Frequently Asked Questions
Direct answers on CMMC readiness, remediation, and what changed with the Phase 2 pause.
On July 13, 2026, DoD suspended CMMC Phase 2 — the milestone that would have made third-party C3PAO certification mandatory on November 10, 2026 — along with the later Phase 3 and Phase 4 milestones. A CMMC Reform Task Force is reviewing the program, with a report expected around mid-September 2026. This is a pause pending review, not a repeal. The underlying CMMC Program rule remains in effect.
What did not pause: Phase 1 self-assessment requirements, your SPRS score obligations, and DFARS 252.204-7012 safeguarding duties. If your organisation handles Controlled Unclassified Information (CUI) under a DoD contract, those obligations apply today regardless of where Phase 2 lands.
No. A complete CMMC Level 2 remediation takes three to six months for most small to mid-size contractors. Prime contractors are still writing CMMC-adjacent requirements into contracts regardless of the DoD’s own rollout timeline, and contractors who are already certified or well-prepared are structurally advantaged while the field waits. Whatever framework the task force produces, the contractors who used this window to get ready will not be starting from zero.
No. Phase 1 self-assessment and SPRS reporting continue unaffected by the pause, and DOJ Civil Cyber-Fraud Initiative enforcement over misrepresented cybersecurity compliance has continued since the announcement. An inflated or inaccurate score remains a legal liability with or without Phase 2.
A gap assessment is a preparation-focused evaluation of your current security posture against all 110 NIST SP 800-171 controls. It identifies compliance gaps, documents your findings, and produces a remediation roadmap. It is conducted by an independent partner like Ikaan before you engage an assessor.
A C3PAO assessment is the official certification audit conducted by a Cyber-AB authorized assessor. You complete remediation first, then engage the C3PAO for the formal assessment that results in certification.
C3PAOs are prohibited by Cyber-AB rules from providing consulting or remediation services to organisations they assess. The separation is a conflict-of-interest requirement, not a procedural suggestion. Starting with a C3PAO before completing remediation is not a shortcut. You need an independent preparation partner first.
Timeline depends on your environment size and complexity. Small contractors with a few dozen endpoints typically complete the assessment phase in one to two weeks. Mid-size contractors generally need two to four weeks. We conduct a scoping call first to give you a realistic estimate before any work begins.
A Plan of Action and Milestones documents all compliance gaps, the actions needed to close them, responsible parties, timelines, and evidence. Under the CMMC framework, a POA&M accepted by your contracting officer can satisfy certain requirements even without full certification. However, full certification is a stronger position and the ultimate goal, especially with Phase 2’s final shape still under DoD review.
Remediation means closing the gaps identified in your assessment. That typically includes building security policies and procedures, implementing technical controls such as endpoint protection and patch management, training employees, and creating the documentation needed to prove compliance to an assessor.
Not every gap requires expensive tooling. Many are policy and documentation fixes that cost more in time than dollars.
Pricing depends on your organisation size and the scope of gaps identified in your assessment. Small contractors typically invest between $12,000 and $25,000 for a full engagement including gap assessment and remediation. Mid-size contractors generally invest $25,000 to $50,000. We provide a fixed-scope quote after your gap assessment so there are no surprises.
Yes. Most remediation work happens in the background. Patch management, policy updates, and security tool deployment do not require downtime. Training and process changes are phased in on a schedule that works around your team. We scope the work around your operational calendar.
You have options. Some organisations prioritise the highest-risk gaps first and continue remediation on a scheduled timeline. Others establish a POA&M with their contracting officer while remediation progresses. We help you sequence the work to maximise compliance impact with your available budget and document the plan for your contracting officer.
No. Remediation gets you assessment-ready. Certification comes from a formal C3PAO assessment. Once Ikaan completes your remediation, you engage a Cyber-AB authorized C3PAO for the official audit. If you pass, you are certified. The certification is valid for three years.
Most Level 2 assessments take two to four weeks from start to conclusion, depending on your organisation size and scope. The C3PAO conducts document reviews, interviews, and technical testing. Once complete, they submit findings to Cyber-AB for certification processing.
CMMC Level 2 certification is valid for three years. During that period you must maintain compliance with all NIST SP 800-171 controls and keep your System Security Plan current. Changes to your environment, new software, staffing changes, or security incidents require documented updates. Many contractors use a managed security partner to handle continuous monitoring and evidence collection.
Not necessarily. Some organisations hire a full-time compliance or security team member. Others outsource to a managed security services partner. Outsourcing is often more cost-effective for smaller contractors and gives you access to specialised expertise without the overhead of a full-time hire.
A Virtual Chief Information Security Officer is an outsourced security leadership role. A vCISO reviews your security posture, recommends controls, oversees your compliance program, and acts as your security advisor without the cost of a full-time executive hire. Many smaller defence contractors use a vCISO as the most practical path to ongoing compliance leadership.
Managed security services for ongoing CMMC compliance typically run $125 to $250 per endpoint per month depending on the level of coverage you need. That range includes endpoint monitoring, 24/7 SOC, patch management, incident response, and compliance reporting. We scope managed services separately from the remediation engagement so you choose only what you need.
Schedule a discovery call. We ask about your current environment, your contract portfolio, your timeline, and what you already have in place. From there we scope your gap assessment and give you a fixed quote. There is no obligation and no sales pressure. We tell you honestly what you need, even if it is not us.
No. Ikaan is a CMMC preparation and remediation partner, not an assessor. We conduct gap assessments, build System Security Plans and POA&Ms, execute remediation, and support you through the C3PAO assessment process as your technical liaison. We maintain the required separation so your certification is never at risk due to a conflict of interest.
We have established working relationships with several Cyber-AB authorized C3PAOs and can provide introductions once you are assessment-ready. The right C3PAO depends on your environment, timeline, and budget. We help you evaluate options and make the introduction so you are not navigating that process alone.
Still have questions?
We answer questions directly and tell you honestly what we think you need. Book a 30-minute call or send us a message and we will get back to you within one business day.
Or email us at cmmc.ready@ikaanconsulting.com
