Elevaire Systems
What CMMC Compliance Actually Requires From Growth-Stage Government Contractors
← Back to Insights
SecurityCMMCcompliancesecuritygovernment contractorsDFARS

What CMMC Compliance Actually Requires From Growth-Stage Government Contractors

Elevaire Systems·

A subcontract renewal notice arrives with a new clause: the prime now expects evidence of CMMC alignment before the next option period. Or an RFP that used to skip past the cybersecurity section suddenly references 32 CFR Part 170 directly. For a 25 to 200 employee company that has treated IT as background infrastructure for years, that's usually the first real signal that a framework built around defense primes has arrived at their door. What makes this harder to navigate right now than it would have been a year ago is that the requirement itself is mid-change. Part of it was suspended in July 2026. The part that predates the suspension is still fully enforced, and getting the two confused is the most expensive mistake a growth-stage contractor can make this year.

What CMMC Actually Covers, and Who It Applies To

The Cybersecurity Maturity Model Certification program verifies that companies doing business with the Department of War, formerly the Department of Defense, actually protect the government information that passes through their systems. It applies to prime contractors and subcontractors alike, at any tier, regardless of size.

The program has three levels, and which one applies depends entirely on what kind of information you handle, not on your revenue or headcount:

Level 1 (Foundational) applies to companies that handle Federal Contract Information, meaning information the government provides or generates under a contract that isn't intended for public release, but also isn't classified or otherwise sensitive. Level 1 requires 15 basic safeguarding practices drawn from FAR 52.204-21, verified through an annual self-assessment. No third party is involved.

Level 2 (Advanced) applies to companies that handle Controlled Unclassified Information, a broader and more sensitive category that includes things like technical drawings, export-controlled data, and certain program details. Level 2 requires 110 security practices aligned with NIST SP 800-171 Revision 2. Depending on the contract, this is verified through a self-assessment or a third-party assessment performed by a Certified Third-Party Assessment Organization, on a three-year cycle with an annual affirmation in between.

Level 3 (Expert) applies to a small number of contractors supporting the most sensitive programs, layering a subset of 24 additional controls from NIST SP 800-172 on top of Level 2, assessed directly by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center. Very few companies in the 25-200 employee range will ever need Level 3.

Most growth-stage contractors and subcontractors land at Level 1 or Level 2. The honest first question isn't "how do we get certified," it's "which information do we actually touch," because that answer determines almost everything else about cost, timeline, and what you actually need to build.

The Rule Changed Twice in the Last Year, and Both Changes Matter

CMMC has existed in some form since 2020, but two regulatory actions made it real and enforceable, and a third just changed how much of it applies right now.

The program rule, 32 CFR Part 170, was finalized in the Federal Register on October 15, 2024, and took effect December 16, 2024. That rule defined the CMMC model itself: the three levels, the assessment types, the scoring methodology. A separate rule was needed to actually put CMMC into contracts, and that came on September 10, 2025, when the Department published a final rule amending the Defense Federal Acquisition Regulation Supplement. That DFARS rule took effect November 10, 2025, and started a phased rollout: Phase 1 began that day, adding Level 1 and Level 2 self-assessment requirements into applicable new solicitations.

Phase 2 was scheduled to begin exactly one year later, on November 10, 2026, adding the requirement for a full third-party C3PAO assessment to applicable Level 2 contracts instead of a self-assessment. That's the phase that got paused. On July 13, 2026, the Department of War suspended the Phase 2 rollout, following sustained pressure from the Small Business Administration over cost and assessor capacity. The Department's own regulatory impact analysis had estimated a Level 2 third-party certification assessment at roughly $101,752 for a small entity, and the SBA's broader analysis put total compliance cost, including remediation, at closer to $593,800. Against a defense industrial base the Department itself estimates at around 221,000 companies, roughly three-quarters of them small businesses, and a C3PAO assessor pool industry groups put at only about 100 accredited firms nationwide, the math didn't hold up. A CMMC Reform Task Force is now reviewing the program, with contractor input due by August 14, 2026, and a report expected in mid-September 2026.

What that suspension did not do is turn CMMC off. Phase 1 self-assessment requirements remain in force. The underlying cybersecurity obligations that predate CMMC entirely are untouched. Treating the Phase 2 pause as a reason to stop preparing is the single most common misread of this news, and it's the one most likely to leave a growth-stage contractor exposed later.

What Still Applies Today, Regardless of the Pause

Three things did not change on July 13, 2026, and all three carry real consequences on their own.

DFARS 252.204-7012 has required contractors handling CUI to implement NIST SP 800-171 and report cyber incidents within 72 hours since long before CMMC existed. That clause is not part of what got paused. If it's in your contract, it's still binding.

Your Supplier Performance Risk System score is the self-assessment mechanism that already applies under Phase 1, and it's a public record your primes and the Department can see. A perfect score is 110 out of 110, matching the total NIST SP 800-171 requirements; a score of at least 88 qualifies for conditional status, but only if every remaining gap is eligible for a Plan of Action and Milestones and gets closed within 180 days of the assessment. A small number of controls, including multi-factor authentication and encryption of CUI at rest and in transit, can never be deferred through a POA&M. An inflated or stale SPRS score isn't just a compliance gap. The Department of Justice's Civil Cyber-Fraud Initiative has actively pursued False Claims Act cases against contractors who misrepresented their cybersecurity compliance, which means a wrong number in that system carries legal exposure that has nothing to do with whether Phase 2 ever restarts.

Flow-down requirements from your prime contractor operate independently of what DoD requires by regulation. A prime can, and often does, require subcontractors to demonstrate CMMC-level practices as a condition of the subcontract itself, regardless of what phase the federal rule is in. If your prime already wrote a Level 2 requirement into your teaming agreement, the Phase 2 suspension doesn't remove it. Only your prime can.

What Certification Actually Costs

Cost estimates for CMMC vary widely depending on your starting posture, but two numbers are worth anchoring on because they come directly from the Department's own rulemaking rather than a vendor's marketing page.

The Department's regulatory impact analysis put the cost of a Level 2 self-assessment, the kind currently required under Phase 1, at roughly $34,000 for a small entity on a three-year cycle. That figure covers the labor of documenting your environment against all 110 NIST SP 800-171 practices and submitting an accurate score, not a rubber stamp.

The cost of a full Level 2 third-party certification assessment, the kind paused under Phase 2, was estimated by the same analysis at roughly $101,752 for a small entity, of which the C3PAO's own assessment fee is only about $31,000. The remainder is internal readiness work: closing control gaps, building a System Security Plan, and preparing evidence, the same work required regardless of whether a C3PAO ever reviews it. As with most compliance frameworks, the assessment fee is rarely the largest line item. Readiness work almost always is.

For a company with no existing security documentation, expect the bulk of first-year cost to go toward the System Security Plan, access control processes, incident response planning, and closing the technical gaps, typically multi-factor authentication, endpoint logging, and encryption, that show up in nearly every initial gap assessment. Costs drop substantially in year two once that foundation exists and the work shifts from building the program to maintaining it.

A Realistic Path Forward for a 25-200 Employee Contractor

  1. Determine your actual exposure. Pull every active and pending DoD contract and subcontract and identify, contract by contract, whether you handle FCI only or CUI. This single step determines whether you're a Level 1 or Level 2 company, and most growth-stage contractors have never actually mapped it out.

  2. Get an honest current SPRS score. If your last self-assessment predates a system change, a new vendor, or new personnel, treat it as stale. A wrong score sitting in a government system is worse than no score at all.

  3. Close the controls that can never wait. Multi-factor authentication and encryption of CUI at rest and in transit can't be deferred through a POA&M under any circumstance. If those aren't fully implemented, they're the first priority regardless of what else is on the list.

  4. Build the System Security Plan and POA&M now, independent of Phase 2. The documentation Level 2 certification requires is the same documentation a defensible Phase 1 self-assessment requires. Waiting for the Reform Task Force to finish before starting this work just compresses the timeline later.

  5. Watch the Reform Task Force output, but don't plan around it. The task force report is expected in mid-September 2026, and it will likely reshape what Phase 2 eventually looks like. Track it, but build your compliance posture against the rules already in force, not the rules you're hoping replace them.

  6. Decide who owns this before a prime asks. CMMC readiness touches contracts, IT operations, HR, and executive reporting at once. Someone needs to own the whole picture, not just the technical controls.

Who Should Own This

This is where the model matters as much as the checklist. Your managed service provider keeps day-to-day infrastructure running: patching systems, managing the help desk, maintaining uptime. That is not the same work as owning a CMMC readiness assessment, building a System Security Plan, tracking a POA&M to closure, and briefing leadership on where the program stands. Most MSP contracts aren't scoped to include that ownership, and asking an MSP to absorb it without a defined engagement tends to produce exactly the kind of stale self-assessment that creates legal exposure under the Civil Cyber-Fraud Initiative.

A full-time compliance hire is one option, but it's a six-figure commitment for a workload that, once mature, doesn't require full-time attention year-round. Fractional technology leadership focused on Compliance & Security is built for this gap: it works alongside your existing MSP, which keeps running infrastructure day to day, while the fractional leader owns the exposure mapping, SPRS accuracy, POA&M discipline, and accountability for closing findings on a schedule your primes can rely on.

Frequently Asked Questions

How much does CMMC compliance actually cost for a company our size?

Plan for roughly $34,000 for a Level 2 self-assessment cycle under current Phase 1 requirements, based on the Department's own regulatory impact analysis. If your contracts eventually require third-party certification, total first-year cost including readiness work commonly runs well into six figures, though the assessment fee itself is typically the smallest piece of that total.

Does our MSP already handle this for us?

Usually not fully. Your MSP keeps infrastructure running and handles day-to-day IT support, but most MSP contracts don't include ownership of a CMMC readiness assessment, System Security Plan development, or POA&M tracking. Fractional technology leadership is designed to work alongside your MSP to close that specific gap, not to replace what your MSP already does well.

Is CMMC still required now that Phase 2 was suspended?

Yes, in part. Phase 1 self-assessment requirements for Level 1 and Level 2, along with the underlying obligations in DFARS 252.204-7012 and NIST SP 800-171, remain fully in force. Only the Phase 2 third-party certification requirement, originally set to begin November 10, 2026, was suspended while a Reform Task Force reviews the program.

What happens if we ignore this until the Reform Task Force finishes its report?

You keep the same exposure you already have today: an SPRS score that may be inaccurate, contract clauses that already require NIST SP 800-171 alignment, and False Claims Act risk under the Civil Cyber-Fraud Initiative if your reported compliance status doesn't match reality. None of that is paused.

Do we need Level 1 or Level 2?

It depends entirely on what type of government information you handle, not your size. Companies that only handle Federal Contract Information need Level 1. Companies that handle Controlled Unclassified Information need Level 2. Many growth-stage contractors haven't mapped this out contract by contract, and that mapping is the right starting point.

How do we get started if we don't know where we stand today?

Start with an exposure and gap assessment scoped against NIST SP 800-171, not a generic checklist. That assessment tells you which of your current controls hold up, what your real SPRS score should be, and what a defensible System Security Plan actually requires, which is the input any accurate budget or timeline depends on.

Ready to Put This Into Practice?

Schedule a free consultation and let's talk through what this means for your organization specifically.

Schedule a Free Consultation