CMMC Level 2 for Small Manufacturers: A Realistic Guide
CMMC Level 2 was written for defense contractors. Most of the defense industrial base is small manufacturers with limited IT resources. This is the guide for those companies - realistic costs, common gaps, and a prioritized path through 110 practices with one IT person and a finite budget.
CMMC Level 2 was written for defense contractors. But the word "contractor" conjures images of large systems integrators with dedicated compliance teams and six-figure IT budgets. The reality of the defense industrial base is different. A large chunk of it is small manufacturers: machine shops, precision parts fabricators, electronics assemblers, small aerospace suppliers. Companies with 15 employees, one IT person who also fixes the printers, and a CNC machine that runs Windows 7.
This post is for those companies. Not the theory of CMMC - the reality of what it takes to get there when you are small, resource-constrained, and the compliance burden lands on people who also have a day job.
First: Do You Actually Need CMMC Level 2?
Before you spend a dollar on compliance, confirm what you actually need. Two questions determine this:
- Do you handle CUI? Controlled Unclassified Information is the trigger. If your contract involves design specifications, technical drawings, test data, or technical manuals with a CUI marking - you handle CUI. If you are only making a commodity part from a public drawing with no special markings, you may not.
- What does your contract say? Look for DFARS clause 252.204-7012 and/or 252.204-7021. If 7012 is in your contract, NIST 800-171 applies. If 7021 is present, CMMC Level 2 certification will eventually be required. If neither is there, you may be Level 1 only (17 practices, not 110).
Do not assume. Ask your contracting officer or prime contractor exactly what CMMC level your contract requires. Over-investing in Level 2 when you only need Level 1 wastes money. Under-investing when you need Level 2 creates legal risk.
The Honest Reality of What Level 2 Costs a Small Manufacturer
CMMC Level 2 is not cheap. Here is a realistic cost breakdown for a small manufacturer - say 10 to 50 employees, one or two locations:
Year-one costs for a small manufacturer getting to CMMC Level 2 from scratch realistically range from $70,000 to $200,000 or more, depending on how far below baseline you are starting. The DoD's own estimate put aggregate SMB compliance costs at over $7 billion annually across the DIB - that average works out to roughly $70,000 per company per year.
This is real money for a company with $5M in annual revenue. Which is why the Phase 2 pause happened.
The Common Gaps in Small Manufacturing Environments
Based on real-world implementation experience, these are the practices that most frequently fail in small manufacturing environments:
Audit logging (3.3.1 through 3.3.9): Most small manufacturers have no logging infrastructure. Windows event logs exist but are not retained, reviewed, or correlated. Getting to a defensible audit logging posture typically requires either a SIEM (expensive) or an MDR provider that includes log management.
Multifactor authentication (3.5.3): Still not universal in small businesses. If your team is using password-only access to email, file shares, or the ERP system that touches CUI, this is a gap. MFA is table stakes and assessors treat it as one of the most basic controls.
Configuration management (3.4.x): "Documented baseline configurations" means someone wrote down what settings are required on every workstation, server, and network device - and those settings are actually enforced. Most small manufacturers have no documented baselines. The systems exist; the documentation does not.
Vulnerability management (3.11.2): Periodic vulnerability scanning is required. Many small manufacturers have never run a vulnerability scanner against their environment. Starting one often produces alarming results - unpatched systems, open services, forgotten test machines still connected to the network.
Scope creep: This is not a practice, but it costs more than any individual gap. Small manufacturers often do not realize how many systems are "in scope" - the engineering workstation in the corner that has design files, the office PC someone used to download contract documents, the server that runs the CAD software. Every system that stores, processes, or transmits CUI is in scope. Defining and shrinking the scope before you start implementing is one of the highest-ROI activities in CMMC preparation.
A Realistic Implementation Sequence for Small Manufacturers
You cannot fix everything at once. Here is a prioritization approach that makes sense for a resource-constrained environment:
Define and shrink your scope
Map which systems touch CUI. Segment them from the rest of your environment if possible. Every system you keep out of scope is a system you do not have to assess or document. An IT consultant with CMMC experience can help you build a network diagram and define your CMMC assessment boundary.
Run a gap assessment
Use the SPRS Score Calculator at secreadynow.com/tools/sprs-calculator/ to self-assess all 110 practices. Be honest. The resulting score and gap list is your remediation roadmap. An inflated self-score does not help you - it just creates legal risk.
Fix the high-weight gaps first
Practices worth -5 points each are your priority. MFA (3.5.3), encryption at rest (3.13.16), audit logging (3.3.1), and malware protection (3.14.2) are all worth 5 points. Fix these before the low-weight items.
Get your documentation in place
A System Security Plan, 12 domain policies, and a POA&M for remaining gaps. The documentation is what assessors actually review - you can have perfectly configured systems and fail an assessment because you cannot show the paperwork. Write the SSP alongside your technical implementation, not after.
Conduct a practice assessment
Have someone walk through your controls as if they were an assessor before you pay for a C3PAO. Internal walk-throughs find gaps in evidence that are easy to fix when you have time, and expensive to discover during the actual assessment.
Should You DIY or Hire a Consultant?
Honest answer: a hybrid approach usually makes sense for small manufacturers. Pure DIY is difficult because the technical and documentation requirements are substantial and the standards language is ambiguous in places. Pure consultant is expensive and leaves you dependent on outside expertise for ongoing maintenance.
The practical split: hire a consultant for the initial gap assessment and scope definition. Use that output to prioritize your own team's effort for remediation and documentation. Bring the consultant back for a pre-assessment readiness review before the C3PAO assessment.
Templates - like a pre-written SSP or domain policy documents - can replace a significant portion of the documentation consultant cost, as long as you actually fill them in with your specific environment details rather than using them as-is. An untailored template that does not describe your actual systems will not pass a C3PAO review.
The Phase 2 Pause: Threat or Opportunity?
For small manufacturers, the Phase 2 suspension is genuinely an opportunity - not to stop working on compliance, but to close gaps without the pressure of an assessment deadline. The contractors who use this window productively will be in a dramatically better position than those who treat it as a break.
When Phase 2 resumes - possibly in 2027 with whatever modifications the Task Force recommends - C3PAO scheduling will be a bottleneck. Companies that are already documented and technically prepared will get through assessments faster and cheaper than companies that have to close large gaps under deadline pressure.
Start with the Documentation
The CMMC Level 2 Certification Kit gives you the SSP, POA&M, and all 12 domain policies in editable Word format. Fill in your environment details and you have the core of your evidence package.
View the Certification Kit - $299