If you're a defense subcontractor with fewer than 200 employees, CMMC probably feels like someone moved the goalposts on you. You've been handling CUI under DFARS 252.204-7012 for years, maybe with a self-assessment and a good-faith POA&M. Now the DoD wants third-party proof — and it's no longer optional.
Here's the thing: CMMC isn't new security. It's the same 110 NIST SP 800-171 controls you were already supposed to have at Level 2. What's new is accountability. A C3PAO assessor is going to walk your environment and verify each control. No more self-attestation with a handshake.
What CMMC Actually Requires at Each Level
CMMC 2.0 collapsed the original five levels into three. Most defense subcontractors dealing with CUI need Level 2. Here's what that means in practice:
CMMC requirements are being phased into new DoD contracts starting 2025. If you're bidding on contracts that involve CUI, the clock is already running. Contracts awarded without CMMC today will eventually require it at option renewal.
Where Small Contractors Actually Struggle
The 110 controls aren't equally hard. Some are straightforward — you probably already have antivirus and password policies. The ones that trip up small companies are the ones that require ongoing processes, not just tools:
- Audit and Accountability (AU) — You need centralized logging that you actually review. Not just "we have logs somewhere."
- Configuration Management (CM) — Documented baselines for every system, and a change management process. Most small shops don't have this formalized.
- Incident Response (IR) — A tested plan with named roles and regular exercises. Not a template you downloaded and never practiced.
- Risk Assessment (RA) — Periodic risk assessments with documented results. This is where most self-assessments had the biggest gaps.
- Security Assessment (CA) — You need to assess your own controls regularly and remediate what's not working. The POA&M can't just sit there.
Under the old self-assessment model, companies could list gaps in a Plan of Action & Milestones and still claim compliance. Under CMMC Level 2 C3PAO assessments, your POA&M items are scrutinized. Certain controls cannot have open POA&Ms at all — you must have them fully implemented to pass.
A Practical Path to Level 2
Scope Your CUI Boundary
Before touching a single control, define exactly where CUI lives in your environment. Every system, network segment, and person that touches CUI is in scope. The smaller your boundary, the less you need to protect — and the less your assessment costs. Consider a CUI enclave if your general IT environment is hard to lock down.
Run an Honest Gap Assessment
Compare your current state against all 110 NIST 800-171 controls. Be brutally honest — the C3PAO will be. Document what you have, what you're missing, and what's partially implemented. This becomes your roadmap.
Prioritize by Risk, Not Alphabetically
Don't start with Access Control just because it's first in the list. Start with the controls that protect against your highest-exposure scenarios. If your biggest risk is a ransomware attack shutting down operations, start with backup, incident response, and endpoint protection.
Build Processes, Not Just Tools
CMMC assessors look for evidence that controls are operationalized — not just installed. A SIEM tool that nobody monitors doesn't satisfy AU-2. An incident response plan that's never been tested doesn't satisfy IR-2. Show that your security actually runs.
Document Everything
If it's not documented, it didn't happen. System Security Plan (SSP), POA&M, policies, procedures, training records, audit logs, incident reports. The documentation burden is real, but it's also where your assessment lives or dies.
Get a Readiness Assessment Before the Real One
Hire a consultant (not your C3PAO — that's a conflict of interest) to do a mock assessment. Find the gaps before the assessor does. This is the cheapest mistake-prevention investment you'll make.
The Business Case Beyond Compliance
CMMC costs money — typically $50K–$300K for a small-to-mid contractor to reach Level 2, depending on gap size and environment complexity. That's real money for a company with $10M in revenue.
But look at it from the other side: what's the cost of not having it?
- You can't bid on new CUI-bearing contracts. Period.
- Existing contracts won't renew without it. That's revenue walking out the door.
- Primes are already flowing CMMC requirements down to subs. If your competitor is certified and you're not, you lose the work.
- A breach involving CUI triggers DoD reporting requirements and potential contract termination — the global average breach now costs $4.4M (IBM, 2025).
$4.2M across three prime contracts, all requiring CMMC Level 2 at next option period.
$180K over 12 months — gap remediation, tooling, documentation, readiness assessment, and C3PAO fees.
$4.2M in revenue at risk at next renewal. Plus ongoing exposure to breach costs — the global average is $4.4M per incident (IBM, 2025).
Where Risk Quantification Changes the Equation
The hardest conversation in CMMC planning is: where do we spend first? You have 110 controls, a limited budget, and a deadline. Doing everything at once isn't realistic.
When you can translate control gaps into dollar exposure — "this missing control exposes us to $340K in expected annual loss from ransomware" vs. "this one is a $15K exposure from insider access" — the priority order becomes obvious. You don't need a consultant to tell you which to fix first. The math does it.
This is what risk quantification was built for. Not color-coded heat maps that say "high" and "medium." Actual dollar figures tied to your specific environment, your industry, and your threat landscape. Controls that protect the most revenue get implemented first. That's how you get the fastest path to both certification and actual security.
CMMC isn't optional for defense contractors handling CUI, and the timeline is now. The companies that approach it as a security investment — scoped tightly, prioritized by risk exposure, documented thoroughly — will spend less, pass faster, and protect more revenue than those who treat it as a compliance fire drill.
Where this matters next
Pursuing SOC 2 alongside CMMC? — both frameworks share controls; here's where they overlap and where they diverge.
Translating the CMMC investment into board-ready language — the ROI framing that CFOs and audit committees actually respond to.
See how vCISO Lite tracks all 110 CMMC L2 controls — through one audit-ready dashboard, with evidence linked to specific NIST SP 800-171 §3.x requirements.