If your manufacturing company works with the Department of Defense — or wants to — you’ve probably heard the acronym CMMC. Maybe a prime contractor mentioned it in a meeting. Maybe it showed up in a contract clause you almost skipped past.
Here’s the problem: most small manufacturers don’t understand what CMMC actually requires until they’re six months from a deadline and scrambling.
This guide breaks down CMMC 2.0 in plain English — what it is, who needs it, what the different levels actually require, and how to start preparing without shutting down your shop floor.
What Is CMMC 2.0?
CMMC stands for Cybersecurity Maturity Model Certification. It’s the Department of Defense’s framework for ensuring that companies in the defense industrial base (DIB) — including thousands of small subcontractors and manufacturers — protect sensitive government information.
The original CMMC 1.0 had five levels. In November 2021, the DoD released CMMC 2.0, which streamlined the model to three levels and aligned it more closely with existing NIST standards most security teams already know.
CMMC 2.0 is now being phased into DoD contracts. By fiscal year 2026, compliance is required across virtually all contracts involving Controlled Unclassified Information (CUI) or Federal Contract Information (FCI).
If you make parts, fabricate components, do machining, perform engineering work, or provide any product or service that ends up in a defense supply chain — you need to understand this.
Who Actually Needs CMMC Certification?
CMMC applies to any company in the DoD supply chain. That includes:
- Prime contractors — companies that hold contracts directly with the DoD
- Subcontractors — companies that receive work from prime contractors (this is where most small manufacturers sit)
- Suppliers — companies that provide materials, components, or services used in defense contracts
Two types of sensitive data drive the requirements:
| Data Type | Definition | Example |
|---|---|---|
| FCI (Federal Contract Information) | Information provided by or generated for the government under a contract | Purchase orders, contract deliverables, specs |
| CUI (Controlled Unclassified Information) | Sensitive but unclassified government information requiring protection | Technical drawings, manufacturing specs, export-controlled data |
If you only handle FCI, you likely need CMMC Level 1. If you handle CUI, you need at minimum CMMC Level 2 — and that’s most defense subcontractors who touch anything technical.
The Three CMMC 2.0 Levels
Level 1 — Foundational (17 Practices)
Level 1 covers basic cyber hygiene. Think of it as the minimum responsible IT practices every business should already have.
Key requirements: – Use antivirus and keep it updated – Limit access to systems and data by role – Sanitize or destroy media before disposal – Perform regular system scans and monitoring – Protect physically — lock server rooms, control building access
Assessment type: Annual self-assessment. No third-party auditor required.
Who this applies to: Companies handling only FCI.
Reality check: Most well-run small businesses already meet Level 1. If you have a managed IT provider running endpoint protection, applying patches, and enforcing access controls, you may be closer than you think.
Level 2 — Advanced (110 Practices)
This is where most DoD subcontractors land — and where the real work is.
Level 2 maps directly to NIST SP 800-171, a set of 110 security requirements across 14 domains. If you’ve ever seen a request to complete a System Security Plan (SSP) or a Supplier Performance Risk System (SPRS) score, this is the framework behind it.
Key domains in NIST 800-171: – Access Control – Audit and Accountability – Configuration Management – Identification and Authentication – Incident Response – Maintenance – Media Protection – Personnel Security – Physical Protection – Risk Assessment – Security Assessment – System and Communications Protection – System and Information Integrity
Assessment type: For contracts with “critical” CUI, a third-party C3PAO (Certified Third-Party Assessment Organization) audit is required. For other CUI contracts, an annual self-assessment with affirmation is required.
Timeline: C3PAO assessments take 3–9 months to prepare for properly. Don’t wait until a contract clause forces your hand.
Level 3 — Expert (130+ Practices)
Level 3 builds on Level 2 and adds requirements from NIST SP 800-172, which covers advanced persistent threats (APTs). This level is reserved for companies working on the DoD’s most sensitive programs.
Assessment type: Government-led assessment by DCSA (Defense Contract Management Agency).
Who this applies to: Very few small manufacturers. If you’re not explicitly told you need Level 3, you don’t.
CMMC vs. NIST 800-171 vs. SOC 2 — What’s the Difference?
If you’ve been hearing multiple compliance acronyms, here’s the quick comparison:
| Framework | Who It’s For | Focus | Assessment |
|---|---|---|---|
| CMMC 2.0 | DoD supply chain | CUI/FCI protection | Self-assessment or C3PAO audit |
| NIST 800-171 | Federal contractors | CUI protection | Self-assessed (SPRS score) |
| SOC 2 | SaaS / service businesses | Customer data security | Third-party auditor |
| ISO 27001 | International businesses | ISMS framework | Third-party certification |
The key insight: CMMC Level 2 is essentially NIST 800-171 with mandatory third-party verification for critical programs. If you’ve already done a serious NIST 800-171 self-assessment, you’ve done much of the CMMC Level 2 groundwork.
What CMMC Level 2 Actually Costs
The honest answer: it depends heavily on your starting point.
Typical cost ranges for small manufacturers (20–100 employees):
| Cost Category | Range |
|---|---|
| Gap assessment and SSP development | $5,000 – $15,000 |
| Remediation work (IT, policies, tools) | $15,000 – $75,000 |
| C3PAO third-party audit | $30,000 – $75,000 |
| Ongoing compliance maintenance (annual) | $10,000 – $25,000 |
These ranges are wide because the gap between “we have a firewall” and “we’re CMMC-ready” varies enormously. Companies with mature IT environments — patched systems, MFA everywhere, documented policies, trained employees — spend far less on remediation than companies starting from scratch.
The business math: A single DoD subcontract worth $500K–$2M makes the compliance investment straightforward. For most manufacturers in the supply chain, the question isn’t whether to pursue CMMC — it’s how to do it efficiently.
The 5 Most Common CMMC Gaps in Small Manufacturing Shops
After working through security assessments with manufacturers in Fort Wayne and across the Midwest, here are the gaps that show up most often:
1. No Multi-Factor Authentication on Remote Access
Remote access without MFA is a Level 2 non-starter. VPN, RDP, email, cloud apps — all of it needs MFA. If your team logs in from home with just a username and password, that’s a gap.
2. No Formal Incident Response Plan
CMMC requires a documented incident response (IR) plan — not a verbal understanding that someone will call IT. You need to define who does what, how fast, and how you’ll report to the DoD if a breach involves CUI.
3. Uncontrolled CUI on Shared Drives or Personal Devices
CUI — technical drawings, contract specs, engineering files — needs to live in controlled environments. If it’s sitting on an open network share or someone’s personal laptop, you have a documentation and configuration problem.
4. Inadequate System Logging and Monitoring
CMMC Level 2 requires audit logging and the ability to detect and investigate anomalies. Many small manufacturers have no centralized logging at all. “We’d know if something happened” isn’t an audit-ready answer.
5. No Formal Security Assessment (SPRS Score Not Submitted)
If you’re a DoD subcontractor and you haven’t submitted a SPRS score at suppliers.gov, you’re technically already out of compliance with DFARS 252.204-7012. Many small manufacturers don’t realize this obligation already exists.
How to Start Preparing: A Realistic 6-Step Path
You don’t need to tackle everything at once. Here’s a logical sequence:
Step 1: Scope your CUI environment Map where CUI lives — which systems store it, process it, or transmit it. This becomes the boundary of your assessment scope.
Step 2: Complete a gap assessment against NIST 800-171 Measure your current state against all 110 requirements. A formal gap assessment gives you your SPRS score (required for DoD contracts) and a prioritized remediation list.
Step 3: Develop your System Security Plan (SSP) The SSP documents how your organization meets (or plans to meet) each requirement. This is the primary artifact auditors review. It’s a living document, not a one-time deliverable.
Step 4: Remediate the critical gaps Prioritize gaps that affect CUI directly: MFA, access controls, encryption, logging, and incident response. These carry the most weight in an audit.
Step 5: Implement a Plan of Action & Milestones (POA&M) Any requirements you can’t immediately meet need a documented remediation timeline. A clean POA&M with realistic milestones is more defensible than claiming full compliance when you’re not there.
Step 6: Schedule your C3PAO assessment (if required) If your contracts require a third-party audit, book early. C3PAO capacity is limited, and assessment windows book out months in advance.
How Managed IT Helps with CMMC Preparation
CMMC compliance isn’t purely a documentation exercise — it’s a technical and operational lift. Most small manufacturers don’t have the internal IT depth to handle it alone.
A managed IT provider with CMMC/NIST 800-171 experience can:
- Conduct the gap assessment against all 110 NIST controls and document your starting SPRS score
- Implement required technical controls — MFA, endpoint detection and response (EDR), centralized logging, patch management, encrypted storage
- Develop your SSP and POA&M — the core documentation artifacts every Level 2 assessment requires
- Provide continuous monitoring — CMMC isn’t a one-time certification for Level 1 and Level 2 self-assessments; you need ongoing evidence of compliance
- Train your team — employees who handle CUI need security awareness training that documents their participation
At SDTEK, we’ve worked with Fort Wayne-area manufacturers navigating defense supply chain requirements. We understand what auditors look for, and we know the difference between box-checking and actual risk reduction.
Questions to Ask Any IT Provider About CMMC
Before hiring a provider to help with CMMC preparation, ask:
- Have you completed gap assessments against NIST 800-171 before? Ask for specifics — not just “yes.”
- Can you help us develop our SSP? This is a documentation skill, not just a technical one.
- Do you have EDR and SIEM capabilities you can deploy for us? These are required technologies for Level 2.
- How do you handle log management and audit evidence collection?
- What’s your incident response process, and how does it support our IR plan?
- Have you worked with C3PAOs or supported clients through Level 2 assessments?
Bottom Line
CMMC 2.0 isn’t optional if you want to stay in the DoD supply chain — or get into it. But it’s also not the compliance nightmare it’s sometimes portrayed as. For most small manufacturers, Level 2 compliance is achievable with the right IT foundation, proper documentation, and a realistic remediation timeline.
The manufacturers who struggle are the ones who wait until a contract deadline forces the conversation. The ones who do well start with an honest gap assessment, build a clear action plan, and bring in the right support.
If you’re a Fort Wayne-area manufacturer navigating CMMC requirements, SDTEK can help you assess where you stand, build the documentation you need, and implement the technical controls that make compliance sustainable.
Schedule a CMMC readiness assessment
Related reading: IT services for manufacturing, Cybersecurity Services in Fort Wayne, MFA for small business, Why manufacturing companies are ransomware targets, and the Ampy AI receivables case study.
