Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

CMMC for Manufacturers: A Plain-English Guide to Defense Compliance

August 11, 2026
hero-cmmc-for-manufacturers-1.png

CMMC for manufacturers means proving your shop protects the defense data it handles.

It verifies that companies in the Defense Industrial Base (DIB) safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). If your shop builds parts, assemblies, or components for a defense prime contractor, CMMC likely applies to you.

This isn’t voluntary. It sets three certification levels tied to how sensitive your data is. For manufacturers, a single missed requirement can knock you out of the bidding pool for defense work.

Key Takeaways

  • Build-to-print manufacturers working from drawings and specs are handling Controlled Technical Information, a category of CUI, and likely need Level 2, not just Level 1. Level 2 covers the 110 requirements of NIST SP 800-171 for companies handling CUI. – CMMC Level 2 maps directly to NIST SP 800-171, organized into 14 control families covering access, encryption, logging, and more. – Even as a small subcontractor, your required CMMC level is often dictated by what the prime contractor above you needs from its supply chain.

Do You Actually Need CMMC? FCI vs. CUI vs. Controlled Technical Information

Not every defense supplier needs the same level of CMMC. It depends on what kind of information touches your systems.

Three terms decide which level applies to you:

TermWhat It MeansWhat It Looks Like in Your Shop
FCI (Federal Contract Information)Information the government gives you, or you generate for it, that isn’t intended for public releasePurchase orders, delivery schedules, basic contract correspondence
CUI (Controlled Unclassified Information)Information that requires safeguarding under law, regulation, or government-wide policyProgram documentation tied to a specific defense contract
CTI (Controlled Technical Information)A category of CUI covering technical data with military or space applicationBuild-to-print drawings, engineering specs, CAD files, inspection and test data

For the full definition and more examples, see our guide on what counts as CUI.

Here’s the test that matters most for manufacturers. Do you build parts from a prime’s drawings, specs, or CAD files?

  1. List every system, drive, and process that touches a prime contractor’s drawings, specs, or CAD files.
  2. Check whether any of it is marked CUI, or clearly qualifies as Controlled Technical Information.
  3. If the answer is yes to either, plan around Level 2, not Level 1.

A build-to-print manufacturer working from a prime’s drawings and specs is very likely handling CUI, and therefore very likely needs Level 2, not just Level 1.

This distinction isn’t academic. DFARS clause 252.204-7012 requires prime contractors to pass CUI safeguarding rules down to any subcontractor that touches it. If you’re only handling FCI, like basic purchase orders and schedules, Level 1 may be enough. If drawings, specs, or CAD files cross your desk, you should be planning for Level 2 now, not after a prime asks for proof.

The Three CMMC Levels, and Which One Applies to Your Shop

CMMC has three levels. They scale with what information you handle, not how big your company is. Each level becomes a binding requirement once it’s written into your contract through DFARS clause 252.204-7021.

LevelWho It’s ForHow It’s Verified
Level 2 (Advanced)Companies that handle CUI, including CTI like drawings and specsAnnual self-assessment, or third-party certification from a Certified Third-Party Assessment Organization (C3PAO) every 3 years, depending on the contract
Level 3 (Expert)A small slice of manufacturers on the most sensitive programsAssessed directly by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)

In practice, most manufacturers land in one of two buckets:

  • Level 1 fits a shop that only sees purchase orders and delivery schedules, with no drawings or technical specs.
  • Level 2 fits a shop that builds from a prime’s drawings, specs, or CAD files, which is most build-to-print manufacturers.
  • Level 3 fits the rare shop working the highest-priority, most sensitive programs. Few manufacturers land here.

For the full breakdown of all three levels, including how the self-assessment and third-party paths actually work, see our CMMC levels guide.

How CMMC Level 2 Maps to NIST SP 800-171 (The 110 Controls, in Shop-Floor Terms)

CMMC Level 2 isn’t a separate standard sitting on top of your existing IT setup. That version has 110 security requirements across 14 control families.

CMMC’s current rule still points to Revision 2, not Revision 3. Don’t build your compliance plan around Revision 3 language until the Department of War formally adopts it into the CMMC rule.

For the full breakdown of every requirement, see our companion guide on NIST SP 800-171 explained.

The 14 control families cover a wide range of security practices:

Control FamilyWhat It Covers
Access ControlWho can log in and what they’re allowed to see
Awareness and TrainingMaking sure employees know the security rules
Audit and AccountabilityLogging who did what, and when
Configuration ManagementKeeping systems set up and patched consistently
Identification and AuthenticationVerifying who’s logging in, including MFA
Incident ResponseA written plan for handling security events
MaintenanceSecure practices for system upkeep and repairs
Media ProtectionProtecting drives, backups, and removable media
Personnel SecurityScreening and offboarding people with system access
Physical ProtectionSecuring the physical space around CUI
Risk AssessmentRegularly checking for new vulnerabilities
Security AssessmentTesting whether the controls actually work
System and Communications ProtectionEncrypting data and securing networks
System and Information IntegrityCatching and fixing security flaws quickly

CMMC Level 2 maps directly to NIST SP 800-171 Revision 2: 110 requirements across 14 control families.

On your shop floor, six of these controls do most of the day-to-day work:

  • Access control: only the right people can log into systems holding CUI, and each login ties to one person, not a shared password.
  • Multifactor authentication (MFA): a stolen password alone can’t get someone into your CUI systems.
  • Encryption: CUI stays unreadable if a laptop, drive, or backup gets lost or stolen.
  • Audit logging: your systems keep a record of who touched what, and when, including on your CNC controllers and ERP system.
  • Incident response: you have a written plan for what happens if something goes wrong.
  • Physical security: drawings, CNC terminals, and ERP screens aren’t left where a visitor or unescorted vendor can see them.

None of this replaces good IT practice. It formalizes it, with documentation an assessor or a prime’s audit will expect to see.

Where CMMC Stands in 2026: The Phase II Suspension

CMMC’s rollout hit a major change this year. On July 13, 2026, the Small Business Administration announced that the Department of War suspended CMMC Phase II. Phase II was set to require third-party certification starting November 10, 2026. That requirement is now paused.

Comparison of the two CMMC paths: self-assessment (about $388,600) costs less and is still required, while third-party C3PAO certification (about $593,800) costs more and is currently paused.

Phase I obligations did not change. Every manufacturer handling FCI or CUI still must complete a self-assessment. Level 1 and Level 2 Self both remain in force today.

Phase I self-assessment obligations under Level 1 and Level 2 Self remain in effect today, even though the Phase II third-party certification requirement is paused.

Cost and capacity drove the suspension:

PathEstimated Cost
Self-assessment (Level 1 / Level 2 Self)About $388,600
Third-party certification (C3PAO)About $593,800

That math doesn’t work yet, which is why DoD paused the third-party requirement rather than the whole program.

Don’t read the suspension as “CMMC is cancelled.” It isn’t. Self-assessment, documentation, and the underlying NIST SP 800-171 controls are still expected of you right now, on today’s contracts.

The Flow-Down Trap: How a Prime’s Requirement Becomes Yours

CMMC obligations don’t stop at the prime contractor. If a prime’s contract requires CMMC, that requirement flows down to every subcontractor touching CUI. This isn’t optional for the prime, either.

How CMMC Flows Down

DFARS 252.204-7012 requires prime contractors to pass CUI safeguarding rules down the supply chain. A prime legally cannot award CUI-relevant work to a subcontractor without the right CMMC level. That means your compliance status can decide whether you get the purchase order at all.

Here’s the practical risk for a small manufacturer:

  • One subcontractor without the required level can block the prime from awarding that work.
  • A prime auditing its supply chain may quietly drop your shop rather than accept the risk.
  • The obligation applies whether or not you signed anything specifically labeled CMMC. It’s baked into the prime contract’s flow-down clause.

For the full mechanics of how these requirements pass down the chain, see our guide on CMMC flow-down requirements.

What Non-Compliance Actually Risks

Falling short of your required CMMC level carries three real risks, not just paperwork headaches.

  • Lost bid eligibility. Primes can’t award CUI-relevant work to a subcontractor without the right level. No level, no contract. – A damaged SPRS score. Every contractor handling CUI needs a current NIST SP 800-171 assessment score on file. A score below 110 requires a written Plan of Action and Milestones (POA&M). See our full guide on SPRS scores for the scoring breakdown. – False Claims Act exposure. The Department of Justice runs a Civil Cyber-Fraud Initiative that treats a false cybersecurity claim as a false claim against the government.

An inaccurate CMMC self-assessment isn’t just a compliance gap.

Scoping Your Compliance Boundary the Right Way

Not every computer in your shop needs to meet CMMC Level 2. The goal is scoping down to only what touches CUI, not locking down your entire network.

CUI Boundary Scoping Steps

Work through this checklist to draw the boundary:

  • Map every system that stores, processes, or transmits CUI: file servers, CAD workstations, CNC controllers, ERP modules holding drawings or specs.
  • Separate that CUI-handling environment from the rest of your network, physically or logically.
  • Keep general office systems, like email for non-CUI correspondence, outside the compliance boundary where possible.
  • Document the boundary in writing. An assessor or a prime’s audit will ask you to show it, not just describe it.

A tight, well-documented boundary is often the single biggest cost lever in a CMMC project. Scope creep, not the actual controls, is what makes assessments expensive.

See Where You Stand

You don’t need to guess where your shop stands. Answer a few plain-English questions about your systems and CUI exposure, and get your readiness level along with the gaps to close. No sign-up required to see your result.

Take the free 2-minute CMMC Risk-Check

How LeadingIT Supports Manufacturers Working Toward CMMC

For a manufacturer working toward CMMC Level 1 or Level 2, LeadingIT operates the technical backbone an assessor actually checks:

CMMC Technical Backbone
  • Access control and multifactor authentication on every system that touches CUI
  • Encryption of CUI at rest and in transit
  • Centralized audit logging
  • Configuration management and patching
  • Security awareness training
  • Incident response planning
  • Documentation: system security plan and POA&M

LeadingIT also helps scope which systems actually touch CUI. That keeps your compliance boundary from ballooning into a lockdown of the whole company. The same scoping work feeds directly into an SPRS score submission or a C3PAO assessment later on.

For the done-for-you path, see LeadingIT’s compliance and managed IT services for defense manufacturers.

Frequently Asked Questions

Does CMMC apply to small manufacturers?

Yes, if you handle FCI or CUI under a defense contract, at any tier. Size doesn’t exempt you. A small build-to-print shop working from a prime’s drawings can face the same Level 2 obligation as a large supplier.

What is Controlled Technical Information?

Controlled Technical Information, or CTI, is a category of CUI covering technical data with military or space application. For manufacturers, that usually means drawings, engineering specs, CAD files, and inspection or test data tied to a defense program.

How much does CMMC certification cost?

Estimates run about $388,600 for the self-assessment path and about $593,800 for third-party certification through a C3PAO. Actual cost depends heavily on how tightly you scope your CUI-handling environment before you start.

Is CMMC Phase II cancelled?

No, it’s suspended, not cancelled. The Department of War paused the Phase II third-party certification requirement in July 2026. Phase I self-assessment obligations under Level 1 and Level 2 Self are still in effect today.

Level 2 covers the 110 requirements of NIST SP 800-171 for companies that handle Controlled Unclassified Information, including technical drawings and specs.</p> </details>

What is a C3PAO?

A Certified Third-Party Assessment Organization, or C3PAO, is an organization authorized to conduct official CMMC Level 2 assessments and issue a Certificate of CMMC Status. It’s different from a consultant who helps you prepare, which has no authority to certify you.

Can a subcontractor lose a contract for not having CMMC?

Yes. A prime contractor cannot legally award CUI-relevant work to a subcontractor that hasn’t met the required CMMC level. One non-compliant link in the supply chain can cost that subcontractor the work, and can put the prime’s own contract at risk.

Ready to Find Your Gaps?

CMMC compliance isn’t going away, even with Phase II paused. The manufacturers who start now, with a clear scope and the right technical controls, won’t be scrambling when a prime asks for proof.

LeadingIT can help you get there with our CMMC and NIST 800-171 compliance services built for defense manufacturers.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.