CMMC for small shops
The Department of Defense wants proof that its suppliers protect the information it shares with them. CMMC is the proof. Here is what it asks of a shop with a few computers and a lot of drawings.
What CMMC is
The Cybersecurity Maturity Model Certification, CMMC, is a Department of Defense program that verifies contractors meet a set of cybersecurity requirements before they can hold contracts that involve sensitive information. It is run by the DoD Chief Information Officer. The current version has three levels, and the level required is written into each contract.
The program exists because earlier rules relied on contractors to say they were compliant. CMMC adds assessment. Depending on the level and the contract, that assessment is a self-assessment you affirm, or an assessment by an authorized third party, or an assessment by the government.
CMMC does not invent new security requirements. It checks whether you meet requirements that already exist in the FAR and DFARS. That is why two other names come up every time someone mentions it.
Why DFARS 252.204-7012 and NIST SP 800-171 come up
DFARS clause 252.204-7012 has been in defense contracts for years. It requires a contractor that handles covered defense information to protect it according to a standard from the National Institute of Standards and Technology, NIST Special Publication 800-171, and to report cyber incidents to the Department of Defense quickly. If a clause on an order says 7012, you have already agreed to meet 800-171.
NIST SP 800-171 is a list of security requirements for protecting controlled unclassified information, CUI, on non-federal systems. It covers things like access control, identification and authentication, audit logs, configuration management, incident response, media protection, physical protection, and system integrity. Each requirement is short. The work is in doing all of them and proving it.
Two more DFARS clauses, 252.204-7019 and 7020, require you to score yourself against 800-171 and post that score in a government system before award. CMMC Level 2 is essentially an assessed version of the same standard. So the chain is: 7012 requires 800-171, 7019 and 7020 require a score, and CMMC checks the score is real.
CMMC levels in plain terms
| Level | Information it protects | What it requires | How it is assessed |
|---|---|---|---|
| Level 1 | Federal contract information, the ordinary details of doing business with the government | The basic safeguarding practices in FAR 52.204-21 | Annual self-assessment and affirmation |
| Level 2 | Controlled unclassified information, including most export controlled drawings | The full set of NIST SP 800-171 requirements | Self-assessment for some contracts; third party assessment by an authorized assessor for most |
| Level 3 | CUI on the most sensitive programs | Level 2 plus a subset of NIST SP 800-172 | Government led assessment |
The program is being phased into contracts over several years. Confirm the current phase and rules on the DoD CIO CMMC site.
Which level a shop needs
The question is what information you handle. If your only federal data is purchase orders, invoices, and unclassified commercial drawings, you are likely a Level 1 shop. If you receive export controlled or distribution restricted technical data, which describes most military parts drawings, that data is generally CUI, and Level 2 is the likely requirement.
The solicitation or the prime's purchase order will state the level. Primes are required to flow the requirement down to subcontractors that will handle CUI, so expect supplier surveys to ask about your CMMC status and your 800-171 score.
If you are unsure whether a given drawing is CUI, ask the customer. Do not assume it is not.
A practical path for a small shop
The most useful decision a small shop can make is to shrink the problem. You do not have to bring every computer, phone, and machine controller up to the standard. You have to protect the systems where CUI lives. If CUI lives on two workstations in an office, a file server, and a CNC programming machine, that is your scope.
Steps that work for most shops
- 1
Find your CUI
List every place controlled drawings and data arrive, get stored, get sent, and get printed. Email, file shares, CAM software, USB sticks, the shop floor.
- 2
Draw a boundary
Decide which systems will hold CUI and keep it there. Many shops set up a separate enclave, either a dedicated network segment or a compliance-focused cloud environment, and keep everything else out of scope.
- 3
Do a gap assessment
Go through the 800-171 requirements one by one for the systems in scope. Record what you do, what you do not, and the evidence for each.
- 4
Write the two documents
A system security plan describing how you meet each requirement, and a plan of action for the ones you do not yet meet, with owners and dates.
- 5
Post your score
Calculate your self-assessment score by the DoD method and enter it in the government reporting system, as 7019 and 7020 require.
- 6
Close the gaps, then get assessed
Fix the open items. When the contract requires it, schedule a third party assessment. Keep the affirmation current every year.
Getting help without losing control
Most small shops use an outside managed service provider or a consultant for part of this. That is reasonable. Two cautions. First, the requirements are yours, and your executive signs the affirmation. Understand what the provider did and keep the documents in your own hands. Second, a provider that touches your CUI may be inside your assessment scope, so ask how they meet the standard themselves.
Costs vary widely with scope, so we do not quote figures here. Shrinking the scope is the single biggest lever you have. Regional manufacturing extension partnerships and APEX Accelerators, the counseling offices that replaced the old procurement technical assistance centers, offer low cost guidance on getting started.
Start with the score, not the certificate
Buyers and primes ask for your 800-171 score today. A real score with an honest plan of action shows you are working the problem. A certificate comes later, when the contract requires it.
Related guides
- ITAR, EAR, and DFARS basicsWhy most military drawings count as CUI.
- Subcontracting to primesHow the cyber clauses reach you as flowdowns.
- Quality systems: AS9100 and ISO 9001The other set of documented practices buyers ask about.
- Your first 90 daysWhere CMMC scoping fits in a new shop's plan.
See who was last awarded in your NAICS
The free report shows who bought your part category, who won, and what is coming up for recompete.