CMMC compliance for defense contractors
CMMC certification is now a condition of doing business with the DoD. We turn the requirements into a practical action plan, whether you're a first-time subcontractor handling FCI or a prime bracing for a Level 2 assessment.
Who this applies to
Any contractor or subcontractor that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) in a DoD contract. Prime contractors flow CMMC requirements down to their subs, so "we're too small to matter" isn't a defense, it's a gap that shows up when a prime audits its supply chain.
Where CMMC stands right now
Level 1 — FCI
17 basic safeguarding practices. Self-assessed annually, with a senior official attestation posted to SPRS. The floor for any contractor touching FCI.
Level 2 — CUI
All 110 practices from NIST SP 800-171. Some contracts allow self-assessment; most that involve CUI will require a third-party C3PAO assessment.
The timeline that matters
Phase 1 (November 10, 2025 to November 9, 2026) accepts self-assessments for most contracts. Phase 2 begins November 10, 2026, when most Level 2 contracts involving CUI shift to mandatory third-party C3PAO certification. By October 1, 2026, all new DoD contracts that require CMMC will name a specific level in the solicitation. If you handle CUI and haven't started, the third-party assessment queue is the thing to plan around, not the paperwork.
How we help
Snapshot Assessment
Fixed-price gap analysis against the 17 or 110 practices, with findings ranked by risk and a scoped remediation quote. $9,500, 2 to 3 weeks.
Remediation & implementation
Policy and procedure templates, technical control implementation (access management, logging, network segmentation), and SPRS posting guidance.
C3PAO preparation
Mock assessments, evidence organization, and system security plan (SSP) documentation so the real assessment isn't the first time you've seen the evidence together.
Frequently asked questions
Do I really need CMMC if I'm just a small subcontractor?
Yes, if you handle FCI or CUI. Prime contractors flow CMMC requirements down to every sub that touches their data, and they're increasingly checking before, not after, awarding work.
Can't I just do the self-assessment myself?
For Level 1, yes. But most contractors miss requirements they didn't know applied, and a failed or incomplete assessment can delay a contract award. A short gap analysis before you self-attest is cheap insurance.
What's the real difference between Level 1 and Level 2?
Level 1 covers 17 basic practices for FCI and is always self-assessed. Level 2 covers all 110 NIST SP 800-171 practices for CUI, and most of those contracts now require a third-party C3PAO assessment rather than self-attestation.
How long does certification actually take?
Level 1 self-assessment prep typically runs 2 to 4 weeks once gaps are known. Level 2 remediation is usually 30 to 90 days depending on your starting posture, and C3PAO scheduling adds its own lead time, which is one more reason to start before Phase 2 arrives.
What happens if I miss the deadline?
You can't win new DoD contracts that require CMMC at your level. Existing contracts aren't affected immediately, but option renewals typically will be.
Let's talk about your CMMC timeline
A short conversation covers your current contracts, whether Level 1 or Level 2 applies, and what it actually takes to get there.