Cybersecurity & Resilience
CMMC for Small Businesses; What Applies and Where to Start
CMMC can affect small businesses supporting defense contracts. Learn the current requirements, how FCI and CUI affect the required level, and where to start preparing.
Current as of September 30, 2026. CMMC implementation requirements continue to evolve; businesses should verify the requirements in the applicable solicitation, contract, subcontract, and current federal guidance.
For many small businesses entering or expanding within the defense supply chain, cybersecurity requirements can feel complicated quickly.
CMMC, DFARS, FCI, CUI, NIST SP 800-171, SPRS, self-assessments, third-party assessments, and contract clauses can all appear in the same conversation.
The first step is not buying a tool or assuming you need the highest certification level.
It is understanding:
- what information your organization handles;
- what your contract or solicitation requires;
- which systems are in scope;
- what CMMC level applies;
- and what evidence you need to support your compliance position.
As of September 30, 2026, the current CMMC rollout is in an unusual transition period. The Department announced on July 13, 2026 that Phase II requirements were suspended, while Phase I self-assessment requirements remain in effect. The Department also said it is conducting a broader review of the program.
That makes it especially important for small businesses to work from the requirements in their actual solicitation, contract, subcontract, and contracting-officer guidance rather than relying on outdated CMMC summaries.
Start With the Information You Handle
CMMC requirements are tied heavily to the type of federal information involved.
Two terms matter immediately:
Federal Contract Information
Federal Contract Information, or FCI, is nonpublic information provided by or generated for the Government under a contract to develop or deliver a product or service, excluding publicly available information and certain transactional information.
DoD small-business guidance associates CMMC Level 1 with the basic safeguarding of FCI.
Controlled Unclassified Information
Controlled Unclassified Information, or CUI, is government information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy.
NIST SP 800-171 is specifically designed to protect CUI when it resides in nonfederal systems and organizations.
Before asking, "What CMMC certification do we need?", a better question is:
"Do our systems process, store, or transmit FCI, CUI, or both?"
That answer drives much of what comes next.
CMMC Has Three Levels
The current CMMC program uses three assessment levels.
Level 1: Basic Safeguarding of FCI
DoD small-business guidance describes Level 1 as covering basic safeguarding of FCI.
It currently requires:
- an annual self-assessment;
- an annual affirmation of compliance;
- and implementation of the 15 safeguarding requirements in FAR 52.204-21.
For a small business that handles FCI but does not handle CUI, Level 1 may be the relevant starting point, depending on the solicitation or contract.
Level 2: Protection of CUI
Level 2 is associated with protecting CUI.
DoD guidance states that Level 2 can involve either:
- a self-assessment; or
- an assessment by a Certified Third-Party Assessment Organization, or C3PAO,
depending on the requirement specified in the solicitation.
DoD's small-business guidance currently ties Level 2 to the 110 requirements in NIST SP 800-171 Revision 2 for purposes of the CMMC program.
That distinction matters because not every Level 2 requirement automatically means a third-party assessment.
The solicitation and contract determine what applies.
Level 3: Higher-Level Protection
Level 3 is intended for higher-risk environments requiring additional protection against advanced threats.
DoD guidance states that organizations seeking Level 3 must first achieve Final Level 2 status and then undergo an assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center.
For many small businesses, the immediate focus will be determining whether Level 1 or Level 2 applies.
Current Rollout Status Matters
CMMC implementation is being phased in.
The current DFARS rule states that until November 9, 2028, CMMC requirements are included in solicitations and contracts when the program office or requiring activity determines that a specific CMMC level is required.
On or after November 10, 2028, the rule provides for broader inclusion when contractor information systems will process, store, or transmit FCI or CUI, subject to applicable exceptions.
However, on July 13, 2026, the Department announced that the planned Phase II requirements scheduled for November 10, 2026 were suspended, while Phase I self-assessment requirements remained in place.
Those two facts are not contradictory.
The underlying DFARS framework remains in place, while the Department has paused the next planned implementation phase and is reviewing the program.
For small businesses, the practical lesson is:
Do not assume a future phase date tells you what applies to your current opportunity. Read the solicitation and contract.
Your Contract Determines More Than a Website Summary
CMMC should not be approached as a generic certification exercise.
A solicitation may specify:
- the required CMMC level;
- whether a Level 2 assessment is self-assessed or third-party assessed;
- contract clauses;
- flow-down obligations;
- handling requirements for FCI or CUI;
- and other cybersecurity requirements.
DFARS 252.204-7021 establishes contractor obligations related to maintaining the required CMMC status when the clause applies.
Before spending money on readiness work, confirm:
"What does the actual procurement require?"
Small Businesses Should Understand Their Scope Before Assessing Controls
One of the easiest ways to make CMMC unnecessarily expensive is to assume the entire company must be treated as a CUI environment.
NIST SP 800-171 applies to components of nonfederal systems that process, store, or transmit CUI, or that provide security protection for those components.
That makes system scoping important.
A business should understand:
- where CUI enters the environment;
- where it is stored;
- who can access it;
- which endpoints handle it;
- which applications process it;
- which networks carry it;
- which cloud services are involved;
- which vendors support those systems;
- and which systems provide security protection to the environment.
A poorly understood scope can lead to gaps.
It can also cause an organization to apply costly requirements more broadly than necessary.
NIST SP 800-171 and CMMC Are Related, but They Are Not the Same Thing
This distinction causes considerable confusion.
NIST SP 800-171 defines security requirements for protecting CUI in nonfederal systems.
The current NIST publication is Revision 3, published in May 2024.
CMMC is the Defense Department's assessment and verification program used to evaluate implementation of applicable cybersecurity requirements for defense contractors.
Current DoD CMMC small-business guidance still describes Level 2 in relation to the 110 requirements in NIST SP 800-171 Revision 2.
This is an important transitional point.
Do not silently substitute Revision 3 into a CMMC assessment simply because it is the newest NIST publication.
Use the version required by the applicable CMMC rule, solicitation, contract, and assessment framework.
Article 9 in this series will examine the relationship among CUI, NIST SP 800-171, and CMMC in more detail.
Assessment Readiness Requires Evidence
CMMC is not simply about saying that controls exist.
Assessment readiness requires the organization to understand whether security requirements are actually implemented and whether that implementation can be demonstrated.
NIST SP 800-171A Revision 3 provides assessment procedures for evaluating the security requirements in NIST SP 800-171.
NIST also published a Small Business Primer for SP 800-171A Revision 3 on September 16, 2026, specifically to help small businesses understand foundational assessment concepts and how to prepare for an assessment.
That reflects an important principle:
Implementation and evidence need to match.
Documentation alone is not enough if the underlying safeguard is not operating.
Technology alone is not enough if the organization cannot explain how the requirement is satisfied.
Do Not Start With Documentation Alone
Small businesses sometimes approach CMMC by immediately creating policies.
Policies matter.
But readiness requires more than documentation.
The organization may also need to examine:
- account management;
- multifactor authentication;
- endpoint configuration;
- logging;
- patching;
- vulnerability management;
- system boundaries;
- administrative access;
- incident-response practices;
- security training;
- media handling;
- cloud configurations;
- vendor relationships;
- and evidence retention.
The right approach is to understand the required safeguards and then verify how those safeguards operate in the actual environment.
Your Vendors May Affect Your CMMC Scope
A cloud provider, managed service provider, security provider, file-sharing platform, or other external service may participate in the environment used to process, store, transmit, or protect CUI.
That can affect scoping and compliance decisions.
This is one reason vendor management and CMMC readiness should not be treated as completely separate programs.
Before assuming a vendor is outside scope, understand:
- what service it provides;
- what information it can access;
- whether it stores or transmits CUI;
- whether it provides security protection;
- and how the contractual requirements apply.
Subcontractors Should Pay Attention Too
CMMC is not limited to companies holding prime contracts.
Cybersecurity obligations may flow down through the defense supply chain.
A small business working as a subcontractor should therefore understand:
- what information the prime contractor will provide;
- whether that information is FCI or CUI;
- what cybersecurity clauses flow down;
- what CMMC status the subcontract requires;
- and what evidence the prime expects.
Do not assume that being a small subcontractor eliminates the requirement.
A Practical Starting Sequence
For a small business beginning CMMC readiness, a reasonable sequence is:
1. Review the Opportunity
Identify the solicitation, contract, subcontract, or expected defense opportunity.
2. Determine the Information Type
Identify whether the organization will handle FCI, CUI, or neither.
3. Identify the Required CMMC Level
Use the procurement documents and contracting guidance rather than assumptions.
4. Define the Environment
Determine which systems, users, applications, networks, locations, and providers are relevant.
5. Establish the Current Baseline
Compare existing safeguards with the requirements that apply.
6. Identify Gaps
Separate:
- implemented requirements;
- partially implemented requirements;
- missing requirements;
- and areas requiring additional evidence.
7. Remediate Deliberately
Prioritize gaps based on the assessment requirement and the actual environment.
8. Organize Evidence
Maintain evidence that supports how applicable requirements are implemented.
9. Conduct the Required Assessment
Follow the assessment path required by the solicitation or contract.
10. Maintain Compliance
CMMC is not intended to be a one-time project.
Applicable affirmations, reassessments, configuration changes, personnel changes, and system changes must continue to be managed.
Use the Free Government Resources Before Buying Everything
Small businesses should not assume that the first step in CMMC is purchasing an expensive consulting package or software platform.
The Defense Department's Office of Small Business Programs points organizations to Project Spectrum, which provides cybersecurity training, readiness checks, and related resources for small and medium-sized businesses supporting the defense supply chain.
NIST has also published small-business-specific CUI guidance, including:
- SP 1318, a small-business primer for NIST SP 800-171 Revision 3; and
- SP 1352, the new small-business primer for NIST SP 800-171A Revision 3 assessments.
These resources can help a business understand the problem before deciding what outside assistance is necessary.
CMMC Readiness Should Support the Business Opportunity
The objective is not to accumulate compliance artifacts without context.
It is to determine:
- what opportunity the business is pursuing;
- what cybersecurity requirements come with that opportunity;
- what the organization already has;
- what needs to change;
- what evidence is required;
- how much the gap will cost to close;
- and whether the opportunity justifies that investment.
For a small company, that is both a cybersecurity decision and a business decision.
Not Sure What CMMC Requirements Apply to Your Business?
CMMC readiness can overlap with IT infrastructure, cybersecurity, compliance, cloud services, vendor management, policies, documentation, and business processes.
The BisGentech AI & Technology Assessment can help identify your current technology and security environment, clarify the issues that deserve attention first, and determine a practical next step.
Key Takeaways
- CMMC requirements depend first on the federal information involved. The relevant starting question is whether your systems process, store, or transmit FCI, CUI, or both.
- The current CMMC program uses three levels. Level 1 addresses basic safeguarding of FCI; Level 2 addresses protection of CUI and may involve self-assessment or C3PAO assessment depending on the procurement; Level 3 is the higher-level assessment path.
- Phase I self-assessment requirements remain in effect, while Phase II requirements scheduled for November 10, 2026 were suspended on July 13, 2026 and the broader program is under review. Confirm requirements from the actual solicitation, contract, subcontract, and current federal guidance.
- NIST SP 800-171 Revision 3 is the current NIST publication, but current DoD CMMC Level 2 guidance still references NIST SP 800-171 Revision 2. Do not silently substitute one for the other; follow the version required by the applicable rule, solicitation, contract, and assessment framework.
- Start with scoping and evidence rather than documentation alone. Free government resources, including Project Spectrum and NIST small-business primers, can clarify the problem before any paid assistance is considered.
Sources and References
- DoD Office of Small Business Programs — Cybersecurity Resources for Small Businesses (source)
- DoD Office of Small Business Programs — Official CMMC Program Information (source)
- Acquisition.gov / DFARS — DFARS Subpart 204.75, Cybersecurity Maturity Model Certification (source)
- NIST — NIST SP 800-171 Revision 3 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations) (source)
- NIST — NIST SP 800-171A Revision 3 (Assessing Security Requirements for Controlled Unclassified Information) (source)
- NIST — NIST SP 1318 (Small Business Primer for NIST SP 800-171 Revision 3) (source)
- NIST — NIST SP 1352 (Small Business Primer for NIST SP 800-171A Revision 3) (source)
- Project Spectrum — Cybersecurity Support for Small Business (referenced by the DoD Office of Small Business Programs) (source)
Related Insights
Related Services
About the Author
Benjamin Isidore
Founder & CEO, BisGentech
Benjamin Isidore is the Founder and CEO of BisGentech. He helps growing small and medium-sized businesses clarify technology decisions, improve operations, and strengthen security with practical, business-first guidance built on more than 24 years of technology leadership.
