The rules changed. Under the final CMMC 2.0 rule, DoD contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) are required to meet specific cybersecurity standards before they can bid on, win, and perform covered contracts. The question for most small suppliers is no longer whether this applies to them. It is whether they will be ready when their next contract requires it.
This roadmap breaks 2026 into four quarters with concrete actions for each. It covers both Level 1 and Level 2 requirements, and it is written for organizations at different starting points — whether you are building your compliance program from scratch or closing gaps in an existing one.
Level 1 vs. Level 2: What Actually Differs
Before getting into the quarterly plan, it helps to be clear on what separates Level 1 from Level 2, because the path and the stakes are meaningfully different.
CMMC Level 1
Level 1 covers organizations that handle FCI but not CUI. It maps to 17 practices drawn from FAR 52.204-21. The compliance mechanism is an annual self-assessment, and a senior official from your company must affirm the results in the Supplier Performance Risk System (SPRS). No third-party assessor is required.
Level 1 is a lower bar, but it is not a rubber stamp. The 17 practices cover basic cyber hygiene: access control, identification and authentication, media protection, physical protection, system and communications protection, and system integrity. Organizations that have not formally inventoried their systems and mapped controls to these requirements will find gaps.
CMMC Level 2
Level 2 applies to organizations handling CUI. It aligns to all 110 practices in NIST SP 800-171 Rev 2, organized across 14 domains. Most Level 2 contractors will be required to undergo a triennial assessment conducted by a C3PAO. The difference in preparation effort between Level 1 and Level 2 is substantial. Level 2 requires a documented System Security Plan, active Plans of Action and Milestones for any gaps, evidence collection across all 110 practices, and an environment that an external assessor can walk through and verify.
Q1 2026 (January – March): Establish Your Baseline
If you do not know where you stand, every other step is guesswork. Q1 is about getting honest with your current state before you start investing time and budget in fixes. The goal by end of Q1 is a documented, honest picture of where you stand today — which systems are in scope, which practices you satisfy and which you do not, and who owns the gaps.
Level 1 — Q1 Actions
-
Identify all systems that process or store FCI
-
Map your environment to the 17 FAR 52.204-21 practices
-
Document any gaps with honest, specific descriptions and assign ownership
-
Pull your current SPRS score and verify it reflects reality
-
Confirm annual affirmation schedule and identify the responsible senior official
Level 2 — Q1 Actions
-
Define your CUI boundary — where does CUI enter, live, move, and exit?
-
Complete a formal asset inventory: endpoints, servers, cloud services, applications
-
Obtain, create, or update your System Security Plan (SSP)
-
Conduct or commission a gap analysis against all 110 NIST 800-171 Rev 2 practices
-
Identify all external service providers and cloud tools that touch your CUI environment
-
Confirm your Microsoft 365 licensing tier — GCC High vs. commercial is not optional for CUI
-
Open POA&M items for any practices not yet implemented, with realistic milestones
-
Identify whether any current contracts already require CMMC compliance at award
For organizations starting from scratch, Q1 will feel like the hardest quarter. That is expected. The gap analysis output is your master working document for the rest of the year. Invest in getting it right.
Q2 2026 (April – June): Close the Gaps That Matter Most
Q2 is about remediation. With a clear baseline from Q1, you now know what needs to be fixed. The challenge is prioritization — small organizations rarely have the resources to fix everything at once, and not every gap carries the same risk or assessment weight.
The practices that assessors focus on most heavily are access control, audit and accountability, configuration management, identification and authentication, and system and communications protection. These should lead your remediation queue.
Level 1 — Q2 Actions
-
Remediate all open items from your Q1 self-assessment
-
Verify multi-factor authentication is in place for all system access
-
Confirm least privilege is enforced, not just documented
-
Confirm physical protection for systems handling FCI
-
Update SPRS score to reflect remediation progress
-
Brief the responsible senior official on affirmation requirements and timeline
Level 2 — Q2 Actions
-
Prioritize high-impact POA&M items: access control (3.1.x), audit logging (3.3.x), configuration management (3.4.x)
-
Implement or harden MFA across all CUI-adjacent systems including remote access
-
Stand up audit logging with appropriate retention — verify log coverage across all systems
-
Review and test your incident response plan with a basic tabletop exercise
-
Document configuration baselines for servers, endpoints, and network devices
-
Assess supply chain: confirm subcontractors handling CUI have their own compliance path
-
Engage a C3PAO or CMMC consultant for a pre-assessment readiness review if your assessment is planned for the second half of 2026
Access control and audit logging are two of the most commonly cited deficiencies in CMMC assessments. For Level 2 organizations planning an assessment in Q3 or Q4, Q2 is the last realistic window for meaningful technical remediation. Changes made after you have engaged a C3PAO are harder to document as established, operational practice.
Q3 2026 (July – September): Validate and Prepare for Assessment
By Q3, your controls should be largely in place. This quarter is about verification, evidence preparation, and making sure the people in your organization can accurately describe your security practices. Both of those last two things matter more than most contractors expect.
Level 1 — Q3 Actions
-
Conduct an internal review of all 17 practices with supporting evidence documentation
-
Prepare the senior official for SPRS affirmation submission
-
Submit or confirm SPRS score with updated assessment date
-
Review contract renewals and new solicitations for CMMC flow-down language
-
Begin planning for the next annual cycle
Level 2 — Q3 Actions
-
Complete a pre-assessment readiness review with a C3PAO or qualified CMMC consultant
-
Update your SSP to reflect all Q2 remediations and the current environment state
-
Build evidence packages for each of the 14 NIST 800-171 domains
-
Conduct mock interviews with IT staff and project managers who will speak to assessors
-
Review and close or formally document all POA&M items with updated milestones
-
Verify your network diagrams, data flow diagrams, and boundary documentation are current
-
Schedule your formal C3PAO assessment if targeting Q4 certification
CMMC assessments are not document reviews. Assessors interview personnel at multiple levels of the organization. When interview answers do not match the SSP, that is a finding. Running through likely interview questions with your key personnel in Q3 is not coaching them to game the assessment — it is closing the gap between your documented practices and your operational reality, which is exactly what the assessment is designed to measure.
Q4 2026 (October – December): Certify, Affirm, and Build for 2027
Q4 is execution. Organizations that have done the work in Q1 through Q3 are positioned to complete their compliance milestone. Organizations that have not are looking at either extending their timeline or accepting the business risk of proceeding without full compliance.
Level 1 — Q4 Actions
-
Complete the annual self-assessment and document results formally
-
Senior official submits affirmation in SPRS with current assessment date
-
Review contracts renewing in early 2027 for CMMC clause updates
-
Document lessons learned and update policies for next cycle
-
Confirm schedule and owner for next annual assessment
Level 2 — Q4 Actions
-
Complete your formal C3PAO assessment
-
Respond to any assessment findings with corrective action documentation
-
Receive and review the Final Assessment Report from your C3PAO
-
Pursue CMMC Level 2 certification through the Cyber AB upon successful assessment
-
Update SPRS with your certified score
-
Establish a continuous monitoring schedule: log review cadence, vulnerability scanning, access reviews
-
Document your recertification timeline and begin the three-year planning cycle
CMMC Level 2 certification does not end your compliance obligations — it starts a three-year cycle. The most common mistake organizations make after achieving certification is treating it as a completed project rather than an ongoing program. Building a quarterly review process into your operations starting in Q4 is significantly easier than rebuilding your compliance posture from scratch when your recertification date approaches.
A Few Practical Notes for Small Suppliers
-
Start with your asset inventory. You cannot protect or document what you have not identified.
-
An honest SSP beats a polished one. A document that accurately describes your environment, including gaps, is a better starting point than a well-formatted plan that does not reflect reality. Assessors compare what the SSP says against what they observe — that gap is where findings come from.
-
The Microsoft 365 licensing question is not optional. If you handle CUI on commercial M365, that is a gap. GCC High exists for a reason, and the licensing tier affects your boundary, your SSP, and your assessment.
-
MSP relationships require scrutiny. Not all managed service providers understand CMMC. Get specifics on which practices they support and how CUI is handled on their end before counting their services toward your compliance posture.
-
POA&Ms are a tool, not a liability. Open items with honest milestones and documented progress are acceptable. A POA&M that has been sitting untouched for 18 months is not.
Where Init Cyber Fits In
Init Cyber works with small and mid-size DoD suppliers on CMMC readiness, gap analysis, SSP development, and pre-assessment preparation. We hold Cyber AB credentials and have worked through both Level 1 and Level 2 engagements with contractors at different stages of readiness.
If you are working through this roadmap and hit a point where you need outside perspective on your environment, your documentation, or your timeline, we are available for a direct conversation about where you stand and what it would take to get where you need to be. Reach us at initcyber.com.