The acquisition rule that brings CMMC requirements into Department of Defense contracts took effect on November 10, 2025, which starts a phased rollout of requirements in solicitations and contracts. For contractors that handle Controlled Unclassified Information, the practical question is no longer whether to prepare, but how to organize the work. This post lays out a realistic timeline for a small firm aiming at Level 2, which aligns with the 110 requirements of NIST SP 800-171.
Every company is different, and the durations below depend on your starting point. Treat them as a planning frame, not a promise.
Phase one: scope and inventory (weeks one to four)
Begin by identifying what the assessment will cover.
- Determine which contracts involve CUI, and what the contract says about it.
- Map where CUI is stored, processed, and transmitted: email, file shares, project platforms, laptops, phones, printers, backups.
- List the people who handle it.
- List the systems that protect it, such as identity providers, security tools, and cloud services.
Reduce the scope
A common and effective strategy is to create a separate, protected environment for CUI instead of bringing the whole company into scope. A smaller boundary means fewer systems to harden, document, and assess. Decide this early because it shapes everything that follows.
Phase two: gap assessment (weeks three to eight)
Compare your environment to each NIST SP 800-171 requirement and record whether it is met, partially met, or not met. Be honest. A gap assessment is useful only if it is accurate.
Common gaps in small firms include:
- Multi-factor authentication missing on some accounts or systems.
- No central logging or review of logs.
- Inconsistent device encryption and patching.
- Weak or undocumented access control, including shared accounts.
- No formal incident response plan.
- Limited security training records.
- Unmanaged personal devices touching CUI.
Phase three: plan and prioritize (weeks six to ten)
Turn the gaps into a plan of action with owners, costs, and dates. Prioritize items that:
- Close the biggest risks.
- Are prerequisites for other work, such as identity and device management.
- Are quick wins that build momentum.
At the same time, begin the system security plan, the document that describes your boundary and how you implement each requirement. Assessors rely on it heavily.
Phase four: remediation (months three to nine)
This is the longest phase and varies the most. Typical work includes:
- Rolling out MFA and tightening access control.
- Standardizing and encrypting devices.
- Deploying monitoring and log retention.
- Implementing patch and vulnerability management.
- Establishing configuration baselines.
- Creating policies and procedures people will actually follow.
- Training staff and recording attendance.
- Writing and testing an incident response plan.
Choose cloud services with care. Providers that store CUI should be able to explain how they meet the relevant requirements.
Phase five: evidence and rehearsal (months eight to twelve)
Assessors evaluate by examining documents, interviewing staff, and testing how systems are configured. Gather evidence as you go: screenshots, configuration exports, logs, policies, training records, meeting notes. Then run a mock assessment, either internally or with an outside advisor, and interview your own staff. Employees should be able to explain, in their own words, how they protect CUI in their daily work.
Phase six: assessment and maintenance
Depending on the contract, Level 2 may be a self-assessment or a third-party assessment. Either way, compliance is not finished on assessment day. Affirmations must be kept current, and requirements must keep being met. Plan an annual review, track changes to your environment, and keep your documentation updated.
Budgeting tips
- Fund the gap assessment first, so later spending is based on facts.
- Include staff time. Documentation and training take real hours.
- Expect recurring costs for monitoring, licensing, and assessments.
Where Ironfield Cyber fits
Ironfield Cyber helps contractors scope, assess, and remediate against NIST SP 800-171, and can work alongside your own staff and any outside assessor. If you want to know where you stand, a scoping call and gap review is a sensible first step.