CMMC Compliance: What Defense Contractors and Suppliers Need to Know

If your company sells into the Department of Defense supply chain — parts, software, engineering, logistics — CMMC is no longer a future problem. It is showing up in contract language, and the moment it does, it stops being a security project and becomes a revenue gate.

Who this actually applies to

CMMC (Cybersecurity Maturity Model Certification) applies to organizations in the defense industrial base that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). That is far broader than the primes. A third-tier machine shop receiving drawings, or a supplier who gets emailed specifications and delivery schedules that are not public, is in scope.

Requirements flow down. A prime that must meet CMMC pushes the same obligation to its subcontractors, and increasingly asks for proof before issuing a purchase order. "We are too small" has never been an exemption — the information does not care how many people you employ.

The levels, in plain terms

  • Level 1 (Foundational) — for companies handling FCI only. A short list of basic safeguarding practices, confirmed by an annual self-assessment and an affirmation signed by a company officer.
  • Level 2 (Advanced) — for companies handling CUI. This is the 110 security requirements in NIST SP 800-171, verified either by self-assessment or by an accredited third-party assessor (a C3PAO), depending on the contract. Most suppliers who see CUI land here.
  • Level 3 (Expert) — for the most sensitive programs. Adds requirements drawn from NIST SP 800-172 and is assessed by the government directly. Relatively few companies will need it.

It is already reaching contracts

The rule defining the CMMC program took effect at the end of 2024, and the acquisition rule that lets contracting officers write CMMC requirements into solicitations followed it, with a phased rollout over several years. In practice, the requirement arrives on your contract when it arrives — at renewal, at re-compete, or on the next new award. Phase-in schedules have shifted before, so confirm current specifics with your contracting officer or prime rather than any article, including this one.

Related obligations already exist. DFARS 252.204-7012 has required NIST SP 800-171 protections for CUI for years, and companion clauses require you to post a self-assessment score in SPRS. Optimistic or stale scores are a real legal exposure, not just an audit finding.

The practical prep path

  1. Scope it. Find where FCI and CUI actually live — email, file shares, laptops, the ERP system, that one engineer’s home PC. Then shrink that footprint on purpose: the smaller the enclave, the cheaper everything after it becomes.
  2. Run a gap assessment. Measure yourself honestly against all 110 requirements. Expect the first pass to be uncomfortable; that is why you do it early.
  3. Write the SSP. The System Security Plan describes how each requirement is met in your environment. Assessors read it first, and a missing or generic SSP is disqualifying on its own.
  4. Build the POA&M. The Plan of Action and Milestones lists what is not done, who owns it, and when it closes. Not every requirement can sit on a POA&M, and open items carry a closure clock, so treat it as a schedule, not a parking lot.
  5. Implement the controls. Multi-factor authentication, encryption, logging, access control, media handling, incident response, and awareness training — plus the validated-encryption question that trips up most first-timers.
  6. Collect evidence. Assessors want artifacts: policies, configuration exports, ticket history, training records. Start collecting on day one rather than reconstructing a year later.

How long it takes

For a small manufacturer starting from typical small-business IT, a realistic Level 2 timeline is measured in many months, not weeks. Scoping and remediation take the longest, and assessor availability adds its own wait. Some work — moving CUI into a compliant cloud enclave, replacing tools that cannot meet the requirements — has lead times money cannot compress.

Do not wait for the RFP

The worst version of this project starts after you see the clause in a solicitation you want to bid. You cannot get scoped, remediated, and assessed inside a response window, so the work goes to a competitor who started earlier. Treat CMMC as a standing capability and you end up bidding on contracts your peers have to pass on.

Equal Tech Solutions helps defense suppliers scope their CUI, run an honest gap assessment, build the SSP and POA&M, implement the controls, and keep evidence current between assessments.

If CMMC language is appearing in your contracts — or you expect it before the next award cycle — the time to start is now. Equal Tech Solutions works with manufacturers and suppliers in Chattanooga, Cleveland, and across the Southeast US. Contact Equal Tech Solutions for a plain assessment of where you stand and what it will take.