Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

CMMC Compliance for Small Businesses: Levels, Requirements, Costs, and Deadlines (2026 Guide)

June 11, 2026

In this article:

TL;DR: If you sell to the Department of Defense, directly or as a sub-supplier, CMMC certification now determines whether you keep those contracts. Most small defense contractors need Level 2, which requires all 110 NIST SP 800-171 security practices and, for prioritized acquisitions, a third-party C3PAO assessment that DoD estimates at approximately $105,000 over the three-year certification cycle for a small entity. Phase 1 enforcement began November 10, 2025, and third-party assessment requirements expand starting November 10, 2026. Contractors starting from a low SPRS baseline routinely need six to 12 months to remediate before they can pass.

The Department of Defense built the Cybersecurity Maturity Model Certification program around a documented problem: defense contractors were submitting cybersecurity compliance scores that didn’t reflect their actual security posture. The self-attestation mechanism was DFARS clause 252.204-7012, which let suppliers self-report their NIST SP 800-171 scores to the Supplier Performance Risk System with no independent verification required. Assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) found widespread gaps between what contractors claimed and what their environments actually delivered.

According to the DoD Chief Information Officer’s CMMC program overview, the program exists specifically to replace self-reported compliance with verified compliance across the defense supply chain.

The CMMC Program Rule (32 CFR Part 170) took effect December 16, 2024, establishing the legal framework. The DFARS enforcement rule that triggered the phased rollout (when CMMC requirements began appearing in new contract solicitations) took effect November 10, 2025. For small businesses in the defense supply chain, the window to prepare is narrowing, and for contractors who haven’t started a structured compliance program, the timeline is already tighter than most realize.

This guide covers what CMMC 2.0 requires at each level, which businesses must comply and by when, how much certification costs, and what small defense contractors need to do before Phase 1 deadlines reach their contracts.


What Is CMMC and Who Has to Comply?

The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense (DoD)-mandated framework requiring defense contractors to demonstrate specific cybersecurity practices as a condition of contract eligibility. DFARS clauses embed these requirements directly into contract language, which means non-compliant suppliers cannot bid on or perform covered contracts. There is no separate registration pathway; CMMC compliance is a contract condition.

Any organization in the Defense Industrial Base (DIB) that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under a DoD contract is subject to CMMC. FCI covers information provided by or generated for the government under a contract. CUI is a broader category of unclassified information that federal law or policy requires to be safeguarded and protected from unauthorized disclosure.

The compliance obligation flows through the entire supply chain. Subcontractors that receive, process, or store FCI or CUI carry the same requirements as prime contractors, regardless of company size or annual revenue.

Existing contracts are not immediately disrupted. CMMC requirements apply to new solicitations and to contracts at option exercise or renewal. That distinction gives some suppliers a narrow window, but only if they use it to prepare rather than wait.


How CMMC 2.0 Changed the Rules

CMMC 2.0, with its final rule effective December 16, 2024, significantly simplified the framework for small contractors. The original five-level model included proprietary maturity practices that drove up compliance costs and created ambiguity about exactly what was required. CMMC 2.0 eliminated those additions and aligned the framework directly with standards from the National Institute of Standards and Technology (NIST).

The structural change that matters most for small contractors: NIST SP 800-171’s 110 security practices now map exactly to CMMC Level 2, with no CMMC-unique requirements added on top. Organizations already working toward NIST SP 800-171 compliance are building toward Level 2 directly. The two efforts are no longer separate.

CMMC 2.0 also introduced a tiered assessment structure at Level 2. Non-prioritized acquisitions accept a documented self-assessment; prioritized acquisitions require a third-party audit. This distinction has significant implications for timeline and budget planning that contractors must understand before beginning any compliance work.

Unlike FTC compliance requirements or payment card security frameworks built around consumer-facing industries, CMMC is a contract condition for DoD suppliers. There is no waiver process and no company-size exception.


The Three CMMC Levels Explained

Which level your contracts require determines your compliance scope, assessment type, and total cost. Here is what each level actually covers.

  1. Level 1 (Foundational): Seventeen basic cyber hygiene practices aligned to FAR 52.204-21. Applies to organizations handling FCI only, with no CUI in scope. Annual self-assessment and SPRS score submission is sufficient. For suppliers handling only routine contract information, this is the applicable level, and the compliance footprint, while real, is manageable.
  2. Level 2 (Advanced): All 110 security practices from NIST SP 800-171 across 14 security domains. Applies to organizations handling CUI. This is the level where the vast majority of small DoD suppliers land. Some contracts at this level accept self-assessment; others require a C3PAO third-party audit. The specific acquisition type, not company size, determines which path applies.
  3. Level 3 (Expert): Extends Level 2 with additional practices drawn from NIST SP 800-172. Reserved for programs involving the most sensitive CUI categories. Government DIBCAC assessors conduct these evaluations directly; Level 3 assessments are not performed by commercial C3PAOs. Level 3 applies to a small subset of the DIB.

At a glance, the data you handle determines the level you need:

LevelData you handlePractices requiredAssessment typeWho lands here
Level 1 (Foundational)FCI only17 practices (FAR 52.204-21)Annual self-assessment + SPRS score submissionSuppliers handling only routine contract information
Level 2 (Advanced)CUIAll 110 NIST SP 800-171 practices across 14 domainsSelf-assessment (non-prioritized) or triennial C3PAO audit (prioritized)The vast majority of small DoD suppliers
Level 3 (Expert)The most sensitive CUI categoriesLevel 2 plus additional NIST SP 800-172 practicesGovernment-led DIBCAC assessmentA small subset of the DIB

For most small businesses in the defense supply chain, Level 2 is the target. The critical decision isn’t which level applies. It’s whether your Level 2 contracts require self-assessment or a C3PAO audit. Those two paths have fundamentally different scope, timeline, and cost requirements.


Is CMMC Replacing NIST SP 800-171? No, It Verifies It

A common point of confusion, and worth settling directly: CMMC is not a new set of security controls, and it does not replace NIST SP 800-171. NIST SP 800-171 defines what to do — the 110 security practices for protecting CUI. CMMC defines how the DoD verifies you actually did it.

Defense contractors have been contractually required to implement NIST SP 800-171 since DFARS clause 252.204-7012 took effect. The problem was that compliance was self-reported to SPRS and frequently overstated. CMMC adds the verification layer: documented self-assessments with affirmations at Level 1 and non-prioritized Level 2, and independent C3PAO audits for prioritized Level 2 acquisitions.

The practical takeaway for small contractors: any work already done toward NIST SP 800-171 compliance counts directly toward CMMC Level 2. They are one effort, not two parallel compliance programs.


CMMC Level 2 Requirements: What Small Businesses Actually Face

Level 2 is the practical challenge for most small defense contractors. The scope is broader than many assume, and the assessment boundary captures more than just core IT systems.

The 14 security domains assessed at CMMC Level 2:

  • Access Control
  • Awareness and Training
  • Audit and Accountability
  • Configuration Management
  • Identification and Authentication
  • Incident Response
  • Maintenance
  • Media Protection
  • Personnel Security
  • Physical Protection
  • Risk Assessment
  • Security Assessment
  • System and Communications Protection
  • System and Information Integrity

For prioritized Level 2 acquisitions, a certified third-party assessor organization (C3PAO) must conduct the assessment. There is no headcount or revenue exception for this requirement. DIBCAC oversees C3PAO quality at Level 2 and conducts government-led Level 3 assessments directly, providing federal oversight across the full compliance ecosystem.

A Plan of Action and Milestones (POA&M) allows contractors with minor gaps to proceed toward contract award while remediating within a defined window. Not all finding types are POA&M-eligible, and treating POA&M deferral as a general remediation strategy fails when findings cluster in high-risk practice areas that DoD won’t defer.

The scope issue that most frequently produces unexpected findings: commercial off-the-shelf (COTS) products that process, store, or transmit CUI fall within the assessment boundary. Assuming off-the-shelf tools are automatically exempt is one of the most common reasons small contractors fail their first Level 2 assessment.


CMMC Self-Assessment vs. Third-Party Certification

The path to compliance (self-assessment or C3PAO audit) is determined by your contract type, not your preference. Understanding which path applies is the first practical step in building a compliance plan with a realistic timeline and budget.

Level 1 contractors and non-prioritized Level 2 contractors complete an annual self-assessment, calculate a score, and submit it to the Supplier Performance Risk System (SPRS). This is the DoD’s live vendor risk scorecard, and contracting officers have direct access to it during procurement. A low or negative SPRS score can eliminate your business from consideration before your proposal is evaluated.

Prioritized Level 2 acquisitions require a triennial C3PAO assessment, mandatory regardless of company headcount or revenue. The three-year certification cycle makes this a recurring operational commitment once your contracts trigger the requirement.

Preparing for a C3PAO assessment requires four things most small contractors don’t have in place when they start:

  • A formal gap analysis mapping the current environment against all 110 NIST SP 800-171 practices
  • A documented System Security Plan (SSP) covering all people, processes, and technology that handle CUI
  • Evidence packages for each control domain
  • Remediation of identified weaknesses before the assessment window opens

Organizations that assume their current IT environment meets Level 2 without a structured gap analysis consistently underestimate their finding count. The domains with the highest gap rates among small contractors are access control, audit logging, and incident response. Each requires both technical configuration and documented procedures.

Structured regulatory compliance support before an assessment converts a high-risk audit into a predictable process. Starting without it means discovering gaps under time pressure, when remediation costs are highest and timelines are shortest.


CMMC Compliance Checklist for Small Businesses

Compliance follows a sequential path regardless of which level applies to your contracts. Skipping steps creates rework; the steps that feel like overhead early are the ones that determine whether your first assessment passes.

  1. Determine your required CMMC level. Review your contract language, DFARS clauses, and CUI handling requirements. If the level isn’t explicit in the solicitation, confirm with your contracting officer before beginning any other compliance work.
  2. Conduct a gap assessment against NIST SP 800-171. Establish your current SPRS score and identify which of the 110 practices are partially or fully unmet. This baseline drives your remediation roadmap and produces a realistic timeline to assessment readiness.
  3. Document your System Security Plan (SSP). The SSP must cover every person, process, and technology that processes, stores, or transmits FCI or CUI. This document is the primary artifact a C3PAO reviews, and the absence of a current SSP is the most common single-item gap in small contractor compliance packages.
  4. Implement required technical controls. Multi-factor authentication, least-privilege access enforcement, encrypted data in transit and at rest, and a tested incident response plan are scored Level 2 practices. Configuring these controls and documenting the configuration are two separate requirements, and both are evaluated during assessment.
  5. Confirm your data backup and recovery services satisfy the media protection and contingency planning domains. CMMC requires verified restoration procedures, not just backup creation. Undocumented or untested recovery processes consistently appear as findings in Level 2 assessments.
  6. Establish continuous monitoring processes. Patch management cadence, log review, and access recertification cycles must remain operational between formal assessments. CMMC controls must be active continuously throughout the certification period, not just at the time of a point-in-time audit.
  7. Schedule your C3PAO assessment early if one is required. Backlogs are growing as Phase 1 requirements take full effect across the supply chain. For contractors starting from a low SPRS baseline, remediation timelines routinely run six to 12 months. The contractors who pass on schedule are typically the ones who started 12 to 18 months before their contract deadline.
  8. Build evidence packages for every domain in scope. Assessors score what you can prove, not what you assert. Collect configuration exports, policy documents, log samples, and training records mapped to each of the 14 security domains. Assembling evidence after the assessment window opens is too late.
  9. Document a POA&M for any remaining gaps. A Plan of Action and Milestones lets you proceed toward contract award while remediating minor findings within a defined window. Not all finding types are POA&M-eligible — gaps in high-risk practice areas generally must be closed before assessment, not deferred.
  10. Train your staff and keep the records. Awareness and Training is a scored Level 2 domain. Personnel who handle FCI or CUI need documented, recurring training, and the records proving that training happened are assessment evidence in their own right.
  11. Run a readiness review before the real assessment. A mock assessment against the same 110 practices a C3PAO will score surfaces documentation gaps and control drift while there is still time to fix them — instead of discovering them under deadline pressure, when remediation costs are highest and timelines are shortest.
  12. Submit your affirmation in SPRS and maintain compliance continuously. Certification is not one-and-done: the Level 2 triennial cycle includes annual affirmations, and controls must remain operational between assessments. Treat the certification date as the start of the maintenance program, not the finish line.

How Much Does CMMC Certification Cost?

Cost is the first question most small contractors ask, and the answer includes more than the assessment fee most vendors quote upfront.

Per DoD cost estimates published in the Federal Register, CMMC Level 1 self-assessment costs are primarily internal labor, with DoD estimating approximately $6,000 for the assessment and affirmation process for a small entity. Total costs including internal labor to document controls and prepare the SPRS submission typically run $5,000 to $15,000, depending on how well-organized and documented the existing environment is. Organizations starting with no prior documentation should budget toward the higher end.

According to DoD cost estimates published in the Federal Register, CMMC Level 2 C3PAO assessments for the triennial certification cycle (including the assessment, affirmation, and two annual affirmations) run approximately $105,000 for a small entity. Organizations with simpler CUI scope may see lower direct assessment fees from individual C3PAOs; larger or more complex environments pay more. The three-year certification cycle makes this a recurring budget line rather than a one-time project cost.

Remediation before the assessment is often the largest single expense. Gaps in access control, audit logging, or incident response frequently require significant infrastructure or software investment. These costs consistently exceed the assessment fee itself for contractors starting from a low compliance baseline. Budgeting only for the assessment while treating remediation as a separate problem is the most common reason small contractors miss their compliance timelines.

Ongoing annual compliance costs after initial certification include:

  • Continuous monitoring tools for log review, patching, and threat detection
  • SSP maintenance as the environment changes throughout the certification period
  • Staff training to keep personnel current on required practices, including a regular cybersecurity awareness training cadence
  • Preparation for triennial C3PAO renewals, which require the same documented evidence as the initial audit

The DoD’s Federal Register cost estimates cover assessment and affirmation processes only. The technical controls, tooling, and documentation infrastructure required to keep those assessments passable are separate operational costs that persist throughout the entire certification period.

The contractors who achieve the best return on CMMC investment treat it as a cybersecurity infrastructure upgrade rather than a compliance tax. The Level 2 controls overlap directly with the practices that reduce actual breach risk, which means the same investment that satisfies the DoD requirement also strengthens the organization against real-world threats.


CMMC Rollout Timeline and 2026 Deadlines

The CMMC rollout is phased across the defense supply chain, and where your contracts fall in that timeline determines how much preparation runway you have.

  • Phase 1 (November 10, 2025 onward): Per the DFARS Final Rule, the Department of Defense began including CMMC Level 1 and Level 2 self-assessment requirements in new DoD solicitations. Contractors must have current SPRS scores on file to compete for covered contracts. This phase is active.
  • Phase 2 (November 2026): C3PAO third-party assessments become required for prioritized Level 2 acquisitions. Beginning November 10, 2026, a growing share of new solicitations will require third-party assessment rather than self-assessment.
  • Phases 3 and 4 (2027–2028): Continue expanding CMMC requirements across the defense supply chain, including Level 3 DIBCAC assessments for the highest-sensitivity programs. Full mandatory application to all applicable DoD contracts (except COTS-only items) takes effect November 10, 2028.
  • Contracts currently in place are not immediately affected but require CMMC compliance at option exercise or renewal, giving some suppliers a narrow preparation window without disrupting active work.

Starting compliance work at contract renewal is a high-risk strategy. C3PAO assessment availability is constrained, and remediation for contractors with low SPRS baselines routinely takes six to 12 months. Treating the renewal deadline as the trigger for compliance work, rather than the target, leaves no margin for assessment delays or remediation overruns.

If you hold or plan to bid on DoD-adjacent contracts, this quarter’s work is concrete: confirm your required CMMC level with your contracting officer, run a gap assessment to establish your current SPRS score, and — if the November 10, 2026 Phase 2 date puts a C3PAO requirement on your contracts — get on an assessor’s calendar now. With remediation running six to 12 months and assessor availability tightening, the realistic runway from a standing start is measured against the Phase 2 date, not past it.


How a Managed IT Partner Supports Ongoing CMMC Compliance

Achieving CMMC compliance is a project. Maintaining it is an operational program. For small defense contractors with one or two IT generalists and no dedicated compliance function, the maintenance load is where compliance programs break down, typically not at initial certification but at the first C3PAO renewal cycle.

A qualified managed IT partner starts with a pre-assessment gap analysis mapping the current environment against all 110 NIST SP 800-171 practices. The output is a prioritized remediation roadmap with realistic cost estimates and timelines, converting an abstract regulatory requirement into a concrete project plan with defined milestones. A CMMC gap assessment starts with knowing your current posture — the same ground a structured cybersecurity risk assessment covers.

Ongoing managed services directly satisfy several continuous monitoring requirements CMMC demands between formal assessments. An MSP running these functions doesn’t just support compliance; it becomes part of the technical infrastructure that compliance depends on. Scored CMMC practices that map directly to managed services include:

  • Endpoint monitoring to satisfy System and Information Integrity domain requirements
  • Log management to maintain the audit trail the Audit and Accountability domain requires
  • Patch management to sustain Configuration Management controls between assessments
  • Access control administration to enforce least-privilege and Identification and Authentication requirements

SSP documentation maintenance is another area where internal teams underestimate the ongoing scope. The SSP must be updated as the environment changes. For a small organization managing this in-house, documentation debt builds quickly and becomes a significant remediation item at the next assessment cycle.

Just as organizations handling patient data rely on HIPAA-compliant IT solutions to meet their federal obligations, defense contractors need a partner who understands CMMC’s specific technical controls and documentation standards. Both frameworks require documented controls, verified procedures, and continuous monitoring, not a one-time configuration pass followed by years of drift. Our breakdown of the HIPAA Security Rule shows how that same documented-safeguards structure works in healthcare.

LeadingIT serves manufacturers, engineering firms, and government contractors across the Chicagoland area: businesses that sit directly in the DoD supply chain and need compliance-focused IT support rather than general IT management. For contractors managing multiple regulatory requirements simultaneously, PCI compliance solutions and CMMC requirements share significant technical overlap in access control, audit logging, and incident response. The same foundational infrastructure serves both frameworks.


Frequently Asked Questions About CMMC Compliance

Is CMMC compliance mandatory?

Yes, for any organization that handles FCI or CUI under a DoD contract. CMMC is a contract condition embedded through DFARS clauses — there is no waiver process and no company-size exception. Phase 1 took effect November 10, 2025 for new solicitations; existing contracts pick up the requirement at option exercise or renewal. Non-compliant suppliers cannot bid on or perform covered contracts.

How much does CMMC certification cost?

DoD estimates approximately $6,000 for a Level 1 self-assessment and affirmation, and approximately $105,000 for a small entity’s Level 2 C3PAO triennial cycle, including the assessment and annual affirmations. Remediation before the assessment is often the largest single expense and frequently exceeds the assessment fee for contractors starting from a low SPRS baseline. Monitoring, SSP maintenance, and training continue as recurring costs after certification.

What are the CMMC levels?

Level 1 (Foundational) covers 17 basic practices for organizations handling FCI only, verified by annual self-assessment. Level 2 (Advanced) requires all 110 NIST SP 800-171 practices for CUI handlers, verified by self-assessment or C3PAO audit depending on the acquisition type. Level 3 (Expert) adds NIST SP 800-172 practices for the most sensitive programs, assessed directly by DIBCAC. Most small defense contractors land at Level 2.

Does CMMC apply to subcontractors?

Yes. The obligation flows through the entire supply chain: subcontractors that receive, process, or store FCI or CUI carry the same requirements as prime contractors, regardless of company size or revenue. A machine shop making parts-of-parts for a prime’s assembly handles FCI at minimum. The required level depends on what information flows down to you, not your position in the chain.

Is CMMC replacing NIST 800-171?

No. CMMC implements NIST SP 800-171; it doesn’t replace it. NIST SP 800-171 defines the 110 security practices for protecting CUI, and CMMC is the DoD’s mechanism for verifying those practices are actually in place. CMMC 2.0 aligned Level 2 exactly with the 110 practices, so any work toward NIST SP 800-171 compliance is work toward CMMC Level 2.


A CMMC-compliant operation looks different from the inside:

  • Contracts go through without last-minute certification emergencies
  • Your SPRS score accurately reflects your actual security posture
  • C3PAO assessments pass because the controls were built and maintained throughout the certification period, not because your team remediated everything under deadline pressure in the 90 days before the auditor arrived
  • Continuous monitoring runs as a routine business function rather than a fire drill triggered by a contract renewal notice

LeadingIT provides CMMC gap assessments, System Security Plan documentation, continuous monitoring, endpoint protection, access control administration, and pre-assessment preparation support for Level 2 C3PAO audits, serving manufacturers, defense-adjacent businesses, and government contractors across the Chicagoland area. The work done between assessments is what makes assessments pass.

Explore our Chicago IT compliance services or call 815-788-6041 to find out exactly where your environment stands against CMMC requirements before your contracting officer asks.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.