CMMC for Manufacturers: A Plain-English Guide to Defense Compliance
CMMC for manufacturers means proving your shop protects the defense data it handles.
It verifies that companies in the Defense Industrial Base (DIB) safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). If your shop builds parts, assemblies, or components for a defense prime contractor, CMMC likely applies to you.
This isn’t voluntary. It sets three certification levels tied to how sensitive your data is. For manufacturers, a single missed requirement can knock you out of the bidding pool for defense work.
Key Takeaways
- Build-to-print manufacturers working from drawings and specs are handling Controlled Technical Information, a category of CUI, and likely need Level 2, not just Level 1. Level 2 covers the 110 requirements of NIST SP 800-171 for companies handling CUI. – CMMC Level 2 maps directly to NIST SP 800-171, organized into 14 control families covering access, encryption, logging, and more. – Even as a small subcontractor, your required CMMC level is often dictated by what the prime contractor above you needs from its supply chain.
Do You Actually Need CMMC? FCI vs. CUI vs. Controlled Technical Information
Not every defense supplier needs the same level of CMMC. It depends on what kind of information touches your systems.
Three terms decide which level applies to you:
| Term | What It Means | What It Looks Like in Your Shop |
|---|---|---|
| FCI (Federal Contract Information) | Information the government gives you, or you generate for it, that isn’t intended for public release | Purchase orders, delivery schedules, basic contract correspondence |
| CUI (Controlled Unclassified Information) | Information that requires safeguarding under law, regulation, or government-wide policy | Program documentation tied to a specific defense contract |
| CTI (Controlled Technical Information) | A category of CUI covering technical data with military or space application | Build-to-print drawings, engineering specs, CAD files, inspection and test data |
For the full definition and more examples, see our guide on what counts as CUI.
Here’s the test that matters most for manufacturers. Do you build parts from a prime’s drawings, specs, or CAD files?
- List every system, drive, and process that touches a prime contractor’s drawings, specs, or CAD files.
- Check whether any of it is marked CUI, or clearly qualifies as Controlled Technical Information.
- If the answer is yes to either, plan around Level 2, not Level 1.
A build-to-print manufacturer working from a prime’s drawings and specs is very likely handling CUI, and therefore very likely needs Level 2, not just Level 1.
This distinction isn’t academic. DFARS clause 252.204-7012 requires prime contractors to pass CUI safeguarding rules down to any subcontractor that touches it. If you’re only handling FCI, like basic purchase orders and schedules, Level 1 may be enough. If drawings, specs, or CAD files cross your desk, you should be planning for Level 2 now, not after a prime asks for proof.
The Three CMMC Levels, and Which One Applies to Your Shop
CMMC has three levels. They scale with what information you handle, not how big your company is. Each level becomes a binding requirement once it’s written into your contract through DFARS clause 252.204-7021.
| Level | Who It’s For | How It’s Verified |
|---|---|---|
| Level 2 (Advanced) | Companies that handle CUI, including CTI like drawings and specs | Annual self-assessment, or third-party certification from a Certified Third-Party Assessment Organization (C3PAO) every 3 years, depending on the contract |
| Level 3 (Expert) | A small slice of manufacturers on the most sensitive programs | Assessed directly by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) |
In practice, most manufacturers land in one of two buckets:
- Level 1 fits a shop that only sees purchase orders and delivery schedules, with no drawings or technical specs.
- Level 2 fits a shop that builds from a prime’s drawings, specs, or CAD files, which is most build-to-print manufacturers.
- Level 3 fits the rare shop working the highest-priority, most sensitive programs. Few manufacturers land here.
For the full breakdown of all three levels, including how the self-assessment and third-party paths actually work, see our CMMC levels guide.
How CMMC Level 2 Maps to NIST SP 800-171 (The 110 Controls, in Shop-Floor Terms)
CMMC Level 2 isn’t a separate standard sitting on top of your existing IT setup. That version has 110 security requirements across 14 control families.
CMMC’s current rule still points to Revision 2, not Revision 3. Don’t build your compliance plan around Revision 3 language until the Department of War formally adopts it into the CMMC rule.
For the full breakdown of every requirement, see our companion guide on NIST SP 800-171 explained.
The 14 control families cover a wide range of security practices:
| Control Family | What It Covers |
|---|---|
| Access Control | Who can log in and what they’re allowed to see |
| Awareness and Training | Making sure employees know the security rules |
| Audit and Accountability | Logging who did what, and when |
| Configuration Management | Keeping systems set up and patched consistently |
| Identification and Authentication | Verifying who’s logging in, including MFA |
| Incident Response | A written plan for handling security events |
| Maintenance | Secure practices for system upkeep and repairs |
| Media Protection | Protecting drives, backups, and removable media |
| Personnel Security | Screening and offboarding people with system access |
| Physical Protection | Securing the physical space around CUI |
| Risk Assessment | Regularly checking for new vulnerabilities |
| Security Assessment | Testing whether the controls actually work |
| System and Communications Protection | Encrypting data and securing networks |
| System and Information Integrity | Catching and fixing security flaws quickly |
CMMC Level 2 maps directly to NIST SP 800-171 Revision 2: 110 requirements across 14 control families.
On your shop floor, six of these controls do most of the day-to-day work:
- Access control: only the right people can log into systems holding CUI, and each login ties to one person, not a shared password.
- Multifactor authentication (MFA): a stolen password alone can’t get someone into your CUI systems.
- Encryption: CUI stays unreadable if a laptop, drive, or backup gets lost or stolen.
- Audit logging: your systems keep a record of who touched what, and when, including on your CNC controllers and ERP system.
- Incident response: you have a written plan for what happens if something goes wrong.
- Physical security: drawings, CNC terminals, and ERP screens aren’t left where a visitor or unescorted vendor can see them.
None of this replaces good IT practice. It formalizes it, with documentation an assessor or a prime’s audit will expect to see.
Where CMMC Stands in 2026: The Phase II Suspension
CMMC’s rollout hit a major change this year. On July 13, 2026, the Small Business Administration announced that the Department of War suspended CMMC Phase II. Phase II was set to require third-party certification starting November 10, 2026. That requirement is now paused.

Phase I obligations did not change. Every manufacturer handling FCI or CUI still must complete a self-assessment. Level 1 and Level 2 Self both remain in force today.
Phase I self-assessment obligations under Level 1 and Level 2 Self remain in effect today, even though the Phase II third-party certification requirement is paused.
Cost and capacity drove the suspension:
| Path | Estimated Cost |
|---|---|
| Self-assessment (Level 1 / Level 2 Self) | About $388,600 |
| Third-party certification (C3PAO) | About $593,800 |
That math doesn’t work yet, which is why DoD paused the third-party requirement rather than the whole program.
Don’t read the suspension as “CMMC is cancelled.” It isn’t. Self-assessment, documentation, and the underlying NIST SP 800-171 controls are still expected of you right now, on today’s contracts.
The Flow-Down Trap: How a Prime’s Requirement Becomes Yours
CMMC obligations don’t stop at the prime contractor. If a prime’s contract requires CMMC, that requirement flows down to every subcontractor touching CUI. This isn’t optional for the prime, either.

DFARS 252.204-7012 requires prime contractors to pass CUI safeguarding rules down the supply chain. A prime legally cannot award CUI-relevant work to a subcontractor without the right CMMC level. That means your compliance status can decide whether you get the purchase order at all.
Here’s the practical risk for a small manufacturer:
- One subcontractor without the required level can block the prime from awarding that work.
- A prime auditing its supply chain may quietly drop your shop rather than accept the risk.
- The obligation applies whether or not you signed anything specifically labeled CMMC. It’s baked into the prime contract’s flow-down clause.
For the full mechanics of how these requirements pass down the chain, see our guide on CMMC flow-down requirements.
What Non-Compliance Actually Risks
Falling short of your required CMMC level carries three real risks, not just paperwork headaches.
- Lost bid eligibility. Primes can’t award CUI-relevant work to a subcontractor without the right level. No level, no contract. – A damaged SPRS score. Every contractor handling CUI needs a current NIST SP 800-171 assessment score on file. A score below 110 requires a written Plan of Action and Milestones (POA&M). See our full guide on SPRS scores for the scoring breakdown. – False Claims Act exposure. The Department of Justice runs a Civil Cyber-Fraud Initiative that treats a false cybersecurity claim as a false claim against the government.
An inaccurate CMMC self-assessment isn’t just a compliance gap.
Scoping Your Compliance Boundary the Right Way
Not every computer in your shop needs to meet CMMC Level 2. The goal is scoping down to only what touches CUI, not locking down your entire network.

Work through this checklist to draw the boundary:
- Map every system that stores, processes, or transmits CUI: file servers, CAD workstations, CNC controllers, ERP modules holding drawings or specs.
- Separate that CUI-handling environment from the rest of your network, physically or logically.
- Keep general office systems, like email for non-CUI correspondence, outside the compliance boundary where possible.
- Document the boundary in writing. An assessor or a prime’s audit will ask you to show it, not just describe it.
A tight, well-documented boundary is often the single biggest cost lever in a CMMC project. Scope creep, not the actual controls, is what makes assessments expensive.
See Where You Stand
You don’t need to guess where your shop stands. Answer a few plain-English questions about your systems and CUI exposure, and get your readiness level along with the gaps to close. No sign-up required to see your result.
Take the free 2-minute CMMC Risk-Check
How LeadingIT Supports Manufacturers Working Toward CMMC
For a manufacturer working toward CMMC Level 1 or Level 2, LeadingIT operates the technical backbone an assessor actually checks:

- Access control and multifactor authentication on every system that touches CUI
- Encryption of CUI at rest and in transit
- Centralized audit logging
- Configuration management and patching
- Security awareness training
- Incident response planning
- Documentation: system security plan and POA&M
LeadingIT also helps scope which systems actually touch CUI. That keeps your compliance boundary from ballooning into a lockdown of the whole company. The same scoping work feeds directly into an SPRS score submission or a C3PAO assessment later on.
For the done-for-you path, see LeadingIT’s compliance and managed IT services for defense manufacturers.
Related Guides
- What Is an SPRS Score? A Plain-English Guide
- NIST SP 800-171 Explained: The 110 Controls for Defense Contractors
- What Is CUI? Controlled Unclassified Information for Defense Suppliers
- CMMC Levels 1, 2, and 3 Explained
Frequently Asked Questions
Does CMMC apply to small manufacturers?
Yes, if you handle FCI or CUI under a defense contract, at any tier. Size doesn’t exempt you. A small build-to-print shop working from a prime’s drawings can face the same Level 2 obligation as a large supplier.
What is Controlled Technical Information?
Controlled Technical Information, or CTI, is a category of CUI covering technical data with military or space application. For manufacturers, that usually means drawings, engineering specs, CAD files, and inspection or test data tied to a defense program.
How much does CMMC certification cost?
Estimates run about $388,600 for the self-assessment path and about $593,800 for third-party certification through a C3PAO. Actual cost depends heavily on how tightly you scope your CUI-handling environment before you start.
Is CMMC Phase II cancelled?
No, it’s suspended, not cancelled. The Department of War paused the Phase II third-party certification requirement in July 2026. Phase I self-assessment obligations under Level 1 and Level 2 Self are still in effect today.
Level 2 covers the 110 requirements of NIST SP 800-171 for companies that handle Controlled Unclassified Information, including technical drawings and specs.</p> </details>
What is a C3PAO?
A Certified Third-Party Assessment Organization, or C3PAO, is an organization authorized to conduct official CMMC Level 2 assessments and issue a Certificate of CMMC Status. It’s different from a consultant who helps you prepare, which has no authority to certify you.
Can a subcontractor lose a contract for not having CMMC?
Yes. A prime contractor cannot legally award CUI-relevant work to a subcontractor that hasn’t met the required CMMC level. One non-compliant link in the supply chain can cost that subcontractor the work, and can put the prime’s own contract at risk.
Ready to Find Your Gaps?
CMMC compliance isn’t going away, even with Phase II paused. The manufacturers who start now, with a clear scope and the right technical controls, won’t be scrambling when a prime asks for proof.
LeadingIT can help you get there with our CMMC and NIST 800-171 compliance services built for defense manufacturers.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
