Part 1 of 3 in the CMMC for Small Defense Contractors series

Part 2: How Do I Know If I'm Ready for My CMMC Assessment? A Small Contractor's Self-Assessment Guide

Part 3: What Is CUI Scoping, and How Can It Cut Your CMMC Compliance Costs in Half?


A precision machining org with 30 employees gets a CMMC flowdown from their prime in Q4 2025. The owner calls an MSP. The MSP quotes $280,000 for a Level 2 enclave: GCC High tenant, MFA rollout, gap assessment, documentation, C3PAO assessment fees.

Six months into planning, a compliance consultant asks one question: "What kind of data does the prime actually send you?"

Purchase orders. Delivery schedules. Standard contract documentation. No technical specs, no engineering drawings, no program details with classification markings.

That's Federal Contract Information — FCI. Not Controlled Unclassified Information — CUI.

CMMC Level 1. Seventeen controls. Self-assessed. No enclave. No C3PAO. The cost: a few days of internal effort and whatever you spend on good documentation.

That $280,000 quote wasn't wrong as a description of what Level 2 costs. It was wrong because no one had established whether Level 2 was required. That's not a failure of your security program; it's a limitation of the model most SMBs follow when they first hear the word CMMC: assume the worst, price the worst, panic accordingly.

Before you spend a dollar on CMMC compliance, you need to know which level you actually need. That determination is simpler than the compliance program it leads to,  and getting it right saves most small contractors more than anything else they'll do.

What Is the Difference Between CMMC Level 1 and Level 2?

CMMC has three levels. Level 1 and Level 2 are the two that affect the majority of small defense subcontractors. Level 3 applies to the highest-priority programs under DoD oversight and is out of scope for most small businesses.

CMMC Level 1:

  • Covers contractors who handle Federal Contract Information (FCI)
  • Requires implementation of 17 basic cybersecurity practices from FAR clause 52.204-21
  • Self-assessed — no third-party assessment required, no C3PAO
  • Annual self-assessment submitted to the SPRS portal
  • Cost of compliance: primarily time and documentation, not infrastructure spend

CMMC Level 2:

  • Covers contractors who handle Controlled Unclassified Information (CUI)
  • Requires implementation of all 110 practices from NIST SP 800-171
  • Third-party assessment required (C3PAO) for most contracts involving CUI
  • Assessment fees alone run $30,000–$80,000; full compliance programs typically $120,000–$350,000 in year one for a 50-person contractor
  • Phase 2 enforcement begins November 10, 2026 — DoD can condition contract awards on Level 2 certification from that date

The gap between Level 1 and Level 2 is not a spectrum. It's two fundamentally different compliance programs with a different type of information at the center of each one.

Don't Let Compliance Fear Bankrupt Your IT Budget

Small defense subcontractors routinely default to the most expensive, disruptive CMMC architectures simply because they assume it's the only way to satisfy an auditor. Before you commit six figures to a sweeping cloud infrastructure migration, map out exactly what data you handle and explore your deployment options.

See How Theodosian Protects Small Business Budgets

Who Actually Needs CMMC Level 2?

Every defense contractor in the supply chain needs some level of CMMC, but not every contractor needs Level 2.

You need Level 2 if your prime sends you, or you generate, Controlled Unclassified Information under the contract. The DoD defines CUI through the National Archives' CUI Registry — a specific list of information categories that carry controlled handling requirements. Examples of CUI relevant to defense contractors:

  • Technical data, engineering drawings, and specifications for controlled programs
  • Export-controlled data (ITAR/EAR-governed technical information)
  • Sensitive contract information relating to program costs, schedules, or capabilities on classified programs
  • Procurement-sensitive information with security implications

You need Level 1 if you handle only Federal Contract Information — information provided by or generated for the government under a contract that is not intended for public release, but does not meet the definition of CUI. Examples:

  • Purchase orders and delivery schedules
  • Standard contract terms and administrative information
  • Invoices and payment records
  • Non-sensitive correspondence related to contract performance

If your DoD contracts involve basic manufacturing, standard services, or logistics work — and your prime does not provide you with technical specifications, program details, or marked CUI documents — you may be a Level 1 contractor.

This is not a self-declaration. The prime contractor is responsible for identifying the CUI in their program and flowing down the appropriate CMMC requirement. If you're receiving a CMMC clause in your subcontract, the prime is telling you what they believe you need. But many primes apply Level 2 flowdown broadly as a risk management decision — which means not all Level 2 flowdown means the subcontractor actually handles CUI.

What Is CUI, and How Do You Actually Handle It?

CUI is the most important concept in CMMC compliance, and it's also one of the most consistently misunderstood.

CUI is not classified. It doesn't require security clearances. It's unclassified information that the government has identified as requiring protection under specific handling rules because its unauthorized disclosure could harm national or economic security. The DoD's CUI categories most relevant to small defense contractors:

Controlled Technical Information (CTI): Technical information related to defense systems and components — engineering drawings, specifications, technical manuals — that requires distribution controls. If your prime sends you engineering drawings for controlled components, you're likely handling CTI, which is CUI.

Export Controlled (ITAR/EAR): Technical data subject to International Traffic in Arms Regulations or Export Administration Regulations. If your company receives ITAR-controlled technical data, you're handling CUI. This is one of the most common CUI categories in small defense subcontracts.

Procurement and Acquisition: Sensitive procurement information relating to source selection, cost estimates, or contract negotiations. Generally applies to contractors more deeply involved in program management.

How to tell if you're receiving CUI: CUI must be marked. The DoD Instruction 5200.48 requires that CUI be identified with a CUI marking (a banner header, footer, or designation indicator). If documents from your prime contain a "CUI" header or designation indicator, you're handling CUI. If your work product contains controlled technical information, you may be generating CUI even if it wasn't marked.

If you're uncertain, ask your prime contractor's security officer directly: "Is this contract designated as requiring CUI handling?" They know. Getting a clear answer saves time and money.

What Does CMMC Level 1 Require?

Level 1 requires 17 cybersecurity practices drawn from FAR 52.204-21. These are basic safeguards that most functional businesses already have at least partially in place. The 17 practices span six domains:

Access Control (AC): Limit system access to authorized users. Limit access to the types of transactions and functions authorized users can perform.

Identification and Authentication (IA): Identify information system users and authenticate them before access. Use of unique usernames (no shared accounts).

Media Protection (MP): Sanitize or destroy information system media containing Federal Contract Information before disposal or reuse.

Physical Protection (PE): Limit physical access to systems that process FCI to authorized individuals. Escort visitors and monitor their activity.

System and Communications Protection (SC): Monitor, control, and protect organizational communications at external boundaries and key internal boundaries.

System and Information Integrity (SI): Identify, report, and correct information system flaws in a timely manner. Protect information systems from malicious code. Update malicious code protection mechanisms when new releases are available. Perform periodic scans and real-time scans of files from external sources.

None of these require a GCC High tenant. None require a C3PAO. What they require is honest documentation that these practices are actually in place — a System Security Plan (SSP) that describes how each of the 17 practices is implemented in your environment.

The annual self-assessment is submitted to the DoD's Supplier Performance Risk System (SPRS) portal. Your score is the sum of implemented practices (max 17 for Level 1). The submission is a legal attestation — it needs to reflect actual implementation, not aspirational compliance. For more on SPRS scoring implications, see our full guide to SPRS scores and how DoD uses them.

What Does CMMC Level 2 Require for a Small Business?

Level 2 requires implementation of all 110 practices from NIST Special Publication 800-171, plus a third-party assessment by a C3PAO (Certified Third-Party Assessment Organization) for most contracts.

For a small business, the practical requirements are:

Infrastructure (The Enclave vs. The Data-Centric Approach): Traditionally, small businesses have been told they must migrate their entire operation into a Microsoft 365 GCC High environment or an equivalent FedRAMP Moderate-authorized cloud enclave to handle CUI. Because standard commercial M365 tenants lack compliance defaults for CUI, this migration usually forces small contractors to maintain split tenants, juggle double licensing (GCC High sits around $60/user/month), and endure months of operational disruption.

However, you do not have to completely lift-and-shift your infrastructure to satisfy Level 2. An increasingly vital alternative for small contractors is to implement a data-centric security model using Theodosian. Instead of spending hundreds of thousands of dollars building a massive cloud perimeter to protect an entire network, Theodosian embeds FIPS 140-3 validated encryption directly into individual files. Because the cryptographic protection is tied to the CUI content itself, your files remain fully compliant even if they reside or move within your existing commercial M365 tenant. This alternative completely bypasses the need for a costly GCC High migration, allowing small businesses to achieve airtight Level 2 data handling while keeping their overhead low.

Encryption: CUI at rest and in transit must be encrypted using FIPS 140-3 validated cryptographic modules. This is a non-deferrable requirement — you cannot receive a conditional CMMC certificate without it. See our plain-language guide to CMMC Level 2 encryption requirements for what this means in practice.

Multi-factor Authentication (MFA): Required for all privileged access and all access to CUI systems. Also non-deferrable.

System Security Plan (SSP): A documented description of your entire CUI environment — every system, every connection, every user with access. This is the foundational document your C3PAO will use during assessment.

Assessment: Scheduled with one of the 83 authorized C3PAOs. Assessment timelines are 6–9 months from scheduling at current capacity — which means for November 2026 enforcement, the window for new scheduling is already tight.

The full breakdown of CMMC Level 2 compliance costs covers each line item in detail, including GCC High infrastructure, C3PAO fees, and the three-year DoD baseline cost for a standard program.

What Happens If You Get Your CMMC Level Wrong?

If you assume Level 2 when you only need Level 1: You spend $120,000–$350,000 on infrastructure, documentation, and assessment that wasn't required. You build a GCC High environment for purchase orders and delivery schedules. You go through a C3PAO assessment that didn't need to happen. This is a real cost mistake that small contractors make regularly.

If you assume Level 1 when you actually need Level 2: The prime finds out, typically when you're asked to demonstrate your CMMC certification as a condition of contract award or renewal. If you've been handling CUI without the required controls, you may be in violation of DFARS 252.204-7012 (which has been in force since 2017) and potentially the False Claims Act if you've been self-certifying compliance you can't demonstrate. For a full picture of enforcement consequences, see what happens when ITAR or CMMC non-compliance is discovered.

Getting the level right is damage prevention, not damage control. The determination costs nothing. Getting it wrong costs either a six-figure compliance program you didn't need, or enforcement exposure you didn't see coming.

How Do You Determine Your CMMC Level Before the C3PAO Does?

Five questions. You can answer most of them today.

1. What does your subcontract say? Look for DFARS clause 252.204-7012 (Safeguarding Covered Defense Information) and DFARS 252.204-7021 (CMMC Requirements). The CMMC clause in your subcontract specifies the required level. If neither clause is present, you may not be subject to CMMC at all — but confirm with your prime.

2. What information does your prime actually send you? Review the documents, files, and data you receive under the contract. Are any of them marked CUI? Do they contain controlled technical information, ITAR-governed data, or sensitive program details? If the files you receive look like purchase orders and delivery schedules, you're likely FCI-only.

3. What information do you generate under the contract? Even if your prime doesn't send you CUI, you may generate it. A machining org that produces controlled components using tolerances or specifications from a defense program may generate CUI in the form of inspection records or manufacturing documentation.

4. Ask your prime's security officer directly. Prime contractors have designated security officers or compliance contacts. A direct question — "Is this contract designated as CUI?" — will get you a direct answer. This is the most reliable path to clarity.

5. Check the CMMC Compliance Checklist. This resource walks through the level determination process alongside all 110 NIST SP 800-171 practices with point weights, POA&M eligibility, and implementation priority — useful whether you're confirming Level 1 or starting Level 2 preparation.

Stop Building Digital Fortresses for Data That Doesn't Need Them

Achieving CMMC Level 2 doesn't have to mean migrating your entire team into a locked-down cloud enclave. By choosing a data-centric architecture over an infrastructure overhaul, you can secure your contract's CUI at the file level while keeping your day-to-day operations exactly as they are today.

Discover the Smart Alternative to GCC High Migrations

FAQs: CMMC for Small Defense Subcontractors

If my prime sends me a CMMC Level 2 flowdown, does that mean I need Level 2?

Not necessarily. Primes sometimes flow down Level 2 requirements broadly to all subcontractors as a risk management default, even to those who don't actually handle CUI. The flowdown creates a contractual obligation, but you can engage your prime to confirm whether CUI handling is actually expected under your specific scope of work. If it isn't, you may be able to negotiate a Level 1 requirement. Get any clarification in writing.

What are the 17 CMMC Level 1 practices?

The 17 Level 1 practices map to FAR 52.204-21's basic safeguarding requirements across six domains: Access Control (AC.L1-3.1.1, 3.1.2), Identification and Authentication (IA.L1-3.5.1, 3.5.2), Media Protection (MP.L1-3.8.3), Physical Protection (PE.L1-3.10.1, 3.10.3, 3.10.4, 3.10.5), System and Communications Protection (SC.L1-3.13.1, 3.13.5), and System and Information Integrity (SI.L1-3.14.1, 3.14.2, 3.14.4, 3.14.5, 3.14.6, 3.14.7). The complete list with implementation guidance is in the CMMC Compliance Checklist.

Can a small business self-certify for Level 1?

Yes. Level 1 requires an annual self-assessment and affirmation — no third-party assessor is required. The self-assessment must be submitted to the SPRS portal by a senior company official. The assessment is a legal attestation, meaning it must accurately reflect your actual implementation. An inflated self-assessment score carries False Claims Act exposure.

When does CMMC Level 2 enforcement actually start?

CMMC Phase 1 enforcement began in November 2025, but primarily for a limited set of contracts. Phase 2, which expands Level 2 C3PAO assessment requirements broadly, begins November 10, 2026. If your prime has indicated CMMC Level 2 is required, contracts issued after that date can require demonstrated certification as a condition of award. The C3PAO scheduling backlog means preparation needs to start well before the deadline.

Do small businesses qualify for any CMMC exemptions?

No general small business exemption exists under CMMC. If you handle CUI, you need Level 2 certification regardless of company size. The SBA has raised concerns about compliance costs for small businesses, but no size-based waiver is in place. The practical path for small contractors is accurate level determination (to avoid unnecessary Level 2) and CUI scoping (to reduce Level 2 scope), covered in Part 3 of this series.