For Level 2 certification, the bulk of the timeline is closing the distance between your environment and NIST 800-171. That means scoping where CUI actually lives, writing the system security plan, and working the POA&M down until the gaps are closed. How long that takes is a function of starting posture and scope — defense-adjacent teams with a contained enclave move in months; a company remediating a whole flat network measures it differently.
The second clock belongs to the C3PAO. Authorized assessors are a finite pool, demand runs ahead of supply, and assessment dates get reserved well in advance. Treat the booking as the long-lead item it is: schedule while remediation is still in flight, and confirm with the assessor what must be closed outright versus what may remain on a POA&M at assessment time.
Scope is the lever. A tight CUI enclave shrinks the control surface, the SSP, and the assessment itself. Level 1, by contrast, is an annual self-assessment against basic safeguarding practices — no third-party calendar at all. The framework’s structure is on the CMMC 2.0 page; for running the whole effort under contract pressure with fractional leadership, see the vCISO for government contractors.
Level 2 certification assessments run on a three-year cycle, with annual affirmations of continued compliance in between. Falling out of posture between assessments is exactly what the affirmations exist to surface.
No. Level 1 is a self-assessment against basic safeguarding requirements for federal contract information — no C3PAO and no scheduling queue. The timeline is simply your own remediation pace.