The email lands on a Tuesday afternoon from the prime contractor you have shipped parts to for six years. There is new language buried in the renewal packet. It mentions CMMC, it mentions a level number, and it asks you to confirm your status in a government database by a date a lot closer than you would like. You read it twice, forward it to your office manager, and get it back with a question mark.

Here is the part that email never explains. There are three levels, the overwhelming majority of small suppliers land in the bottom one, and the program just went through a shakeup aimed at making life easier for small businesses. So before you panic or start shopping for a compliance consultant, let us translate this and figure out where you actually sit.

One note first. This article is general information, not legal, tax, or insurance advice. Contract language is specific to your contract, so talk to your own attorney or contracting officer before you sign anything or make a representation to the government.

What CMMC Actually Is

CMMC stands for Cybersecurity Maturity Model Certification. It is the Department of Defense’s way of checking that companies in its supply chain actually do the security work they have been promising for years. Defense contracts have carried cybersecurity clauses for a long time. What CMMC added was verification, meaning somebody checks and there is a record of it.

The program lives in federal regulation at Title 32 of the Code of Federal Regulations, Part 170, which defines three levels. Which one applies to you is not a judgment call you get to make. It is driven entirely by what kind of government information touches your computers.

Level 1 Is Where Most Small Suppliers Land

Level 1 covers Federal Contract Information, usually shortened to FCI. Per the acquisition regulation, that is information provided by or generated for the government under a contract and not intended for public release. Think a delivery schedule, a statement of work, a drawing of a bracket you are machining. Not classified, but not something you would post on your website either.

Level 1 asks for fifteen basic safeguarding requirements, all from a clause that has been in federal acquisition rules for years, FAR 52.204-21. FAR stands for Federal Acquisition Regulation, the rulebook for how the government buys things. Those fifteen items are basics almost any competently run business should already have:

  • Limit who gets into your systems. Only authorized people, on authorized devices, reaching only what their job requires.
  • Verify people are who they claim to be. Real accounts with real passwords, no shared logins that four people know.
  • Control the boundary. Know where your network touches the public internet and put a firewall there.
  • Run antivirus and patch things. Protection that expired two years ago counts as no protection at all.
  • Lock the physical doors. Servers and network gear in a room that closes, plus an escort policy for visitors.
  • Destroy data before hardware leaves. Wipe or physically destroy drives in old computers, copiers, and servers before they go out the door.

Level 1 is confirmed with an annual self-assessment. You evaluate your own systems and a senior person affirms the result. No auditor shows up at your building.

Level 2 Is a Real Jump

Level 2 covers Controlled Unclassified Information, or CUI. That is a broader and more sensitive category: technical data, engineering specifications, export controlled drawings, certain program information. If a prime sends you CUI, it is generally marked as such and your contract will say so plainly.

Level 2 requires the 110 security requirements in NIST SP 800-171 Revision 2. NIST is the National Institute of Standards and Technology, the federal agency that publishes security standards, and SP just means Special Publication. That is not fifteen requirements with extras bolted on. It is a different scale of effort covering access control, audit logging, encryption, incident response, personnel screening, and physical protection.

Level 2 has two paths under the regulation. A self-assessment path, where you evaluate yourself and affirm, and a certification path, where a CMMC Third-Party Assessment Organization, called a C3PAO, assesses you against all 110. Which one applies depends on your contract.

Level 3 Is Almost Certainly Not About You

Level 3 sits on top of Level 2 and adds 24 selected requirements from NIST SP 800-172, a companion publication aimed at well funded, patient attackers. Level 3 is assessed by the government itself, specifically the Defense Industrial Base Cybersecurity Assessment Center, or DIBCAC, inside the Defense Contract Management Agency.

If you run a twelve person shop in Lewisville or Flower Mound and you are wondering whether Level 3 applies, it almost certainly does not. It targets companies handling the most sensitive unclassified information on the highest priority programs, and you would not be guessing about it. Your contract would say so.

What Just Changed, and What Did Not

Now the part that matters most right now. In July 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements, which had been set to take effect on November 10, 2026, and stood up a reform task force for a sixty day review. Its stated reason was that the program had created prohibitive compliance costs and bureaucratic burdens pushing small and non-traditional businesses out of the defense industrial base.

Good news if you are small. But read what follows carefully, because this is where people talk themselves into trouble.

  • Phase I self-assessment requirements are still in place. The announcement says so directly. Suspended does not mean everything stopped.
  • NIST SP 800-171 Revision 2 still applies. The underlying standard for protecting CUI did not move. Only the certification machinery around it paused.
  • DFARS 252.204-7012 still applies. DFARS is the Defense Federal Acquisition Regulation Supplement, the defense-specific add-on to the FAR. That clause carries its own safeguarding and incident reporting duties, separate from CMMC.
  • A suspension is not a repeal. The regulation is still on the books, and a review can end in a revised program with new dates.
  • A false affirmation is still a false statement. Affirm compliance you do not have and the exposure comes from laws about lying to the government. None of that paused.

What to Do Before Anyone Asks

  • Figure out what you actually hold. Walk your file server, your email, and the shared drive. Is anything marked CUI? A clean no means you are almost certainly a Level 1 shop.
  • Read the clauses in the actual contract. Not the summary email from your prime. The clause list in the contract itself tells you what you signed up for.
  • Do the fifteen basics regardless. Every one is something you should be doing anyway, and none of it requires a consultant.
  • Write down what you do. A short document covering accounts, patching, backups, and disposal is worth more at assessment time than any product you can buy.
  • Ask your prime a direct question. “What CMMC level does this contract require of me, and does any CUI flow down to us?” Get it in writing and keep it.

Bottom line: your level is set by the information you touch, not by how big your company is. Most small suppliers around DFW are Level 1 shops needing fifteen basics and an honest annual self-assessment, and the suspension buys breathing room rather than a permanent pass. The companies that get hurt are not the slow ones. They are the ones who affirm something they never did.

Again, this is general information and not legal advice, so talk to your own attorney or contracting officer before affirming anything. If you want help sorting out what your systems look like and what the fifteen basics would take at your shop, get in touch with Harrison Ward Technology. We work with businesses across Denton County, and we would rather scope this honestly than sell you a level you do not need.


Sources

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).