Start with the sentence that decides everything else
CMMC does not decide what you have to protect. Your contract does. The Cybersecurity Maturity Model Certification program is a verification wrapper around an obligation that has existed since 2017, when DFARS 252.204-7012 began requiring contractors to implement NIST SP 800-171 on any system that holds covered defense information. If that clause is in your contract and controlled unclassified information touches your systems, you owe the 110 requirements today, whether or not anyone has assessed you. CMMC only changes who checks, how often, and what they write down.
That framing separates two questions people fuse together. The first is whether you have a security problem to solve. The second is what paperwork proves you solved it. The first has a fixed answer no policy review will alter. The second has been moving all year.

On July 13, 2026 the Department of Defense suspended the Phase 2 requirements that were set to take effect on November 10, 2026 — the ones that would have made a third-party Level 2 certification a standard condition of award. A reform task force was convened to review the program. Phase 1, in force since November 10, 2025, was not suspended: Level 1 and Level 2 self-assessment statuses in the Supplier Performance Risk System remain conditions of award on applicable contracts, and Phase 1 already permits a requiring activity to ask for a third-party certification on a specific requirement when it decides one is warranted.
So the accurate statement of your position, if you are reading this in the second half of 2026, is this. The obligation to implement 800-171 is untouched. The self-assessment and the annual affirmation are live award conditions. The automatic, date-driven certification trigger is paused and nobody outside the task force knows what replaces it. Your primes will make their own decisions on their own timetable and several already have.
You are probably here because
- A prime sent a supplier questionnaire with a due date and the word CMMC in it
- Your quality manager was handed this on top of AS9100 and has no idea where to start
- Somebody quoted you a six-figure readiness program and you cannot tell whether that is real
- You want to know whether you can keep doing this work at all
The section on deciding whether you have CUI is the one that saves the most money. Read it before you buy anything.
Do you actually have CUI, or do you have FCI
This is the fork in the road, and a surprising number of shops take the expensive branch by default because a prime's questionnaire assumed it.
Federal contract information is defined in FAR 52.204-21. It is information not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service, and it excludes routine transactional information such as what appears on a purchase order. Most contract paperwork qualifies: statements of work, delivery dates, correspondence about performance. FCI triggers Level 1 — fifteen basic requirements, an annual self-assessment, scored pass or fail with no partial credit and no deferral.
Controlled unclassified information is information that law, regulation, or government-wide policy requires be safeguarded, organized into categories in the registry the National Archives maintains. In manufacturing, the category you will meet is almost always Controlled Technical Information: drawings, models, specifications, test data, technical data packages. Export-controlled data is the other common one and it brings its own separate regime along with it. CUI triggers Level 2 and the full 110.
Here is the practical test for a shop. Look at what the prime actually sends you to make the part. If it is a purchase order, a quantity and a part number against a drawing you already own commercially, you may have no CUI at all. If it is a technical data package, a model, or a drawing carrying a distribution statement other than the public-release one, you have CUI in the building. The statement is printed on the drawing. Anything more restrictive than public release is what this program exists to protect.
Two warnings on that test. The absence of a marking does not settle it, because the designating agency owns the marking obligation and unmarked information that meets the definition is still CUI in the hands of whoever holds it. And the answer can differ by contract inside the same building. If you are unsure, ask the contracting officer or the prime's supply chain contact in writing, before award, which CUI categories the effort involves. A written answer is worth more than a year of internal debate, and asking is normal.
The 110, and how they are actually distributed
CMMC Level 2 is the whole of NIST SP 800-171 Revision 2: 110 security requirements in fourteen families. There is no separate CMMC control set to learn. The work is 800-171 implementation, written down in a system security plan, with evidence good enough that a stranger can confirm it.
| Family | Count | What it is really asking a shop |
|---|---|---|
| Access Control | 22 | Who can reach the drawings, from where, on what device, and what happens on a remote connection |
| Awareness and Training | 3 | People know what CUI is and what they are not allowed to do with it |
| Audit and Accountability | 9 | Logs exist, are protected, and somebody looks at them |
| Configuration Management | 9 | You know what is on the network and it is built to a known baseline |
| Identification and Authentication | 11 | Accounts are individual, passwords are managed, and multifactor is on |
| Incident Response | 3 | There is a plan, it has been exercised, and reporting happens |
| Maintenance | 6 | Who touches the machines, including the vendor with a laptop |
| Media Protection | 9 | Drives, USB sticks, printouts, and what happens to them at end of life |
| Personnel Security | 2 | Screening before access, and access removed on the day someone leaves |
| Physical Protection | 6 | Doors, visitors, escorts, and a log |
| Risk Assessment | 3 | Vulnerability scanning and doing something about the results |
| Security Assessment | 4 | The system security plan, the plan of action, and periodic self-review |
| System and Communications Protection | 16 | Network segmentation, boundary control, and encryption of CUI |
| System and Information Integrity | 7 | Patching, malware protection, and monitoring |
Read that table with a plant in mind and the shape of the work appears. Physical Protection is close to free for a manufacturer — you already control doors and log visitors. Personnel Security is a human resources process you already run. Awareness and Training is an afternoon and a sign-in sheet. The expensive families are Access Control, Identification and Authentication, System and Communications Protection, and Audit and Accountability, because those are the ones that require the network to change rather than the binder to grow.
The score is arithmetic, and the number to know is 88
Level 2 is scored with the DoD Assessment Methodology. You start at 110 and subtract points for each requirement not implemented — 5, 3, or 1 depending on the weight the methodology assigns. Forty-two requirements carry five points, fourteen carry three, and the remaining fifty-four carry one. The published floor is negative 203, which tells you something useful about how the arithmetic runs: a shop that has done nothing does not score zero, it scores badly negative.
Two requirements have partial credit. Multifactor authentication loses three points instead of five if it is implemented for remote and privileged users but not for everyone. FIPS-validated cryptography loses three instead of five if encryption is used but the module is not validated.
A score of 88 or above — exactly eighty percent of 110 — permits a Conditional status with a plan of action and milestones attached to the remaining gaps, closed out within 180 days. Below 88 there is no conditional path; you are simply not there yet.
The consequence for a shop with limited money is that remediation order matters enormously. The forty-two five-point items hold most of the available points. A program that works alphabetically through the families spends the same money for a materially worse number than one that works down the weights. Ask any consultant to show you their remediation sequence. If it is in control-number order, they are optimizing for the appearance of progress.
Six requirements can never sit on a plan of action at any score: the two Access Control requirements covering external connections and control of publicly posted information, the system security plan requirement itself, and the three Physical Protection requirements covering visitor escorting, physical access logs, and management of physical access. If any of those six is not implemented, there is no conditional path regardless of your total. That list is short enough to check in an afternoon and consequential enough to check first.
Where the work usually lands for a shop of this size — our read
Our judgement of relative effort at this company size, not a survey. Your mix will differ if you already run managed endpoints and a modern identity provider.
What the shop floor does to your scope
This is the part software-oriented guidance gets wrong, and it is the part that decides whether Level 2 is affordable for you.
The CMMC rule sorts everything in a company into five asset categories. Assets that process, store or transmit CUI are assessed against all applicable requirements. Assets providing security functions to that environment are assessed against the requirements relevant to what they do. Assets kept away from CUI by policy and practice are documented and subject only to a limited check. Specialized assets — operational technology, government-furnished equipment, restricted systems and test equipment — are documented but not assessed against the full set. Everything else is out of scope.
Your CNC machines, your coordinate measuring machine, and your test stands sit in the specialized asset category. That is a genuine relief and it is written into the rule. It is not, however, a blanket exemption for the shop floor, and the distinction is worth getting exactly right.
The machine is specialized. The PC next to the machine is not. If a shop-floor workstation receives the technical data package, opens the model, posts the program, and holds the drawing on its desktop, that workstation processes CUI and is assessed like any other CUI asset. The most common expensive discovery in a small manufacturer is a Windows box on the shop floor, running an old operating system because the post-processor will not run on anything newer, holding four years of drawings in a folder called Jobs.
So the design question is not how to secure the machines. It is how the program gets from the drawing to the spindle without leaving CUI on general-purpose computers that cannot be patched. Several answers work: a controlled workstation that pushes programs and retains nothing, a virtual desktop that keeps files server-side, removable media under a written procedure with sanitization. Which one fits depends on your controllers and your throughput. The answer that never works is deciding the floor is out of scope because the machines are specialized.
Two more scope decisions deserve real thought: your ERP and your email. If the ERP holds part numbers, routings, quantities and dates while the controlled model lives elsewhere, you have a defensible argument that the ERP is not a CUI asset, and that argument is worth money because bringing an ERP inside a boundary is expensive. If people attach drawings to ERP records, the argument is gone. Email is the same story with worse odds — forwarding an attachment is the easiest thing a person can do.
What it costs, without a made-up number
We are not going to print a figure, because anyone who prints one without seeing your network is guessing. What we can tell you is which variables move the bill, roughly in order of impact.
- How many people need CUI access. Six engineers is a different project from forty users
- Whether you build an enclave or assess the whole company. The single largest lever, and it is decided once
- Whether CUI has to land on endpoints at all. Keeping data server-side removes whole families of work
- Your cloud posture. If CUI goes into a cloud service, that service has to meet the FedRAMP Moderate equivalency requirement in the safeguarding clause, and that constrains which products you can use
- Your managed service provider. Their tooling reaches into your environment, which makes them part of it
- How much evidence already exists. Firms already running AS9100 have a documentation culture, and it genuinely helps
The Department's own statements during the July suspension named the aggregate cost to small and medium businesses as a central reason for it. That is not a reason to do nothing. It is a reason to be disciplined about scope, because scope is the variable you control and the one nobody will optimize on your behalf.
A ninety-day order of operations
If you have a prime asking questions and no program yet, this is the sequence we would use. It front-loads the decisions that are cheap now and expensive later.
- Weeks 1–2. Establish, in writing, whether CUI touches you and on which contracts. Ask the prime or the contracting officer. Collect the actual drawings and read the distribution statements
- Weeks 2–4. Map where that data has gone. Mail, file shares, ERP, shop-floor PCs, laptops, backups, and the supplier you send overflow work to
- Weeks 3–5. Draw the boundary. Decide what will be inside, what becomes risk-managed, and what goes out of scope. This drawing is the budget
- Weeks 4–6. Score yourself honestly against the 110, five-point items first, and check the six that can never be deferred
- Weeks 6–10. Remediate in weight order. Multifactor, encryption, logging, segmentation
- Weeks 8–12. Write the system security plan while you remediate. It is scored in its own right and cannot sit on a plan of action
- Week 12. Post the score and the affirmation, then set a recurring date to re-score. A stale affirmation is the real risk
Where the honest answer is that you do not need this
Four situations come up often enough to name. In each, the right advice is to spend less, not more.
You only have FCI. If no controlled technical data ever reaches you, Level 1 is the ceiling. Fifteen requirements, done properly, documented, affirmed. Do not let a supplier questionnaire talk you into the 110 because the form only had one box.
You can decline the data. On some programs the prime can keep the model on its own portal and have you work in it. That is worth asking about before you build an enclave. It is not always possible and it is sometimes free.
You are a Level 1 shop with one Level 2 program. Build a small enclave for that program rather than lifting the whole company.
You already run a modern managed environment. Shops with a competent provider, managed endpoints, a current identity platform and centralized logging are often much closer than they think. A two-week honest self-score costs less than a discovery engagement and will tell you.
- Buying a tool before drawing the boundary — the boundary determines which tools you need and how many licenses
- Treating the whole company as in scope because it felt safer, and paying for it for three years
- Assuming the shop floor is exempt because the machines are specialized assets
- Letting the managed service provider self-certify without reading what their tooling actually reaches
- Writing the system security plan last, when it is a scored requirement that cannot be deferred
- Posting a score nobody can substantiate, which converts a compliance gap into a false statement problem
- Reading the Phase 2 pause as the end of the obligation — the safeguarding clause never paused
Bottom line
For a forty-person manufacturer, CMMC Level 2 is not principally a security project. It is a scoping project with a security project inside it. The firms that get through at a survivable cost spend their first month deciding precisely where controlled data is allowed to exist, then build a small, well-instrumented place for it. The 110 requirements are fixed and public. The size of the thing you apply them to is yours to decide, and it is the only variable with an order of magnitude in it.
The paperwork is genuinely unsettled right now and it would be dishonest to pretend otherwise. The underlying obligation is not. Work spent implementing the requirements holds its value regardless of what the task force recommends. Work spent on the wrapper might not.
Frequently asked questions
You can wait on the third-party certification. You cannot wait on the requirements. Phase 1 has been in force since November 10, 2025 and makes a Level 1 or Level 2 self-assessment status in SPRS a condition of award on applicable contracts, with an annual affirmation by a named official. DFARS 252.204-7012 has required NIST SP 800-171 since 2017 and was untouched by the suspension. Primes set their own supplier terms and many are not waiting.
The machines fall into the specialized asset category: documented in your inventory, system security plan and network diagram, but not assessed against the full requirement set. The general-purpose computers around them are a different matter. If a shop-floor PC opens the model, posts the program or stores the drawing, it processes CUI and is assessed like any other CUI asset. Design the data path so controlled files never have to live on machines you cannot patch.
Possibly not. The level follows the data. Purchase orders, quantities and delivery dates are federal contract information and point to Level 1: fifteen requirements and a self-assessment. Controlled technical information — drawings and technical data packages carrying a restrictive distribution statement — points to Level 2. Confirm in writing which categories the effort involves before you build anything.
110 out of 110 is full implementation. A score of 88 or above permits a Conditional status with a plan of action covering the remaining eligible gaps, closed within 180 days. Below 88 there is no conditional path. Six requirements can never appear on a plan of action at any score, so check those first.
Both, and you need to know which. A provider whose tooling reaches into your environment is providing security protection to your assessment scope, which puts their platform inside your boundary. Ask in writing which of the 110 they implement on your behalf, and what their own posture is. A good provider answers plainly. One who says the question does not apply has answered it.
