Assessment Guide

The Phase 2 Deadline Is a Queue, Not a Date: The C3PAO Capacity Math Every DIB Contractor Should Run

Last updated: 2026-07-06

The Wrong Number The Capacity Math Readiness vs. Eligibility Work Backward From the Slot The Conditional Path The Claim Exposure What to Do This Quarter

Everyone Is Watching the Wrong Number

Phase 2 of the CMMC rollout is the point where a passing third-party assessment stops being a nice-to-have and starts being a condition of award. Most coverage of it fixates on one figure: November 10, 2026, the date the Department of Defense can begin requiring a Level 2 certification in new solicitations. That date is real. It is also the least useful number in the entire conversation.

Here is the uncomfortable version. The deadline is not a calendar problem. It is a scheduling problem. There are far more contractors who need an assessment than there are organizations authorized to perform one, and that gap does not close by November. It gets worse through it. If you are treating Phase 2 as a date you can hit by getting your documentation in order that autumn, you are doing the math wrong, because the binding constraint is not your readiness. It is whether anyone is available to assess you before your next contract comes up for recompete.

This article does the math the fear-driven coverage skips. We are going to lay out the actual capacity numbers with their source, show you how to work a realistic timeline backward from an assessment slot instead of forward from today, walk the conditional certification path so you know exactly what a partial pass buys you, and explain why your self-reported score and your assessed score being on record at the same time is now its own category of legal risk. Then we close with a concrete sequence of what to do this quarter, based on where you actually sit in the pipeline.

The one-sentence version
Readiness and eligibility are now two separate problems. You can solve the first one on your own schedule. The second one is a queue, and the queue is filling.

The Capacity Math, With Its Sources

These are the numbers that matter, drawn from the February 2026 Cyber AB Town Hall and the DoD's own program estimates. We are publishing them with their provenance so you can verify them yourself rather than take our word for it. This is the supply side and the demand side of the same market, side by side.

FigureCountSource
Organizations authorized to conduct Level 2 assessments (C3PAOs)98Cyber AB Town Hall, Feb 2026
Certified CMMC Assessors (CCAs) credentialed748Cyber AB Town Hall, Feb 2026
Organizations with a final Level 2 certification to date896Cyber AB Town Hall, Feb 2026
Contractors DoD projects will need a third-party Level 2 assessment80,000+DoD CMMC program estimates
Assessor pool industry estimates say the market actually requires2,000 to 3,000Industry capacity estimates
Projected wait time for a new C3PAO client by Q3 202618+ monthsIndustry capacity estimates

Put the two sides together and the picture is not subtle. Roughly 100 authorized firms and fewer than 800 credentialed assessors are the entire supply. The demand is on the order of 80,000 organizations. Even the optimistic reading, where the assessor pool triples to the 2,000 to 3,000 that industry estimates say is needed, still leaves a market where one assessor is responsible for something like thirty to forty contractors. That pool is not tripling this year.

The certification count is the tell. After the program has been live and organizations have been able to pursue Level 2, the running total of final certifications is still under a thousand. That is not evidence of a slow start that will accelerate cleanly. It is evidence of a throughput ceiling. Every quarter that ceiling holds, the backlog of contractors who waited grows, and the wait time for the next client to book grows with it. That is the mechanism behind the 18-month projection: not a spike in interest, but a fixed number of assessment-days divided by a demand curve that keeps climbing.

Why we date every number
Capacity figures move every quarter as the Cyber AB reports new authorizations and certifications. The numbers above are anchored to the February 2026 Town Hall. We refresh this page each quarter against the latest Town Hall data. If you are reading this well after the last-updated date at the top, treat the counts as a floor and verify the current numbers at cyberab.org before you build a timeline on them.

Readiness and Eligibility Are Two Different Problems

The most expensive mistake in Phase 2 planning is collapsing these two things into one. They are not the same, they are not solved the same way, and they are not on the same clock.

Readiness is whether your environment actually satisfies the 110 requirements and whether you can prove it. Your System Security Plan describes reality, your evidence is organized, your POA&M is credible, your scope is defined. This is entirely inside your control. You can start it today, work it at whatever pace your budget and staffing allow, and finish it on your own schedule. Nobody else is in the queue for your readiness.

Eligibility is whether you actually hold a certification recorded in the government's systems when a contract requires one. That depends on an authorized C3PAO having assessed you, which depends on you having booked a slot, which depends on there being a slot to book. This is not inside your control. It is a market with a hard supply limit, and you are competing for capacity with tens of thousands of other contractors who are all realizing the same thing at roughly the same time.

The reason this distinction matters so much: you can be fully ready and still be ineligible, purely because you have not been assessed yet. A contractor who finished remediation in September but could not get on a C3PAO's calendar until the following spring is ready and ineligible at the same time. When a solicitation lands that requires certification, ready does not win the award. Certified does. The queue is the part of this problem that money and effort cannot compress at the last minute, which is exactly why it has to be the first thing you plan around, not the last.

Work Backward From the Slot, Not Forward From Today

Most contractors build their timeline forward. They look at today, estimate their remediation work, add it up, and land on a date. That method quietly assumes an assessor is standing by the moment you finish. In a capacity-constrained market, that assumption is the error. The correct method runs the other direction. You start from the date you need to hold a certification, subtract the assessment process, subtract the booking lead time, and only then find out how much runway you actually have for remediation.

Here is the sequence in reverse, which is the order you should reason about it.

Certification in handThe date a solicitation you intend to bid can require a Level 2 certification. This is your fixed point. Everything else is measured backward from here.
Conditional to Final closeoutIf you pass conditionally, add up to 180 days to close your POA&M items and be upgraded to a Final certificate. Plan as if you will need part of this window, because most organizations do.
Assessment and reportingThe formal engagement runs roughly 6 to 8 weeks from kickoff to a delivered result: a few days of active assessment plus reporting and quality review. See our C3PAO assessment process walkthrough for the phase-by-phase detail.
Booking lead timeThe wait between signing with a C3PAO and the assessment actually starting. As of early 2026 this ran several months and is projected to exceed 18 months for new clients by Q3 2026. This is the number that is growing, and the one you cannot buy your way past at the last minute.
Remediation and readinessWhatever runway is left after the three items above is what you have to close gaps, build your SSP, and organize evidence. Notice that this is the last thing the timeline gives you, not the first, and it is the only piece you fully control.

Run that subtraction honestly and the conclusion is uncomfortable for a lot of contractors: the booking you need may already be behind schedule, even if your remediation has not started. That is not a reason to panic. It is a reason to book the slot early, in parallel with readiness work, rather than treating the assessment as something you arrange only once you feel finished. The queue is the constraint, so you get in it first.

Book before you are done
A competent C3PAO runs a readiness review before the formal assessment. That gate check is the mechanism that lets you reserve a slot now and firm up your evidence against a real date, instead of forfeiting months of queue position while you polish documentation nobody is waiting on. Reserving capacity early is not jumping the gun. In this market it is the plan.

The Conditional Certification Path, Precisely

You do not have to be perfect on assessment day to walk away with a certification. The rule allows a Conditional Level 2 status that gives you a limited window to finish. But the conditions are specific, and the parts people gloss over are exactly the parts that decide whether a partial pass is a certification or a rejection letter.

The 80 percent floor. To qualify for Conditional status, your assessment score has to clear a minimum of 80 percent, which on the 110-point SPRS scale means at least 88 of 110 points. Below that line there is no conditional path. You get a determination letter and you remediate before you can be reassessed. If you want to understand how the point values that produce that score are assigned, our SPRS scoring guide breaks down the 1, 3, and 5-point weighting.

The 180-day closeout. A Conditional certificate is a clock, not a resting point. Every requirement you left as NOT MET goes onto a POA&M, and you have up to 180 days to close all of it and be upgraded to a Final certificate. Miss the window and you lose the conditional status. The POA&M is not a formality here. It has to name owners, interim mitigations, and credible completion dates, or the C3PAO will not accept the closeout. Our guide on how to write a CMMC POA&M covers what a defensible one looks like.

The requirements that cannot go on a POA&M at all. This is the part that catches people. Not every gap is survivable with a conditional pass. The highest-weighted requirements, the 5-point controls, generally cannot be placed on a POA&M, and two foundational controls in particular have to be fully met on assessment day: multifactor authentication and FIPS-validated encryption of CUI. If either of those is NOT MET, you do not get Conditional status regardless of your total score. You get a determination letter. So an 88 built by leaving MFA broken is not an 88 that certifies. Know which of your gaps are POA&M-eligible before you sit the assessment, because that map, not the raw total, is what decides your outcome.

The distinction that matters
A conditional pass and a determination letter can be one requirement apart. Two contractors can post the same score. The one whose gaps are all POA&M-eligible walks out conditionally certified with 180 days to finish. The one whose gaps include MFA or FIPS-validated encryption walks out with nothing and starts over. Score alone does not tell you which one you are.

The Part Nobody Priced In: Claim Exposure

There is a second reason the assessment matters, and it has nothing to do with winning the next contract. Once you have been assessed, the government holds two numbers about you at the same time: the self-assessment score you posted in SPRS, and the score a C3PAO independently produced. Both are on record. A gap between them is not just an operational embarrassment. It is a documented discrepancy between what you claimed and what an independent assessor found, and under the False Claims Act that discrepancy is a measurable trigger.

The Department of Justice has already been enforcing this through its Civil Cyber-Fraud Initiative, and the settlements make the point clearly. MORSECORP resolved a matter for roughly 4.6 million dollars. Raytheon-affiliated entities resolved one for roughly 8.4 million. Read the framing carefully: these were not breach cases. Nothing had to be stolen. The exposure was the accuracy of the representation, the assertion that a required cybersecurity posture was in place when the record showed otherwise. The claim was the violation.

Phase 2 sharpens this because it puts a verified number next to your asserted one. If your SPRS self-score says 95 and your assessment comes back materially lower, you have not just failed to certify. You have created a written, dated record that your prior self-assessment overstated your posture, on a score the government relied on for eligibility. That is precisely the kind of gap these settlements were built on. The defense is not clever wording. It is making sure the self-score you post is one you could actually defend under assessment. Our SPRS self-assessment guide and our System Security Plan guidance both come down to the same discipline: claim only what your evidence supports.

What to Do This Quarter, by Where You Sit

Advice that ignores your starting position is useless. Here is a concrete sequence for each stage of the pipeline. Find the one that matches you and do those things this quarter, not next year.

If you have not started

Do not begin with a twelve-month remediation plan. Begin with two things in parallel. First, get a real gap assessment against the 110 requirements so you know your true starting score instead of a hopeful one. Second, contact C3PAOs now and get on a calendar, even a provisional one, so you are holding queue position while you remediate. The remediation is the part you control and can compress. The queue is not, so you claim it first.

If you are mid-remediation

Stop assuming an assessor will be available when you finish. Book the slot now against your projected ready date, and use the C3PAO's readiness review as your forcing function. Prioritize the gaps that cannot go on a POA&M, MFA and FIPS-validated encryption above all, because those are the ones that turn a conditional pass into a determination letter. Everything POA&M-eligible can be sequenced behind them.

If you think you are ready

Pressure-test the claim before an assessor does. Run a mock assessment, reconcile your SPRS self-score against what your evidence actually proves, and close any daylight between the two before it becomes a discrepancy on the government's record. If you have not booked, the fact that you feel ready does not move you up the queue. Confirm your slot and your date.

If you hold a conditional certificate

Treat the 180 days as the hard deadline it is. Work your POA&M against named owners and real dates, and get your closeout evidence to the C3PAO with margin, not at the buzzer. The conditional status you already earned is the thing you are protecting, and it expires if the window does.

Where 1TEN fits
The queue is the one variable you cannot control. Everything else, mapping your environment to all 110 requirements, producing an SSP that matches reality, keeping a defensible POA&M, and knowing your live SPRS score before an assessor does, is what 1TEN gets you through fast. We make you assessment-ready quickly enough that the C3PAO calendar is your only remaining constraint, and then you are competing on timing instead of scrambling on readiness.

Frequently Asked Questions

Is the CMMC Phase 2 deadline November 10, 2026?

November 10, 2026 is the date the DoD can begin including a Level 2 third-party certification requirement in new solicitations. It is a real milestone, but treating it as your deadline is misleading, because the practical constraint is assessment capacity, not the calendar. With a limited number of authorized C3PAOs and a projected 18-plus-month wait for new clients, the date you can be assessed matters more than the date the requirement turns on.

How many C3PAOs and assessors are there right now?

As of the February 2026 Cyber AB Town Hall, 98 organizations were authorized to conduct Level 2 assessments, 748 Certified CMMC Assessors were credentialed, and 896 organizations held a final Level 2 certification. The DoD projects more than 80,000 contractors will need a third-party assessment. Verify current figures at cyberab.org, since the counts move each quarter.

What is the difference between readiness and eligibility?

Readiness is whether your environment meets the 110 requirements and you can prove it, which you control and can work on your own schedule. Eligibility is whether you actually hold a certification recorded in the government's systems, which depends on an authorized C3PAO assessing you and therefore on the queue. You can be fully ready and still ineligible if you have not yet been assessed.

What score do I need for a conditional CMMC certification?

At least 80 percent, which is 88 of 110 points on the SPRS scale. Below that there is no conditional path. But score alone is not enough: certain requirements, including multifactor authentication and FIPS-validated encryption of CUI, must be fully met on assessment day and cannot be placed on a POA&M. If one of those is NOT MET, you receive a determination letter regardless of your total.

How long do I have to close a POA&M after a conditional pass?

Up to 180 days. Within that window you must close every POA&M item and have the C3PAO validate the remediation to be upgraded to a Final certificate. Miss the window and you lose the conditional status. The POA&M must have named owners, interim mitigations, and credible completion dates for the closeout to be accepted.

Can a gap between my SPRS self-score and my assessed score create legal risk?

Yes. Once you are assessed, the government holds both your self-reported score and the independently assessed one. A material gap is a documented discrepancy between what you claimed and what was found, which is the kind of trigger the Department of Justice has pursued under the False Claims Act. Recent settlements, including MORSECORP at roughly 4.6 million dollars and a Raytheon-affiliated matter at roughly 8.4 million dollars, were about the accuracy of the cybersecurity claim, not a breach.

Should I book a C3PAO before I finish remediation?

In a capacity-constrained market, yes. Booking lead times are long and growing, and queue position is the one thing you cannot compress at the last minute. Reserve a slot now and use the C3PAO's readiness review as a forcing function to firm up your evidence against a real date, rather than forfeiting months of queue position while you polish documentation nobody is waiting on.

All 110. Tracked.

1TEN is an air-gapped, on-premises GRC platform engineered for defense contractors handling CUI.

Request a Demo