CMMC Compliance for Small Defense Contractors: A Practical Guide

CMMC Compliance for Small Defense Contractors: A Practical Guide

How small defense contractors meet CMMC on a limited budget as of September 2026: which level applies, how to scope CUI, and free government help.

Deep Fathom Updated Last verified

Small defense contractors carry the same CMMC obligations as large primes, because 32 CFR Part 170 contains no exemption for company size. Where a contract designates a CMMC level, it is Level 1 (Self) for Federal Contract Information only, and at least Level 2 (Self) for any Controlled Unclassified Information (CUI). As of September 2026, with CMMC Phase 2 suspended by the Department of War (DoW) since July 13, 2026, new designations are limited to those two self-assessment levels, and existing contracts are to drop Level 2 (C3PAO) at the next option or administrative modification. DFARS 252.204-7012 still requires the 110 NIST SP 800-171 Revision 2 requirements on contractor systems that handle CUI under a DoD contract. The main cost levers are scope, through a separated CUI enclave, and sequence: the 63 requirements that must be MET for a Conditional status come first.

Small businesses make up 73 percent of companies in the defense industrial base, according to the SBA Office of Advocacy’s 2024 comment on the CMMC rule. They machine precision parts, write specialized software, provide engineering services and support logistics across the DoD supply chain. Yet they face the same CMMC requirements as a prime with 5,000 employees and its own security operations center.

This guide is for the 50-person manufacturer, the 20-person engineering firm and the 10-person software shop. Each needs a current CMMC status wherever a DoD contract designates a CMMC level. It assumes no compliance team and no six-figure consulting budget.

CMMC Requirements for a Small Contractor as of September 2026

A small contractor’s CMMC requirement depends on the information it handles and the level its contract designates. On July 13, 2026, the Department of War (DoW) suspended the move to CMMC Phase 2, which had been due November 10, 2026. It also held all later implementation milestones in abeyance. The implementing memo from USW(A&S) states that “the allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).” Phase 1 self-assessment requirements, in effect since November 10, 2025, remain in place.

SituationWhat applies as of September 2026What must be in SPRSRule
Federal Contract Information (FCI) onlyLevel 1 (Self): an annual self-assessment of the 15 safeguarding requirements in FAR 52.204-21, every one MET. No POA&M is allowed.The self-assessment result and an affirmation. Level 1 has no score.32 CFR 170.15, 170.22
CUI in a new solicitation or contractLevel 2 (Self), where the solicitation designates a CMMC level: a self-assessment of the 110 NIST SP 800-171 Revision 2 requirements every three years. A POA&M is allowed only for eligible requirements, at a score of 88 or more. Level 2 (C3PAO) and Level 3 may not be designated.Level, status date, assessment scope, CAGE codes in scope, overall score and POA&M status, then an affirmation before award and every year after32 CFR 170.16, 170.21, 170.22; USW(A&S) memo
CUI in an existing contract that still names Level 2 (C3PAO)The implementing memo directs removal of the C3PAO requirement by modification before the next option period or at the next scheduled administrative modification. A voluntary C3PAO assessment remains available.Contracting officers check SPRS before exercising an option. Confirm the modification with the contracting officer before that date.USW(A&S) memo; class deviation 2026-O0025
DFARS 252.204-7012 with no CMMC level statedNo CMMC status is designated. DFARS 252.204-7012 still requires NIST SP 800-171 Revision 2.A contract awarded before class deviation 2026-O0025 may still carry 252.204-7019 and 252.204-7020. Under 7020, a prime must not award a subcontract unless the subcontractor has a Basic NIST SP 800-171 DoD Assessment no more than three years old, with its score in SPRS. New solicitations under the deviation carry 252.240-7997, which covers only assessments by government personnel.DFARS 252.204-7012; class deviation 2026-O0025

Three rules sit behind the table. According to the DoW CIO memo, the cybersecurity requirements in DFARS 252.204-7012 “are still in effect.” Under class deviation 2026-O0025, contracting officers “must not award” a contract to an offeror without a current CMMC status at the level the solicitation requires. They check SPRS to confirm it, and again before exercising an option. And where the prime contract carries DFARS 252.204-7021, the prime must confirm that a subcontractor holds a current status appropriate to the information flowed down before awarding the subcontract.

Two edge cases are common for small firms. A company that handles CUI only on paper doesn’t need a CMMC third-party assessment, according to the DoW CIO CMMC FAQ. It must still protect that paper under 7012 and NIST SP 800-171. If it scans, prints or emails that CUI, the system it uses is expected to meet the CMMC requirements first. A cloud service that stores CUI must meet FedRAMP Moderate or equivalent under DFARS 252.204-7012.

Determining Your CMMC Level

The contract decides the level. Under 32 CFR 170.3(d), DoD program managers or requiring activities select the CMMC status “based upon the type of information, FCI or CUI.” It isn’t the contractor’s choice.

Level 1 (FCI only). If a contract involves only Federal Contract Information, Level 1 (Self) applies. It covers the 15 safeguarding requirements in FAR 52.204-21, assessed across 59 assessment objectives in DoD’s Level 1 Assessment Guide. Every year, the contractor self-assesses, enters the result in SPRS and has a senior official affirm it. No POA&M is allowed, so all 15 requirements must be MET.

Level 2 (CUI). If CUI enters the environment at any point, Level 2 (Self) is the minimum. The basis is 32 CFR 170.23 for subcontractors and DoW’s stated Phase 1 policy for contracts. Level 2 covers all 110 NIST SP 800-171 Revision 2 security requirements, evaluated across 320 assessment objectives. Scoring is weighted. The maximum is 110, each NOT MET requirement subtracts 5, 3 or 1 point, and the score can go negative. MFA and FIPS-validated encryption receive partial credit in defined cases. As of September 2026, new contracts cannot require a C3PAO assessment. Existing contracts that name one are to drop it at the next option or administrative modification.

Don’t assume Level 1 is sufficient. Technical drawings, test results, procurement specifications and export-controlled data can all be CUI. Ask the contracting officer or the prime, in writing, which information in the contract is CUI and how it is marked. Guessing tends to pull everything into scope, as the next section shows.

Clause Numbers in 2026 Contract Paperwork

  • DFARS 252.204-7012 in new DoD contracts is dated “(JUN 2026) (DEVIATION 2026-O0025)” and names NIST SP 800-171 Revision 2.
  • FAR 52.204-21 may appear as FAR 52.240-93 in new DoD solicitations. Class deviation 2026-O0025 directs contracting officers to use the overhauled FAR Part 40 text, where the basic safeguarding clause carries that number. 32 CFR Part 170 and the DoW CIO pages still say 52.204-21.
  • DFARS 252.204-7019 and 252.204-7020 are not prescribed for new solicitations under the deviation, which uses 252.240-7997 for government-led assessments. Where a contract designates a CMMC level, the self-assessment obligation now runs through 252.204-7021 and 32 CFR Part 170.
  • NIST’s website lists NIST SP 800-171 Revision 2 as withdrawn and superseded by Revision 3. DoD still assesses against Revision 2 until a rule incorporates Revision 3. That rule was targeted for July 2026 and hadn’t been published as of September 2026.

Why CMMC Hits Small Businesses Harder

CMMC’s requirements don’t scale with company size. A 30-person machine shop handling CUI faces the same 110 NIST SP 800-171 requirements and the same 320 assessment objectives as a 3,000-person prime. It works under the same self-assessment, scoring and affirmation rules, too.

Capacity is what scales. SBA’s Office of Advocacy wrote an August 14, 2026 letter to the CMMC Reform Task Force. It reported firms with “a single IT employee” and named five cost drivers for small businesses.

  1. Identifying CUI and setting the compliance boundary
  2. Implementing NIST SP 800-171
  3. Assessor cost and capacity
  4. Documentation and recurring evidence
  5. Commercial technology and FedRAMP equivalency

On the first driver, the letter observes that “when a contractor cannot confidently determine what information is CUI, they will generally err on the side of including all of it into their compliance boundary.”

When it suspended Phase 2, the Department of War cited the same burden. Its July 13, 2026 memo says the program “imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses.” The suspension limited new CMMC designations to self-assessment levels. But the 110 requirements under DFARS 252.204-7012 stayed in effect.

Most Challenging CMMC Requirements for Small Contractors and Manufacturers

The last column of the table below is Deep Fathom’s view, built on the rule text cited in each row. On this page, “can never go on a POA&M” means the requirement cannot be on the POA&M that supports a Conditional status under 32 CFR 170.21. But 32 CFR 170.24 still requires a POA&M entry for every NOT MET requirement.

Requirement areaWhat the rule requiresCost-effective way to meet it
Identifying CUI and setting the scopeThe assessment scope must be “specified prior to assessment” (32 CFR 170.19).Get written confirmation of what is CUI, then keep it in a separated enclave so fewer assets are CUI Assets. The Scoping Guide says separation is “required only for Out-of-Scope Assets.”
Cloud services and emailAny cloud service that holds covered defense information must meet FedRAMP Moderate or equivalent (7012(b)(2)(ii)(D)). The DoW CIO FAQ says encrypting CUI does not make a non-FedRAMP Moderate cloud acceptable.DoD’s FedRAMP equivalency memo says authorized offerings “can be leveraged without further assessment.” Put the provider’s customer responsibility matrix in the SSP.
FIPS-validated encryption (SC.L2-3.13.11)Encryption that protects CUI must use a FIPS-validated module. A FIPS-approved algorithm alone does not meet the requirement. FIPS 140-2 validations stayed active only until September 21, 2026, and NIST now lists them as Historical. NIST supports their continued use in existing systems, and DoW has not said how assessors will treat them.Check the module’s certificate in NIST’s Cryptographic Module Validation Program before relying on it, and buy FIPS 140-3 validated modules for new systems where one fits, since NIST warns the selection may be limited. A free archive tool that offers AES-256 meets the requirement only if its module is validated.
Multifactor authentication (IA.L2-3.5.3)MFA “for local and network access to privileged accounts and for network access to non-privileged accounts.” MFA for remote and privileged users only loses 3 points.Turn on MFA for every in-scope account type in the identity service already in use. Participants in SBA Advocacy’s July 2026 roundtable identified MFA as “one of the most valuable and cost-effective controls for reducing risk.”
System Security Plan and evidenceThe SSP requirement (CA.L2-3.12.4) can never go on a POA&M. Evidence “must be in final form and not draft,” and 32 CFR 170.16 requires keeping assessment artifacts for six years from the CMMC Status Date.Assign one person to write the SSP from the actual environment.
Printed CUI on the shop floorFive of the six physical protection requirements can never go on a POA&M: PE.L2-3.10.1 and 3.10.2 are worth 5 points, and 32 CFR 170.21 names PE.L2-3.10.3, 3.10.4 and 3.10.5.Keep printed CUI to defined areas so the physical protections cover less of the building.
Shop-floor and test equipmentOperational technology, IoT and test equipment can be Specialized Assets.See scoping CNC machines and shop-floor systems.

The same SBA letter lists the controls its roundtable participants identified as producing real cybersecurity benefits. They’re MFA, physical access controls, least privilege, encryption of CUI at rest and in transit, network segmentation, incident response procedures and exercises, and awareness training that builds resistance to phishing.

Scoping a 15-Person Company: A Worked Example

This example is illustrative. A 15-person precision parts supplier receives marked drawings (CUI) from a prime under a subcontract that carries DFARS 252.204-7012 and a Level 2 (Self) requirement.

32 CFR 170.19 sorts every asset into one of five categories, and each carries a different workload. CUI Assets are assessed against all Level 2 requirements. Security Protection Assets are assessed for “the capabilities provided.” Contractor Risk Managed Assets “can, but are not intended to, process, store, or transmit CUI,” and get a documented review with limited checks. Specialized Assets, such as operational technology and test equipment, are documented in the SSP and not assessed against the other requirements. Out-of-Scope Assets need a justification that they cannot process, store or transmit CUI.

Variant A: 4 of the 15 people handle CUI, so the company builds an enclave.

AssetCategoryWhy
Virtual desktops and file storage for the 4 CUI users, in a FedRAMP Moderate authorized (or equivalent) cloud offeringCUI AssetsThe company is assessed against every Level 2 requirement for its share. The provider’s share rests on its FedRAMP Moderate authorization or equivalency, the on-premises side that connects to the offering is in scope, and the provider’s customer responsibility matrix goes in the SSP (32 CFR 170.16(c)(2); 170.19).
The 4 users’ laptops, used only as virtual desktop clientsOut-of-Scope Assets, if configured and verified to pass only keyboard, video and mouse, with MFA to the virtual desktop separate from the laptop. Otherwise CUI Assets.DoW CIO FAQ, questions F-A1 and F-A2
Identity and MFA service for the enclave, and the log service that holds enclave logsSecurity Protection AssetsAssessed for the capabilities they provide (32 CFR 170.19)
The MSP that administers the enclaveExternal service providerIts services are in the assessment scope. It needs no CMMC certification of its own, and a customer responsibility matrix records who does what.
Corporate email and file server (commercial)Contractor Risk Managed Assets, if CUI could reach them but documented policy and practice keep it out. Out-of-Scope Assets only if they cannot process, store or transmit CUI.A Contractor Risk Managed Asset stays in the assessment scope: it goes in the asset inventory, SSP and network diagram, and the assessor can run a limited check (32 CFR 170.19). If CUI keeps arriving by email, the mailbox becomes a CUI Asset, so ask the prime to send CUI to the enclave.
Accounting and HR software-as-a-serviceOut of scope in most casesThe Scoping Guide says such services “typically do not contribute to the security of the OSA’s environment” or handle CUI.
CNC controllers that receive programs derived from the CUI drawingsSpecialized AssetsDocumented in the asset inventory, SSP and network diagram, and not assessed against the other requirements
Printed drawings on the shop floorCovered by the physical protection requirementsSee the printed CUI row in the previous section’s table.
Encrypted CUI crossing the corporate network to reach the enclaveDoes not pull corporate networking into scope, when the enclave is otherwise logically separatedDoW CIO FAQ, questions F-A3 and F-A4. Encryption alone does not create the separation.

Every requirement still has to be MET inside the enclave. As the Scoping Guide puts it, the contractor “determines which requirements are implemented and which requirements are inherited; all requirements must be MET.”

Variant B: all 15 people handle drawings every day, so the boundary is the whole company. In Deep Fathom’s view, an enclave would separate almost nothing here and add a second environment to run. In this variant, the cost levers shift to the cloud choice, the spending order in the next sections and the free government services.

Neither variant carries a savings figure. No official source measures the savings, and the result depends on the environment. For boundary patterns and controls, see CUI enclave patterns and boundary controls and how to define your CUI boundary.

The Real Cost of CMMC for Small Businesses

The only official per-company estimates are DoD’s, published with the 2024 CMMC rule in 2023 dollars. Nothing has replaced them since the suspension. For a small entity, DoD estimated a Level 2 (Self) assessment and affirmation at $34,277, or $37,196 over three years. Its estimate for the annual affirmation alone was $1,459.

Those figures cover the assessment only. DoD states that “there are no nonrecurring or recurring engineering costs associated with Level 2 self-assessment since it is assumed the contractor or subcontractor has implemented the NIST SP 800-171 R2 security requirements.” The DoW CIO FAQ adds that the cost of implementing DFARS 252.204-7012 isn’t counted as a CMMC cost. DoD’s model behind the $34,277 assumed 56 hours of a company director’s time. It also assumed 88 hours of an outside specialist at $260.28 an hour and about 8 hours of a staff IT specialist.

A voluntary C3PAO assessment costs more. DoD’s small-entity estimate for Level 2 (C3PAO) was $101,752, including a C3PAO fee of $31,234 (120 hours at $260.28). DoD also stated that “market forces of supply and demand will determine C3PAO pricing.”

SBA’s figures are much higher. In a July 13, 2026 news release, SBA said total compliance costs “can reach approximately $593,800” for a small firm requiring third-party assessment and “about $388,600” for a firm eligible for self-assessment. The release gives no method. These two sets of figures measure different things: DoD’s covers the assessment and affirmation, and SBA’s covers total compliance cost. For market prices with their publishers and dates, see the full breakdown of CMMC compliance costs.

The cost of losing eligibility. For a contractor whose revenue depends on DoD work, a lapsed status or affirmation puts the next award and the next option at risk.

Where Small Businesses Can Save

Reduce your scope. Separating CUI into a defined enclave limits the assets assessed. The Scoping Guide says that “by separating assets, the CMMC Assessment Scope can be limited.” Still, the tools that protect the enclave and any MSP services that touch it stay in scope.

Use your MSP strategically. An MSP the company already pays can implement a share of the technical requirements. Record its responsibilities in a customer responsibility matrix so every requirement has one owner.

Use existing tools first. Before buying new tools, check which requirements the current identity, email and endpoint services already meet when configured. Also check whether any service that will hold CUI is FedRAMP Moderate authorized or equivalent.

Split the work between inside and outside help, too. DoD’s own model pairs internal time with outside specialist hours. Deep Fathom’s advice for a small firm: keep the SSP, the evidence and the affirmation decisions in house. Buy outside help for defined tasks such as a scope review, specific configurations or a pre-assessment walkthrough.

Fund These First: The 63 Requirements That Must Be MET

A limited budget needs an order, and 32 CFR Part 170 supplies one. Under 32 CFR 170.21, a Conditional Level 2 status requires a score of at least 88 of 110. Its POA&M may hold only requirements worth 1 point. There’s one exception: SC.L2-3.13.11 may go on a POA&M when encryption is employed but is not FIPS-validated. Six requirements outside the 5-point and 3-point lists can never go on a POA&M: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4 and PE.L2-3.10.5. CA.L2-3.12.4, the SSP, has no point value: without an SSP, the assessment cannot be completed and no score results.

Deep Fathom derived the split below by counting the point values in 32 CFR 170.24 against the POA&M rule in 32 CFR 170.21.

Group of requirementsCountCan it go on a POA&M?
5-point requirements42No
3-point requirements14No
IA.L2-3.5.3, multifactor authentication (5 or 3 points)1No
Requirements that 170.21 names as never eligible (five 1-point requirements and the SSP, CA.L2-3.12.4)6No
SC.L2-3.13.11, FIPS-validated cryptography (5 or 3 points)1Only when encryption is employed but not FIPS-validated
Other 1-point requirements46Yes
Total110

That leaves 63 requirements (42 + 14 + 1 + 6) that must be MET at assessment. The 88-point floor allows at most 22 points of deductions. So no more than 22 of the 46 eligible 1-point requirements can be open at once. Fewer are allowed if SC.L2-3.13.11 is also on the POA&M at 3 points.

In Deep Fathom’s view, the budget order follows from that arithmetic. Fund the 63 must-meet requirements first, starting with the 5-point ones. Next, close enough 1-point requirements to reach 88 with a margin. Close the rest within 180 days of the Conditional status date. For Level 2 (Self), the closeout is a self-assessment “performed by the OSA in the same manner as the initial self-assessment.” If the 180 days pass without a closeout, the contractor becomes ineligible for additional awards that require Level 2 (Self) or higher for that scope.

Free and Low-Cost Government Help for Small Contractors

In its July 13, 2026 memo, the DoW CIO says three existing services “will continue to serve as no-cost resources” during the suspension. Those three are DoW Cyber Crime Center (DC3) services, NSA Cybersecurity Collaboration Center services, and the Office of Small Business Programs’ Project Spectrum.

ProgramWho runs itWhat is freeWho qualifies
NSA DIB Cybersecurity ServicesNSA Cybersecurity Collaboration CenterProtective DNS, attack surface management, threat intelligence, and Continuous Autonomous Penetration Testing, which NSA says gives small businesses a way to run their own internal pentests “at no cost and with no prior expertise.” NSA says the services are free “because DoW currently funds them.”Any company “that contracts with DoW (sub or prime) or has access to non-public DoW information”
Project Spectrum”Partnered with DoW Office of Small Business Programs,” according to its siteSelf-assessments against NIST SP 800-171 and CMMC Levels 1 and 2, training, and a no-cost advisory session. The site also sells tailored packages and hosting, so not everything on it is free.Designed for small and medium-sized DIB businesses, and open to others. Access starts with a free account, and the advisory session is booked through the platform.
APEX AcceleratorsDoW. The site says the Office of Small Business Programs has managed the program since FY 2023, and its footer names the “Office of Industrial Base Growth” as operator.”No-cost guidance and support services” through more than 300 offices. The listed services are contracting help, such as registration, proposals and market research. Cybersecurity and CMMC are not named among them.Eligibility terms are not stated on the pages reviewed.
NIST Manufacturing Extension Partnership (MEP)NIST, through state-designated MEP Centers in every state and Puerto RicoNIST’s publications are free, including a segmentation guide for small manufacturers. NIST withdrew its 2017 MEP self-assessment handbook (Handbook 162) in 2022 in favor of NIST SP 800-171A, so use DoD’s CMMC Level 2 Assessment Guide for a self-assessment. NIST’s pages do not describe MEP engagements as free. In one NIST case study, Arizona MEP ran a fixed-price engagement that delivered a gap assessment, an SSP and a draft POA&M for a small aerospace manufacturer.Manufacturers
DC3 and Warfighting Acquisition UniversityDoWThe CIO memo names DC3 services as no-cost resources. The DoW CIO FAQ points to a DC3 list of “no-cost cybersecurity resources” and to free online cybersecurity training from the Warfighting Acquisition University.Not stated in the memo or the FAQ

The FAQ’s resource list also includes the Cyber AB Marketplace, a directory of C3PAOs and Registered Provider Organizations. It helps a contractor find a provider. Providers listed there set their own prices.

The Five-Step Approach for Small Contractors

The steps below are a planning sequence for the Level 2 (Self) path. They follow the order the DoW CIO FAQ gives for preparing: self-assess, correct the gaps, then assess. No rule sets the week ranges. They’re Deep Fathom’s planning estimates.

Step 1: Scope and Baseline (Weeks 1-4)

Map the CUI data flows. Identify every system, application and endpoint that touches CUI, and document the assessment boundary, which 32 CFR 170.19 requires before assessment. Then run an honest gap assessment against all 110 NIST SP 800-171 requirements at the assessment-objective level.

Score the result with the 32 CFR 170.24 method. Scores can go negative, and a low first score is still a useful, quantified starting point.

Step 2: Must-Meet Requirements and Quick Wins (Weeks 5-10)

Work through the must-meet requirements in the order the funding section above sets out. These quick wins are common for small contractors.

  • Enable MFA for local and network access to privileged accounts and for network access to all other accounts
  • Confirm that encryption protecting CUI at rest and in transit uses a FIPS-validated module
  • Configure audit logging with defined retention and review procedures
  • Lock down remote access with encryption and MFA
  • Set session lock and account lockout policies
  • Complete security awareness training for all personnel and record attendance

Step 3: Documentation Build (Weeks 8-16)

System Security Plan (SSP). The SSP describes the actual environment: the system boundary, how each of the 110 requirements is implemented and the connections to other systems (NIST SP 800-171 3.12.4). Recording who owns each requirement and where its evidence sits makes the SSP usable at assessment. In Deep Fathom’s view, it stalls in small companies because nobody’s assigned to write it.

Policies. Organizing policies by the 14 NIST SP 800-171 families is a common practice. Deep Fathom’s test is whether each policy matches what the company does in practice. A short, specific policy does that better than a long template.

POA&M. Record each open requirement with the gap, the remediation action, the owner and the target date. For a Conditional Level 2 status, every item must close within 180 days of the Conditional status date.

Step 4: Evidence Collection (Ongoing from Step 2)

32 CFR 170.24 says “all evidence must be in final form and not draft,” so collect it as each requirement is implemented.

For each requirement, capture an artifact that shows it working: configuration exports, access control lists, training records, scan reports, policy approvals, audit log samples. In a small company, the common trap is doing the work without keeping the record. For example, MFA gets enabled with no configuration export, or training is held with no attendance list. An assessment can only credit what the evidence shows.

Step 5: Self-Assess, Enter the Result in SPRS and Affirm (Weeks 14-24)

Walk through every requirement as an assessor would, test evidence retrieval, and prepare the people who handle CUI to explain their procedures. Then run the Level 2 self-assessment.

Enter the results in the Supplier Performance Risk System (SPRS). The Level 2 row of the requirements table above lists the fields to enter. Then the Affirming Official, the senior representative responsible for the company’s compliance, affirms in SPRS. The official affirms again after any POA&M closeout and every year after that. Suppliers may print their SPRS status to share with primes.

A voluntary C3PAO assessment remains an option for a contractor that wants independent assurance or whose prime asks for it. See Level 2 self-assessment versus C3PAO certification.

If You Are the Only IT Person: The First 30 Days

At a 40-person machine shop with one IT person, the first month should produce decisions and a baseline before any tool purchase. Here’s the sequence Deep Fathom recommends.

  1. Week 1: collect the contracts and clauses. List every DoD contract and subcontract. Note which carry FAR 52.204-21 (or 52.240-93), DFARS 252.204-7012 and a CMMC level in 252.204-7021. Ask the contracting officer or the prime, in writing, which information is CUI.
  2. Also in week 1, name the owners. 32 CFR 170.22 makes the Affirming Official “the senior level representative … responsible for ensuring the OSA’s compliance.” Ask the owner or a senior executive to take that role, and name who controls the compliance budget.
  3. Week 2: draw a one-page CUI flow. Show where CUI arrives (email, portal, removable media, paper), where it’s stored, who uses it, which machines receive programs derived from it and where it leaves. That sketch starts the assessment scope that 32 CFR 170.19 requires.
  4. Enroll in NSA’s free services in week 2 as well. Protective DNS and attack surface management cost nothing for DoW primes and subcontractors.
  5. Weeks 3 and 4: score a baseline. Self-assess the 110 requirements, mark the must-meet gaps, and use the worked example above to decide between an enclave and the whole company.
  6. On day 30, give the Affirming Official a one-page plan. List the scope decision, the must-meet gaps, the estimated cost of each fix and the outside help needed.

Shop-floor specifics, such as CNC controllers and program transfer, are covered in CMMC for manufacturers.

Working with an MSP for CMMC

A small contractor that uses a managed service provider (MSP) for IT has to decide how the MSP fits the CMMC scope before the self-assessment.

Clarify ESP status. An MSP or managed security service provider that processes, stores or transmits CUI or security protection data for the contractor is an External Service Provider (ESP). Under 32 CFR 170.19, “the services provided by the ESP are in the OSA’s assessment scope.” Those services, rather than the MSP’s entire environment, are what the contractor’s assessment covers. A provider that handles neither CUI nor security data isn’t an ESP.

Build a customer responsibility matrix (CRM). 32 CFR 170.19 requires ESP use to be “documented in the OSA’s SSP and described in the ESP’s service description and customer responsibility matrix (CRM).” The CRM records which requirements the contractor owns, which the MSP owns and which are shared. Every requirement needs one clear owner.

Verify the MSP’s practices. The DoW CIO FAQ says “the MSP is not required to have its own CMMC assessment.” An ESP may choose certification voluntarily. Ask for evidence that the services the MSP runs meet the requirements assigned to it in the CRM. See when your MSP is in your CMMC scope.

Common Mistakes Small Contractors Make

Waiting for a solicitation. Level 2 preparation is measured in months, and a solicitation’s CMMC requirement applies at award. Starting before a solicitation arrives keeps the work on the company’s schedule.

Over-scoping the boundary. Small contractors often put the entire network in scope because they haven’t separated CUI. Every in-scope system needs documentation, monitoring and assessment evidence. The scope-reduction advice above applies.

Then there’s documentation that doesn’t match the environment. A downloaded SSP template that does not describe the actual systems, policies and procedures will not hold up. Boilerplate policies and pre-packaged evidence have the same problem.

Treating the status as a finish line. A Final Level 2 (Self) status stays current for up to three years. After that, the self-assessment and its cost recur. An affirmation stays current for up to one year. In 2021 the Department of Justice announced a Civil Cyber-Fraud Initiative that uses the False Claims Act against contractors “knowingly misrepresenting their cybersecurity practices or protocols.”

The Suspension and the Task Force: What Holds Until a Rule Changes

As of September 24, 2026, the status is as follows:

  • The review. A CMMC Reform Task Force was set up for a 60-day review, which ended around September 11, 2026. No report or decision had been published.
  • The outcomes. This guide doesn’t predict the result. The self-assessment-only designations may continue. The program may be redesigned: the CIO memo asks the task force to recommend a framework that replaces “prohibitive, third-party compliance models with scalable, realistic security measures.” Or third-party certification may return in some form. Separately, the rule that moves CMMC to NIST SP 800-171 Revision 3 may be published.
  • What stays in force until a rule or contract changes it. DFARS 252.204-7012 applies, and NIST SP 800-171 Revision 2 stays the baseline. The SSP and the evidence serve 7012 whatever the task force decides, because NIST SP 800-171 requires the SSP (3.12.4). A current CMMC status and affirmation in SPRS stay valid for the periods DFARS 252.204-7021 sets. No source yet says how a redesigned program would treat existing statuses, or what deadline would apply if third-party certification returns.

There’s also a separate proposal. FAR Case 2026-001 proposes a governmentwide CUI clause based on NIST SP 800-171 Revision 3, with 72-hour incident reporting. It is a proposed rule only. Comments closed on July 23, 2026, and no final rule had been published.

For what to check in a specific solicitation or contract during the suspension, see what the July 2026 suspension changes.

Getting Started

Deep Fathom organizes the requirement, work and evidence record for CMMC: each requirement, its owner, its evidence and the changes that affect an affirmation. Solicitation and contract requirements come from the contracting office. The Affirming Official affirms in SPRS, and a C3PAO, when engaged, determines assessment results.

Send us three things: the clauses in your contracts (FAR 52.204-21 only, or DFARS 252.204-7012 with CUI), which people and systems touch CUI, and your current self-assessment score if you have one. Our team will review them and reply within one business day with what needs attention before your next SPRS entry or affirmation. Send them to our team, see how Deep Fathom organizes CMMC work or create a free workspace to track the work yourself.


References · 6 official sources
SourceWhat it covers in this articleType
32 CFR Part 170 (CMMC Program Rule)Applicability with no size exemption, Level 1 and Level 2 self-assessment, SPRS entries, scoring, POA&M limits, the 180-day closeout, asset categories, external service providers, affirmations and evidence retentionRegulation
DFARS 252.204-7012 (Safeguarding Covered Defense Information)The NIST SP 800-171 requirement (Revision 2 in the JUN 2026 deviation text), still in effect during the suspension, and the FedRAMP Moderate rule for cloud services holding covered defense informationRegulation
DFARS 252.204-7021 (CMMC Level Requirements)The contract clause that carries the CMMC level, how long a status and an affirmation stay current, and the prime’s check of a subcontractor’s statusRegulation
NIST SP 800-171 Rev 2The 110 security requirements, including FIPS-validated cryptography and multifactor authentication. NIST lists it as withdrawn, while DoD still assesses against itStandard
DoW CIO memo suspending CMMC Phase II (July 13, 2026)The Phase 2 suspension, the self-assessment-only designations, 7012 remaining in effect, the burden on small businesses and the three no-cost DoW resourcesGuidance
CMMC Scoping Guide, Level 2 (v2.13)Separation and scope reduction, enclave inheritance, and HR and accounting services outside the ESP definitionGuidance