CMMC Phase 2 enforcement begins November 2026. If you’re a Houston defense contractor that handles Controlled Unclassified Information (CUI) — or supports a prime contractor who does — here is exactly what you need to do, in sequence. This checklist covers the end-to-end path from initial assessment through Level 2 certification.
The 14-Step CMMC 2.0 Compliance Checklist
Step 1: Determine your CMMC level. Level 1 for companies handling FCI only. Level 2 for companies handling CUI — which is most Houston defense subcontractors in aerospace, energy, and professional services. Check your contract for DFARS clause 252.204-7012 or ask your prime contractor directly.
Step 2: Identify your CUI boundary. Map every system, application, and network that stores, processes, or transmits CUI. This is your assessment scope. If you don’t know what’s in scope, you can’t assess it.
Step 3: Conduct a gap assessment against NIST SP 800-171. Evaluate your current security controls against all 110 requirements. Every gap is a finding that must be remediated before certification. Be honest — an inflated SPRS score is a federal contracting violation.
Step 4: Document your System Security Plan (SSP). The SSP is a required artifact that describes how you implement each of the 110 controls across your in-scope environment. It must be comprehensive, accurate, and maintained over time.
Step 5: Develop a Plan of Action & Milestones (POA&M). Every gap from Step 3 gets a remediation plan with assigned owner, target completion date, and milestone tracking. The POA&M demonstrates that you know what’s broken and have a plan to fix it.
Step 6: Calculate your SPRS score. Use the DoD CMMC scoring methodology to calculate your current score based on implemented vs. not-implemented controls. Negative scores are expected before remediation — the DoD scoring algorithm can produce scores as low as -203.
Step 7: Submit your SPRS score. Submit your current score to the DoD Supplier Performance Risk System at piee.eb.mil. This is a required step for most DoD contracts, separate from formal CMMC certification. Contracting officers can see your score.
Step 8: Prioritize and begin remediation. Don’t try to implement everything at once. Prioritize by risk — access controls, MFA, audit logging, and incident response are typically the highest-impact gaps to close first. Build a project plan with realistic timelines.
Step 9: Implement all 110 NIST 800-171 controls within scope systems. This is the main work of the engagement. Technical controls (MFA, EDR, network segmentation, encryption, SIEM) plus administrative controls (policies, procedures, training, incident response plans).
Step 10: Update your SSP to reflect remediated posture. As controls are implemented, update the SSP to reflect the current state. The SSP is a living document — it should always accurately represent your current environment.
Step 11: Conduct an internal pre-assessment. Walk through every control as if you’re the C3PAO assessor. For each control, ask: do we have the evidence to demonstrate this control is implemented? Document what evidence exists and where it can be found.
Step 12: Select and schedule your C3PAO. Choose a Certified Third-Party Assessment Organization from the CMMC AB marketplace (cyberab.org). Start this process early — C3PAO audit slots are booking 2–3 months in advance. The C3PAO will conduct the formal Level 2 assessment.
Step 13: Complete the C3PAO assessment. Respond to all findings with evidence. The C3PAO will review your SSP, interview personnel, and test controls. A finding that you can’t evidence — even if the control is actually implemented — is counted as not met.
Step 14: Receive CMMC Level 2 certification. Maintain certification with annual self-assessments confirming ongoing compliance and triennial re-certification through a C3PAO. CMMC is not a one-time project — it’s an ongoing program.
Houston CMMC Timeline Reality Check
Gap assessment and SSP documentation: 4–8 weeks. Remediation for a typical Houston defense subcontractor: 3–6 months (most need significant work across multiple control families). C3PAO scheduling: 2–3 month lead time from when you request an assessment. Total from contract signature to certification: 6–12 months for most companies. If you haven’t started yet, start today.
The November 2026 deadline means your C3PAO assessment needs to complete by approximately October 2026. Work backward: if assessment takes 2–3 months to schedule, you need to be assessment-ready by July–August 2026. That means remediation complete by June 2026. That means gap assessment starting no later than January–February 2026. That means now.
xSIT Can Walk You Through Every Step
xSIT provides end-to-end CMMC advisory services for Houston defense contractors — from initial gap assessment through C3PAO preparation. We’ve helped Houston aerospace, energy, and professional services firms navigate CMMC requirements and understand what Level 2 certification actually requires in practice, not just on paper.