Why a small subcontractor is on the hook at all
If any of your revenue traces back to the Department of Defense, even through two or three layers of primes and subs, the security requirements in the prime contract flow down to you. Flow-down means the prime is contractually obligated to push those requirements onto its subcontractors, and primes are now asking small shops for proof, not promises.
I meet machine shops, logistics firms, and small IT vendors around Northern Virginia who assumed CMMC was a problem for the big primes. Then a questionnaire arrives from their biggest customer with a deadline attached. The companies that started early answer it calmly. The ones that did not are suddenly shopping for help with a contract at stake.
Level 1 versus Level 2 in plain language
Which level applies depends on what information touches your systems.
Federal Contract Information, or FCI, is non-public information you get or create while performing the contract: schedules, specs, ordinary contract correspondence. Handling only FCI puts you at Level 1, a set of 15 basic safeguarding practices, things like limiting who has accounts and keeping protections current. Level 1 is an annual self-assessment with a company executive affirming it. No outside assessor required.
Controlled Unclassified Information, or CUI, is sensitive but unclassified data the government specifically protects: technical drawings, certain performance data. Handling CUI puts you at Level 2, the 110 requirements of NIST SP 800-171, and for most contracts a formal third-party assessment. The jump from 15 practices to 110 requirements is the difference between a weekend project and a real program.
The SSP and the gap analysis, translated
Two documents drive readiness work.
The System Security Plan, or SSP, describes your environment and how each of the 110 requirements is met, or honestly, not yet met. Assessors read it first. An SSP full of aspirational language fools nobody.
The gap analysis compares your reality against the requirements and produces your starting score. The scoring scale runs from minus 203 to a perfect 110, and most companies I see score negative on their first honest pass. That is normal, not shameful.
Gaps become a Plan of Action and Milestones, a POA&M, which is a dated list of what you will fix and when. Under CMMC only a limited set of lower-weight items may remain open at assessment time, and they must close within 180 days, so a POA&M is a short runway, not a parking lot.
Realistic timelines and costs
Ranges vary with your starting point, but for a shop of roughly five to twenty people:
- A readiness gap assessment typically runs $3,000 to $15,000.
- Remediation is the big variable: commonly $15,000 to $75,000 or more across tooling, configuration work, and policy writing. Scoping CUI into a small enclave, meaning one contained environment instead of your whole network, is the single best way to shrink this number.
- The formal Level 2 assessment itself is a separate fee paid to the assessment organization, often tens of thousands of dollars.
On timeline, Level 1 is usually a few weeks to a few months of part-time effort. Level 2 readiness realistically takes six to eighteen months. If a customer deadline is twelve months out, you are not early. You are on time only if you start now.
Who can certify you, and who cannot
This part is a hard boundary, and any honest consultant will state it plainly.
Only a certified assessor working through an authorized C3PAO, a CMMC Third-Party Assessment Organization, can assess or certify you at Level 2. No consultant, no matter how experienced, can certify you. Anyone who says they will get you certified themselves is misrepresenting how the program works, and that alone should disqualify them.
What consultants legitimately do is readiness: the gap analysis, the SSP, the remediation, the preparation that makes the real assessment go smoothly. HashWhales works on exactly that side of the line. I advise on CMMC and NIST 800-171 readiness as a Cyber AB Registered Practitioner, and I do not and cannot assess or certify anyone. Keep your preparation help and your assessor separate, because that separation is how the program is designed to work.
What to do next
- Find out what you actually handle. Ask your prime, in writing, whether your contract involves FCI only or CUI, and which clauses flow down to you.
- If it is CUI, map where it lives: email, file shares, laptops, that one engineer's desktop. You cannot protect what you have not located.
- Get an honest gap assessment and a real starting score. Do not submit a guessed score; false scores carry legal risk under the False Claims Act.
- Shrink scope before you spend. An enclave for CUI often cuts remediation cost dramatically.
- Start the SSP early and keep it truthful.
If you want a plain-English readiness conversation before committing to anything, that is the work I do every week with small defense subcontractors around the DMV.
