CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense program that verifies contractors and subcontractors actually protect the government information they handle. It applies to any company whose contract, or whose customer's contract, includes the CMMC clause, and the level you must reach depends on whether you handle Federal Contract Information or the more sensitive Controlled Unclassified Information, known as CUI. For most small manufacturers and engineering firms on the Treasure Coast, that means Level 2.
What is CMMC compliance in plain terms?
For years defense contractors have been required by contract clause to follow the NIST SP 800-171 security standard, and they attested to it themselves. Self-attestation did not work well. CMMC keeps the same underlying requirements but adds verification: depending on your level, you either submit an annual self-assessment with an executive signing off on it, or you pass an independent assessment by a certified third-party assessor organization, usually called a C3PAO.
The program is being phased into new contracts over several years, and prime contractors are already asking their suppliers about status. If you machine parts, build cable assemblies, write software, provide engineering services, or even do calibration work that flows up to a defense prime, expect the question.
Which contractors need CMMC?
The rule of thumb is that CMMC follows the data, not the company size. You need it if:
- You hold a DoD contract directly and the solicitation includes the CMMC requirement.
- You are a subcontractor at any tier and your customer flows the requirement down to you, which they must do if you receive covered information.
- You receive drawings, specifications, technical data, or other files marked as CUI, or that would be marked if the government had labeled them properly.
Companies that only sell commercial off-the-shelf items with no government information involved are generally exempt. Pure commercial work is out of scope, but a shop doing both needs to be careful about where defense drawings go.
On the Treasure Coast this touches more businesses than people assume: precision machine shops in Indian River and St. Lucie counties, composites and marine fabricators near the Fort Pierce and Stuart waterfronts who take on Navy or Coast Guard work, avionics and electronics shops near the airports, and the engineering and IT consultants who support them.
How does CUI determine your CMMC level?
Level 1: Federal Contract Information
If you only handle basic contract information that is not meant for public release, such as purchase orders and delivery schedules, Level 1 applies. It has 15 basic practices, things like using antivirus, changing default passwords, and limiting who can log in. It requires an annual self-assessment.
Level 2: Controlled Unclassified Information
If you receive CUI, which includes most technical drawings, specifications, and export-controlled data, Level 2 applies. It aligns with the 110 requirements of NIST SP 800-171 across 14 areas, including access control, audit logging, configuration management, incident response, media protection, and system integrity. Most Level 2 contracts will require a third-party assessment every three years with an annual affirmation in between; a smaller subset allows self-assessment.
Level 3: Critical programs
Level 3 adds requirements from NIST SP 800-172 and is assessed by the government itself. It applies to a small number of high-priority programs and is unlikely to affect a typical Treasure Coast subcontractor.
What does the assessment process look like?
- Scoping. Identify every system, person, and location that stores, processes, or transmits CUI. Scoping well is the single most important cost decision: a shop that keeps CUI in a small enclave of a few workstations and a controlled file server has far less to assess than one where drawings live on every machine and in personal email.
- Gap assessment. Compare current practice to each of the 110 requirements and score using the DoD methodology. Nearly every small business starts with significant gaps, usually around multi-factor authentication, logging, encrypted removable media, and written policies.
- Remediation. Close the gaps. Some are technical, such as deploying MFA and centralized logging; many are documentation, such as a system security plan and incident response procedures.
- Self-assessment and SPRS score. Submit your score to the Supplier Performance Risk System. Primes look at this number.
- C3PAO assessment. For Level 2 certification, an accredited assessor reviews evidence, interviews staff, and tests controls. A limited number of items can be on a time-boxed plan of action; most must be fully met.
- Maintain. Annual affirmations, continuous monitoring, and reassessment every three years.
How should a small manufacturer prepare for CMMC?
The businesses that get through this affordably do a few things right.
- Shrink the boundary. Decide where CUI is allowed to live and keep it there. A dedicated engineering workstation group, a controlled file share or a government-cloud tenant such as Microsoft 365 GCC High, and a policy that CUI never touches personal devices or ordinary email dramatically reduces scope.
- Fix the basics early. Multi-factor authentication everywhere, endpoint detection and response on every machine, full-disk encryption on laptops, centralized log retention, and tested backups. These are also what your cyber-insurance carrier wants, so the work pays twice.
- Write the policies as you go. Assessors want evidence that practices are documented and followed, not just configured. A system security plan, access control policy, incident response plan, and training records are mandatory, not optional.
- Train the shop floor. Machinists and program managers handle drawings every day. They need to know what CUI looks like, how to store it, and what to do if it ends up somewhere it should not.
- Plan for hurricane season. Physical protection and backup requirements in 800-171 map neatly onto the storm preparedness Florida businesses should have anyway; a documented shutdown and recovery plan counts as evidence.
What does CMMC cost a small business?
Honest answer: it depends on your starting point and scope. The technical remediation for a well-run shop that already has managed IT is often modest; the documentation effort and the third-party assessment fee are the larger items, and assessment costs are widely reported to run into the tens of thousands of dollars for Level 2. Shops starting from consumer-grade IT should budget for a multi-month project. The alternative is losing the contract, which is usually the more expensive outcome.
MainSail Data helps Treasure Coast manufacturers and contractors scope their CUI boundary, close NIST 800-171 gaps, and produce assessment-ready documentation through our compliance services, usually as part of a managed IT relationship so the controls stay in place after the assessor leaves. If a prime has asked about your CMMC status, call (772) 794-1194 or request a free readiness review and we will tell you plainly where you stand.

