HomeBlogCMMC
CMMCSmall Business2026-07-25SecReadyNow

CMMC Level 2 for Small Manufacturers: A Realistic Guide

CMMC Level 2 was written for defense contractors. Most of the defense industrial base is small manufacturers with limited IT resources. This is the guide for those companies - realistic costs, common gaps, and a prioritized path through 110 practices with one IT person and a finite budget.

CMMC Level 2 was written for defense contractors. But the word "contractor" conjures images of large systems integrators with dedicated compliance teams and six-figure IT budgets. The reality of the defense industrial base is different. A large chunk of it is small manufacturers: machine shops, precision parts fabricators, electronics assemblers, small aerospace suppliers. Companies with 15 employees, one IT person who also fixes the printers, and a CNC machine that runs Windows 7.

This post is for those companies. Not the theory of CMMC - the reality of what it takes to get there when you are small, resource-constrained, and the compliance burden lands on people who also have a day job.

First: Do You Actually Need CMMC Level 2?

Before you spend a dollar on compliance, confirm what you actually need. Two questions determine this:

  1. Do you handle CUI? Controlled Unclassified Information is the trigger. If your contract involves design specifications, technical drawings, test data, or technical manuals with a CUI marking - you handle CUI. If you are only making a commodity part from a public drawing with no special markings, you may not.
  2. What does your contract say? Look for DFARS clause 252.204-7012 and/or 252.204-7021. If 7012 is in your contract, NIST 800-171 applies. If 7021 is present, CMMC Level 2 certification will eventually be required. If neither is there, you may be Level 1 only (17 practices, not 110).

Do not assume. Ask your contracting officer or prime contractor exactly what CMMC level your contract requires. Over-investing in Level 2 when you only need Level 1 wastes money. Under-investing when you need Level 2 creates legal risk.

The Honest Reality of What Level 2 Costs a Small Manufacturer

CMMC Level 2 is not cheap. Here is a realistic cost breakdown for a small manufacturer - say 10 to 50 employees, one or two locations:

$15K-40K
Initial gap assessment and remediation (consultant)
$20K-50K
Technology upgrades (MFA, EDR, SIEM, logging)
$5K-15K
Documentation (SSP, policies, evidence package)
$30K-100K+
C3PAO assessment (when Phase 2 resumes)

Year-one costs for a small manufacturer getting to CMMC Level 2 from scratch realistically range from $70,000 to $200,000 or more, depending on how far below baseline you are starting. The DoD's own estimate put aggregate SMB compliance costs at over $7 billion annually across the DIB - that average works out to roughly $70,000 per company per year.

This is real money for a company with $5M in annual revenue. Which is why the Phase 2 pause happened.

The Common Gaps in Small Manufacturing Environments

Based on real-world implementation experience, these are the practices that most frequently fail in small manufacturing environments:

Audit logging (3.3.1 through 3.3.9): Most small manufacturers have no logging infrastructure. Windows event logs exist but are not retained, reviewed, or correlated. Getting to a defensible audit logging posture typically requires either a SIEM (expensive) or an MDR provider that includes log management.

Multifactor authentication (3.5.3): Still not universal in small businesses. If your team is using password-only access to email, file shares, or the ERP system that touches CUI, this is a gap. MFA is table stakes and assessors treat it as one of the most basic controls.

Configuration management (3.4.x): "Documented baseline configurations" means someone wrote down what settings are required on every workstation, server, and network device - and those settings are actually enforced. Most small manufacturers have no documented baselines. The systems exist; the documentation does not.

Vulnerability management (3.11.2): Periodic vulnerability scanning is required. Many small manufacturers have never run a vulnerability scanner against their environment. Starting one often produces alarming results - unpatched systems, open services, forgotten test machines still connected to the network.

Scope creep: This is not a practice, but it costs more than any individual gap. Small manufacturers often do not realize how many systems are "in scope" - the engineering workstation in the corner that has design files, the office PC someone used to download contract documents, the server that runs the CAD software. Every system that stores, processes, or transmits CUI is in scope. Defining and shrinking the scope before you start implementing is one of the highest-ROI activities in CMMC preparation.

A Realistic Implementation Sequence for Small Manufacturers

You cannot fix everything at once. Here is a prioritization approach that makes sense for a resource-constrained environment:

1

Define and shrink your scope

Map which systems touch CUI. Segment them from the rest of your environment if possible. Every system you keep out of scope is a system you do not have to assess or document. An IT consultant with CMMC experience can help you build a network diagram and define your CMMC assessment boundary.

2

Run a gap assessment

Use the SPRS Score Calculator at secreadynow.com/tools/sprs-calculator/ to self-assess all 110 practices. Be honest. The resulting score and gap list is your remediation roadmap. An inflated self-score does not help you - it just creates legal risk.

3

Fix the high-weight gaps first

Practices worth -5 points each are your priority. MFA (3.5.3), encryption at rest (3.13.16), audit logging (3.3.1), and malware protection (3.14.2) are all worth 5 points. Fix these before the low-weight items.

4

Get your documentation in place

A System Security Plan, 12 domain policies, and a POA&M for remaining gaps. The documentation is what assessors actually review - you can have perfectly configured systems and fail an assessment because you cannot show the paperwork. Write the SSP alongside your technical implementation, not after.

5

Conduct a practice assessment

Have someone walk through your controls as if they were an assessor before you pay for a C3PAO. Internal walk-throughs find gaps in evidence that are easy to fix when you have time, and expensive to discover during the actual assessment.

Should You DIY or Hire a Consultant?

Honest answer: a hybrid approach usually makes sense for small manufacturers. Pure DIY is difficult because the technical and documentation requirements are substantial and the standards language is ambiguous in places. Pure consultant is expensive and leaves you dependent on outside expertise for ongoing maintenance.

The practical split: hire a consultant for the initial gap assessment and scope definition. Use that output to prioritize your own team's effort for remediation and documentation. Bring the consultant back for a pre-assessment readiness review before the C3PAO assessment.

Templates - like a pre-written SSP or domain policy documents - can replace a significant portion of the documentation consultant cost, as long as you actually fill them in with your specific environment details rather than using them as-is. An untailored template that does not describe your actual systems will not pass a C3PAO review.

The Phase 2 Pause: Threat or Opportunity?

For small manufacturers, the Phase 2 suspension is genuinely an opportunity - not to stop working on compliance, but to close gaps without the pressure of an assessment deadline. The contractors who use this window productively will be in a dramatically better position than those who treat it as a break.

When Phase 2 resumes - possibly in 2027 with whatever modifications the Task Force recommends - C3PAO scheduling will be a bottleneck. Companies that are already documented and technically prepared will get through assessments faster and cheaper than companies that have to close large gaps under deadline pressure.

Start with the Documentation

The CMMC Level 2 Certification Kit gives you the SSP, POA&M, and all 12 domain policies in editable Word format. Fill in your environment details and you have the core of your evidence package.

View the Certification Kit - $299

Frequently Asked Questions

It depends on your contracts. If your contracts contain DFARS clause 252.204-7021 and you handle CUI at the Level 2 threshold, yes - CMMC Level 2 will eventually be required. If you only handle FCI (Federal Contract Information) without CUI, CMMC Level 1 applies - which is 17 practices, much less burdensome. Check your specific contract language and confirm with your contracting officer or prime contractor.
Technically yes, but practically it is difficult without some external help. The 110 practices require both technical implementation and detailed documentation. Most small manufacturers do not have staff with CMMC-specific experience. A hybrid approach - using a consultant for gap assessment and scope definition, handling documentation and some implementation internally - is usually the most cost-effective path.
Realistically 6 to 18 months from a standing start. The timeline depends on how many gaps you have, how quickly you can implement technical controls, and how fast your team can produce documentation. Organizations starting from near-zero take longer. Organizations that already have strong IT practices (MFA, endpoint management, logging) can move faster because the documentation layer is the primary remaining work.
There is no fixed minimum - it depends entirely on your starting point. A small manufacturer with many gaps could easily spend $100,000 to $200,000 in year one on technology, consulting, and assessment fees. A company that is already well-configured and needs primarily documentation support might spend $30,000 to $60,000. The DoD's aggregate cost estimate for SMBs across the DIB is over $7 billion annually, which works out to roughly $70,000 per company per year when spread across all affected contractors.
This is a real problem for some small manufacturers. Your options include: pursuing only contracts that do not require Level 2 (limiting your DoD market), partnering with a prime contractor that manages your CUI handling within their own CMMC-certified environment (reducing your scope), or joining a shared services model where CMMC infrastructure is provided to multiple small contractors collectively. Some DIB support organizations are developing shared CMMC infrastructure programs specifically for small manufacturers.

Related Resources

🔒

Get the Free CMMC Level 2 Practice Checklist

All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, instant access.