The CMMC deadline is real. The path is not linear.
Five phases, one boundary decision, and the reason "just do CMMC" is the wrong instruction for most suppliers.
Defense suppliers have heard about CMMC for long enough that a certain fatalism has set in. The requirement is now flowing down through contract clauses, capacity at authorized assessment organizations is finite, and the suppliers who treat this as a single project with a single deadline tend to discover the sequencing problem late.
The path to a Level 2 certification runs through five distinct phases, and each one gates the next. Scoping defines the CUI boundary — which systems, which people, which physical locations handle controlled unclassified information. Assessment scores all 110 NIST SP 800-171 controls and produces the SPRS figure. Remediation closes the gaps, which for most suppliers means both technical work and a substantial documentation effort. Preparation runs the mock assessment against the CMMC assessment guide. Certification is performed by an authorized C3PAO, which is a separate organization on its own schedule.
The boundary decision in phase one drives everything downstream. A supplier who draws the CUI boundary around the entire company is committing to implement 110 controls across every system and every user. A supplier who scopes an enclave — a defined set of systems where CUI is received, processed, and stored, with controlled paths in and out — is committing to a fraction of that. The enclave costs engineering effort up front and saves a great deal afterward.
This is also where "just doing CMMC" stops being the whole answer. Most DIB manufacturers carry obligations beyond the defense contract. NIST CSF often provides the governance layer the assessment expects to see operating. Suppliers with automotive-adjacent product lines carry TISAX for European OEM customers, assessed against a different catalogue by a different provider. Run those independently and the same physical security, access control, and media handling work gets built two or three times.
One structural note. Framewise handles readiness, implementation, and audit preparation. The formal Level 2 assessment is performed by an authorized C3PAO we partner with, and we do not hold C3PAO status. Any firm offering to both prepare you and certify you is describing an arrangement the program does not permit.