Devin Colomba

How Long Does CMMC Level 2 Actually Take?

Ask five consultants how long CMMC Level 2 certification takes and you’ll get five versions of “it depends.” That’s not wrong, but it’s not useful either. The truth is that timelines follow predictable patterns based on where an organization starts. This article lays out realistic timeframes for mid-size defense contractors (50-250 employees) pursuing Level 2[…]

Evidence, Artifacts, and “Show Me, Don’t Tell Me”: What Assessors Look For in a CMMC Assessment

For many business owners, the most frustrating part of preparing for a CMMC Level 2 assessment isn’t the controls themselves. It’s understanding what an assessor will accept as proof that those controls are in place. Policies get written. Tools get purchased. Screenshots get collected. And yet, when the assessment starts, uncertainty creeps in. What exactly[…]

What to Expect When Engaging a C3PAO: Inside the CMMC Level 2 Assessment Process

For many organizations in the Defense Industrial Base (DIB), achieving Cybersecurity Maturity Model Certification (CMMC) Level 2 is no longer optional — it’s essential for winning and maintaining Department of Defense (DoD) contracts involving Controlled Unclassified Information (CUI). Yet for executives and business owners, the path to certification often feels uncertain. What actually happens during[…]

Part 1 – Why Scoping Makes or Breaks CMMC Compliance

When organizations begin their CMMC compliance journey, the most common and most expensive—mistake is getting scoping wrong. CMMC scoping is the first and most critical step in compliance. It defines exactly which systems, users, and processes fall under CMMC requirements. Get it wrong, and you risk overspending on unnecessary protections or leaving dangerous gaps that[…]