If you handle Controlled Unclassified Information (CUI) for the Department of Defense, CMMC 2.0 requires you to implement all 110 security requirements in NIST SP 800-171 Rev. 2 at Level 2. If you only handle Federal Contract Information (FCI), Level 1 applies, with 15 basic safeguards. Either way, three actions can’t wait:
- Confirm whether your contracts, drawings, or files actually contain CUI.
- Start documenting your assessment scope and building a System Security Plan (SSP).
- Decide now whether you’ll pursue Level 2 self-assessment or need a C3PAO, since certified assessor availability is tightening.
Key Takeaways
CMMC 2.0 compliance hinges on correctly scoping CUI, implementing all 110 NIST SP 800-171 requirements at Level 2, and maintaining evidence that proves controls operated over time.
| Point | Details |
|---|---|
| Identify your level first | Confirm whether you handle FCI (Level 1, 15 safeguards) or CUI (Level 2, 110 requirements) before doing anything else. |
| Scope before you remediate | Isolate CUI into a defined enclave using the four asset categories to shrink your assessment surface. |
| Evidence beats policy | Assessors need logs, dated procedures, and records proving controls operated over time, not just written policy. |
| Plan around assessor queues | Engage a C3PAO early if certification is required, since limited assessor capacity can add months to your timeline. |
| Choose a documentation-ready partner | Machiningtechllc supports defense suppliers with segregated production runs and tracked change control for CMMC-sensitive components. |
Table of Contents
- Understanding CMMC 2.0 Requirements: Levels, Triggers, and Rules
- What Level 2 Actually Demands From Your Systems
- Self-Assessment vs. C3PAO: Choosing Your Path and Scoping It Right
- Building the Evidence Trail: SSP, Logs, and SPRS Submission
- Your CMMC Readiness Checklist: Timeline and Cost Planning
- A Manufacturer’s Approach to Scoping CUI on the Shop Floor
- Level 1 Requirements: The Baseline Most Contractors Overlook
- Why Timelines Get Underestimated
- How Machining Technologies Supports CMMC-Ready Production
- Sources
Understanding CMMC 2.0 Requirements: Levels, Triggers, and Rules
CMMC 2.0 has three levels, and which one applies to you depends entirely on the data you touch. Level 1 covers companies handling only FCI, basic contract information not meant for public release. Level 2 applies once CUI enters the picture, requiring full alignment with NIST SP 800-171 Rev. 2. Level 3 sits on top of that for a smaller group of contractors working with the most sensitive programs, adding requirements beyond the Level 2 baseline.
The rules governing all this aren’t buried in a vendor’s marketing page. They live in 32 CFR Part 170, the federal rule that establishes the CMMC program itself, plus DFARS clauses that get written directly into DoD solicitations and FAR 52.204-21 for basic safeguarding of FCI.
Here’s what trips people up: your CMMC obligation often isn’t stated plainly in your own contract. It flows down. A prime contractor negotiating a CUI-heavy award will push the same Level 2 requirement onto every subcontractor touching that data, sometimes several tiers deep. If you’re a small machine shop supplying a Tier 2 subcontractor, read your flow-down clauses carefully, because your certification requirement was likely decided by someone else’s contract, not yours.
What Level 2 Actually Demands From Your Systems
Level 2 means implementing all 110 requirements across 14 control families defined in NIST SP 800-171 Rev. 2. That’s not a checkbox exercise. The CMMC Assessment Guide for Level 2 organizes every requirement by domain and tells assessors exactly what to examine, whom to interview, and what to test before marking an objective MET, NOT MET, or NOT APPLICABLE.
A few families carry outsized weight in practice:
- Access Control: limiting system access to authorized users and enforcing least privilege.
- Audit and Accountability: generating and retaining logs that prove events actually happened, not just that logging is theoretically enabled.
- Identification and Authentication: multifactor authentication for both local and network access to CUI systems.
- System and Communications Protection: encrypting CUI at rest and in transit.
- Incident Response: a tested plan, not a document that’s never been exercised.
The CMMC Assessment Guide uses NIST SP 800-171A assessment objectives to judge whether a control is genuinely operating, not merely written into policy. That distinction fails more contractors than any single technical gap. A firewall rule that exists on paper but was never verified in production won’t satisfy an assessor.
Certain requirements also can’t sit on a Plan of Action and Milestones (POA&M) indefinitely. MFA, FIPS-validated encryption, and a handful of other high-priority controls generally need to be fully implemented before certification, since a POA&M is meant to close minor gaps, not carry your core security posture.
Self-Assessment vs. C3PAO: Choosing Your Path and Scoping It Right
Most Level 2 contractors fall into one of two lanes. Self-assessment lets you evaluate your own environment against the 110 requirements and submit your score directly into the Supplier Performance Risk System (SPRS). Third-party certification requires a Certified Third-Party Assessment Organization (C3PAO), which uploads results into eMASS before you receive a Certificate of CMMC Status and your score lands in SPRS.
Which path applies depends on your contract, not your preference, so check your solicitation language before assuming self-assessment is an option.
Scoping determines how much of your business actually falls under the microscope. The CMMC Scoping Guide for Level 2 breaks assets into four categories:
- CUI assets that process, store, or transmit CUI directly.
- Security protection assets that provide security functions for the CUI environment, like your SIEM or firewall.
- Specialized assets such as IoT devices, OT, or government furnished equipment that can’t run standard security controls.
- Out-of-scope assets that are logically or physically separated from CUI and can’t reach it.
You’ll need an asset inventory and network diagram documenting every category before an assessor looks at anything else.
Pro Tip: Isolating CUI into a dedicated network enclave, rather than letting it touch your whole business network, is the single fastest way to shrink your assessment scope and your remediation bill.
Building the Evidence Trail: SSP, Logs, and SPRS Submission
Your SSP is the backbone document. It maps each of the 110 requirements to how you actually implement it, names the responsible party, and describes the procedure in enough detail that a stranger could verify it. Assessors don’t just read the SSP, though. They test it against reality.
The Cyber AB’s assessment process framework makes clear that C3PAO assessors verify evidence against NIST SP 800-171A objectives, and a documented SSP paired with persistent evidence showing controls operated over time is where most organizations get stuck. A policy that says MFA is required means nothing without login logs proving it’s enforced.
Evidence assessors commonly ask for includes:
- Configuration exports from firewalls, servers, and endpoint tools.
- SIEM or log management exports covering weeks or months, not a single snapshot.
- Current user access lists showing least-privilege enforcement.
- Security awareness training completion records.
- Change management logs and dated network diagrams.
Once you’re ready, submission goes through SPRS, and an Affirming Official inside your company must annually certify continued compliance, a signature with real legal weight behind it.
Your CMMC Readiness Checklist: Timeline and Cost Planning
Work through this roughly in order:
- Review active and upcoming contracts to identify your required CMMC level.
- Inventory where CUI lives and define your assessment scope.
- Build or update your SSP against all 110 requirements.
- Remediate high-priority gaps, MFA and encryption first.
- Collect evidence over a period of weeks, not days, so logs show sustained operation.
- Schedule your self-assessment or engage a C3PAO.
Realistic budgeting matters here. Remediation for an open POA&M item typically needs to close within 180 days of a conditional certification. C3PAO capacity is limited, and engaging one early matters because queues can add months to your timeline before an assessor ever walks in the door.
Costs vary widely by company size and current maturity, but expect spending across three buckets: technical remediation (tools like SIEM, MFA, encryption), documentation effort (SSP development, either internal or through outside consulting like the guidance found in Symmnet’s CMMC 2.0 breakdown), and the assessment fee itself if you’re going the C3PAO route.
A Manufacturer’s Approach to Scoping CUI on the Shop Floor

Picture a machine shop running both commercial and defense work on the same floor. The smart move isn’t certifying the entire facility. It’s isolating the engineering file server, CAD/CAM workstations, and the CNC program repositories touching defense drawings into one documented enclave, with everything else logically separated and out of scope.
Machine shops often lack one thing assessors specifically look for: dated change-control records showing who modified a CNC program and when, plus a labeled repository proving which drawings actually carry CUI markings.
Correct scoping is what separates a two-week assessment from a six-month one. Facilities that isolate CUI to a defined enclave, rather than opening the whole floor to review, consistently move faster through certification.
Pro Tip: Label your engineering drawing repository by classification the day you receive a contract, not the week before your assessment.
Level 1 Requirements: The Baseline Most Contractors Overlook
Level 1 doesn’t get the attention Level 2 does, but it applies to far more contractors, anyone handling FCI without CUI. FCI is information provided by or generated for the government under contract that isn’t intended for public release. Think purchase orders, technical specs shared for a bid, or basic program details, information that’s sensitive in a business sense but doesn’t carry the classification weight of CUI.
Level 1 requires implementing 15 basic safeguarding requirements drawn from FAR 52.204-21. These cover fundamentals: limiting system access to authorized users, verifying identity before granting access, sanitizing media before disposal or reuse, restricting physical access to systems and facilities, and monitoring for unauthorized connections.
The good news for Level 1 contractors: no third-party assessment is required. You self-assess annually and submit an affirmation, with no SPRS score submission tied to a numeric scoring model the way Level 2 sometimes involves. That said, don’t mistake “basic” for “optional.” Every one of the 15 requirements has to actually be implemented and documented, and an Affirming Official still puts their name behind the annual certification.
For a small supplier that only exchanges basic order data with a prime, Level 1 might be the entire compliance journey. But contracts change. A supplier that starts receiving technical drawings marked CUI has effectively jumped into Level 2 territory, whether or not their contract has been formally updated to reflect it. Watch what data you’re actually receiving, not just what your contract said on day one.

Why Timelines Get Underestimated
Manufacturers preparing for Level 2 usually need more calendar time than they expect, mostly because evidence has to accumulate, not just get written. Reach out if you want to talk through what a compliance-ready production partnership looks like for your supply chain.
— Andrew
How Machining Technologies Supports CMMC-Ready Production
Segregating a production run for defense work isn’t just good practice, it’s often exactly what an assessor wants to see documented. Machiningtechllc has run defense and firearms component work on dedicated equipment with tracked change control since 1985, long before “CUI enclave” was a term anyone used.

That means engineering drawings get handled through a documented chain, machine programs carry version history, and production runs for sensitive components stay logically and physically separated from general commercial work. If your SSP needs to show a subcontractor with real change-control discipline and secure drawing handling, not just a promise of it, that’s the kind of evidence an assessor wants to see backing your supply chain. Explore subcontract machining services built for OEMs and defense suppliers who need a production partner that already understands what documentation looks like under a DFARS clause. Request a quote to talk through your next compliance-sensitive production run.
Sources
Recommended
- Machinist Certifications Explained for OEM Procurement | Machining Technologies
- Achieve Consistent Quality Assurance in Firearms Parts | Machining Technologies
- How to verify machined part quality: methods for aerospace OEMs | Machining Technologies
- Industrial machining safety protocols: Proven compliance tips | Machining Technologies


