Skip to content

CMMC for Small Defense Contractors: What to Actually Focus On Right Now

Travis Sands
Travis Sands

If you're a small business in the defense space, you're juggling contracts, tight margins, limited staff, and now the pressure of Cybersecurity Maturity Model Certification (CMMC) on top of it all. It can feel overwhelming — the big primes have entire compliance teams, while you're wearing all the hats yourself.

Here's the good news: CMMC isn't designed to put small contractors out of business. It exists to raise the baseline of cybersecurity across the defense supply chain. If you handle Controlled Unclassified Information (CUI) or Federal Contract Information (FCI), here's what you actually need to focus on right now — no fluff, just practical steps, updated for where the program actually stands today.

A quick, important update: where CMMC stands as of September 2026

CMMC is no longer theoretical. The DFARS rule took effect on November 10, 2025, and CMMC requirements — via clauses 252.204-7021 and 252.204-7025 — are now showing up in real Department of War (formerly Department of Defense) solicitations and contracts. Phase 1 is fully in force: contracts touching FCI or CUI can require a Level 1 or Level 2 self-assessment, logged in the Supplier Performance Risk System (SPRS), right now.

Here's the twist worth knowing: Phase 2 — which would have made third-party C3PAO certification mandatory for most Level 2 contracts starting November 10, 2026 — was suspended in July 2026. The Department's CIO stood up a CMMC Reform Task Force to review the whole program over 60 days, citing concerns about cost and bureaucratic burden on small and non-traditional businesses. That review is wrapping up right around now, with a report expected any day.

What this does and doesn't mean for you:

  • It does not mean CMMC is going away, or that the underlying security requirements have loosened. Officials have been explicit that the 110 NIST SP 800-171 controls, your System Security Plan (SSP), your Plan of Action and Milestones (POA&M), and your annual affirmation obligations are unchanged.
  • It does mean the third-party certification requirement for Level 2 — the part that would have forced many small businesses into costly C3PAO assessments starting this November — is on pause while the rules get reconsidered.
  • Self-assessment requirements (Phase 1) are still very much alive and enforceable. Misreporting your compliance status in SPRS carries real legal exposure — the government has already pursued a False Claims Act case tied to misrepresented cybersecurity compliance.
  • There's also a proposed Senate grant program that would help small businesses cover assessment costs. It isn't law yet, so don't build your plan around it — but it's worth watching.

The practical takeaway: don't stop working on this because a deadline moved. Treat the pause as a chance to get your house in order before certification requirements return, not as permission to deprioritize security. Companies that keep building now will be ready to certify quickly and cheaply once the rules firm back up; companies that stand down will be scrambling again next year with less runway.

Step 1: Determine your required CMMC level

Most small contractors land in one of two places:

  • Level 1 — self-assessment, basic hygiene for FCI.
  • Level 2 — required for organizations handling CUI, currently verified through self-assessment under Phase 1, with third-party (C3PAO) certification on hold pending the Reform Task Force outcome. This is where most small-to-medium defense businesses end up.

Check your contracts and talk to your prime before you assume anything — and don't assume a C3PAO assessment is off your radar for good just because Phase 2 is paused. Existing contracts that already carry Phase 2 language are being modified to remove it for now, but that could shift once the task force reports back. Don't over-certify, either — scope matters, and going after a higher level than your contracts require just adds cost and complexity.

Step 2: Understand your scope

This step matters enormously for small teams. Identify exactly where CUI enters, flows through, and leaves your environment:

  • Map your systems and networks.
  • Limit the in-scope environment as much as you can — segmentation helps.
  • Document everything in a System Security Plan (SSP).

Small contractors often succeed by keeping their CUI environment small and tightly controlled, rather than trying to bring their whole business into scope.

Step 3: Conduct a gap assessment

Don't guess — assess. Work through the 110-plus controls required under NIST SP 800-171 for Level 2 and evaluate honestly where you stand. Many small businesses already have solid basic security in place; the work is often more about formalizing what you're already doing than building from scratch.

Areas that commonly need attention for small teams:

  • Documented policies and procedures
  • Multi-factor authentication (MFA) everywhere it's feasible
  • Proper CUI marking, storage, and transmission
  • Employee awareness training
  • Incident response planning
  • Log generation and review

Step 4: Implement and document controls

You don't need enterprise-grade tools to get this right. Practical, cost-effective solutions go a long way:

  • Compliant platforms like Microsoft 365 GCC High
  • Built-in logging and monitoring, enabled and configured properly
  • Access controls and encryption
  • Simple, clear policies your team will actually follow

Whether you're ultimately verified by self-assessment or a future C3PAO review, the bar is the same: controls need to be implemented and working — not backed by six figures of software just to prove it.

Step 5: Prepare your people and your evidence

Train your team on CUI handling and security awareness. Run mock interviews so people know what to expect. Organize your evidence so you can show — not just tell — how you meet each requirement. Keep your SPRS score current and accurate; even with third-party certification paused, self-affirmed scores are the thing contracting officers and primes are checking today.

Step 6: Assess, affirm, and stay ready

For now, that means keeping your Level 1 or Level 2 self-assessment current in SPRS and closing out your POA&M items on a real timeline — not letting them age. When the Reform Task Force's recommendations land and Phase 2 rules are finalized, expect a revised phase-in for C3PAO certification. Contractors who've kept their SSP accurate and their controls current will move through that process fast; the ones who paused everything will be starting over. Either way, compliance isn't a one-time milestone — it's an ongoing program.

The small contractor reality check

You don't need a large compliance department to do this well. Many small businesses partner with consultants for the heavy lifting — the SSP, the gap analysis — and then manage day-to-day operations themselves. Prioritize, phase your implementation, and tackle the highest-impact controls first.

The investment in CMMC protects your ability to win and keep Department of War contracts, and it genuinely strengthens your overall security posture in the process — regardless of which phase the certification requirement happens to be in this month.

If you're ready to get started without the overwhelm, begin with a simple scoping exercise and a gap assessment this month.

What's your biggest CMMC question as a small contractor? Reach out if you'd like recommendations for affordable tools or implementation partners.

#CMMC #SmallBusiness #DefenseContracting #Cybersecurity #NIST800171

Share this post