Who Actually Needs CMMC Compliance
CMMC compliance for small business only applies if your company holds, or plans to bid on, a direct or subcontract with the U.S. Department of Defense (DoD) that involves federal contract data. The Cybersecurity Maturity Model Certification (CMMC) is a DoD program that verifies contractors and subcontractors in the Defense Industrial Base (DIB), the network of companies that supply goods and services to the military, meet a required level of cybersecurity controls before they can win or keep certain contracts. If your business has no DoD contracts, direct or through a prime contractor, CMMC does not apply to you, though the underlying practices it requires are still worth reviewing.
Quick Answer
CMMC compliance is required only for businesses in the Defense Industrial Base: a company with a direct DoD contract, or a subcontract under one, that will handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Most small businesses that qualify need either Level 1 (FCI only, self-assessed annually) or Level 2 (CUI, built on 110 NIST SP 800-171 controls, self-assessed or third-party assessed depending on the contract). If you don't do business with the DoD, CMMC doesn't apply, but the FTC Safeguards Rule or HIPAA Security Rule may still govern your data protection obligations.
The Three CMMC Levels
CMMC 2.0 has three levels tied to the sensitivity of the information a contractor handles. Level 1 (Foundational) covers 17 basic safeguarding practices for companies that only process FCI, information not intended for public release that's provided by or generated for the government under a contract. Level 2 (Advanced) applies to companies handling CUI, unclassified information that still requires safeguarding under federal law or agency policy. According to the DoD's CMMC program office, Level 2 requires implementing 110 security controls drawn from NIST Special Publication 800-171. Level 3 (Expert) adds controls from NIST SP 800-172 for a small number of contracts involving the most sensitive CUI and is government-assessed; it rarely applies to small businesses.
CMMC 2.0 Levels at a Glance
Data protected
- Level 1: Foundational
- Federal Contract Information (FCI)
- Level 2: Advanced
- Controlled Unclassified Information (CUI)
Number of practices
- Level 1: Foundational
- 17
- Level 2: Advanced
- 110, based on NIST SP 800-171
Assessment type
- Level 1: Foundational
- Annual self-assessment
- Level 2: Advanced
- Self-assessment or third-party (C3PAO) assessment, depending on the contract
Typical small business fit
- Level 1: Foundational
- Subcontractors handling basic contract data
- Level 2: Advanced
- Subcontractors handling technical, program, or engineering data
| Feature | Level 1: Foundational | Level 2: Advanced |
|---|---|---|
| Data protected | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
| Number of practices | 17 | 110, based on NIST SP 800-171 |
| Assessment type | Annual self-assessment | Self-assessment or third-party (C3PAO) assessment, depending on the contract |
| Typical small business fit | Subcontractors handling basic contract data | Subcontractors handling technical, program, or engineering data |
How to Tell If CMMC Applies to Your Business
Ask three questions before you assume CMMC affects you. First, do you or a prime contractor you support hold a DoD contract or respond to DoD solicitations? Second, does that work involve FCI or CUI rather than purely commercial data? Third, does the solicitation or contract include DFARS clause 252.204-7021, the clause that specifies a required CMMC level? If you answer yes to all three, you'll need to meet the level your contract specifies before award or renewal.
If your business is an accounting firm, tax practice, healthcare office, or general small business with no DoD ties, CMMC isn't the compliance framework to focus on. You're more likely governed by the FTC Safeguards Rule, IRS Publication 4557, or the HIPAA Security Rule, and a written information security plan addresses those obligations directly.
Action Checklist: Preparing for a CMMC Assessment
- Confirm whether your contract or subcontract requires CMMC Level 1 or Level 2, and by what date
- Identify where FCI or CUI lives in your systems and define your assessment boundary
- Map current controls against NIST SP 800-171 (for Level 2) and document the gaps
- Write or update a System Security Plan (SSP) and Plan of Action and Milestones (POA&M)
- Implement required technical controls: access control, multi-factor authentication, endpoint protection, audit logging, and incident response
- Submit your self-assessment score to the DoD's Supplier Performance Risk System (SPRS), or schedule an assessment with a certified C3PAO if your contract requires one
Rollout Timeline
The DoD finalized the CMMC 2.0 program rule (32 CFR Part 170) in late 2024, and contracting officers are expected to add CMMC requirements to new solicitations on a phased basis through 2028, according to the DoD's CMMC program office. Check your specific solicitation or contract clause for the exact date your requirement takes effect, since the rollout schedule can shift.
Where Managed Security Fits Into CMMC Readiness
CMMC certification is issued through self-assessment or by an accredited third-party assessor organization (C3PAO), not by a security vendor. What a managed security provider can help with is building and maintaining the technical controls NIST SP 800-171 requires, which is often the hardest part for a small business without an in-house IT team. Managed endpoint security for small business supports the system and information integrity control family; multi-factor authentication and access monitoring support the access control family; centralized logging and alerting support the audit and accountability family; and a documented response process supports the incident response family required for small business ransomware protection.
If you're deciding whether to build these controls in-house or bring in outside help, our guide on cybersecurity company vs MSP and managed security service provider comparisons can help you scope the decision. Larger subcontractors preparing for a Level 2 assessment often benefit from penetration testing and a structured review of enterprise security for small business to close gaps before a C3PAO ever looks at their environment.
Build the Technical Controls CMMC Requires
Bellator Shield and Bellator Core provide managed endpoint detection and response, monitoring, and incident response support that map to core NIST SP 800-171 control families. Compare plans to see what fits your environment before your assessment.
Frequently Asked Questions
Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn't intended for public release; it triggers CMMC Level 1. Controlled Unclassified Information (CUI) is unclassified information that requires safeguarding under federal law, regulation, or agency policy, such as technical drawings or program details; it triggers CMMC Level 2.
It applies to subcontractors too. If a small business handles FCI or CUI as part of a subcontract under a prime DoD contractor, the prime can require the subcontractor to meet the applicable CMMC level as a condition of the subcontract.
Cost depends on your company size, scope, and whether you need a Level 1 self-assessment or a Level 2 third-party assessment through a C3PAO. There's no fixed government fee for self-assessment beyond your own preparation time; C3PAO assessment costs vary by scope, so ask prospective assessors for a quote based on your specific environment rather than relying on a flat estimate.
Only if they hold a DoD contract or subcontract involving FCI or CUI, which is uncommon for most tax, accounting, and healthcare practices. These practices are typically governed instead by the FTC Safeguards Rule, IRS Publication 4557, or the HIPAA Security Rule.
From requirement to defensible practice
Turn the requirement into a security plan people can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring EDR, MDR & RMM
Compare managed security options, understand pricing, and decide what level of endpoint oversight fits a smaller organization.
- Common question: MDR pricingCompare MDR and EDR pricingSee the cost drivers, coverage differences, and tradeoffs behind common managed detection options.
- Common question: EDR cost per endpointCalculate EDR total cost of ownershipLook beyond the license price to setup, monitoring, response, and internal labor.
- Common question: EDR for small businessUnderstand EDR for a small businessLearn what endpoint detection changes compared with traditional antivirus.
- Common question: EDR vs MDR vs XDRCompare EDR, MDR, and XDRMatch each model to the visibility, staffing, and response help your organization needs.
- Common question: what does RMM stand forLearn how RMM supports managed ITSee how remote monitoring and management keeps devices patched, visible, and supportable.

