June 30, 2026

CMMC Level 2 certification: what MSPs need to know before their clients ask

Estimated reading time: 8 minutes

If you have clients touching Department of Defense contracts, or clients whose clients do, the CMMC conversation is coming. It may already be at the door. The question isn’t whether you’ll need to support it. The question is whether you’ll be ready to answer when your client receives a solicitation requiring proof.

This post is the practical rundown: what CMMC Level 2 actually demands, where MSPs typically get caught flat-footed, and what delivering it through a partner looks like versus trying to stand it up yourself.

CMMC, the Cybersecurity Maturity Model Certification, is the DoD’s framework for securing Controlled Unclassified Information (CUI) across the defense industrial base. Level 2 is the tier most contractors will need to hit. It maps directly to the 110 security practices in NIST SP 800-171, covering 14 domains including access control, incident response, audit and accountability, risk assessment, and system monitoring.

There is no partial credit. The assessment is pass or fail, and the passing threshold requires that all 110 practices be documented, implemented, and verified by a third-party assessor (a C3PAO). Self-attestation, which was allowed under previous iterations of the framework, is no longer enough for most contracts.

The enforcement timeline matters here. The CMMC Acquisition Rule became effective November 10, 2025, meaning CMMC requirements can now be written directly into new DoD solicitations. Full implementation across the broader defense industrial base is projected by 2028. If your clients are waiting to see what enforcement actually looks like before starting, they’re already behind the assessor queue.

Here’s the number that reframes the urgency: roughly 80,000 organizations are currently in the backlog for CMMC certification. There are approximately 75 certified C3PAO assessors in the US to work through that queue. Only around 250 organizations worldwide have achieved certification to date.

That gap between demand and assessor supply is the real reason to start early. The certification process itself, scoping, gap analysis, remediation, documentation, assessment scheduling, takes months in a best-case scenario. If your client receives a solicitation requiring CMMC in six months and hasn’t started, they have a contract problem, not a cybersecurity problem.

MSPs who can tell that story clearly and back it with a credible delivery path will be the ones clients call. The ones who can’t will watch the conversation drift elsewhere.

CMMC Level 2 is not a checklist you run through and check off. The 110 controls span operational security practices that have to be running continuously, not just in place at assessment time. The most common gaps show up in five areas.

  • Incident response documentation: IR.L2-3.6.1 through IR.L2-3.6.3 require a full incident response capability, including testing. Many organizations have an IR policy. Far fewer have an IR program with tracked tickets, documented containment timelines, and evidence of tabletop exercises. Assessors know the difference.
  • Continuous monitoring: SI.L2-3.14.6 requires active monitoring of inbound and outbound traffic. A weekly vulnerability scan is not continuous monitoring. A SIEM that generates alerts for someone to review in the morning is not continuous monitoring. The control expects real-time coverage backed by a 24/7 managed SOC.
  • Audit log retention and integrity: AU.L2-3.3.1 requires audit logs to be created, protected, and retained long enough to support investigation. 365-day retention with tamper-evident storage is the standard that holds up in practice. A lot of smaller environments are running 30 or 90 days and assuming that’s close enough.
  • Vulnerability scanning and remediation: RA.L2-3.11.2 through 3.11.3 require not just running scans but documenting that discovered vulnerabilities were addressed and prioritized by risk. The evidence trail matters as much as the scan.
  • Scoping the CUI environment: Before any of the above, you have to correctly identify what systems process, store, or transmit CUI. Getting the scope wrong means you either over-engineer the controls (expensive) or leave gaps the assessor will find (worse).

The most important decision an MSP makes on a CMMC engagement isn’t which tools to deploy. It’s whether they’re trying to build the operational capability themselves or partnering with a provider that has already done it.

The build path is expensive. Staffing a 24/7 US-only SOC with personnel cleared to handle CUI, deploying FedRAMP-authorized infrastructure, maintaining the documentation and evidence trail across 110 controls, and going through your own C3PAO assessment runs between $1.2M and $3M before you’ve delivered a single client outcome. That math works for a handful of large security practices. It doesn’t work for most MSPs.

The partner path looks different. When the MSSP you work with has already achieved C3PAO-verified CMMC Level 2 certification with a perfect 110/110 score, their controls become part of the evidence package. Clients inherit FedRAMP High controls through the GovCloud infrastructure. The 46 Level 1 and Level 2 control mappings across access, audit, incident response, risk, and monitoring are operational, not theoretical. That’s the inheritance model, and it dramatically compresses the certification timeline for the clients you’re supporting.

Cyflare is one of approximately 250 organizations worldwide with C3PAO-verified CMMC Level 2 certification. US-only SOC and TechOps staffing. CrowdStrike GovCloud infrastructure authorized at FedRAMP High. The controls aren’t on paper. They’re running.

When a client comes to you with a CMMC requirement, they need four things.

Scoping help. Someone who can sit down with them, map their CUI environment correctly, and tell them honestly what’s in scope and what isn’t. Scope bloat is expensive. Scope gaps are fatal to certification.

A remediation roadmap. Not a list of controls with checkboxes. A sequenced plan that moves them from current state to assessor-ready, with timeline and resource requirements built in.

Operational controls they can evidence. This is where the partner model earns its keep. Controls that are running and logged inside a certified environment produce audit-ready evidence as a natural byproduct. You’re not generating reports for the assessor. You’re pulling logs that already exist.

A partner who won’t strand them. CMMC is not a one-time project. The framework requires continuous compliance. The partner relationship has to support the ongoing monitoring, log retention, and incident response capability that keeps the certification current.

The defense supply chain extends further down than most MSPs realize. Prime contractors have flow-down requirements, meaning their subcontractors and suppliers, many of them mid-market companies that look exactly like your current clients, face the same CMMC obligations. The MSPs who build a credible CMMC delivery capability in the next 12 months will own a segment of that market before the backlog clears.

The ones who wait will be competing for it after someone else already locked up the relationships.

The certification math is working in favor of MSPs who move early. There are only ~75 assessors, roughly 80,000 organizations in queue, and enforcement rolling into new solicitations right now. The conversation your client hasn’t had with you yet is the one where they tell you a contract depends on it.

Be ready for it.

Cyflare’s CMMC compliance services show exactly how managed security services align to Level 2 requirements, domain by domain.

Get the CMMC Mapping Guide or book a working session to walk through what CMMC delivery looks like for your partner practice.

Book a working session.


Frequently Asked Questions

What’s the difference between CMMC Level 1 and Level 2?

Level 1 covers basic safeguarding requirements for Federal Contract Information, 17 practices, self-assessed annually. Level 2 covers the full 110 practices from NIST SP 800-171 for Controlled Unclassified Information, and requires third-party assessment by a C3PAO for most contracts. Level 2 is the tier most MSP clients in the defense supply chain will need.

How long does CMMC Level 2 certification actually take?

For most organizations, six to twelve months from initial scoping to a passed assessment, assuming no major remediation gaps. Add time if the CUI environment isn’t cleanly scoped yet, or if you’re waiting in the assessor backlog. Starting early is the single biggest lever on timeline.

Can my client self-attest instead of going through a C3PAO?

Not for most current and upcoming DoD contracts requiring Level 2. Self-attestation was allowed in earlier framework iterations, but the CMMC Acquisition Rule that took effect November 2025 enables contracting officers to require independent C3PAO assessment directly in new solicitations.

What happens if my client misses their CMMC deadline?

They become ineligible for new DoD contract awards requiring that certification level, and existing contracts can be put at risk depending on contract terms. With roughly 80,000 organizations in the assessor backlog, missing a deadline because certification wasn’t started early enough is becoming a common and avoidable failure.

Do all of an MSP’s clients need CMMC, or just the ones with direct DoD contracts?

Flow-down requirements extend the obligation to subcontractors and suppliers throughout the defense industrial base, not just prime contractors. If your client supplies a company that supplies the DoD, they may be in scope even without a direct contract. Scoping the CUI environment correctly determines this.

How is Cyflare different from a CMMC consulting firm?

A consulting firm helps you document and prepare for an assessment. Cyflare operates the underlying security controls directly, with our own C3PAO-verified 110/110 certification, so the evidence your clients need comes from a system that’s actually running, not a one-time engagement that ends at the assessment date.

CONTENTS

Related Articles