Everyone Is Watching the Wrong Number
Phase 2 of the CMMC rollout is the point where a passing third-party assessment stops being a nice-to-have and starts being a condition of award. Most coverage of it fixates on one figure: November 10, 2026, the date the Department of Defense can begin requiring a Level 2 certification in new solicitations. That date is real. It is also the least useful number in the entire conversation.
Here is the uncomfortable version. The deadline is not a calendar problem. It is a scheduling problem. There are far more contractors who need an assessment than there are organizations authorized to perform one, and that gap does not close by November. It gets worse through it. If you are treating Phase 2 as a date you can hit by getting your documentation in order that autumn, you are doing the math wrong, because the binding constraint is not your readiness. It is whether anyone is available to assess you before your next contract comes up for recompete.
This article does the math the fear-driven coverage skips. We are going to lay out the actual capacity numbers with their source, show you how to work a realistic timeline backward from an assessment slot instead of forward from today, walk the conditional certification path so you know exactly what a partial pass buys you, and explain why your self-reported score and your assessed score being on record at the same time is now its own category of legal risk. Then we close with a concrete sequence of what to do this quarter, based on where you actually sit in the pipeline.
The Capacity Math, With Its Sources
These are the numbers that matter, drawn from the February 2026 Cyber AB Town Hall and the DoD's own program estimates. We are publishing them with their provenance so you can verify them yourself rather than take our word for it. This is the supply side and the demand side of the same market, side by side.
| Figure | Count | Source |
|---|---|---|
| Organizations authorized to conduct Level 2 assessments (C3PAOs) | 98 | Cyber AB Town Hall, Feb 2026 |
| Certified CMMC Assessors (CCAs) credentialed | 748 | Cyber AB Town Hall, Feb 2026 |
| Organizations with a final Level 2 certification to date | 896 | Cyber AB Town Hall, Feb 2026 |
| Contractors DoD projects will need a third-party Level 2 assessment | 80,000+ | DoD CMMC program estimates |
| Assessor pool industry estimates say the market actually requires | 2,000 to 3,000 | Industry capacity estimates |
| Projected wait time for a new C3PAO client by Q3 2026 | 18+ months | Industry capacity estimates |
Put the two sides together and the picture is not subtle. Roughly 100 authorized firms and fewer than 800 credentialed assessors are the entire supply. The demand is on the order of 80,000 organizations. Even the optimistic reading, where the assessor pool triples to the 2,000 to 3,000 that industry estimates say is needed, still leaves a market where one assessor is responsible for something like thirty to forty contractors. That pool is not tripling this year.
The certification count is the tell. After the program has been live and organizations have been able to pursue Level 2, the running total of final certifications is still under a thousand. That is not evidence of a slow start that will accelerate cleanly. It is evidence of a throughput ceiling. Every quarter that ceiling holds, the backlog of contractors who waited grows, and the wait time for the next client to book grows with it. That is the mechanism behind the 18-month projection: not a spike in interest, but a fixed number of assessment-days divided by a demand curve that keeps climbing.
Readiness and Eligibility Are Two Different Problems
The most expensive mistake in Phase 2 planning is collapsing these two things into one. They are not the same, they are not solved the same way, and they are not on the same clock.
Readiness is whether your environment actually satisfies the 110 requirements and whether you can prove it. Your System Security Plan describes reality, your evidence is organized, your POA&M is credible, your scope is defined. This is entirely inside your control. You can start it today, work it at whatever pace your budget and staffing allow, and finish it on your own schedule. Nobody else is in the queue for your readiness.
Eligibility is whether you actually hold a certification recorded in the government's systems when a contract requires one. That depends on an authorized C3PAO having assessed you, which depends on you having booked a slot, which depends on there being a slot to book. This is not inside your control. It is a market with a hard supply limit, and you are competing for capacity with tens of thousands of other contractors who are all realizing the same thing at roughly the same time.
The reason this distinction matters so much: you can be fully ready and still be ineligible, purely because you have not been assessed yet. A contractor who finished remediation in September but could not get on a C3PAO's calendar until the following spring is ready and ineligible at the same time. When a solicitation lands that requires certification, ready does not win the award. Certified does. The queue is the part of this problem that money and effort cannot compress at the last minute, which is exactly why it has to be the first thing you plan around, not the last.
Work Backward From the Slot, Not Forward From Today
Most contractors build their timeline forward. They look at today, estimate their remediation work, add it up, and land on a date. That method quietly assumes an assessor is standing by the moment you finish. In a capacity-constrained market, that assumption is the error. The correct method runs the other direction. You start from the date you need to hold a certification, subtract the assessment process, subtract the booking lead time, and only then find out how much runway you actually have for remediation.
Here is the sequence in reverse, which is the order you should reason about it.
| Certification in hand | The date a solicitation you intend to bid can require a Level 2 certification. This is your fixed point. Everything else is measured backward from here. |
| Conditional to Final closeout | If you pass conditionally, add up to 180 days to close your POA&M items and be upgraded to a Final certificate. Plan as if you will need part of this window, because most organizations do. |
| Assessment and reporting | The formal engagement runs roughly 6 to 8 weeks from kickoff to a delivered result: a few days of active assessment plus reporting and quality review. See our C3PAO assessment process walkthrough for the phase-by-phase detail. |
| Booking lead time | The wait between signing with a C3PAO and the assessment actually starting. As of early 2026 this ran several months and is projected to exceed 18 months for new clients by Q3 2026. This is the number that is growing, and the one you cannot buy your way past at the last minute. |
| Remediation and readiness | Whatever runway is left after the three items above is what you have to close gaps, build your SSP, and organize evidence. Notice that this is the last thing the timeline gives you, not the first, and it is the only piece you fully control. |
Run that subtraction honestly and the conclusion is uncomfortable for a lot of contractors: the booking you need may already be behind schedule, even if your remediation has not started. That is not a reason to panic. It is a reason to book the slot early, in parallel with readiness work, rather than treating the assessment as something you arrange only once you feel finished. The queue is the constraint, so you get in it first.
The Conditional Certification Path, Precisely
You do not have to be perfect on assessment day to walk away with a certification. The rule allows a Conditional Level 2 status that gives you a limited window to finish. But the conditions are specific, and the parts people gloss over are exactly the parts that decide whether a partial pass is a certification or a rejection letter.
The 80 percent floor. To qualify for Conditional status, your assessment score has to clear a minimum of 80 percent, which on the 110-point SPRS scale means at least 88 of 110 points. Below that line there is no conditional path. You get a determination letter and you remediate before you can be reassessed. If you want to understand how the point values that produce that score are assigned, our SPRS scoring guide breaks down the 1, 3, and 5-point weighting.
The 180-day closeout. A Conditional certificate is a clock, not a resting point. Every requirement you left as NOT MET goes onto a POA&M, and you have up to 180 days to close all of it and be upgraded to a Final certificate. Miss the window and you lose the conditional status. The POA&M is not a formality here. It has to name owners, interim mitigations, and credible completion dates, or the C3PAO will not accept the closeout. Our guide on how to write a CMMC POA&M covers what a defensible one looks like.
The requirements that cannot go on a POA&M at all. This is the part that catches people. Not every gap is survivable with a conditional pass. The highest-weighted requirements, the 5-point controls, generally cannot be placed on a POA&M, and two foundational controls in particular have to be fully met on assessment day: multifactor authentication and FIPS-validated encryption of CUI. If either of those is NOT MET, you do not get Conditional status regardless of your total score. You get a determination letter. So an 88 built by leaving MFA broken is not an 88 that certifies. Know which of your gaps are POA&M-eligible before you sit the assessment, because that map, not the raw total, is what decides your outcome.
The Part Nobody Priced In: Claim Exposure
There is a second reason the assessment matters, and it has nothing to do with winning the next contract. Once you have been assessed, the government holds two numbers about you at the same time: the self-assessment score you posted in SPRS, and the score a C3PAO independently produced. Both are on record. A gap between them is not just an operational embarrassment. It is a documented discrepancy between what you claimed and what an independent assessor found, and under the False Claims Act that discrepancy is a measurable trigger.
The Department of Justice has already been enforcing this through its Civil Cyber-Fraud Initiative, and the settlements make the point clearly. MORSECORP resolved a matter for roughly 4.6 million dollars. Raytheon-affiliated entities resolved one for roughly 8.4 million. Read the framing carefully: these were not breach cases. Nothing had to be stolen. The exposure was the accuracy of the representation, the assertion that a required cybersecurity posture was in place when the record showed otherwise. The claim was the violation.
Phase 2 sharpens this because it puts a verified number next to your asserted one. If your SPRS self-score says 95 and your assessment comes back materially lower, you have not just failed to certify. You have created a written, dated record that your prior self-assessment overstated your posture, on a score the government relied on for eligibility. That is precisely the kind of gap these settlements were built on. The defense is not clever wording. It is making sure the self-score you post is one you could actually defend under assessment. Our SPRS self-assessment guide and our System Security Plan guidance both come down to the same discipline: claim only what your evidence supports.
What to Do This Quarter, by Where You Sit
Advice that ignores your starting position is useless. Here is a concrete sequence for each stage of the pipeline. Find the one that matches you and do those things this quarter, not next year.
If you have not started
Do not begin with a twelve-month remediation plan. Begin with two things in parallel. First, get a real gap assessment against the 110 requirements so you know your true starting score instead of a hopeful one. Second, contact C3PAOs now and get on a calendar, even a provisional one, so you are holding queue position while you remediate. The remediation is the part you control and can compress. The queue is not, so you claim it first.
If you are mid-remediation
Stop assuming an assessor will be available when you finish. Book the slot now against your projected ready date, and use the C3PAO's readiness review as your forcing function. Prioritize the gaps that cannot go on a POA&M, MFA and FIPS-validated encryption above all, because those are the ones that turn a conditional pass into a determination letter. Everything POA&M-eligible can be sequenced behind them.
If you think you are ready
Pressure-test the claim before an assessor does. Run a mock assessment, reconcile your SPRS self-score against what your evidence actually proves, and close any daylight between the two before it becomes a discrepancy on the government's record. If you have not booked, the fact that you feel ready does not move you up the queue. Confirm your slot and your date.
If you hold a conditional certificate
Treat the 180 days as the hard deadline it is. Work your POA&M against named owners and real dates, and get your closeout evidence to the C3PAO with margin, not at the buzzer. The conditional status you already earned is the thing you are protecting, and it expires if the window does.
We refresh this tracker every quarter.
These counts move with every Cyber AB Town Hall. Leave your work email and we will send the next capacity update the day it publishes, along with new assessment readiness guides as they land. No noise, and unsubscribe anytime.