Skip to content
Bellator Cyber Guard
Small Business13 min readStandard

CMMC Compliance for Small Business: What to Know

CMMC compliance for small business explained: who actually needs it, the level requirements, and how to prepare in 2026. Get practical next steps.

By Bellator Cyber Guard Security Team

Who Actually Needs CMMC Compliance

CMMC compliance for small business only applies if your company holds, or plans to bid on, a direct or subcontract with the U.S. Department of Defense (DoD) that involves federal contract data. The Cybersecurity Maturity Model Certification (CMMC) is a DoD program that verifies contractors and subcontractors in the Defense Industrial Base (DIB), the network of companies that supply goods and services to the military, meet a required level of cybersecurity controls before they can win or keep certain contracts. If your business has no DoD contracts, direct or through a prime contractor, CMMC does not apply to you, though the underlying practices it requires are still worth reviewing.

Quick Answer

CMMC compliance is required only for businesses in the Defense Industrial Base: a company with a direct DoD contract, or a subcontract under one, that will handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Most small businesses that qualify need either Level 1 (FCI only, self-assessed annually) or Level 2 (CUI, built on 110 NIST SP 800-171 controls, self-assessed or third-party assessed depending on the contract). If you don't do business with the DoD, CMMC doesn't apply, but the FTC Safeguards Rule or HIPAA Security Rule may still govern your data protection obligations.

The Three CMMC Levels

CMMC 2.0 has three levels tied to the sensitivity of the information a contractor handles. Level 1 (Foundational) covers 17 basic safeguarding practices for companies that only process FCI, information not intended for public release that's provided by or generated for the government under a contract. Level 2 (Advanced) applies to companies handling CUI, unclassified information that still requires safeguarding under federal law or agency policy. According to the DoD's CMMC program office, Level 2 requires implementing 110 security controls drawn from NIST Special Publication 800-171. Level 3 (Expert) adds controls from NIST SP 800-172 for a small number of contracts involving the most sensitive CUI and is government-assessed; it rarely applies to small businesses.

CMMC 2.0 Levels at a Glance

Data protected

Level 1: Foundational
Federal Contract Information (FCI)
Level 2: Advanced
Controlled Unclassified Information (CUI)

Number of practices

Level 1: Foundational
17
Level 2: Advanced
110, based on NIST SP 800-171

Assessment type

Level 1: Foundational
Annual self-assessment
Level 2: Advanced
Self-assessment or third-party (C3PAO) assessment, depending on the contract

Typical small business fit

Level 1: Foundational
Subcontractors handling basic contract data
Level 2: Advanced
Subcontractors handling technical, program, or engineering data

How to Tell If CMMC Applies to Your Business

Ask three questions before you assume CMMC affects you. First, do you or a prime contractor you support hold a DoD contract or respond to DoD solicitations? Second, does that work involve FCI or CUI rather than purely commercial data? Third, does the solicitation or contract include DFARS clause 252.204-7021, the clause that specifies a required CMMC level? If you answer yes to all three, you'll need to meet the level your contract specifies before award or renewal.

If your business is an accounting firm, tax practice, healthcare office, or general small business with no DoD ties, CMMC isn't the compliance framework to focus on. You're more likely governed by the FTC Safeguards Rule, IRS Publication 4557, or the HIPAA Security Rule, and a written information security plan addresses those obligations directly.

Action Checklist: Preparing for a CMMC Assessment

  • Confirm whether your contract or subcontract requires CMMC Level 1 or Level 2, and by what date
  • Identify where FCI or CUI lives in your systems and define your assessment boundary
  • Map current controls against NIST SP 800-171 (for Level 2) and document the gaps
  • Write or update a System Security Plan (SSP) and Plan of Action and Milestones (POA&M)
  • Implement required technical controls: access control, multi-factor authentication, endpoint protection, audit logging, and incident response
  • Submit your self-assessment score to the DoD's Supplier Performance Risk System (SPRS), or schedule an assessment with a certified C3PAO if your contract requires one

Rollout Timeline

The DoD finalized the CMMC 2.0 program rule (32 CFR Part 170) in late 2024, and contracting officers are expected to add CMMC requirements to new solicitations on a phased basis through 2028, according to the DoD's CMMC program office. Check your specific solicitation or contract clause for the exact date your requirement takes effect, since the rollout schedule can shift.

Where Managed Security Fits Into CMMC Readiness

CMMC certification is issued through self-assessment or by an accredited third-party assessor organization (C3PAO), not by a security vendor. What a managed security provider can help with is building and maintaining the technical controls NIST SP 800-171 requires, which is often the hardest part for a small business without an in-house IT team. Managed endpoint security for small business supports the system and information integrity control family; multi-factor authentication and access monitoring support the access control family; centralized logging and alerting support the audit and accountability family; and a documented response process supports the incident response family required for small business ransomware protection.

If you're deciding whether to build these controls in-house or bring in outside help, our guide on cybersecurity company vs MSP and managed security service provider comparisons can help you scope the decision. Larger subcontractors preparing for a Level 2 assessment often benefit from penetration testing and a structured review of enterprise security for small business to close gaps before a C3PAO ever looks at their environment.

Build the Technical Controls CMMC Requires

Bellator Shield and Bellator Core provide managed endpoint detection and response, monitoring, and incident response support that map to core NIST SP 800-171 control families. Compare plans to see what fits your environment before your assessment.

Frequently Asked Questions

Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn't intended for public release; it triggers CMMC Level 1. Controlled Unclassified Information (CUI) is unclassified information that requires safeguarding under federal law, regulation, or agency policy, such as technical drawings or program details; it triggers CMMC Level 2.

It applies to subcontractors too. If a small business handles FCI or CUI as part of a subcontract under a prime DoD contractor, the prime can require the subcontractor to meet the applicable CMMC level as a condition of the subcontract.

Cost depends on your company size, scope, and whether you need a Level 1 self-assessment or a Level 2 third-party assessment through a C3PAO. There's no fixed government fee for self-assessment beyond your own preparation time; C3PAO assessment costs vary by scope, so ask prospective assessors for a quote based on your specific environment rather than relying on a flat estimate.

Only if they hold a DoD contract or subcontract involving FCI or CUI, which is uncommon for most tax, accounting, and healthcare practices. These practices are typically governed instead by the FTC Safeguards Rule, IRS Publication 4557, or the HIPAA Security Rule.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn the requirement into a security plan people can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring EDR, MDR & RMM

Compare managed security options, understand pricing, and decide what level of endpoint oversight fits a smaller organization.