Guide · 7 min · For Owners

Who CMMC applies to, and why a machine shop is in scope.

The Cybersecurity Maturity Model Certification program is how DoD verifies the security requirements suppliers have been agreeing to since DFARS 252.204‑7012 set a December 31, 2017 deadline for NIST SP 800-171. The program rule, 32 CFR Part 170, took effect December 16, 2024 and applies to every DoD contract and subcontract awardee that handles two kinds of information on its own systems:

  • Federal Contract Information (FCI). Information not intended for public release, provided by or generated for the government under a contract: purchase orders, delivery schedules, quote requests. Almost every supplier has it.
  • Controlled Unclassified Information (CUI). Information a law, regulation, or government-wide policy requires to be safeguarded, such as export-controlled technical data. If a prime sends you a marked drawing to quote, you have CUI.

It applies at every tier, commercial buys included; the only carve-outs in 32 CFR 170.3(c) are buys solely for commercial off-the-shelf items and buys at or below the micro-purchase threshold. A 12-person machine shop three tiers below the prime is in scope the moment a marked drawing arrives.

The three levels, and the one a small supplier usually faces.

CMMC 2.0 has three levels; the DoD program office picks one per procurement.

  • Level 1 (Self). The 15 basic safeguarding requirements of FAR 52.204-21, for FCI only: an annual self-assessment entered in the Supplier Performance Risk System (SPRS) plus an affirmation. No Plan of Action and Milestones (POA&M) is permitted.
  • Level 2. The 110 requirements of NIST SP 800-171 Revision 2, for CUI, in two forms: Level 2 (Self), a self-assessment every three years, and Level 2 (C3PAO), a certification assessment every three years by an authorized CMMC Third-Party Assessment Organization. Both carry an annual affirmation. DoD picks which applies per contract; as written, the rule intended Level 2 (C3PAO) for applicable CUI contracts once Phase 2 began.
  • Level 3 (DIBCAC). Selected NIST SP 800-172 requirements, assessed by DCMA DIBCAC, with Final Level 2 (C3PAO) as a prerequisite. Not a small-supplier concern.

For a small supplier the realistic picture is Level 1 if you only see FCI and Level 2 if you see CUI. A Level 2 POA&M is allowed only if you score at least 80 percent, only for one-point requirements (one narrow exception: encryption in place but not FIPS-validated), never for six named requirements including the System Security Plan, and only if it closes within 180 days.

Where the rollout stands in September 2026.

The acquisition rule that puts the clause into contracts, DFARS Case 2019-D041, took effect November 10, 2025. The four phases in 32 CFR 170.3(e) run from that date, and the rule says what DoD “intends” to require in each, not what it must:

The four phases as 32 CFR 170.3(e) defines them, and their status as of September 4, 2026
Phase Begins (per the rule) What the rule says DoD intends to require Status
Phase 1 Effective date of the DFARS rule: November 10, 2025 Level 1 (Self) or Level 2 (Self) as a condition of award; Level 2 (C3PAO) at DoD’s discretion In effect
Phase 2 One calendar year after Phase 1: November 10, 2026 Level 2 (C3PAO) as a condition of award for applicable contracts Suspended July 13, 2026; no new date published
Phase 3 One calendar year after Phase 2 Level 2 (C3PAO) for all applicable contracts and options; Level 3 (DIBCAC) as a condition of award A plan in the rule, now under review
Phase 4 One calendar year after Phase 3 Full implementation, including options on earlier contracts A plan in the rule, now under review

On July 13, 2026, the Department of War announced that its Chief Information Officer had suspended the November 2026 transition to Phase 2 and opened a 60-day review of the program. An implementing memorandum from the Under Secretary of War for Acquisition and Sustainment, dated the same day, directs program offices to designate only Level 1 (Self) or Level 2 (Self) and contracting officers to strip C3PAO and DIBCAC requirements from solicitations and existing contracts. It keeps DFARS 252.204‑7012 in effect, enforces NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments, and promises further guidance when the review ends. As of September 4, 2026, no further guidance or new schedule has been published and the phase language in 32 CFR 170.3(e) is unchanged; see the DoD CIO CMMC page.

The honest reading: the certification deadline is gone for now, the self-assessment and affirmation obligations are not, and the 110 requirements have been in your contracts since 2017.

What the 110 controls mean in plain terms.

Revision 2 organizes its 110 requirements into 14 families. NIST published Revision 3 in May 2024 with 17 families and marked Revision 2 withdrawn, but 32 CFR 170.14 still incorporates Revision 2, so that is what you are assessed against. Most technical families reduce to controls a well-run business already has:

  • Identification and authentication, access control. Everyone signs in as themselves, with multifactor authentication for network access and privileged accounts, and access granted by role and removed at departure.
  • System and information integrity, configuration management. Endpoint detection and response on every device, scheduled patching with evidence, and a documented configuration baseline.
  • Audit and accountability. Logs that record who did what, retained long enough to reconstruct an incident, and actually reviewed.
  • Media protection. Encrypted laptops and drives, controlled removable media, a wiped-before-disposal rule, and (requirement 3.8.9) the confidentiality of backup CUI.
  • Incident response. A written plan, a named owner, and the ability to report a cyber incident to DoD within 72 hours, which DFARS 252.204‑7012 already requires.
  • Awareness and training. Documented security training for everyone who touches CUI, including recognizing phishing.
  • System and communications protection. A managed firewall, segmentation that keeps CUI systems away from guest Wi-Fi and shop-floor controllers, and encryption in transit.

The paperwork: an SSP, a POA&M, and an annual affirmation.

Three documents carry the program. The System Security Plan describes your scope, every system in it, and how each requirement is met; it can never sit on a POA&M. The Plan of Action and Milestones lists what is not yet met, with owners and dates. The affirmation is your Affirming Official, a senior person at the company, attesting in SPRS to continuing compliance after every assessment and annually thereafter. Assessment evidence must be kept for six years.

None of that is IT work; it is management work with IT input, and it is where small suppliers stall.

What it realistically costs.

DoD’s own estimates in the final program rule are the defensible numbers. For a small entity: $5,977 for a Level 1 self-assessment and affirmation, done annually; $34,277 for a Level 2 self-assessment and affirmation, or $37,196 over the three-year cycle; and $101,752 for a Level 2 C3PAO certification assessment, or $104,670 over three years.

Every figure assumes the requirements are already implemented; they cover planning, the assessment, and the affirmation, not the work of getting there. For a shop with shared logins, no EDR, and untested backups, implementation is the larger number, and easier spread over 12 to 18 months than forced by a solicitation.

What an IT provider should own, and what stays on you.

Micro-IT is not a C3PAO, a Registered Provider Organization, or a certification body; no managed IT provider can certify you. What one can do is run the technical controls and produce the evidence.

The seven-layer stack every Micro-IT client runs (identity, endpoint, email, DNS, network, backup, and people, monitored by a 24/7 SOC) maps onto the technical families above: MFA on every account, EDR and patching on every device, log collection and review, encrypted and restore-tested backups, DNS filtering, managed firewall and segmentation, and documented security awareness training. That covers a large share of the 110, run as monthly operations with evidence kept current.

What stays with you: deciding what is in scope, owning the System Security Plan, naming the Affirming Official, screening personnel, physical security, and the assessment itself. Put that line in writing; assessment failures live in the seam between the two.

Flow-down: your subcontractors are your problem too.

If you pass CUI to a heat-treater, a plating shop, or a contract inspector, 32 CFR 170.23 and DFARS 252.204‑7021 make you responsible for flowing the requirement down: Level 1 (Self) for a sub that only sees FCI, at least Level 2 (Self) for one that sees CUI, and Level 2 (C3PAO) if your own prime contract requires it. You must confirm the sub’s status before award. The simplest defense is to send CUI to fewer people and know who has it.

Three things to do this month.

  1. Find out what you hold. Ask your prime whether anything they send is CUI, and check the markings on your drawings.
  2. Pull your SPRS score. If you do not have one, a self-assessment against the 110 requirements is the first document to produce.
  3. Decide who owns the System Security Plan. If the answer is “IT,” it is wrong; IT contributes, the business owns it.

For a second set of eyes, book a 20-minute intro call. We will say plainly which layers are done, which are not, and which parts are not ours to do.

Frequently asked questions.

Does CMMC apply to a small subcontractor that never signs a contract with DoD directly?
Yes, if the subcontract involves Federal Contract Information or Controlled Unclassified Information. 32 CFR 170.23 applies CMMC at every tier of the supply chain, and DFARS clause 252.204‑7021 requires the prime to flow the requirement down and to confirm the sub’s CMMC status before awarding the subcontract. A sub that handles only FCI needs Level 1 (Self); a sub that handles CUI needs at least Level 2 (Self), and Level 2 (C3PAO) if the prime contract requires it.
Is CMMC Level 2 certification still required in November 2026?
Not as of September 2026. Under the program rule, Phase 2 was to begin one year after the DFARS rule took effect, which worked out to November 10, 2026, and would have added C3PAO certification as a condition of award. On July 13, 2026, the Department of War announced that its Chief Information Officer had suspended that transition, and program offices were directed to designate only Level 1 (Self) or Level 2 (Self) while a 60-day review runs. The rule text has not been amended and no new schedule has been published. Self-assessments, annual affirmations, and DFARS 252.204‑7012 remain in effect.
How many controls does CMMC Level 2 actually require?
110. 32 CFR 170.14 states that the Level 2 security requirements are identical to NIST SP 800-171 Revision 2, which has 110 requirements across 14 families. NIST published Revision 3 in May 2024 and reorganized the requirements into 17 families, but the CMMC rule still incorporates Revision 2, and the July 2026 memoranda say DoD will continue to enforce Revision 2 during the review.
Can an IT provider get us CMMC certified?
No. Only an authorized C3PAO can conduct a Level 2 certification assessment, and Micro-IT is not a C3PAO, a Registered Provider Organization, or any kind of certification body. What a managed IT provider can do is implement and run the technical controls that make up a large share of the 110 requirements, and hand you the evidence. The System Security Plan, the affirmation, and the assessment itself stay with the business.

Your next step

Reading is the easy part — the gap closes when someone owns it. Book a free 20-minute call and we’ll walk through how this applies to your environment, in plain English.