
If your company sells to the Department of Defense, or supplies a prime contractor that does, CMMC 2.0 is no longer a future problem. The rule is final, and the certification requirement is being written into new contracts on a rolling schedule. The short version: if you handle basic Federal Contract Information you need Level 1, and if you touch Controlled Unclassified Information (CUI) you need Level 2. The time to start is before the requirement shows up in a solicitation, because getting ready for a Level 2 assessment can take most of a year.
What is CMMC 2.0, in plain terms?
CMMC 2.0 is the Defense Department's method for verifying that contractors actually follow the cybersecurity rules already in their contracts. It has three levels. Level 1 covers basic safeguarding of Federal Contract Information. Level 2 maps to the 110 controls in NIST SP 800-171. Level 3 applies to the most sensitive programs.
For years, defense contractors self-attested to those controls and nobody checked. Breaches in the supply chain made it clear that a signature on a form is not the same as a working security program. CMMC closes that gap by requiring proof, and in many cases an outside assessor, before a contract can be awarded.
Which level does your business actually need?
It comes down to the data you handle. Level 1 is for Federal Contract Information, the routine, non-public data involved in delivering a product or service. It covers 15 basic requirements measured against 54 assessment objectives, and it is an annual self-assessment you can run yourself with an internal signoff.
Level 2 is for CUI, the more sensitive technical and program data. It requires all 110 controls from NIST SP 800-171 Rev 2, checked against 320 assessment objectives. Most CUI contracts will require a third-party assessment by a certified C3PAO rather than a self-assessment. If you are unsure which bucket your contracts fall into, that scoping question is where a compliance-minded IT partner earns its fee, because getting it wrong in either direction is expensive.
What does CMMC compliance cost?
The Defense Department published its own estimates, and they scale sharply with level. A Level 1 self-assessment runs roughly $4,000 to $6,000, a Level 2 self-assessment $37,000 to $49,000, and a Level 2 C3PAO assessment $105,000 to $118,000. Those are assessment costs alone. The real number for most small firms is higher once you add the work of closing gaps: multi-factor authentication, encryption, logging, access controls, written policies, and the staff time to maintain them.
This lands hardest on the smallest shops. Small businesses make up roughly 73% of the Defense Industrial Base, so a rule aimed at protecting national security data ends up being a small-business budgeting exercise. The upside is that the same controls that satisfy CMMC also happen to be the controls that stop the ransomware and email fraud already hitting companies your size.
When do you actually have to comply?
CMMC is rolling out in phases, not all at once. The self-assessment phase is already underway, and Level 1 and some Level 2 self-assessment requirements are appearing in contracts now. The bigger shift is Phase 2, which begins November 10, 2026, when C3PAO assessments for Level 2 start appearing in most CUI contracts.
Do not let a 2026 date feel comfortable. Readiness for Level 2 typically takes six to nine months, and C3PAO assessor capacity is limited. If you wait until a contract names a deadline, you may not have time to build the program and get on an assessor's calendar before it lapses.
How a small contractor gets ready without panic
Start by scoping where CUI and Federal Contract Information actually live in your environment: which systems, which mailboxes, which shared drives. Then run a gap assessment against NIST SP 800-171 to see how far your current setup is from the 110 controls. From there you build a System Security Plan documenting how you meet each control and a Plan of Action and Milestones for the gaps you have not closed yet.
Most of the remediation is standard security hygiene done thoroughly: enforced MFA, encryption for data at rest and in transit, centralized logging, tightened access, and a real incident response process. Our rundown of the controls that actually stop attacks covers much of the same ground, and if you have looked at frameworks before, our explainer on NIST, ISO 27001, and CIS shows how they connect. Many small contractors handle this with a fractional security leader or a managed security partner rather than a full-time hire, which keeps the cost proportional to the size of the contract.
By The NetSys Group Team. The NetSys Group has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Frequently asked questions
Does CMMC apply to subcontractors?
Yes. If you are a subcontractor handling Federal Contract Information or CUI, the certification requirement flows down to you from the prime contractor. A prime cannot legally pass CUI to a subcontractor that lacks the appropriate CMMC level, which is why primes are already asking their suppliers about certification status.
Is a self-assessment enough for Level 2?
Sometimes, but not usually. A limited set of Level 2 contracts allow an annual self-assessment, yet the majority of CUI contracts will require a C3PAO third-party assessment. Assume you will need an outside assessor for Level 2 unless a specific contract states otherwise.
How long is a CMMC certification valid?
A Level 2 C3PAO certification is valid for three years, paired with an annual affirmation from a company official that you are still meeting the requirements. Self-assessments at Level 1 are performed annually. Certification is not a one-time project; it is a program you maintain.
What happens if we miss the deadline?
You become ineligible for contracts that carry the CMMC requirement. There is no partial credit at award time. For a company that relies on defense work, losing eligibility is an existential problem, which is why the planning has to start well ahead of any single contract's deadline.
We are not a defense contractor. Does any of this matter?
The certification does not, but the controls do. NIST SP 800-171 is a solid baseline for any small business, and cyber insurers and larger customers increasingly ask for the same safeguards. Treating CMMC-style controls as good practice puts you ahead of those requests.
Not sure whether your contracts pull you into Level 1 or Level 2, or how big the gap is? Reach out for a complimentary risk assessment and we will help you scope it before a deadline forces the question.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



