CMMC for Small Contractors, Explained Plainly

In This Article

  1. The one question that sets your cost
  2. What the three levels actually require
  3. Which phase you are in right now
  4. The scoring math, and why “we’ll POA&M it” mostly fails
  5. Where the effort concentrates: scope, then evidence
  6. What goes wrong

Key Takeaways

The one question that sets your cost

It usually arrives one of two ways. Either a solicitation you planned to bid comes back with a CMMC level written into it, or a prime you already work for sends a flowdown notice telling you what your subcontract now requires. Either way, someone whose actual job is contracts or engineering has to answer a question the company has never had to answer precisely.

The question is not “are we secure.” It is narrower and more mechanical: does this work put Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on our systems? That single classification sets your level, your assessment type, your assessor, your cadence, and most of your cost. Firms that get it wrong either buy an enclave they did not need, or self-assess into a contract that required a third party.

The flowdown rules in 32 CFR 170.23 are unusually direct, and worth reading literally if you subcontract. A subcontractor handling only FCI needs Level 1 (Self). One handling CUI needs Level 2 (Self) at minimum. If the prime contract requires Level 2 (C3PAO), so does the subcontract. And if the prime contract requires Level 3 (DIBCAC), the subcontractor still needs only Level 2 (C3PAO) — a Level 3 prime does not push Level 3 down to you. That asymmetry is worth knowing before you panic about a Level 3 program.

What the three levels actually require

The rule defines the levels by counting requirements, which makes them easier to reason about than the marketing suggests. Per § 170.4, CMMC security requirements are “the 15 Level 1 requirements listed in the 48 CFR 52.204-21(b)(1), the 110 Level 2 requirements from NIST SP 800-171 R2, and the 24 Level 3 requirements selected from NIST SP 800-172 Feb2021.”

For most small firms the honest range is Level 1 or Level 2. Level 3 is not a tier you drift into.

Which phase you are in right now

Two separate rules matter, and confusing them is the most common timeline error. The CMMC Program rule at 32 CFR Part 170 was published October 15, 2024 and took effect December 16, 2024. That rule built the program; by itself it put nothing into a contract.

The contract clause did. The DFARS acquisition rule (DFARS Case 2019-D041) was published September 10, 2025 and became effective November 10, 2025. Section 170.3(e) ties the phase-in directly to it: Phase 1 “begins on the effective date of the complementary 48 CFR part 204 CMMC Acquisition final rule,” and each following phase begins one calendar year after the last.

The planning consequence is specific. A self-assessment is enough to keep bidding at the front of the schedule, and stops being enough on a published timetable. A C3PAO assessment depends on a third party's calendar — it is a scheduled event with lead time, not something you start the week a solicitation drops. If a Level 2 (C3PAO) opportunity sits in your capture plan, the assessment slot is the long-lead item, not the controls.

The scoring math, and why “we'll POA&M it” mostly fails

Level 2 scoring is arithmetic, and the arithmetic is where optimistic plans die. Per § 170.24, the maximum score equals the number of Level 2 requirements — 110. Each requirement assessed NOT MET subtracts 1, 3, or 5 points. The rule notes plainly that this “may result in a negative score.”

To reach a Conditional Level 2 status with open items, § 170.21(a)(2) requires the assessment score divided by the total number of requirements to be at least 0.8 — a score of 88 or better out of 110. That sounds generous. It is not, because of the second condition: no requirement worth more than 1 point may be on the POA&M. The one exception is SC.L2-3.13.11, CUI encryption, which may sit on a POA&M at 3 points if encryption is employed but not FIPS-validated.

Count the enumerated lists in § 170.24 and the shape becomes clear. Forty-two requirements are worth 5 points (23 basic and 19 derived). Fourteen are worth 3 points (7 and 7). Two more — multi-factor authentication (IA.L2-3.5.3) and CUI encryption (SC.L2-3.13.11) — are scored variably at 3 or 5 depending on how far implementation got. Everything else is worth 1. So of the 22 points of deficit the 0.8 threshold allows you, essentially all of it has to come from one-point requirements. The high-value controls are not deferrable. They are the gate.

Six requirements are barred from a POA&M outright regardless of point value: AC.L2-3.1.20 (external connections), AC.L2-3.1.22 (control public information), CA.L2-3.12.4 (system security plan), and PE.L2-3.10.3, PE.L2-3.10.4 and PE.L2-3.10.5 (escort visitors, physical access logs, manage physical access). Five of those six map to Level 1 basic safeguarding items — the things you were supposed to have already. The sixth is the SSP itself.

Then the clock. Under § 170.21(b), a POA&M closeout assessment must confirm the closure “within 180-days of the Conditional CMMC Status Date,” and if it is not successfully closed out in that window, the Conditional status “will expire.” For a Level 2 (C3PAO) firm that means booking a second assessor engagement inside six months.

Where the effort concentrates: scope, then evidence

Scope comes first, and it is the highest-leverage decision you make. Table 3 to § 170.19(c)(1) sorts every asset into five categories, and the burden differs sharply between them. CUI Assets are assessed against all Level 2 requirements. Security Protection Assets are assessed against the requirements relevant to the capabilities they provide. Contractor Risk Managed Assets get an SSP review and, only if the documentation raises questions, a limited check that the rule says “shall not materially increase the assessment duration nor the assessment cost.” Specialized Assets (IoT, operational technology, government-furnished equipment, test equipment) get an SSP review and are not assessed against other requirements. Out-of-Scope Assets carry no assessment requirement, but you must justify why they cannot touch CUI.

This is why narrowing where CUI lives moves cost more than any other decision. It is also why it is not free: an enclave — in practice a GCC High tenant, a VPC-isolated GovCloud environment, or a dedicated network that only CUI work touches — shrinks the population of assets assessed against 110 requirements, and it adds friction for the people who work inside it. Friction is what puts a drawing into somebody's personal email. An enclave people route around has enlarged your real scope while shrinking the documented one — the worst of both.

Third parties are the second scoping trap. Table 4 to § 170.19(c)(2)(i) is short and consequential. If a cloud service provider processes, stores, or transmits CUI, that CSP “shall meet the FedRAMP requirements in 48 CFR 252.204-7012.” If a non-cloud external service provider handles CUI, its services “are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment.” A provider handling only security protection data is assessed as a Security Protection Asset. In every case the relationship must be documented in your SSP and described in the provider's customer responsibility matrix. Your managed service provider's certifications are not a substitute for that paperwork, and “our MSP handles security” is not an answer an assessor can score.

Evidence is the second concentration of effort, and more demanding than most firms plan for. Section 170.24(b)(1) states all evidence “must be in final form and not draft,” and that “working papers, drafts, and unofficial or unapproved policies” are unacceptable. Artifacts are retained six years from the CMMC Status Date, and for certification assessments hashed with a NIST-approved algorithm so they can be shown unaltered.

The SSP is not a deliverable at the end of that process — it is a precondition, and the one that holds up is the one that describes the environment actually running and is organized the way a C3PAO reads it. The rule is blunt: absence of an up-to-date SSP at assessment time produces a finding that “an assessment could not be completed due to incomplete information and noncompliance with 48 CFR 252.204-7012.” Not a deduction. A stopped assessment.

Finally, someone signs. Under § 170.22 an Affirming Official — a senior representative of the company — submits an affirmation in SPRS on reaching a Conditional status, on reaching Final, after any POA&M closeout, and annually thereafter. That is a named person attesting to systems they may not personally operate. Make sure that person has read the SSP.

What goes wrong

Five failure patterns account for most of the pain, and all five are visible in the rules before they are visible in an assessment.

None of this is exotic engineering. It is ordinary engineering held to an evidentiary standard most commercial firms have never had applied to them, on a schedule set by someone else. The firms that struggle are rarely the ones with weak security. They are the ones who started with the controls instead of the scope, and found out late that they had implemented 110 requirements across an environment far larger than the contract ever required.

If you want help with this

A CMMC level just showed up in a solicitation or a flowdown, and nobody at your firm owns it.

That is the usual shape: CUI already moving through a general-purpose environment, no written SSP, a self-assessment score nobody trusts, and a date on the calendar. Precision Federal — a federal software and AI firm, and the sister company of this site — builds the implementation side of this work.

Per its CMMC capability page, the firm does:

What an engagement looks like. A scoped assessment first: what CUI you actually hold, where it flows, which assets fall into which category under § 170.19, and what your honest score is today. You get back a written scope recommendation and a gap list ranked by point value, and that document is yours whether or not the work continues. If it goes forward, the build follows the capability page — enclave, controls, SSP and POA&M, incident response, then a mock assessment before the real one.

Where this is not the right fit — worth saying plainly:

  • Precision Federal is not a C3PAO and does not perform certification assessments. Under 32 CFR 170.9 that is a separate accredited role bound by the Accreditation Body's conflict-of-interest policy. The firm prepares you for an assessment; someone else conducts it.
  • If your work only touches FCI, the answer is Level 1 — 15 requirements and an annual self-assessment. Expect to hear that at the assessment stage rather than after an enclave has been sold to you.
  • The firm will not write an SSP describing controls that are not implemented. The rule itself says a POA&M “is not a substitute for a completed requirement,” and a document that overstates the environment fails at the worst possible moment.
  • This is not a managed security service. The firm designs, implements and documents the environment; it does not staff a 24/7 monitoring desk on your behalf.

Sources: 32 CFR Part 170 — Cybersecurity Maturity Model Certification (CMMC) Program (GovInfo); Federal Register — CMMC Program final rule, published October 15, 2024, effective December 16, 2024; Federal Register — DFARS: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041), published September 10, 2025, effective November 10, 2025; DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting; NIST SP 800-171 Rev. 2; NIST SP 800-172. Point-value counts in the scoring section were tallied from the enumerated lists in 32 CFR 170.24(c)(2). Analysis and framing by Precision AI Academy. Always confirm the current text of a rule against the primary source before acting on it.

Common questions

How many requirements does each CMMC level have? 32 CFR 170.4 defines them as the 15 Level 1 requirements listed in 48 CFR 52.204-21(b)(1), the 110 Level 2 requirements from NIST SP 800-171 Revision 2, and the 24 Level 3 requirements selected from NIST SP 800-172 (February 2021). Level 1 is a self-assessment, Level 2 is either a self-assessment or a certification assessment by an accredited C3PAO depending on the contract, and Level 3 is assessed by DCMA DIBCAC.

Can a small contractor just put the hard requirements on a POA&M? Mostly no. Under 32 CFR 170.21(a)(2), a Conditional Level 2 status requires an assessment score of at least 0.8 of the total requirements, and no requirement worth more than 1 point may sit on the POA&M — with one exception, SC.L2-3.13.11 CUI encryption, which may be included at 3 points if encryption is employed but is not FIPS-validated. Six further requirements are barred outright: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4 and PE.L2-3.10.5.

How long do I have to close a CMMC POA&M? 180 days. Under 32 CFR 170.21(b), the closing of a POA&M must be confirmed by a closeout assessment within 180 days of the Conditional CMMC Status Date, and if it is not successfully closed out in that window the Conditional CMMC Status for the information system expires.

What CMMC level does a subcontractor need? Per 32 CFR 170.23: Level 1 (Self) if the subcontractor will only handle FCI; Level 2 (Self) at minimum if it will handle CUI; Level 2 (C3PAO) at minimum if the prime contract requires Level 2 (C3PAO); and Level 2 (C3PAO) at minimum if the prime contract requires Level 3 (DIBCAC).

About Precision AI Academy

Precision AI Academy publishes practical AI news, plain-language analysis, and free courses for builders and working professionals. It is a sister site of Precision Federal, a federal software and AI firm. We verify the numbers, cite the primary sources, and skip the hype.