Blog

CMMC in Plain English: What Defense Suppliers Need to Know Now

CMMC requirements are appearing in DoD contracts now, and the third-party certification phase begins in November 2026. What the levels mean, who they apply to, and what to do first.

If your business sells to the Department of Defense, or to somebody who does, CMMC has stopped being a thing to watch and become a thing to do. CMMC requirements started appearing in new defense solicitations in November 2025, and the phase that lets contracts demand third-party certification begins in November 2026. Getting certified takes months, so the time to work out what applies to you is now, not when a contract shows up with the clause in it.

What CMMC actually is

The Cybersecurity Maturity Model Certification is the Department of Defense's way of verifying that the companies in its supply chain protect the government information they handle. The security requirements themselves are mostly not new. Defense contracts have required them for years through DFARS clauses, largely on the honor system. CMMC is the end of the honor system: instead of promising you meet the requirements, you demonstrate it, and for many companies an independent assessor confirms it.

It applies well beyond the big primes. If a prime contractor holds a DoD contract and sends you drawings, specifications, or parts requirements that include controlled information, the requirement flows down to you. Machine shops, fabricators, electronics assemblers, engineering firms, and logistics providers are all in scope when the information they touch is. Being two or three tiers down the supply chain does not take you out of it.

The three levels

  • Level 1 applies when you handle Federal Contract Information (FCI), meaning information provided by or generated for the government under contract that is not meant for public release. It requires 15 basic safeguarding practices, verified by an annual self-assessment that a senior company official personally affirms.
  • Level 2 applies when you handle Controlled Unclassified Information (CUI), which covers the technical drawings, specifications, and similar material most defense work involves. It requires all 110 security requirements of NIST SP 800-171. Most companies at this level need an assessment by an authorized third-party assessment organization (a C3PAO) every three years, plus an annual affirmation in between.
  • Level 3 adds selected requirements from NIST SP 800-172 for a small set of contractors supporting the most sensitive programs, and the government performs that assessment itself.

Most small and midsize defense suppliers land at Level 1 or Level 2. Which one you are is a question about the information moving through your shop, not about the size of your company.

The timeline that matters

  • December 2024. The CMMC program rule took effect, defining the levels and how assessments work.
  • November 2025. The acquisition rule took effect, and CMMC requirements began appearing in new DoD solicitations, starting with self-assessments.
  • November 2026. Phase two begins. Applicable new solicitations can require Level 2 certification by a C3PAO rather than a self-assessment.
  • Through 2028. The requirements phase into essentially all applicable defense contracts.

The practical consequence is about sequencing. Certification has to exist before a contract that requires it can be awarded to you. The assessment has to be scheduled, and assessors are a limited pool. The implementation work has to be done before the assessment. For a company starting from a typical baseline, that chain is measured in months, which is why waiting for the first solicitation that names CMMC is the expensive way to find out.

What to do first

  1. Work out what information you actually handle. FCI, CUI, or neither. Your contracts, your primes' flow-down clauses, and the markings on the documents you receive answer this. It determines your level, and everything else follows from it.
  2. Scope the environment. CMMC applies to the systems that store, process, or transmit that information, plus what protects them. Many shops can shrink the problem dramatically by keeping CUI in one well-controlled place instead of everywhere email reaches.
  3. Assess the gap. Compare what you have against the requirements for your level, honestly. For Level 2 this produces a score that goes into the government's Supplier Performance Risk System (SPRS), and primes increasingly ask for that number before they will send work your way.
  4. Close the gaps and write it down. A System Security Plan describing how each requirement is met, and a plan of action for anything still open. CMMC allows a conditional status with some items on a plan of action, but they have to be closed out within 180 days, and some requirements cannot be deferred at all.
  5. Book the assessment early. If your level and contracts require a C3PAO, the queue is real. Companies that schedule early get to pick their timing. Companies that schedule late get picked by it.

Where the effort usually goes

Across the 110 Level 2 requirements, a handful of areas absorb most of the work in a small business: multifactor authentication everywhere it is required, encryption that meets the standard rather than merely existing, logging that would actually support an investigation, and documentation. Documentation is the one that surprises people. Plenty of shops are doing much of the right work and have almost none of it written down, and for an assessor, undocumented is indistinguishable from undone.

The other surprise is that this is not a project with an end date. Annual affirmations are a legal commitment by a company officer that the requirements are still met, which means the monitoring, patching, and reviews have to keep running between assessments.

An honest note on scope

Not every business needs this. If nothing in your contracts touches FCI or CUI, CMMC is not your problem, and anybody who tells you otherwise is selling something. The first step of any conversation with us is establishing whether the requirement genuinely applies to you and at what level, and if the answer is that it does not, that is the answer you will get.

If it does apply, this is work we do. Our compliance services cover the gap assessment, remediation, documentation, and the ongoing operation that keeps an affirmation true. For manufacturers in the defense supply chain we have seen most versions of this problem, and if you have your own IT staff, we do this work alongside internal teams as well.

The useful first step is a conversation about what your contracts require, and it costs nothing. Schedule a call or contact us and we will help you work out where you stand.

  • Fast Track 50 Emerging Business Award, 2025
  • Top 3 Computer Support, Lake County, 2025
  • CyberCert SMB1001 Bronze
  • MSPAlliance member
  • Microsoft Partner
  • Dell Partner
  • Lenovo Partner
  • More than 20 years of experience
  • Managed services since 2010
  • Based in Northeast Ohio
  • Offices in Lake and Summit counties
  • Owner operated and independent
  • CMMC and HIPAA experience