CMMC guide
CMMC Level 2 requirements, explained for a 20 person shop
CMMC Level 2 means your company meets all 110 security requirements in NIST SP 800-171 Revision 2, writes down how each one is met, and can show evidence that it is actually happening. The requirement applies to any contract where you handle Controlled Unclassified Information, which is most machining, fabrication, engineering and sustainment work for the Department of War. As of October 2026 the Department has suspended the rule that would have required a third party certification before award; the self assessment, the SPRS score and the annual affirmation are still required.
What exactly is required?
Four things, and the fourth is the one small shops miss.
- The 110 requirements. They come from NIST SP 800-171 Rev 2, and CMMC still points at Rev 2 even though NIST has published Rev 3. Each requirement is a specific, testable statement, such as limiting system access to authorized users or using multifactor authentication for network access.
- A System Security Plan. One document that describes the boundary of the systems that touch CUI, every asset inside it, and how each of the 110 requirements is met. The SSP is itself one of the requirements (CA.L2-3.12.4), so a company without one has not met Level 2 by definition.
- A Plan of Action and Milestones for anything not yet met. Level 2 allows a limited plan for open items, and each item has to close within 180 days of the assessment. The plan is for finishing work, not for parking it.
- Evidence. A policy says what should happen. Evidence proves it did: the configuration screen that shows MFA enforced, the training records with dates, the log that shows the alert fired. Assessors work from 320 assessment objectives underneath the 110 requirements, and every objective has to be met for the requirement to count.
What are the 14 families?
The 110 requirements are grouped into 14 families. One line each, with the count at Level 2.
- Access Control (22): who can get into what, from where, and what they can do once in.
- Awareness and Training (3): everyone who touches the systems is trained, and you can prove when.
- Audit and Accountability (9): logs exist, are kept, and tie an action to one named person.
- Configuration Management (9): a known baseline for every system, and changes are controlled.
- Identification and Authentication (11): unique accounts, password rules, multifactor.
- Incident Response (3): you can detect, respond to, report and learn from an incident.
- Maintenance (6): who maintains systems, with what tools, and how off site repair is handled.
- Media Protection (9): USB drives, backups, paper and old disks are controlled and destroyed.
- Physical Protection (6): who can walk up to the equipment, and how visitors are escorted.
- Personnel Security (2): screening before access, and access removed when someone leaves.
- Risk Assessment (3): you look for weaknesses on a schedule, including vulnerability scans.
- Security Assessment (4): you assess yourself, keep the SSP current, and track open items.
- System and Communications Protection (16): the network boundary, encryption, separation.
- System and Information Integrity (7): patching, malware protection, monitoring, alerts.
Access Control and System and Communications Protection together are 38 of the 110, which is why the shape of your network decides most of the cost.
Who checks, and when?
Three mechanisms exist, and only two are active today.
A self assessment against all 110 requirements, scored and posted to SPRS, the Department's supplier portal, with an annual affirmation signed by a senior official. This is required now under DFARS 252.204-7019 and 7020, and it is what most contracts check today.
A third party assessment by a C3PAO. The CMMC rule made this the default for most Level 2 contracts in its second phase, which was scheduled for November 10, 2026. On July 13, 2026 the Department of War suspended that requirement pending a reform review. The review's report was due in September 2026 and had not been published when this page was written.
Government led assessments. The Department said it would continue to enforce compliance through self assessments and select government led assessments during the suspension.
What did not change: DFARS 252.204-7012, which requires the 110 controls and 72 hour incident reporting, the self assessment, the SPRS score and the affirmation. The affirmation is signed by a named officer of your company. False Claims Act settlements in 2025 against contractors who certified compliance they did not have ran into the millions, and the suspension removed the assessor who would otherwise have caught an inflated score before the government did. The signature now carries the whole weight.
What counts as CUI in a small shop?
Controlled Unclassified Information is information the government or a prime marks as controlled under 32 CFR Part 2002. In a machine shop it is usually the drawings, the technical data package, the specifications and the part files attached to a purchase order. If your prime sends you drawings with a distribution statement or a CUI marking, you handle CUI. Federal Contract Information, the lower bar covered by Level 1, is the non public information in the contract itself.
If nobody has ever sent you a marked document, you may be a Level 1 company. Read the contract clauses. DFARS 252.204-7012 in the contract means CUI is expected.
What do small shops always miss?
Three things, in the order assessors find them.
Scoping. Every computer, server, phone and cloud service has to be sorted into one of five categories: CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out of scope. The assessor expects four pieces of paper: a CUI flow diagram, a network boundary diagram, a physical site diagram and an authorized user list. Missing any of the four is the most common scoping finding, and a shop that has not scoped is assessing its whole company instead of the ten machines that matter.
The SSP. Most small suppliers have policies. Fewer have one document that walks the boundary and answers all 110 requirements. The SSP is where "we do that" turns into "here is how, here is who, here is the evidence".
Evidence that exists only on paper. A policy dated 2019 with no review since, a training roster that lists 40 people when 28 completed it, an incident procedure that names a tool you replaced last year. Assessors read for consistency between the policy and the system, and the system wins every argument.
What does it cost?
It depends on how much of your company touches CUI, which is why the first step is a gap assessment, not a quote. Our CMMC Level 2 gap assessment scores all 110 requirements against your environment and names what closing each gap takes, for a published price. Industry wide, first year spend for a mid sized supplier runs from the low hundreds of thousands, and an enclave approach that keeps the shop floor out of scope is the single biggest lever on that number.
What should a 20 person shop do this quarter?
- Find the clauses. Pull your active contracts and look for DFARS 252.204-7012, 7019, 7020 and 7021. That tells you whether CUI is expected and whether a SPRS score is already owed.
- Draw where CUI goes. One page: how it arrives, where it sits, who opens it, where it leaves. That drawing decides the scope and most of the cost.
- Get an honest score. A gap assessment against all 110 requirements, with evidence, not a questionnaire. Post the real number to SPRS.
- Fix in order. Multifactor on every login, a boundary around the CUI machines, logging that names a person, and an SSP that matches reality. Then everything else.
Questions contractors ask
FAQIs CMMC cancelled?
No. The third party certification requirement was suspended in July 2026 pending a review. The 110 requirements, the self assessment, the SPRS score and the annual affirmation are all still required under DFARS 252.204-7012, 7019 and 7020.
Do I need Level 2 if I only make parts?
If your prime sends you marked drawings or technical data, yes. The information makes it Level 2, not the kind of work.
How long does it take?
A focused shop with a small CUI boundary can reach an honest, evidenced Level 2 posture in six to nine months. Shops that try to bring the whole company into scope take longer and spend more.
Can I put everything on a POA&M and sort it out later?
No. Open items have to close within 180 days, and some requirements have to be in place before an assessment can succeed. The plan is for finishing, not deferring.
Is NIST 800-171 Revision 3 required?
Not yet for CMMC. The rule still cites Revision 2, and that is what assessors test against.
Already know you want to talk?
BOOK A CALLSkip the form. Pick a time and talk to us directly.
What happens in 30 minutes
- We learn about your business and the defense contracts you hold or are bidding on.
- We walk you through a gap assessment, the first step toward CMMC, and what it covers.
- If you qualify, we help you apply for an in-kind grant from Cyber Grants Alliance to cover it. No slides.
Defense supplier under 25 people? Start with the grant.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the work itself, including CMMC Level 1 and Level 2 gap assessments, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.