What Defense Contractors Need to Do Before November 10, 2026
CMMC Phase 2 begins November 10, 2026. For thousands of defense contractors and subcontractors, that date is not a suggestion. It is a contract requirement. Here is what you need to have in place, in the order you need to do it, with enough time to actually get it done.
The deadline is real. So is the risk.
The Department of Defense has been signaling the CMMC enforcement timeline for years. Phase 1 began in December 2024, requiring CMMC conditions in select new contracts. Phase 2 begins November 10, 2026, and broadens that requirement significantly across the Defense Industrial Base.
What that means practically: if your organization handles Controlled Unclassified Information (CUI) and you do not have a CMMC Level 2 certification in place or a Plan of Action and Milestones (POA&M) accepted by your contracting officer, you will not be eligible for new DoD contracts and you may be at risk on existing ones.
C3PAOs, the certified assessors who conduct CMMC Level 2 assessments, are prohibited from providing consulting or remediation services to organizations they assess. You need an independent preparation partner before you engage an assessor. Starting with a C3PAO is not a shortcut — it is a gap in your preparation.
Where most contractors are right now
Based on what we see across the Defense Industrial Base, most contractors fall into one of three situations:
They have not started. They know CMMC is coming but have not taken meaningful steps to assess their current posture. This group is running out of runway — five months is not a long time when a full Level 2 remediation can take three to six months for a small to mid-size organization.
They think they are compliant but have not verified it. Many contractors have been self-attesting to NIST SP 800-171 compliance through their SPRS score for years. Self-attestation and C3PAO assessment are not the same thing. Many organizations that believe they are compliant have significant gaps that will surface in a formal assessment.
They are in progress but moving too slowly. They have identified gaps but have not remediated them. Remediation takes longer than most organizations expect, especially when it involves technical controls, policy development, and evidence collection simultaneously.
What you need to do, in order
-
01
Get an honest gap assessment
Not a self-assessment. A structured gap analysis against all 110 practices in NIST SP 800-171 conducted by an independent practitioner who will tell you what you actually have, not what you think you have. This produces your baseline SPRS score and identifies every control that needs work before you are assessment-ready.
-
02
Build your System Security Plan
The SSP is the foundational document of your CMMC assessment. It describes your CUI environment, your system boundaries, and how each of the 110 practices is implemented in your organization. C3PAOs will review your SSP before and during the assessment. An incomplete or inaccurate SSP is one of the most common reasons assessments stall.
-
03
Develop and execute your POA&M
A Plan of Action and Milestones documents every gap, the remediation approach, the responsible owner, and the timeline to close it. DoD allows conditional CMMC status with an accepted POA&M, but the window to remediate is 180 days. Your POA&M needs to be credible and executable, not aspirational.
-
04
Remediate the gaps that matter most
Not all 110 practices carry equal weight. Some gaps are quick wins. Others require infrastructure changes, vendor replacements, or policy overhauls that take months. Prioritize by risk and by assessment impact. A good remediation partner will sequence your work so the highest-risk gaps close first.
-
05
Select and engage a C3PAO
Once you are assessment-ready, engage a Cyber-AB authorized C3PAO to conduct your formal Level 2 assessment. There are approximately 90 authorized assessors. Assessment capacity is limited and wait times are growing as the November deadline approaches. Do not wait until you are fully remediated to start the conversation with a C3PAO.
The organizations that will be in the best position by November 10 are the ones that started their gap assessment in the first half of 2026. If you have not started yet, the time to move is now — not after the summer.
What happens if you miss the deadline
Missing the Phase 2 deadline does not mean your existing contracts automatically disappear. It means you will not be eligible to bid on new DoD contracts that require CMMC Level 2 certification as a condition of award. As the requirement spreads across more contract vehicles, the pool of available work for non-certified contractors shrinks.
For subcontractors, the risk is more immediate. Prime contractors are increasingly including CMMC flow-down requirements in their subcontractor agreements. If your prime contractor needs Level 2 compliance from their supply chain, your certification status becomes a condition of staying on the team.
How Ikaan can help
Ikaan Consulting works exclusively as a preparation partner, not as an assessor. We conduct gap assessments, build SSPs and POA&Ms, execute remediation, and support organizations through the C3PAO assessment process. We do not assess — which means there is no conflict of interest and no confusion about whose side we are on.
If you are a defense contractor who has not started CMMC preparation, or one who is not confident in your current posture, a 30-minute conversation is the right first step. We will tell you where you stand and what it will take to get where you need to be before November 10.
Ready to find out where you actually stand?
Schedule a 30-minute CMMC readiness call. We will review your current posture and give you a clear picture of what needs to happen before November 10.
Schedule a CMMC Readiness Call