How long does it take to complete the entire CMMC process?
Gap analysis is a short-term project, usually three to four months, but the entire process of CMMC compliance can take more than a year. So, start early.
What happens after the gap analysis?
A gap analysis is followed by:
- Gap remediation: You implement policies, procedures and systems to meet the CMMC standard. (This step alone will take one to two years.)
- Choosing an assessor: Find a Certified Third-Party Assessor Organization (C3PAO). These organizations are currently in short supply for the expected demand so find one early. (If we work with you as a Registered Practioner, we can’t also do your assessment. But we can help you find a good assessor.)
- Assessment: An assessment for a smaller business will cost between $25,000 and $50,000.
- DoD submission: Submit your report to the DoD. You must meet at least 80% of the criteria to go on to the next step.
- Compliance: Reach 100% compliance and become certified. You’ll have 180 days (about 6 months) to correct any issues. The CyberAB will issue you a certificate, which will be good for three years.
Are there follow-up services?
Our ongoing services include CMMC consulting and managed services tailored to CMMC compliance.