Skip to main content

Elevate

CMMC for Small Business: The Affordable Path to Level 2

CMMC for small business is a harder problem than CMMC for a prime, and not because the rules are different. A ten-person machine shop supplying the defense industrial base has to meet the same 110 security requirements as a company a thousand times its size, with none of the compliance staff, tooling budget, or legal department that a large contractor takes for granted. The requirements do not scale down with headcount, which is why so many small suppliers assume Level 2 is simply out of reach. This guide shows why that assumption is wrong, and how the right scoping choices, an enclave strategy, and a realistic sequence turn CMMC from a budget-breaker into a manageable investment. The affordability of CMMC does not come from doing less security, because the obligation to protect controlled unclassified information is fixed regardless of company size. It comes from controlling what falls under that obligation and spreading the work sensibly over time. A small supplier that scopes tightly, reuses pre-built artifacts where it can, and sequences the work in the right order pays a fraction of what a small supplier that treats its entire environment as in-scope will pay for the same certification outcome. Why CMMC for Small Business Feels Out of Reach The core difficulty is structural: the CMMC Level 2 bar is the 110 requirements in NIST SP 800-171 Revision 2, and that bar is the same whether you employ ten people or ten thousand. There is no small-business tier of the standard and no reduced control set for low headcount. A small supplier reads the requirements, multiplies the effort by an environment that was never built with compliance in mind, and concludes the number is impossible. That conclusion is understandable and, handled correctly, wrong. What the small supplier is really reacting to is scope, not the standard. The 110 requirements apply to the systems that store, process, or transmit controlled unclassified information, and the cost of meeting them scales with how much of your environment that turns out to be. A company that lets regulated data spread across every laptop, email account, and file share has quietly signed up to secure and document all of it. A company that confines that data to a small, defined space has far less to secure. The lever that decides affordability is therefore how much of your business you allow into scope, and that is a lever a small business controls. What the 2026 Suspension Changes for a Small Supplier The 2026 pause on third-party assessment matters to a small supplier’s budget in a specific, near-term way. During the suspension, a program office may require a Level 1 or Level 2 self-assessment rather than a third-party audit, which means the accredited-assessor fee that weighs heavily on a small budget is not part of the near-term path. For a company counting every dollar, that is real relief on timing. It is relief on cost, not on obligation, and the distinction is one a small supplier cannot afford to blur. DFARS clause 252.204-7012 still applies, the 110 requirements still have to be met, the self-assessed score still gets submitted to the Supplier Performance Risk System, and a false self-attestation still carries False Claims Act exposure. The suspension lowers the near-term outlay and buys time; it does not lower the security bar. The smart reading for a small business is to use the breathing room to get genuinely ready rather than to treat the pause as permission to defer the work. The Biggest Lever: Scope Reduction and the Enclave Strategy If there is one decision that separates an affordable CMMC path from an unaffordable one for a small business, it is whether to secure the whole environment or to isolate controlled unclassified information into a small, controlled enclave. An enclave is a deliberately bounded environment, a defined set of systems, that holds all of your controlled unclassified information, walled off from the rest of your operations. Only that enclave has to meet the 110 requirements, which is what makes the strategy so powerful for a company without an enterprise budget. How an Enclave Lowers the Cost The economics are straightforward. Every asset in scope is an asset whose controls you have to implement, document, monitor, and eventually have assessed, so the fewer assets in scope, the smaller every downstream cost becomes. An enclave shrinks the in-scope footprint from your entire company to a handful of systems, and that reduction cascades through licensing, engineering effort, documentation, and assessment. A small supplier that would have needed to bring dozens of endpoints into compliance may instead need to secure a small, well-defined workspace. Approach What is in scope Controls burden Best fit Broad scope The whole environment where CUI has spread Every in-scope asset must meet all 110 requirements A supplier whose CUI genuinely touches most systems Enclave A small, isolated environment holding all CUI Only the enclave meets the 110 requirements Most small suppliers with a containable CUI footprint The table makes the trade explicit: the broad approach spends effort proportional to your whole company, while the enclave approach spends effort proportional to a small, bounded space. For most small suppliers the enclave is the difference between a feasible project and an impossible one, though it only works if the isolation is real and the data genuinely stays inside the boundary. The detail of when an enclave fits and how to build one correctly is covered in the guide to scoping an enclave for CMMC, which is worth reading before committing to a scoping model. Scope Choices That Control Cost Even with an enclave, the scoping decisions inside it determine how lean the project stays. Three choices do most of the work. The first is mapping where controlled unclassified information actually lives today, because you cannot bound what you have not located, and small suppliers are frequently surprised by how far regulated data has drifted. The CMMC scoping guide walks through that mapping in detail. The second choice is actively

CMMC Readiness Assessment: What It Includes and When to Run One

A CMMC readiness assessment is the evaluation that tells you where your organization actually stands against the CMMC requirements before that standing is scored, attested to, or examined by anyone else. It is diagnostic and advisory, not official: its job is to surface every gap while you can still close it quietly, rather than discovering it when the stakes are highest. For defense contractors handling controlled unclassified information, that early, honest picture has become more valuable, not less, because of how the program changed in 2026. This guide covers what a readiness assessment includes, when to run one, how it differs from a mock assessment and a C3PAO audit, and what drives its cost. The reason the timing matters is a recent shift many contractors have misread. In July 2026 the Department of War paused the third-party certification side of CMMC, which has led some organizations to conclude that readiness can wait. That reading is backwards. The obligation to protect controlled unclassified information did not pause, the requirement to self-assess and attest did not pause, and the legal exposure attached to a false attestation did not pause. What changed is who checks your work in the short term, not whether the work has to be right. A readiness assessment is how you make sure it is right. What a CMMC Readiness Assessment Is A CMMC readiness assessment is a structured, advisory evaluation of your environment against the 110 security requirements in NIST SP 800-171 Revision 2, the control set that underpins CMMC Level 2. It examines how each requirement is implemented, what evidence supports that implementation, and where the gaps are, and it produces a prioritized picture of the work needed to reach compliance. It is deliberately not a pass-or-fail verdict. It is the diagnostic that comes before any verdict, designed so that the organization learns its weaknesses from an advisor rather than from an assessor or, worse, from a contract dispute. The distinction between advisory and official is the one that matters most, and it is worth stating plainly. A readiness assessment is delivered by an advisor who works for you and whose goal is to get you ready. The formal CMMC certification assessment is performed by a Certified Third-Party Assessment Organization, a separately accredited body whose role is to judge, not to help. Elevate operates on the advisory side of that line: it delivers the readiness assessment and the remediation support that follow, and it does not perform the certification assessment itself. Understanding which side of the line you are engaging protects you from the conflict of interest that arises when the same party both prepares and judges the same work. Why Readiness Matters More Under the Current Suspension The 2026 suspension paused third-party assessment, but it left the substance of the obligation fully intact. During the suspension, a program office may require Level 1 self-assessment or Level 2 self-assessment, and those self-assessments run against the same 110 requirements that were always there. DFARS clause 252.204-7012 remains in force, controlled unclassified information still has to be protected to the same standard, and the score you calculate still gets submitted to the Supplier Performance Risk System. What makes readiness sharper right now is the nature of self-attestation. When you self-assess and submit a score, you are making a representation the government relies on, and a knowingly false or reckless representation carries False Claims Act exposure regardless of whether a third party is currently auditing you. The paused audit does not reduce that exposure; if anything it raises the premium on getting your own assessment right, because there is no assessor in the loop to catch an honest mistake before it becomes an attestation. A readiness assessment is how a contractor confirms that the score it is about to attest to is defensible, and how it stays prepared for the return of third-party assessment, which the program has framed as a pause rather than a repeal. What a CMMC Readiness Assessment Includes A readiness assessment worth its fee covers four areas, and the value is in doing all four rather than treating the exercise as a checklist pass. The four move from defining what is in scope, through evaluating the controls and their evidence, to producing a remediation plan you can actually execute. Scope Definition and CUI Boundary The assessment begins by establishing what is in scope, because a control evaluation is only meaningful once the boundary is correct. This means identifying where controlled unclassified information lives, flows, and is processed, and categorizing assets by how they relate to that information. Getting the boundary right is what prevents two opposite failures: an over-scoped environment that makes compliance far more expensive than it needs to be, and an under-scoped environment that leaves regulated data outside the controls and invalidates the whole assessment. For the detail of how to draw that boundary, the CMMC scoping guide walks through the asset categories and the decisions that define them. Control Evaluation Against the 110 Requirements With scope set, the core of the assessment is a requirement-by-requirement evaluation against NIST SP 800-171 Revision 2. This is where implementation is examined honestly rather than assumed, and it typically splits into two related reviews. Implementation of the 110 Requirements Each of the 110 requirements is examined for whether it is implemented, partially implemented, or not implemented in the current environment. The point of the exercise is to replace the optimistic self-perception most organizations carry with an evidence-based reading of reality, because the gap between believing a control is in place and being able to demonstrate it is where most assessments are lost. A good evaluation does not just mark a requirement as met; it confirms the implementation would hold up to scrutiny. Evidence and Documentation Review Alongside the technical implementation, the assessment reviews the documentation that has to substantiate it, principally the System Security Plan and the Plan of Action and Milestones. A control that works in practice but cannot be evidenced is treated, in an

CMMC Certification Timeline: How Long Level 2 Really Takes

The CMMC certification timeline has two clocks running at once, and confusing them is how defense contractors miss deadlines. One clock is regulatory: the phased rollout that decides when a Level 2 certification requirement lands in your contracts. The other is operational: how long your own path from gap assessment to a passed C3PAO audit actually takes, which depends far more on where you start than on any published figure. This guide separates the two, gives you the dates that are fixed, and treats the durations honestly as ranges you can shorten with the right moves. The single most important date is November 10, 2026, when third-party Level 2 certification becomes the default requirement for applicable new contracts. If that date and your own readiness timeline do not line up, the gap is a lost contract, so the planning has to run backward from the regulatory clock, not forward from wherever your program happens to be today. The Regulatory Clock: Why November 2026 Matters The CMMC certification timeline you cannot control is the phased rollout the Department of Defense set in 32 CFR 170.3(e). It runs across four phases, each roughly a year apart, and it determines when the requirement appears in solicitations rather than how long your certification takes. Phase Start What changes for contractors Phase 1 November 10, 2025 Self-assessment requirements begin appearing in applicable contracts Phase 2 November 10, 2026 Third-party Level 2 certification becomes the default for applicable contracts Phase 3 November 10, 2027 Level 2 certification and Level 3 requirements expand Phase 4 November 10, 2028 Full implementation across all applicable DoD contracts The load-bearing date is Phase 2. From November 10, 2026, the Department of Defense begins including the Level 2 third-party certification requirement in applicable solicitations as a condition of award, though it retains discretion to defer inclusion to an option period in some cases. This is not universal application: that arrives at Phase 4 in November 2028. The accurate way to read Phase 2 is that third-party certification becomes the default for applicable Level 2 contracts, not that every contractor must hold a certification on that day. The practical effect is still decisive, because if your target contracts fall in scope and you are not certified, you are not eligible. A second regulatory fact shapes every plan built today: CMMC assessments are conducted against NIST SP 800-171 Revision 2, and they have already begun. The Department has stated it will move to Revision 3 through future rulemaking, but no finalized transition timeline or deadline has been published. Any plan should be built on Revision 2, which is what assessors use now, while staying alert for a Revision 3 rule that does not yet have a date. The CMMC Certification Timeline Stage by Stage The part of the CMMC certification timeline you do control is the journey from where you are today to a passed assessment, and it is the half of the timeline that actually decides whether you make the date. It runs in a fixed order, and each stage depends on the previous being done well. It begins with scoping. You define which systems, people, and data handle Controlled Unclassified Information, because that boundary determines everything that follows. A precise, minimized scope is the single highest-leverage decision in the entire timeline, since every asset inside the boundary is something you must secure, document, and have assessed. Contractors who scope loosely pay for it in every later stage. Next is the gap assessment. You measure your current state against the 110 requirements of NIST SP 800-171 Revision 2 and produce a score. This is where most contractors first learn how far they actually are from certification, and the honest number is often lower than the self-image. The gap assessment converts an abstract goal into a concrete list of what is missing. Remediation follows, and it is the stage that varies most between contractors. You close the gaps the assessment found, implement the missing controls, and write the documentation, including the System Security Plan and supporting policies, that an assessor will expect. Anything you cannot close immediately and that is eligible goes onto a Plan of Action and Milestones, but eligibility is limited and the clock on those items is short, which the next section covers. Before the third-party assessment, your self-assessment score goes into the Supplier Performance Risk System, known as SPRS. A perfect score is 110, and your SPRS score is both a contract-eligibility signal and a realistic predictor of how much remediation still stands between you and a passed audit. Knowing that number early is what lets you plan the rest of the timeline instead of guessing at it. The certification assessment itself is conducted by a CMMC Third-Party Assessment Organization, a C3PAO. This is the audit that produces the certification, and the C3PAO’s availability is a real scheduling variable, not an afterthought. Assessor capacity across the ecosystem is finite, and booking late can add waiting time that has nothing to do with your own readiness. The final stage is the certification decision and any Plan of Action and Milestones closeout. A contractor that meets the minimum threshold but has a small number of eligible open items can receive a conditional certification, then has 180 days to close those items and convert it to a final certification. A Level 2 certification, once achieved, is valid for three years, with annual affirmations required in between. The timeline does not end at the certificate; it shifts into maintenance. How Long Each Stage Takes Here honesty matters most. The Department of Defense does not publish official durations for the contractor journey, and any source quoting a single confident number is presenting an estimate as a fact. The real driver is your starting point, and it varies enormously. Within the CMMC certification timeline, the only fixed stages are the regulatory ones. The Plan of Action and Milestones closeout window is 180 days, a hard limit set by the rule. The certification, once granted,

CMMC Level 2 in 2026: What the Phase 2 Suspension Actually Means for Your Contracts

On July 10, 2026, the Department of War suspended the Phase 2 requirements of the Cybersecurity Maturity Model Certification, and with them the CMMC Level 2 third-party assessment that was scheduled to take effect on November 10, 2026. If you have been racing toward a C3PAO assessment, that deadline is gone for now. What did not go away is your legal obligation to protect the government’s data, and reading the suspension as permission to stop is the most expensive mistake you can make right now. The memo is explicit on this point, and so is this article. The Department suspended who verifies your cybersecurity. It did not suspend what you are required to do. This guide covers exactly what the suspension changed, what remains in force, and why the contractors who keep preparing are the ones who will win work when the pause ends. What the July 2026 Suspension Actually Did The suspension is narrower than the headlines suggest, and the details decide what happens to your specific contract. The Phase 2 Transition Is Paused The upcoming November 10, 2026 transition to Phase 2 of CMMC implementation is suspended. During the suspension, program managers and requiring activities may only include CMMC Level 1 (Self) or CMMC Level 2 (Self) assessment requirements in procurement documents. They may not designate CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) assessments. In plain terms, the third-party assessment requirement that defined Phase 2 cannot be placed on new work during the pause. The Department framed this as a burden problem, not a security reversal. Officials pointed to a defense industrial base with over 100,000 businesses needing a third-party assessment against roughly 100 available assessors, and concluded that the math did not work for small and mid-sized firms to certify by the November deadline. The Small Business Administration had documented that the program, as executed, was pushing companies out of the defense industrial base. Active Solicitations and Contracts Get Cleaned Up This is the part that affects you today rather than in the abstract. If an active solicitation or an existing contract already contains a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, contracting officers have been directed to remove it. For solicitations, program managers must provide an amended requirements document removing those requirements, and the contracting officer issues a corresponding amendment as soon as practicable. For existing contracts, the requirement is to be removed by modification before the next option period is exercised or during the next scheduled administrative modification. If you hold a contract with a looming C3PAO obligation, the relief is real and it is being applied through normal contracting mechanisms. You do not need to request it, but you should confirm the modification actually reaches your contract rather than assuming it will. No Waivers During the Pause Because program managers can no longer select requirements that would trigger a Level 2 (C3PAO) or Level 3 (DIBCAC) assessment, the waiver process is also suspended. No waivers will be granted during program review. This directive took effect immediately. A 60-Day Review Is Under Way The suspension is not the end state. The Department established a CMMC Reform Task Force to conduct a top-to-bottom review of the program, synthesize feedback from a public Request for Information, and deliver a final report to the DoW CIO within 60 days. Further guidance will follow at the conclusion of that review. The direction of travel the Department has signaled is toward measures that lower the barrier for small and non-traditional businesses, not toward abandoning cybersecurity requirements. What Did Not Change, and Why It Matters Here is the uncomfortable part, and it is the reason this article exists. The suspension changed the verification mechanism. It did not touch the underlying legal obligation, and several requirements remain fully in force. Your Contractual Duty to Protect CUI Stands The cybersecurity requirements in DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect. That clause is what contractually obligates you to safeguard covered defense information and to report cyber incidents, and it is untouched by the suspension. The Department stated the point directly: the action does not eliminate the legal requirement for industry partners to protect federal data. If your systems process, store, or transmit Controlled Unclassified Information, the obligation to protect it did not pause. Only the third-party check on whether you are doing so did. Level 1 and Level 2 Self-Assessments Continue Phase 1 self-assessment requirements remain firmly in place. During the suspension, the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment, along with select government-led assessments. CMMC Level 2 is aligned with NIST SP 800-171 Rev 2, and the self-assessment version of that requirement can still appear in your contracts. Read that carefully. A CMMC Level 2 (Self) requirement is still a live contract requirement. You still attest to meeting the security requirements for CUI. What changed is that an accredited third party is not, for now, checking your attestation. The 110 Requirements Have Applied Since 2014 This is the argument that should settle any internal debate about standing down. The 110 security requirements in NIST SP 800-171 are not new, and they are not a CMMC invention. Defense contractors handling CUI have been contractually required to implement them for years, since well before CMMC existed. CMMC was built to verify compliance that was already mandatory, not to create a new obligation. So a contractor treating the suspension as a reason to stop implementing controls is not returning to a pre-CMMC baseline of no requirements. It is choosing to be non-compliant with an obligation it already carries, and government-led assessments can still check that compliance during the pause. Government-Led Assessments Can Still Happen The suspension removes the C3PAO and DIBCAC designations from new procurements. It does not remove the Department’s ability to conduct select government-led assessments of NIST SP 800-171 Rev 2 compliance. A contractor that has let its controls

Build vs Managed Secure Enclave for CMMC: The Level 2 Decision

The choice between a build vs managed secure enclave for CMMC decides more than where your controlled unclassified information lives; it sets the scope, the cost, and the timeline of your entire Level 2 assessment. Most defense contractors treat the enclave as an IT project and discover too late that it is a compliance operating model they now have to run every day. The wrong model does not just waste budget. It expands your assessment boundary, adds controls you did not need, and pushes your certification date past the contract award you were trying to protect. This article compares both paths against the factors that actually move an assessment outcome, so you can commit to a model before you spend a dollar on infrastructure. Why the Enclave Decision Drives Your Entire CMMC Program The enclave is the single architectural choice that determines how large, expensive, and slow the rest of your CMMC program becomes. Contractors who understand this early treat the build vs managed question as a scoping decision, not a procurement one. Scope is the lever that sets cost and risk Under CMMC Level 2, the assessment covers every asset that stores, processes, or transmits controlled unclassified information (CUI), plus the assets that provide security functions to that environment. A secure enclave exists to draw a tight boundary around CUI so the rest of your corporate network stays out of scope. When the boundary is clean, an assessor evaluates a contained set of systems. When the boundary leaks, the assessment expands to touch the workstations, servers, and services that were supposed to be excluded. This is where the build vs managed decision starts paying off or costing you. A well designed enclave, whether you build it or subscribe to a managed one, can reduce the number of in-scope assets by an order of magnitude compared to attempting compliance across a full enterprise network. The model you choose changes who is responsible for keeping that boundary tight, and responsibility is exactly what an assessor tests. For the mechanics of drawing that boundary, see Elevate’s guide to scoping your enclave for CMMC compliance requirements, which explains how asset categories map to assessment scope. The core problem: the enclave is a system you must operate, not just stand up Standing up an enclave is a one time event. Operating it to a passing standard is a continuous obligation. The NIST SP 800-171 control set that underpins Level 2 is not a checklist you satisfy once; it demands ongoing evidence that access is controlled, logs are reviewed, vulnerabilities are patched, incidents are handled, and configurations stay locked. The build vs managed question is really a question about who runs that machine after the servers are configured. If you build, your team owns monitoring, patching, log review, evidence collection, and the discipline to keep all of it audit ready between assessments. If you buy a managed enclave, a provider assumes a defined slice of that operational load, and you inherit their control implementations along with their evidence. Elevate makes the same point in its analysis of why one time CMMC readiness assessments fall short: a certification reflects a moment in time, but the obligation is permanent, and the operating model has to survive the three year cycle. The cost of getting the model wrong A misjudged enclave decision surfaces in three predictable ways. First, scope creep: an enclave that was supposed to isolate CUI ends up connected to shared identity, shared file storage, or unmanaged endpoints, and the assessment balloons. Second, evidence gaps: the environment is technically compliant but no one is producing the artifacts that prove it, so the assessment stalls on documentation. Third, timeline slip: the certification arrives after the award window, and the contract goes to a competitor who was ready. Each of these traces back to the same root cause, which is choosing a model that does not match your internal capacity to operate it. The decision is not build versus managed in the abstract. It is build versus managed given your team, your timeline, and your tolerance for carrying security operations in house. What a CMMC Secure Enclave Actually Is Before comparing the two models, both parties need the same definition. A secure enclave is a logically or physically separated environment engineered to hold CUI and the security functions that protect it, isolated from the rest of the organization so that only the enclave falls inside the CMMC assessment boundary. The enclave as a scoped boundary for CUI The enclave concept solves a specific problem. Federal contract information (FCI) can often live across ordinary business systems, but CUI carries the heavier Level 2 obligations tied to NIST SP 800-171. Rather than dragging an entire enterprise up to that bar, contractors carve out a dedicated space where CUI is created, stored, and handled, and they wrap it in the required controls. Everything outside the enclave, provided the boundary holds, stays out of scope. The most common landing zone for a CUI enclave is Microsoft GCC High, a government community cloud built to meet the data handling and sovereignty requirements that CUI and ITAR regulated data demand. GCC High is infrastructure, not a compliance program. It provides a compliant place for data to live, but it does not implement your access policies, monitor your logs, or produce your assessment evidence. That distinction is the entire build vs managed conversation. The build model: own the environment and the controls In a build model, your organization designs the enclave, provisions the cloud tenant, configures the security controls, and operates the environment with internal staff or directly contracted engineers. You hold the administrative keys. You write the policies, implement the technical controls, run the monitoring, and assemble the evidence package your C3PAO assessor will review. The build model gives you maximum control and maximum responsibility in equal measure. Nothing about your environment depends on a third party’s roadmap or shared tenancy. In exchange, every control on the NIST SP 800-171 list is yours

External Service Providers and CSPs in CMMC

External service providers and the cloud platforms that run alongside them are the single biggest source of confusion in a CMMC assessment, and for good reason. The rules changed. Under the earlier proposed rule, a managed service provider that touched a defense contractor’s environment generally had to hold its own CMMC certification. Under the final rule, that requirement is gone, replaced by a more nuanced set of tests that turn on what kind of data the provider handles. The result is a landscape where two contractors with nearly identical vendors can face very different obligations, and where a single wrong assumption about who is responsible for a control can stall an assessment. This guide explains the definitions that decide everything, what the final rule actually requires of each provider type, and how to keep a provider from becoming the reason your certification slips. Why External Service Providers Are the Biggest CMMC Blocker Almost every defense contractor relies on outside help for IT and security, from a local managed service provider to a hyperscale cloud platform. That reliance is sensible, but it introduces a question the contractor cannot answer alone: where does the contractor’s responsibility end and the provider’s begin. Most CMMC delays are not caused by a lack of concern for security. They come from boundary confusion, thin documentation, and unresolved shared-responsibility gaps with the very providers meant to make compliance easier. The confusion is worse here than almost anywhere else in CMMC because the requirements shifted between the proposed and final rules, and a great deal of published guidance still reflects the older position. A contractor reading two-year-old advice may believe every vendor needs a certificate, budget for it, and lose months chasing something the final rule no longer requires. Getting the current rules right is not a technicality. It determines cost, timeline, and whether an assessment proceeds cleanly. The Definitions That Decide Everything In CMMC, the label attached to a provider is not marketing language. It is a regulatory classification that determines exactly what the provider and the contractor must do. Four definitions carry the weight, and each one is drawn from the CMMC Program Rule at 32 CFR Part 170. External Service Provider An external service provider is defined as external people, technology, or facilities that an organization uses to provide and manage IT or cybersecurity services on its behalf. The definition carries a critical qualifier: in the CMMC program, Controlled Unclassified Information or Security Protection Data must be processed, stored, or transmitted on the provider’s assets for that provider to count as an external service provider. A vendor that touches neither CUI nor Security Protection Data does not meet the definition and does not enter your assessment on this basis at all. This single test filters out a surprising number of vendors that contractors assume are in scope. Cloud Service Provider A cloud service provider is an external company that delivers cloud services in the sense defined by NIST, meaning on-demand network access to a shared pool of configurable computing resources. CSPs are a distinct category under the rule because a cloud offering that holds CUI triggers a specific federal requirement that other providers do not. The distinction between a general external service provider and a CSP is one of the most consequential in the entire framework, because it decides whether FedRAMP enters the picture. Managed Service Provider A managed service provider manages IT infrastructure without hosting its own cloud platform. Many contractors use one for day-to-day administration, monitoring, and support. The important nuance is conditional: if a managed service provider delivers a cloud offering that itself processes, stores, or transmits CUI or Security Protection Data, it is treated as a cloud service provider for that offering, and the CSP rules apply. A provider can therefore wear more than one hat, and the classification follows the service, not the company name. Security Protection Data and Security Protection Assets Security Protection Data is the hinge that the lighter treatment turns on. The rule defines it as data used to protect your assessed environment, including configuration data needed to operate a security tool, log files generated or ingested by that tool, vulnerability status data for in-scope assets, and passwords that grant access to the in-scope environment. The assets that provide those security functions, such as a SIEM, an endpoint detection tool, or a multifactor authentication service, are Security Protection Assets. A provider that handles only Security Protection Data, and never CUI itself, sits in a different and less demanding category than one that handles CUI, and recognizing that difference is often where the real savings live. Does Your Provider Need Its Own CMMC Certification? This is the question that stalls more programs than any other, and the answer changed with the final rule. In earlier versions of the proposed rule, external service providers, including managed service providers, were required to obtain their own CMMC certification. Under the final rule, that is no longer required. The shift meaningfully reduces cost and effort for contractors and their providers alike. For an external service provider that is not a cloud service provider and that handles CUI or Security Protection Data, the services are assessed within your assessment scope rather than through a separate certification of the provider. The relationship, the provider, and the services it delivers must be documented in your System Security Plan, and the provider participates in your assessment for the objectives it touches. No independent certificate is required for the provider to support you. There is an optional path that many capable providers choose. A provider may voluntarily pursue its own CMMC Level 2 certification covering just the services it offers, which spares it from being folded into every client’s assessment one at a time. This is not mandatory, but it is a genuine competitive differentiator, because a certified provider simplifies and shortens the assessment for every contractor it serves. The flip side is the practical consequence of skipping it: if a provider is not certified, its

Adequate and Sufficient Evidence for CMMC

Adequate and sufficient evidence is the standard that separates a CMMC practice scored MET from one scored NOT MET, and most assessments are lost not because a control is missing but because the evidence presented is the wrong kind, or there is not enough of it. The two words describe two entirely different tests. Adequate asks whether the evidence is the right evidence for the control in front of the assessor. Sufficient asks whether there is enough of it to cover the full scope. A defense contractor can fail either test while genuinely operating a strong security program, which is why understanding the distinction matters as much as implementing the controls themselves. This guide explains what each test means, why a passing package has to clear both, and how an assessor decides. Why Evidence, Not Controls, Decides a CMMC Assessment The most common misconception heading into a Level 2 assessment is that the assessor evaluates your controls. They do not, at least not directly. A CMMC practice is not what the assessor tests; the assessment objectives underneath it are. Each of the 110 Level 2 practices decomposes into a set of smaller, discrete assessment objectives, and there are 320 of them in total. The assessor works at that level, scoring each individual objective rather than the practice as a whole. Every objective is scored MET, NOT MET, or Not Applicable, and a practice is only MET when all of its underlying objectives are MET. A single objective without adequate and sufficient evidence pulls the entire practice down with it. This is why contractors who are confident in their security posture still fail: the control may work perfectly, but if the evidence does not prove a specific objective, that objective is scored NOT MET regardless of operational reality. The assessor reaches those scores using three methods drawn from NIST SP 800-171A: examine, interview, and test. Examine means reviewing artifacts such as policies, configurations, and records. Interview means questioning the people who perform the work. Test means observing a control actually function. Evidence feeds all three, and the CMMC Assessment Guide describes, objective by objective, what the assessor is looking for. The practical takeaway is that preparation is an exercise in evidence, and evidence is judged on two axes at once. What Adequate Means: The Right Evidence Adequate is a test of relevance. It asks a single question: is this the right evidence for this control, and does it directly demonstrate performance of the specific practice being assessed? Evidence can be completely real, accurate, and professionally produced and still fail this test, because being genuine is not the same as being relevant to the objective on the table. Consider a concrete example. An objective concerns password complexity, and the contractor offers a screenshot of the antivirus management dashboard showing full endpoint coverage. The screenshot is authentic and reflects a well-run environment, but it says nothing about password complexity. It is the wrong evidence for this objective, so it is not adequate, and no amount of it will change that. The evidence has to speak to the exact objective being scored, not to the general health of the security program. The failure mode behind most inadequate evidence is scope drift. Contractors import requirements and artifacts from adjacent controls, assuming that related evidence is close enough. It is not. Each objective has to be answered on its own terms with evidence that maps directly to it. Evidence that would satisfy a neighboring objective does nothing for the one actually under assessment, and an assessor who has to reach for another control to justify a score will not do it. What Sufficient Means: Enough Evidence Sufficient is a test of coverage and quantity. Once the evidence is the right kind, sufficiency asks whether there is enough of it. Enough to cover all required samples, enough to cover the full scope of the assessment rather than a single system or department, and enough to match the evidence collection approach the CMMC Assessment Guide lays out for that objective. Adequate evidence that stops short of full coverage is still incomplete. Return to a concrete example. An objective requires evidence of access reviews, and the environment has 100 users. The contractor provides clean, well-documented access review records for 8 of them. The evidence is exactly the right kind, so it is adequate, but a sample of 8 out of 100 is not a defensible basis for concluding that access reviews happen across the organization. It is not sufficient. The assessor needs enough of a sample to be convinced the objective holds everywhere it must, not just in the handful of cases presented. Sufficiency has three dimensions worth separating. The first is sampling: enough instances to represent the population, not a token few. The second is scope: evidence that spans the entire assessment boundary, because a control that works in one department and not another is a control that fails. The third is method coverage: producing artifacts, interviews, and tests where the guide calls for more than one, rather than leaning on a single document to carry an objective that requires demonstration. The CMMC Assessment Guide relies on nonstatistical sampling, which means there is no fixed percentage that guarantees sufficiency. The assessor decides whether the sample provides enough depth and coverage to represent the full population with confidence. That judgment is why contractors so often misjudge sufficiency, treating a few clean examples as proof when the assessor is asking whether the same evidence would hold if the lens widened to the rest of the environment. Why You Need Both Adequate and Sufficient Evidence The two tests are independent, and evidence has to pass both. This is the heart of the concept, and it is where preparation most often goes wrong, because contractors tend to optimize for one axis and assume the other follows. It does not. The table below sets the two tests side by side. Dimension Adequate Sufficient What it tests Relevance Coverage and quantity Question it

GCC High for CMMC: Do You Really Need It?

GCC High is the answer most defense contractors reach for the moment CMMC enters the conversation, yet for a large share of them it is the wrong answer, or at least a more expensive one than the contract requires. The premium runs 40 to 70 percent above commercial licensing, which can mean tens of thousands of dollars a year for a mid-sized organization. The reason so many contractors overbuy is simple: the decision is usually made from a sales deck rather than from the contract language and the type of Controlled Unclassified Information actually being handled. This guide explains what GCC High is, when your contract genuinely requires it, the alternatives that can satisfy CMMC for less, and the ownership trap that catches contractors who pick the cheapest provider without reading the fine print. Why the GCC High Question Trips Up So Many Contractors The confusion is understandable. GCC High has become shorthand for CMMC compliance, and most of the vendors in the market are Microsoft resellers whose default recommendation is the highest tier. The result is a market where the environment gets chosen before anyone has looked at what the contract actually demands. CMMC Does Not Name a Cloud CMMC is a cybersecurity framework. It defines the security practices and controls a contractor must implement, and it does not mandate a specific cloud vendor or licensing tier. The requirement that actually drives cloud decisions is DFARS clause 252.204-7012, which states that any cloud service used to store, process, or transmit Covered Defense Information must meet security requirements equivalent to the FedRAMP Moderate baseline. Microsoft publicly recommends GCC High for organizations pursuing CMMC Level 2 and Level 3, and that recommendation carries real weight, but a recommendation is not the same as a requirement. This distinction matters because it puts the decision back where it belongs. The question is not what does Microsoft recommend, but what does your contract require given the data you handle. Two contractors pursuing the same CMMC level can land on very different environments depending on whether their CUI is export-controlled, and neither is cutting corners. The Cost of Buying the Wrong Environment Buying too much environment wastes money, and buying too little fails an assessment. Both mistakes are expensive. The GCC High premium is significant, and it applies to every licensed user, so overbuying licenses for staff who never touch CUI compounds quickly. On the other side, placing CUI in an environment that cannot support it is the fastest way to fail a Certified Third-Party Assessment Organization review, and in the case of export-controlled data it can draw scrutiny that goes well beyond CMMC. Migration adds another layer of cost. Standing up GCC High generally requires a specialized partner, a new tenant, and a validation process that can take weeks. Environments also cannot be upgraded in place, so a contractor who starts in the wrong tier faces a full migration to correct the mistake. Getting the decision right the first time is far cheaper than fixing it later. What GCC High Actually Is Understanding the decision starts with understanding what separates GCC High from the environments beneath it. The differences are not a matter of price tiers on the same product. They are differences in compliance architecture. A US Sovereign Cloud Built for Defense Microsoft 365 GCC High is a version of Microsoft 365 built to meet the strict requirements of the Department of War and its contractors. It runs on Azure Government, a physically separated infrastructure hosted in data centers located exclusively in the continental United States. All data is stored on US soil, and access is restricted to screened US citizens who have passed background checks. It is the only Microsoft 365 environment that meets the full set of DFARS 252.204-7012, ITAR, EAR, DoW Impact Levels 4 and 5, and CMMC Level 2 and 3 requirements at once. That architecture is the reason GCC High exists and the reason it costs more. The US-person access controls, the sovereign infrastructure, and the FedRAMP High authorization are not features you can bolt onto a commercial tenant. They are structural, which is why the decision to move to GCC High is a compliance decision rather than a licensing preference. How GCC High Differs from GCC and Commercial Microsoft offers three relevant environments, and they sit on very different foundations. Commercial Microsoft 365 is the everyday business suite. GCC is a segregated environment for government customers that runs on the commercial Azure backbone. GCC High runs on Azure Government and is purpose-built for defense. The table below summarizes where each one fits. Environment FedRAMP Level Infrastructure US-Person Access Typically Suitable For Commercial M365 Not authorized for CUI Azure Commercial, global No FCI and CMMC Level 1 only GCC FedRAMP Moderate Azure Commercial, US data centers Not guaranteed Non-export CUI at Level 2, when configured GCC High FedRAMP High Azure Government, US only Yes, screened US citizens Export-controlled CUI, ITAR and EAR, Level 2 and 3 The table shows why commercial Microsoft 365 dropped out of the picture for CUI. It lost the FedRAMP standing needed to handle CUI under DFARS 7012, which leaves it viable only for contractors handling Federal Contract Information at CMMC Level 1. GCC and GCC High remain the two real options for CUI, and the line between them is drawn almost entirely by whether your data is export-controlled. When You Actually Need GCC High The honest answer to whether you need GCC High is that it depends on your CUI and your contract, not on a general rule. There are cases where it is genuinely required, cases where a lighter environment is enough, and a short list of questions that settles which situation you are in. Export-Controlled CUI Sets a Higher Bar If your contract involves export-controlled data under ITAR or EAR, your options narrow, but they do not collapse to a single product. Export-controlled technical data includes items on the US Munitions List, such as CAD models, engineering drawings, and source

System Security Plan (SSP): The Foundation of CMMC Compliance

A System Security Plan, or SSP, is the formal document that describes the security requirements of an information system and the controls in place or planned to meet them, and for defense contractors it is the single document that can stop an assessment before it begins. Federal assessment guidance is blunt on this point: the absence of a system security plan results in a finding that the assessment cannot be completed, which means no SSP equals no certification. Yet most plans that reach an assessor fail not because controls are missing, but because the document lacks detail or does not match how the systems actually operate. This guide explains what an SSP is, what it must contain, how it differs from a Plan of Action and Milestones, and how to build one that holds up under scrutiny. Why the System Security Plan Is the Most Important Document You Will Build Most compliance documents support an assessment. The SSP is the assessment. It is the first artifact a Certified Third-Party Assessment Organization reviews, the reference point for every control an assessor tests, and the document that determines whether your organization is even ready to be evaluated. Treating it as paperwork to finish at the end of a project is the fastest way to derail certification. The Document That Gates Your Assessment For CMMC Level 2, the SSP is not optional and it is not eligible for a workaround. The DoD Assessment Guidance for the underlying NIST requirement states that the absence of a system security plan results in a finding that the assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012. In practice, a Certified Third-Party Assessment Organization reviews the SSP as a prerequisite, and if it lacks sufficient detail or fails to address the required controls, the assessor can deem the organization not ready and stop before testing anything. This is what separates the SSP from the Plan of Action and Milestones. A missing control can sometimes be placed on a remediation timeline, but a missing or inadequate SSP cannot. There is no plan of action for not having a plan. That single fact is why mature organizations build the SSP first and treat it as the spine of the entire program rather than a closing formality. A Requirement Across CMMC, FedRAMP, and FISMA The SSP is not unique to defense contracting, which is part of why it carries so much weight. Under the Federal Information Security Modernization Act, federal agencies are required by law to maintain system security plans for their information systems. Under DFARS clause 252.204-7012 and CMMC, defense contractors handling Controlled Unclassified Information are contractually obligated to have one. For cloud service providers pursuing FedRAMP, the SSP is the central document in the authorization package, describing how every required control is implemented. The common thread is accountability. In every one of these frameworks, the SSP is the document that lets an external reviewer understand how an organization protects sensitive data and where its responsibilities begin and end. The format and the specific controls differ by framework, but the role of the document does not. What a System Security Plan Is Understanding the document starts with the federal definition, because the definition explains why assessors expect so much from it. An SSP is not a policy binder or a marketing summary of your security program. It is a precise account of how each required control operates in your specific environment. The Federal Definition of an SSP According to the National Institute of Standards and Technology, a system security plan is a formal document that provides an overview of the security requirements for an information system and describes the security controls in place or planned for meeting those requirements. A useful way to think about it is as the single source of truth for your security program, the document an external auditor can read to understand the full picture without needing to interview your team. It is also a living document, which means it is expected to evolve as your systems and controls change. The plan relates security requirements to the controls that satisfy them, and it describes at a high level how those controls meet the requirements. It is not meant to be a deeply technical design specification. It is meant to tell the complete and accurate story of how your organization protects its in-scope systems, in language an assessor can follow and verify. The Authority Behind the Requirement For defense contractors, the SSP requirement comes from NIST SP 800-171, specifically control 3.12.4, which CMMC maps to practice CA.L2-3.12.4. That control requires organizations to develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. The companion guidance for actually building the plan is NIST SP 800-18, the Guide for Developing Security Plans for Federal Information Systems, which provides the recommended structure. NIST does not mandate one specific template, which surprises some organizations. What it mandates is content and accuracy. Following the structure in NIST SP 800-18 is recommended because it ensures nothing required is overlooked, and aligning the plan with the assessment objectives in NIST SP 800-171A is what makes each control testable and traceable to evidence. The detailed control obligations are covered in the breakdown of CMMC requirements for primes and subcontractors. What a System Security Plan Must Include An SSP has a required core and a recommended extended set of content. Getting the core right is what keeps an assessment moving, and getting the extended content right is what makes the plan defensible. The required elements come directly from the language of control 3.12.4. The Core Required Elements System Boundary and Environment of Operation The plan must define the system boundary, meaning exactly which systems, networks, and components fall inside the assessment scope, and it must describe the environment in which they operate. This is where network diagrams, data flow diagrams,

Controlled Unclassified Information: A 2026 Guide to CUI

Controlled Unclassified Information, or CUI, is unclassified federal information that a law, regulation, or Government-wide policy requires an agency to protect with safeguarding or dissemination controls. Before the program existed, more than 100 different markings for sensitive information were scattered across the executive branch, which created confusion about what to protect and how. Today a single Government-wide framework governs CUI, and for the roughly 220,000 companies in the Defense Industrial Base, getting it right is the difference between winning federal work and losing eligibility for it. This guide explains what CUI is, the two types you will encounter, how it differs from Federal Contract Information, and what protecting it actually requires. Why Controlled Unclassified Information Matters Now CUI sits between two extremes. It is not classified national security information, so it does not carry the restrictions of Confidential, Secret, or Top Secret material. It is also not freely shareable, because the government has determined that releasing it could cause real harm. That middle ground is exactly where most organizations struggle, because the obligation to protect CUI is easy to overlook until an auditor, a contracting officer, or a breach makes it impossible to ignore. A Government-Wide Program, Not Just a Defense Rule The most common misunderstanding is that CUI is a Department of Defense concept. It is not. The CUI Program was established by Executive Order 13556 in November 2010, and the National Archives and Records Administration (NARA), through its Information Security Oversight Office, serves as the Executive Agent that oversees it across the entire federal executive branch. In September 2016, NARA issued the final rule at 32 CFR Part 2002, which set uniform policy for designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI. The program replaced a patchwork of agency-specific labels such as For Official Use Only and Sensitive But Unclassified with one consistent system. That history matters because it explains why CUI rules feel rigid. They were designed to remove the inconsistency that let the same document be treated as restricted at one agency and shared openly at another. Every federal agency, from the Environmental Protection Agency to the General Services Administration, now operates under the same baseline, and any contractor that handles CUI on behalf of an agency inherits those obligations. The Compliance Stakes for Contractors For defense contractors, CUI is not an abstract policy. Protecting it is a contractual requirement enforced through DFARS clause 252.204-7012, which points to the security controls in NIST SP 800-171, and verified through the Cybersecurity Maturity Model Certification program. An organization that handles CUI for a defense contract must implement those controls, document them, and increasingly prove that implementation to an independent assessor rather than simply attesting to it. The cost of getting this wrong is concrete. A contractor that misjudges what counts as CUI can under-protect sensitive data and expose itself to breaches and legal liability, or over-protect everything and waste resources on controls it never needed. Both outcomes are expensive, and both trace back to the same root cause: an unclear understanding of what CUI is and where it lives. Understanding the broader framework of CMMC compliance starts with getting this foundation right. What Controlled Unclassified Information Actually Is The federal definition is precise, and the precision is the point. Controlled Unclassified Information is information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. In the words of the rule itself, all unclassified information throughout the executive branch that requires any safeguarding or dissemination control is CUI. Two parts of that definition carry the most weight. First, the obligation must come from a law, regulation, or Government-wide policy, not from an individual employee deciding something feels sensitive. Second, the information must not already be classified under Executive Order 13526 or the Atomic Energy Act. If it meets both conditions, it is CUI, and the standardized handling rules apply. CUI Basic vs CUI Specified CUI comes in two forms, and the distinction determines how you handle it. The difference is whether the authority that requires protection also dictates specific handling rules. Most organizations encounter both types, often within the same project, which is why understanding the split is essential before you build any safeguarding process. Aspect CUI Basic CUI Specified Handling controls The standard safeguarding requirements in 32 CFR Part 2002 Specific controls set by the authorizing law, regulation, or policy Source of rules The uniform CUI baseline The underlying statute or regulation for that category Dissemination Per the standard CUI rules Per the specific authority, with CUI Basic rules filling any gaps Typical examples General personnel or privacy information Certain tax, export control, or law enforcement categories In practice, CUI Basic is the default. When a category requires protection but the governing authority does not spell out particular handling instructions, you apply the standardized controls in 32 CFR Part 2002. CUI Specified is the exception that demands extra attention, because the authorizing law imposes its own requirements that may go beyond or differ from the baseline. Where a Specified authority is silent on a particular point, the CUI Basic rules fill the gap, so you are never left without a standard to follow. How CUI Is Organized in the CUI Registry NARA maintains the CUI Registry at archives.gov/cui as the authoritative, Government-wide repository of every approved category. The categories and subcategories listed there are the exclusive designations for CUI, which means an agency cannot invent its own label outside the Registry. This is what makes the program consistent across more than 100 departments and agencies that once used their own systems. The Registry organizes information into more than 20 groupings that cover the full range of sensitive but unclassified data. Common categories include privacy information such as Social Security numbers and health records, law enforcement sensitive information, proprietary business information, tax information, export-controlled information, and controlled technical information. For defense