFR Part 170, published October 15, 2024; effective December 16, 2024. (Federal Register checked June 3, 2026.)
- DFARS mechanism: DFARS 252.204-7012, -7019, -7020, -7021, and -7025 — the latter two effective November 10, 2025. (Acquisition.gov and eCFR checked June 3, 2026.)
- Levels: Level 1 (15 requirements, FAR 52.204-21, all MET, no POA&M); Level 2 (110 requirements from NIST SP 800-171 Rev. 2, 14 families); Level 3 (adds 24 requirements selected from NIST SP 800-172, assessed by DIBCAC, after Final Level 2 (C3PAO)).
- Scoring and POA&M: the 88/110 threshold, 1/3/5 point values, and the 180-day closeout — 32 CFR §170.24 and §170.21.
- The six prohibited POA&M controls: pulled verbatim from 32 CFR §170.21(a)(2)(iii).
- The conflict-of-interest rule: the three-year prohibition at 32 CFR §170.8(b)(17)(ii)(G), confirmed against the Cyber AB Code of Professional Conduct v2.0.
- CSP vs. ESP handling: 32 CFR §170.17 and §170.19.
- Subcontractor flow-down minimums: 32 CFR §170.23.
- Population and capacity: DoD's estimate of ~8,350 entities requiring Level 2 C3PAO and its year-by-year assessment projection (Federal Register); a March 2026 Cyber AB Marketplace count of roughly 103 authorized C3PAOs.
- Cost and readiness reality: ranges compiled from multiple 2026 analyses plus DoD's published estimates; SBA Office of Advocacy's reported small-business cost data; and the 2025 State of the DIB Report (Merrill Research, commissioned by CyberSheath).
What we could not independently verify
- The status of any proposed federal tax relief for small-business CMMC costs — confirm current law before relying on it.
- The live Cyber AB Marketplace assessor count on your read date (the 103 figure is a dated March 2026 snapshot).
- Individual provider claims about pass rates, customer outcomes, or market leadership.
Disclosure and independence
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We update this page quarterly and after rulemaking changes. Read our editorial standards and corrections policy. Last verified: June 3, 2026. Next scheduled review: September 2026.
CMMC remediation services: frequently asked questions
What are CMMC remediation services?
CMMC remediation services help a defense contractor close the gaps between its current cybersecurity, documentation, and evidence and the CMMC status its contracts require. For Level 2, that means implementing the 110 NIST SP 800-171 Revision 2 requirements and proving it.
Is CMMC remediation the same as CMMC consulting?
Not quite. Consulting can include advice, gap assessments, and readiness planning. Remediation is the actual closure of gaps and the production of evidence — the work that moves your SPRS score and prepares you to pass.
Do I need a gap assessment before remediation?
Usually, yes — unless your gaps are already mapped. Without a gap register, “remediation” tends to become random tool buying. Scope and assess first. See our CMMC gap assessment guide.
Can an RPO certify us?
No. The Cyber AB describes Registered Provider Organizations as advisory and consultative. Only an authorized C3PAO can conduct a Level 2 certification assessment.
Can a C3PAO remediate our gaps?
Treat assessment and remediation as separate. Under 32 CFR §170.8(b)(17)(ii)(G), a firm that prepared you cannot participate in your Level 2 certification assessment for three years. The firm that fixes your gaps generally cannot be the one that certifies you.
What's the difference between a POA&M and remediation?
A POA&M records planned corrective actions; remediation is the work that closes them and produces evidence. Conditional Level 2 and Level 3 require closing valid POA&M items within 180 days. Level 1 doesn't allow POA&Ms.
How many CMMC Level 2 requirements are there?
110, drawn from NIST SP 800-171 Revision 2 and organized into 14 control families. Level 2 is verified by a self-assessment or a C3PAO assessment depending on the contract, plus an annual affirmation. See our CMMC levels guide.
Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3?
For the current rule, Level 2 maps to Revision 2 unless and until DoD amends the rule. The Department confirmed this via FAQ under a class deviation.
What SPRS score do I need to pass Level 2?
An assessment score of at least 88 out of 110, calculated after subtracting the 1-, 3-, and 5-point values of each NOT MET requirement. Below 88, a POA&M can't help; you have to implement first. See our full SPRS score guide.
Which CMMC requirements can never go on a POA&M?
Six Level 2 requirements, under 32 CFR §170.21(a)(2)(iii): AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4 (the SSP), PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. Missing any of them results in no CMMC status, not a Conditional pass.
What documents should remediation produce?
At minimum: an updated SSP, a POA&M (where applicable), an asset inventory, a data-flow diagram, policy and procedure updates, technical evidence, a control-owner map, and assessment-readiness evidence.
When should we schedule a C3PAO?
After scope, SSP, controls, evidence, and independence are stable. A C3PAO should not be your first call if you still have major remediation ahead — and with limited assessor capacity before the November 10, 2026 Phase 2 milestone, booking early matters once you're genuinely ready. See our guide to choosing the best C3PAO for CMMC Level 2.
Can our MSP handle CMMC remediation?
Sometimes — but only if it can map technical implementation to NIST 800-171 evidence and work alongside a readiness lead. And remember: an MSP that handles your CUI is an External Service Provider (ESP) in your scope, documented in your SSP and Customer Responsibility Matrix and assessed within your assessment.
Are CUI enclaves a shortcut to certification?
No. They can reduce or clarify scope — often the biggest cost lever you have — but you still need an SSP, a responsibility matrix, implemented controls, and evidence. Read our enclave vs. enterprise compliance guide for the full picture.
What if we only handle FCI?
Level 1 focuses on FCI: 15 requirements from FAR 52.204-21, self-assessed annually with an affirmation, all of which must be MET, and no POA&Ms. You likely don't need a full remediation program. See our Level 1 vs. Level 2 guide.
What if our prime flowed down CMMC but didn't explain the level?
Get the required CMMC level, assessment type, and information type in writing before you buy anything. Scope your remediation to the flowed-down information, not your whole business. See our guide on CMMC for subcontractors.
How do we get matched with the right provider category?
Use the Path Finder with non-sensitive inputs only — level, scope, environment, current artifacts, provider status, and timeline — and we'll point you to source-checked options that fit.
The bottom line
CMMC remediation isn't one purchase — it's a sequence, and the order matters more than the brand on the invoice. Scope before you fix. Build the SSP before you buy a tool. Implement before you schedule an assessor. And keep the firm that fixes your gaps separate from the firm that certifies you — that's not red tape, it's what makes your certification mean something.
The companies that move now have options. The ones that wait until they see a CMMC clause in a solicitation they want are usually already out of time.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline and we'll match you with source-checked CMMC provider options. Already at 110 and just need the assessment? See our guide to finding and verifying a C3PAO instead.
Find my remediation path →Dropdowns and general descriptions only — please don't paste contract numbers, system details, or anything sensitive. We screen each provider category before routing. Provider-matching may generate referral compensation for us. Matching is not an endorsement or certification guarantee.
Related guides
- CMMC Gap Assessment: What It Covers and What to Do With the Results
- CMMC Gap Assessment Services: Provider Comparison Guide (2026)
- CMMC SSP and POA&M Services: Cost, Options & Rules (2026)
- CMMC Readiness Checklist: What to Have Ready Before Your Assessment
- SPRS Score: What It Is, How It Works, and How to Raise It
- CMMC RPO vs. C3PAO: Which One Do You Actually Need?
- CMMC Level 2 Self-Assessment vs. C3PAO: Which Assessment Path Applies to You
- CMMC Enclave vs Enterprise Compliance: Which Scope? (2026)
- CMMC External Service Provider Requirements: What MSPs, MSSPs & CSPs Have to Do
- CMMC Certification Cost in 2026: DoD Estimate vs. Real Budget
- Best CMMC Providers for Small Business (2026)
- Best C3PAO for CMMC Level 2 (2026 Evaluation Guide)
- CMMC RPO and Readiness Consultants Directory
- CMMC for Subcontractors: What the Flow-Down Actually Requires
- CMMC for Small Defense Contractors: Cost, Timeline, and Options
- CMMC Rescue Services: What to Do If Your CMMC Fails (2026)
Primary and authoritative sources
- CMMC Program Rule — 32 CFR Part 170 (Federal Register, Oct. 15, 2024; effective Dec. 16, 2024)
- POA&M requirements — 32 CFR §170.21 (ecfr.gov)
- CMMC Scoring Methodology — 32 CFR §170.24
- CMMC Level 2 certification assessment and ESP/CSP handling — 32 CFR §170.17; scoping at §170.19
- Application to subcontractors (flow-down) — 32 CFR §170.23
- Conflict of interest — 32 CFR §170.8(b)(17)(ii)(G) and the Cyber AB Code of Professional Conduct v2.0
- C3PAO roles — 32 CFR §170.9; CMMC Assessment Process (CAP) v2.0 (Cyber AB / CAICO)
- DFARS 252.204-7012, -7019, -7020, -7021, and -7025 — Acquisition.gov; DFARS Case 2019-D041
- CMMC levels and model — DoD CIO: dodcio.defense.gov/cmmc
- NIST SP 800-171 Revision 2 and NIST SP 800-171A; NIST SP 800-172 — NIST CSRC: csrc.nist.gov
- Cyber AB Marketplace (assessor/ecosystem directory and counts): cyberab.org
- SBA Office of Advocacy — CMMC small-business cost comments and roundtable reporting (2026): advocacy.sba.gov
- 2025 State of the DIB Report (Merrill Research, commissioned by CyberSheath) — DIB readiness/SPRS data
Last verified: June 3, 2026. Next scheduled review: September 2026.