Skip to main content

CMMC Pause: What DoW & Primes Still Require

  • blog
  • CMMC for Small Business: Requirements, Costs, and How to Reduce Them

CMMC for Small Business: Requirements, Costs, and How to Reduce Them

  • August 13, 2026
Author

Anna Fitzgerald

Senior Content Marketing Manager

Estimates from the DoD and NSA put small businesses at roughly three quarters of the Defense Industrial Base (DIB).

Because small businesses are the backbone of the DIB, they are a target of adversaries. Enhancing their cybersecurity and operational resilience as well as companies at every tier of the defense supply chain has been the focus of the DoD for years, culminating in the development and rollout of the CMMC program.

However, the DoD, now more commonly referred to by the secondary official title Department of War (DoW), recently paused the CMMC rollout and put the program under review for the stated purpose of reducing the “prohibitive compliance costs and bureaucratic burdens” on small businesses as well as mid-sized and non-traditional companies.

One thing that hasn't changed is the underlying security requirement. If you handle Controlled Unclassified Information (CUI) under a defense contract or subcontract, all 110 requirements of NIST SP 800-171 Rev 2 are still required today under DFARS 252.204-7012 and CMMC Phase 1 self-assessment requirements remain firmly in place. While compliance is continuing to be enforced through self-assessments and select government-led assessments during this interim period, what's being reconsidered is how the government uses third-party assessments (C3PAO and DIBCAC) to verify that you've met them.

We’ve written this guide for all the small businesses that make up the backbone of the DIB, covering CMMC and the underlying security requirements and realistic costs, practical ways to bring those costs down, the government programs built to help, and what the current review and reform could change.

A note on naming: Existing CMMC rules, clauses, and source documents still read "Department of Defense (DoD)," so this post uses DoD, the Department, and DoW depending on which is accurate for the document being cited.

Recommended reading

CMMC Phase 2 Paused: Which Requirements Still Apply After the Latest DoW Announcement and Prime Notices?

Do small businesses need CMMC?

Yes, if your small business handles FCI or CUI under a DoD contract, you need CMMC. CMMC applies to every organization in the defense supply chain regardless of size, with requirements rolling out in contracts from the Department directly or flowing down from primes to subcontractors at every tier.

The practical reality for most small businesses:

  • If you only handle FCI → you need Level 1 (15 requirements, self-assessment, relatively low cost)
  • If you handle CUI → you likely need Level 2 (110 requirements, self- or third-party assessment, potentially costly)

Most small subcontractors fall into Level 1 or Level 2. Level 3 is reserved for the most critical programs facing advanced persistent threats, which the DoD estimated as less than 1% of the entire DIB.

Two points are worth emphasizing here. First, being a small business doesn't exempt you from CMMC. There is no small business exemption in 32 CFR Part 170, and while the current program review is focused on reducing small business burden, the DoW has not cancelled the existing program or proposed changes. Phase 1 self-assessment requirements remain firmly in place.

Second, your prime operates on its own timeline. Many primes have been sending flowdown and verification requests ahead of the government's rollout schedule, driven by supply chain risk management rather than the CMMC phases. Those requests have generally continued even as the government transition to Phase 2 and other implementation milestones has shifted.

Elbit America’s supplier notice that was sent out the same week as the DoW’s announcement, for example, told suppliers to continue implementing NIST SP 800-171 and be prepared to complete a CMMC Level 2 (Self) assessment when required. They also said to confirm the applicable requirement with their Elbit America buyer “before scheduling or cancelling a C3PAO assessment,” indicating that existing third-party assessment requirements may still apply to subcontractors even during the DoW’s pause.

So the practical starting point for your CMMC cybersecurity program is your contract rather than the government rollout calendar. Review your DFARS clauses and confirm with your prime what data and CMMC assessment requirement is actually flowing down to you.

Recommended reading

Who Needs CMMC? Defense Contractor Requirements in 2026

CMMC requirements for small businesses

CMMC requirements for a small business come down to four steps: determine your level, implement the security requirements for that level, document how you meet them, and complete the assessment your contract calls for. Here's a closer look at each.

1. Determine your level

The first and most important step is understanding what data you handle and what your contracts require. If you're unsure, check with your prime contractor and review your contract's DFARS clauses.

  • Level 1 applies to organizations handling only FCI (contract-related information like contract performance reports)
  • Level 2 applies to most organizations handling CUI (controlled unclassified data like technical drawings or specifications)

This step is worth spending real time on, since it determines the scope of everything that follows. If you assume you need Level 1 when your contract actually involves CUI, you may end up losing the bid due to our inability to prove you’re capable of protecting this type of data.

Overclassification of unclassified data as CUI is also a common complaint across the DIB, which would expand your scope, costs, and operational burden when CMMC Level 1 might have satisfied your contractual obligation so it's worth confirming with your DoW contracting officer or prime rather than assuming.

Defining FCI and CUI for CMMC small business requirements

Recommended reading

CMMC Levels Explained: Level 1 vs 2 vs 3

2. Implement the underlying cybersecurity requirements at your level

Level 1 includes 15 basic safeguarding requirements from FAR 52.204-21 and 54 assessment objectives. These cover fundamental security hygiene: access controls, user identification, media sanitization, physical protection, and basic system and communications protections. They also represent a subset of NIST 800-171 requirements that have been tailored for FCI instead of CUI, as marked in the CMMC.com Requirement Explorer for Level 2.

Level 2 includes all 110 requirements in NIST SP 800-171 Rev 2 and 320 assessment objectives. Requirements span 14 control families including access control, audit and accountability, incident response, risk assessment, system and communications protection, and more.

CMMC access control requirements from Level 1 built on and expanded in Level 2

Recommended reading

CMMC Requirements: All Domains and Controls by Level

Step 3: Document your compliance posture

Regardless of level, you'll need a System Security Plan (SSP) that documents how your organization meets each requirement and assessment objective of your required level.

To achieve a Final Level 1 status, all requirements must be fully implemented. For Level 2, organizations can achieve a conditional status with a Plan of Action and Milestones (POA&M) that documents certain requirements that haven't been implemented at the time of assessment. These open items must be closed within 180 days.

These documents are not optional. They're core deliverables that assessors, primes, or DoD contracting officials may review, and they're what keeps your program defensible over time. They also carry legal weight, since your SSP and POA&M along with your SPRS score and affirmation of compliance are the records that would likely be examined if the accuracy of your compliance claims were ever questioned under the False Claims Act.

Recommended reading

CMMC System Security Plan (SSP): What to Include + Template

Step 4: Complete your assessment

Level 1 requires an annual self-assessment, with the results and an affirmation of compliance submitted to the Supplier Performance Risk System (SPRS).

Level 2 has two paths under the 32 CFR CMMC program rule: a triennial third-party assessment conducted by a CMMC Third-Party Assessment Organization (C3PAO), or a self-assessment for a smaller set of contracts involving non-critical CUI. Under the 32 CFR rule, the DoD estimated the vast majority of Level 2 contractors (95%) would require third-party assessments.

What applies right now: On July 13, 2026, the Department of War paused the transition to CMMC Phase 2, which would have made Level 2 (C3PAO) certification the default for a condition of award on most CUI contracts beginning November 10, 2026. During the pause, requiring activities may designate only Level 1 (Self) or Level 2 (Self), and existing C3PAO and DIBCAC designations must be amended out of active solicitations and awarded contracts at the next option exercise or scheduled modification.

Until your specific contract is modified, the clause on it is still the clause on it, so confirm the status of your awards in writing rather than assuming. Confirm the applicable CMMC requirement in your purchase order with any prime contractor as well.

During this interim period, DFARS 252.204-7012 still requires you to implement NIST SP 800-171 Rev 2 and report cyber incidents, CMMC self-assessments and SPRS submissions are still required, annual affirmations still carry legal weight, and primes are still asking.

For most small businesses, then, a self-assessment is likely required today. The implementation and maintenance behind that assessment is the same that a third-party assessment would have evaluated, so the work is largely identical. Completing it now will help ensure you’re prepared for whatever verification requirements remain in place or return.

Recommended reading

CMMC Self-Assessment Guide: Level 1 and Level 2 Process

How much does CMMC cost for a small business?

There is no single answer, and the published estimates vary widely. For example, the DoD and SBA have put out very different numbers, with a gap of roughly 5x between the low and high ends. Understanding why they differ is useful, because it tells you which parts of the work each estimate is actually pricing.

SourceLevel 2 self-assessmentLevel 2 with C3PAO assessmentWhat the estimate covers
DoD, 32 CFR program rule~$37,000 to $49,000~$105,000 to $118,000Assessment, reporting, and affirmation only
SBA analysis~$388,600up to ~$593,800Total compliance cost per certification
Secureframe and other research$37,000 to $80,000$100,000 to $200,000+Implementation and preparation costs

The spread comes down to what each estimate includes. The DoD's figures assume you have already implemented the underlying security requirements, since those have been a contractual obligation under FAR and DFARS clauses for years.

The SBA's figures don't make that assumption. In practice, many small businesses haven't fully implemented those requirements, so the distance between their current posture and the standard is where a significant portion of the real cost sits.

The SBA's estimate has been influential in the current policy discussion. In its July 2026 statement supporting the Phase 2 pause, the SBA said compliance costs approaching $600,000 were pushing small businesses out of the DIB and estimated that more than 100,000 small businesses were affected. SBA Administrator Kelly Loeffler described CMMC compliance as an untenable barrier for firms the DIB depends on, and Under Secretary of War for Acquisition and Sustainment Michael Duffey cited the program's paralyzing costs in the same round of announcements.

It's worth noting these are upper-bound figures rather than typical ones, and they reflect a total compliance cost rather than an assessment fee. Your own number will depend heavily on your starting posture, your scope, and the approach you take.

According to our research and others like Redspin’s second annual DIB readiness report, we estimate that a 25 to 50 person contractor using disparate tools is likely to spend $37,000 to $80,000 for Level 2 (Self) and upwards of $100,000 to $200,000 for Level 2 (C3PAO) just for implementation.

Chart comparing observed CMMC costs for small businesses for CMMC Level 1, Level 2 (Self), Level 2 (C3PAO)

Here's the end-to-end breakdown behind those numbers.

Gap assessment: $3,500 to $20,000

Before you can remediate, you need to understand where you stand. A formal gap assessment evaluates your current controls against FAR 52.204-21 (for Level 1\) and NIST SP 800-171 Rev 2 (for Level 2), produces an SPRS score, and identifies priority areas for remediation.

Cost varies based on your organization's scope, the service provider or consultant, and whether they use an automation platform.

Remediation and implementation: $5,000 to $250,000+

This is where costs vary the most and where the biggest surprises tend to appear. Depending on your starting cybersecurity posture, remediation may require you to fill gaps using internal IT resources, new technologies, or outsourced service providers, for things such as:

  • deploying multi-factor authentication
  • upgrading endpoint protection
  • implementing logging and monitoring
  • hardening system configurations
  • updating policies and procedures
  • refining access controls

For Level 1 organizations with basic controls already in place, remediation may be minimal. For Level 2 organizations with incomplete NIST 800-171 Rev 2 implementation, remediation can be extensive, especially if your infrastructure needs re-configuration or your CUI footprint is broad.

Consulting support: $250 to $400/hour

Organizations without internal security expertise or resources may consider outsourcing CMMC to consultants. Costs vary widely depending on fees, service offerings, project length, and whether the firm uses software.

For basic Level 2 preparation, consulting spend might start in the $20,000 to $100,000 range. Larger or more complex engagements can run $200,000 to $300,000 or more. The good news: platforms and automation tools significantly reduce how much consulting time you actually need.

Security tools: $10,000 to $50,000+ annually

CMMC Level 2 compliance may require you to purchase and implement technical security tools that don't currently exist in your environment, covering controls like encryption, SIEM or log management, vulnerability scanning, endpoint detection and response (EDR), and secure email.

If you're assembling point solutions, annual licensing costs add up quickly, ranging anywhere from $10,000 to ten times that per year.

Internal staff time: significant but invisible

Hundreds of hours across IT, security, HR, and leadership don't appear on an invoice, but they're very real. Every hour spent on manual CMMC documentation, policy reviews, or evidence collection is an hour not spent on billable work.

For most small businesses, the assessment fee ends up being one of the smaller lines on this list. If you're building a budget from the DoD's published estimates alone, it's worth remembering that those figures cover the assessment itself and not the implementation work leading up to it.

Recommended reading

CMMC Certification Costs Breakdown: $15K-$150K+

Not sure where you stand against the 110 requirements? Our CMMC Level 2 compliance checklist walks through NIST 800-171 Rev 2 requirements needs to be in place now, pause or no pause.

4 ways small businesses can reduce CMMC costs

The cost estimates above are real, but they're not fixed. There are proven strategies small businesses can use to bring CMMC costs down significantly. Here are four of the most effective, in the order we'd generally recommend working through them, since each one reduces the scope of the problem the next one has to solve.

1. Ask if your prime can limit CUI flowdown

Review your contracts carefully. If your prime is flowing CUI down to you, you likely need Level 2. But if the prime can restructure data handling to keep CUI out of your environment, you'll likely only need Level 1.

Since Level 1 has fewer security requirements and no third-party assessment requirement, it's more manageable and affordable for most small businesses than Level 2.

It's worth having a direct conversation with your prime: "Can the contract be structured so that CUI is not shared with my organization?"

2. Use the enclave approach to reduce scope

If your prime can't limit the flowdown of CUI and Level 2 requirements, you can still limit the CUI footprint at your organization.

One of the most effective cost-reduction strategies available to small businesses is isolating CUI in a dedicated enclave. Since only systems that store, process, or transmit CUI are in scope for CMMC Level 2, everything outside the enclave would not need to meet the full 110 requirements. That means you wouldn't have to apply and maintain CMMC controls across your entire IT environment, just the enclave.

This enclave is a logically or physically isolated cloud environment with the access controls, logging, segmentation, and endpoint protections required by CMMC, so CUI is stored and accessed only there.

By minimizing how many users and systems touch CUI, you minimize how much of your infrastructure is subject to CMMC requirements, and therefore how big your assessment scope is. That scope reduction translates directly to lower costs: less remediation work, less documentation, and less review for your assessor.

The government and industry agree. In a comment letter during the CMMC rulemaking process, the SBA Office of Advocacy specifically asked the DoD for clear enclave guidance so small businesses could “avoid unduly costly compliance expenses.”

Steve Pratt, the CISO, Lead Certified CMMC Assessor (CCA), and Director of Programs for the Cyber Risk and Compliance Sector at Sentar, explained at the Secureframe National Cybersecurity Summit 2026 that de-scoping is really the purpose and the driver behind choosing an enclave over an enterprise or “all in” approach: “If you have so many controls that you have to implement as part of CMMC, and if you can shrink down what you have to apply that to, then that will be more affordable and easier to get assessed and pass.”

Read our blog to learn more about how CUI enclaves work and how you can auto-provision one with Secureframe Defense at a fraction of the typical time and cost. Or watch the session recording featuring Pratt and other experts on CMMC Enclaves 101 below.

Embed: CMMC Enclave Explained: What DIB Contractors Need to Know

3. Select a cloud provider with an SMB-specific licensing tier

If you take the enclave approach, the cloud provider and licensing tier you select matter significantly to your bottom line.

Microsoft 365 GCC High is a strong choice for all CMMC levels, since this FedRAMP High Authorized environment is suitable for handling all types of CUI, including export controlled data. But its enterprise licensing can be too pricey for small contractors. That's why Microsoft launched a licensing tier, Business Premium, designed specifically as an affordable alternative for small businesses in the DIB.

See our GCC High Business Premium guide for a detailed overview of what it costs and what's included, compared to other GCC High licensing tiers.

As an authorized AOS-G reseller, Secureframe offers competitive pricing on Microsoft 365 GCC High licenses, including Business Premium, G3, and G5. Browse licenses on our Marketplace.

Purchase Microsoft 365 GCC High licenses through Secureframe

As an authorized AOS-G reseller, Secureframe offers competitive pricing on Microsoft 365 GCC High licenses, including Business Premium, G3 and G5.

4. Consolidate instead of stitching tools together

One of the most common cost traps in CMMC compliance is assembling a patchwork of disconnected tools: one for gap analysis, another for SSP documentation, a third for evidence collection, with consultants filling the gaps between them. Each handoff introduces cost, delay, and the risk of misconfiguration or compliance decay, like documentation that no longer matches your actual environment.

Tool consolidation reduces these risks and is an increasingly common trend across cybersecurity. According to a study by IBM and Palo Alto Networks, organizations juggle an average of 83 different security solutions from 29 vendors, and those that consolidated into a unified platform saw higher ROI, reduced costs, and stronger operational efficiency.

Consolidating onto a single platform that automates and centralizes as much of the CMMC process as possible (infrastructure, control implementation, documentation, evidence collection, assessment support, monitoring) provides a single record of evidence to back a defensible assessment and affirmation every time and reduces cost, complexity, and the chance of surprises during an assessment or, worse, an incident or False Claims Act investigation.

Secureframe Defense was built for this problem. It brings together automated cloud provisioning and device management to isolate CUI, guided control implementation, AI-generated SSPs and POA&Ms, and continuous evidence collection and monitoring in a single platform. Instead of managing dozens of disparate tools across multiple vendors, DIB organizations get one system that carries them from gap analysis through assessment and then keeps them there.

These strategies tend to compound. Keeping CUI out of your environment where possible, isolating what remains in an enclave, choosing a licensing tier sized for your organization, and automating the documentation on top of that can meaningfully change the total. How much depends on where you're starting from, but the organizations that see the biggest reductions are usually the ones that address scope before they start buying tools.

Recommended reading

Introducing Secureframe Defense: A Complete, End-to-End Solution for CMMC Compliance

How has the government tried to reduce CMMC costs and burden for small businesses?

The 2026 pause and program review are not the first efforts to reduce the CMMC burden on small contractors. They're the most recent in a series that stretches back roughly five years, spanning changes to the program itself, free assistance programs, and proposed funding. The table below lays them out on a timeline.

DateWhat happenedWhat it does for small businesses
Restructured for CMMC in FY2023APEX Accelerators. Congress first authorized the Procurement Technical Assistance Program in 1985, which was renamed APEX Accelerators in November 2022 and moved under the DoD Office of Small Business Programs (OSBP).~100 centers nationwide offering free advisory support on CMMC level determination, readiness, SPRS registration, and referrals to accredited RPOs and C3PAOs.
Formally tied to APEX Accelerators in 2022Small Business Development Centers (SBDCs). SBA-funded network of more than 1,000 centers. A December 2022 DoD/SBA memorandum of understanding formally tied SBDCs and APEX Accelerators together.Free business advising, including planning and cost-recovery strategy for compliance investments.
January 2023 (named in the DoD Small Business Strategy)Project Spectrum. A DoD OSBP initiative focused on DIB cybersecurity readiness, which the Small Business Strategy committed to expanding with guidance and tools for voluntary cyber self-assessments.Free cybersecurity training, tools, and readiness resources built specifically for small and mid-sized DIB companies and the federal manufacturing supply chain.
November 2021CMMC 2.0 announced. The DoD cut the model from five levels to three, aligned Level 2 exactly to NIST SP 800-171's 110 requirements, permitted self-assessment at Level 1 and for some Level 2 contracts, and allowed POA&Ms.Still the single largest scope reduction the program has had, and the clearest precedent for what "reform" has meant in practice.
February 2024SBA Office of Advocacy comment letter on the CMMC proposed rule.Asked the DoD for clear enclave guidance so small businesses could avoid unduly costly compliance expenses. Enclaves remain the most effective cost lever available.
November 2024Small Business Cybersecurity Act of 2024 introduced by Rep. Scott Fitzgerald (R-Wis.).Would have given firms with 50 or fewer employees a 30% tax credit on qualified CMMC expenditures, capped at $50,000 annually, covering assessments and POA&M remediation. Never enacted.
November 2025DoD OSBP pulse survey of small business CMMC readiness, concerns, and challenges.Collected the readiness data that later informed the case for reform.
Early 2026Army NCODE program. Roughly $49 million awarded across eight companies under its Next-Generation Commercial Operations in Defended Enclaves (NCODE).Provides secure, government-adjacent enclave environments small businesses can use to hold CUI rather than build and certify their own.
June 17, 2026Senate FY27 NDAA proposes a CMMC grant program.Up to $100,000 per grant against direct Level 2 third-party assessment costs, capped at $50 million total, to be stood up by July 1, 2027, prioritizing firms that have not previously held a DoD contract or subcontract.
July 13, 2026Phase 2 paused, CMMC Reform Task Force established, RFI issued.The Task Force was directed to recommend a framework that lowers barriers for small, medium, and non-traditional businesses and replaces prohibitive third-party compliance models with scalable, realistic security measures.
August 14, 2026RFI closes at 12:00 p.m. ET, 30 days after the DoW announced its pause. Public comments collected will inform the Task Force’s recommendations for reform.RFI allows any DIB company to provide direct feedback to the Task Force during its review of the CMMC program, specifically about “utilizing existing commercial cybersecurity capabilities, leveraging and optimizing self-attestation capabilities, and streamlining cybersecurity compliance.”
Early October 2026Task Force report due to the DoW CIO, expected 15 days after the 60-day program review ends. The report is intended to recommend realistic, scalable security measures that prioritize speed to capability and lower barriers for small and non-traditional businesses.The Task Force’s goal is to “definitively reduce compliance and cost burdens on small, medium, and non-traditional companies while ensuring an uplift of cybersecurity and operational resiliency across the DIB.”

A pattern runs through most of these efforts. Grants, tax credits, free advisory centers, expanded self-assessment paths, enclave guidance, and the Phase 2 pause are largely aimed at reducing the cost of demonstrating compliance, or at helping small businesses pay for it.

To date, few of them have focused on reducing the cost and complexity of the underlying security standard. The 110 requirements in NIST SP 800-171 Rev 2 have been contractually required through DFARS 252.204-7012 since that clause took effect in 2017, and they've remained in place through every one of these changes.

That's worth keeping in mind if you're weighing whether to wait for relief before starting your cybersecurity program. Relief has historically arrived in the form of more time, more flexibility in how compliance is verified, or help paying for it, rather than in the form of rolling back security requirements.

However, NIST 800-171 was created as a derivative of NIST 800-53, tailoring the catalog of over 1,000 controls to focus on a subset of requirements that best matched requirements related to protecting the confidentiality of CUI. And CMMC 2.0 removed some new requirements referred to as the delta 20. Whether the current review follows that pattern remains to be seen.

Recommended reading

The CMMC 2.0 Timeline: Key Dates, Deadlines & the Current Phase

What could CMMC reform change for small businesses?

The Department has not said what changes it will make, and the RFI is market research rather than a rulemaking, so nothing described below is decided. What we do have is the set of questions the DoW asked the DIB to answer, which gives some indication of the areas of reform under consideration.

The RFI, titled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base", asks contractors to identify:

  • their top five cost drivers and administrative burdens
  • which security controls deliver the most tangible risk reduction
  • which controls impose the greatest burden relative to the security benefit they provide
  • what commercial cybersecurity capabilities the Department could accept in place of current requirements
  • how the self-assessment process could be streamlined and whether self-assessments improve security posture in practice
  • what policy reforms would reduce barriers for small and non-traditional businesses, and
  • what changes would most improve real resilience against attacks.

Those questions cluster into four areas. Here's what each could mean for a small business, with the caveat that these are possibilities rather than announced changes.

Four possible CMMC reform directions to reduce burden on small businesses

1. Leveraging and optimizing self-assessments

Two of the seven questions deal with self-assessment specifically, and the Department framed the RFI around leveraging and optimizing self-attestation capabilities. The pause period offers a partial preview of what a larger reform could mean, since requiring activities can currently designate only Level 1 (Self) and Level 2 (Self).

The Task Force may recommend reducing the number of Level 2 contractors required to complete a third-party assessment, which the DoD originally estimated in the 32 CFR rule as 95% (and only 5% for self-assessments).

Potential cost effect: For organizations that would otherwise need a third-party assessment, this is the difference between the DoD's $37,000 to $49,000 self-assessment estimate and its $105,000 to $118,000 third-party estimate, before any implementation spending.

What likely wouldn't change: The preparation behind the assessment. Currently, a Level 2 self-assessment still evaluates all 110 requirements across 320 assessment objectives, still requires an SSP, still produces an SPRS score, and still requires a senior executive affirmation. A self-assessment is a lower-cost way to demonstrate compliance, not a lower standard of compliance.

2. Tailoring the requirements applied at Level 2

The RFI asks which controls deliver the most tangible risk reduction and, separately, which impose the greatest burden for the least security benefit. Answers to those two questions could support a more tailored or tiered set of requirements, though the Department hasn't said that's the intent. 

It would be broadly consistent with the Task Force's charge to recommend scalable, realistic security measures, and with the DoW CIO's Brilliant at the Basics campaign, which published a prioritized IT Top 10 and OT Top 10 for DIB partners.

Potential cost effect: Remediation and implementation, which is typically the largest and most variable line for small businesses. A smaller applicable control set could reduce implementation work, tooling purchases, and documentation volume together, but the biggest benefit would be tangible improvements to your actual cybersecurity posture, not cost reduction. 

What to watch: Changing what CMMC assesses would not by itself change DFARS 252.204-7012, which requires NIST SP 800-171 Rev 2 under a current class deviation. Reconciling the two would likely require separate rulemaking, so this is probably the slowest of the four to materialize.

3. Credit for commercial security tools you already use

The Department asked what existing commercial cybersecurity capabilities contractors are using and how they could better accept or recognize them within a compliance or risk framework.

Potential cost effect: The $10,000 to $50,000+ annual security tooling line, particularly for organizations that end up buying a compliance-specific product to satisfy a requirement something they already own could arguably address.

What to watch: A version of this already exists. When you use a FedRAMP-authorized or equivalent cloud, you inherit some controls from the provider, as covered in our guide to CMMC in the cloud. Broader credit for commercial tools would extend a mechanism that's already part of the program rather than introduce a new one.

4. Direct financial assistance

The seventh question asks what policy reforms would reduce barriers for small and non-traditional businesses. The two most concrete proposals are already in the table above: the Senate's proposed CMMC grant program and the tax credit concept from the Small Business Cybersecurity Act of 2024.

Potential cost effect: Laws or programs like these would offset costs rather than reduce them, and both are capped well below the SBA's estimate of total small business compliance cost. So they would help, but they wouldn't remove the need to manage scope carefully.

None of these areas removes the underlying standard. The RFI asks which controls to keep and how to verify them, not whether a standard should exist, and DFARS 252.204-7012 remains in effect while the review runs. So the work in front of you is largely the same work it was before the pause, on a timeline you now have more control over.

Small business CMMC timeline: What to do and when?

With the phased rollout on hold, there isn't a government-set third-party assessment deadline in front of you right now. Your timing is instead driven by three things: the cybersecurity standards and self-assessment your contract already requires, your prime's flowdown schedule, and how long readiness actually takes.

That last factor is the one small businesses tend to underestimate. DIB organizations have been spending over a year on CMMC preparation on average, and most Level 2 contractors need six to nine months to get ready if they're starting from a limited security posture.

Sequencing the work this way keeps you compliant with what your contract requires today while positioning you for whatever the Task Force recommends.

Now

  • Confirm your scope. Determine what data you actually handle and where it lives. Scoping decisions carry over across every version of the program and affect every other cost line, so this is the highest-leverage hour you'll spend.
  • Run a gap analysis against NIST 800-171 Rev 2 and calculate your SPRS score.
  • Confirm your contract status in writing with your contracting officer, specifically whether any C3PAO designation on your existing awards has been modified out. Separately, confirm with your primes what they still expect regardless of the government schedule.
  • Complete your SSP and self-assessment and submit your results and affirmation in SPRS if you haven't already. This is required under CMMC Phase 1 requirements still in place today, not after the Task Force reports.

Next 60 to 90 days

  • Fill in any gaps, starting with highest-value ones first. Close any identified security gaps, including open Plans of Action and Milestones. Consider using the Brilliant at the Basics campaign to prioritize any unmet gaps in NIST 800-171 to start. Read our guide to see how the Top 10 IT list maps to NIST 800-171.
  • Get your documentation and evidence to match your actual environment. An SSP and record of evidence that accurately reflects what you've implemented and maintained in your current environment is required now, and every reform scenario described above still requires one.

Ongoing

  • Monitor and maintain your controls and documentation as your environment evolves. CMMC was never a one-time project, and the annual affirmation requires an operational record built through the year rather than reconstructed the week it's due.
  • Keep your SPRS score and affirmation accurate. Whatever the verification model becomes, an SPRS score and affirmation that doesn't match your actual posture creates exposure that tends to compound over time.

Recommended reading

How to Meet CMMC Level 2 Compliance Requirements + Checklist

Get CMMC compliant on a budget and timeline built for SMBs

Cost, time, and complexity are the obstacles small businesses run into most often with CMMC, and they're a large part of why the program is under review. But the levers that reduce all three are available to you now: narrowing what's in scope, and automating the documentation and evidence work that remains.

Secureframe Defense is built around those levers, in three steps.

Step 1: Deploy and manage secure infrastructure.

Secureframe stands up a CMMC-compliant environment in Microsoft GCC High or Google Workspace, with devices configured for the access control, logging, monitoring, notification, and segmentation that NIST 800-171 Rev 2 requires for storing and accessing CUI. Because CUI lives in that environment rather than across your whole network, this is also where the enclave scope reduction described earlier actually happens.

Step 2: Implement and document controls following Defense Navigator.

The 110 requirements and 320 assessment objectives become a guided implementation workflow, generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than from templates. This is the part that typically absorbs the most consulting hours and internal staff time, which is why automating it moves your total cost more than anything else on the list.

Step 3: Maintain cybersecurity with continuous monitoring and operational guardrails.

Ongoing control testing, automated evidence collection, drift detection, risk assessments, and vendor tracking keep your SPRS score aligned with your real posture, so the executive signing the annual affirmation has a record behind it.

Whatever the Task Force recommends, all three steps still apply. A scoped environment, documentation that matches it, and a continuous operating layer behind your program and attestation are what every version of the program has asked for.

CMMC resources for small businesses

Small businesses don't have to navigate CMMC alone. Several resources exist specifically to help small defense contractors prepare faster, and most are free.

Government resources

  • APEX Accelerators: No-cost counseling and support for small businesses navigating CMMC and other government contracting requirements. As of the DoD's 2023 Small Business Strategy there were 96 centers serving 49 states, Washington DC, Puerto Rico, Guam, the U.S. Virgin Islands, the Northern Marianas, and Bureau of Indian Affairs regions
  • Project Spectrum: Free tools, training, and cybersecurity readiness resources created by the DoD Office of Small Business Programs, including voluntary cyber preparedness self-assessments
  • Small Business Development Centers: SBA-funded advising centers that can help with planning and cost strategy for compliance investments
  • SBA Office of Advocacy: Tracks CMMC rulemaking from a small business perspective and hosts roundtables where small contractors can put their experience on the record
  • Cyber AB: Resources, events, and the official marketplace of authorized RPOs and C3PAOs
  • Official CMMC documentation: The DoW CIO's assessment guides, scoping guides, and model overview

Secureframe resources

This post was originally published in March 2026 and has been updated for accuracy and comprehensiveness.

Get secure. Stay compliant.

Talk to a CMMC expert

FAQs

Is CMMC still required for small businesses?

Yes. The Department of War paused the transition to CMMC Phase 2 on July 13, 2026, which halted third-party (C3PAO) certification as a condition of award. It did not cancel CMMC and it did not change your underlying obligations. DFARS 252.204-7012 still requires small businesses handling CUI to implement all 110 requirements of NIST SP 800-171 Rev 2, Level 1 and Level 2 self-assessment requirements are still being written into contracts, and SPRS submissions and annual affirmations are still required. Primes are also still enforcing flowdown on their own schedules.

How much does CMMC cost for a small business?

It depends on your level and your starting posture. The DoD's own estimates cover assessment activities only: roughly $4,000 to $6,000 for a Level 1 self-assessment, $37,000 to $49,000 for a Level 2 self-assessment, and $105,000 to $118,000 for a Level 2 third-party assessment. End-to-end costs including implementation are much higher: typically $5,000 to $15,000 for Level 1, $37,000 to $80,000 for Level 2 (Self), and $100,000 to $200,000 or more for Level 2 with a C3PAO assessment. The SBA has estimated total compliance costs can reach approximately $593,800 per certification for small firms requiring a third-party assessment and about $388,600 for firms eligible for self-assessment.

What if I can't afford CMMC compliance?

Start with the basics and shrink the problem before you spend on it. Level 1 costs under $15,000 for most small businesses and covers 15 fundamental security requirements. For Level 2, ask your prime whether the contract can be structured to keep CUI out of your environment, which could allow you to stay at Level 1. If it can't, the enclave approach, especially with an affordable licensing tier like Microsoft 365 Business Premium for GCC High, significantly reduces scope and cost by limiting which systems and users need to meet all 110 requirements. Free government resources like APEX Accelerators and Project Spectrum can help you plan without consulting fees. And if you're pursuing Level 2, using an automation platform to replace consultant hours and manual work is one of the most effective ways to control spend.

Can small businesses get financial help with CMMC costs?

Not yet, though two proposals are live. The Senate's fiscal 2027 defense authorization bill would create a CMMC grant program offering up to $100,000 per award against direct Level 2 third-party assessment costs, capped at $50 million total and prioritizing firms that have not previously held a DoD contract. Separately, the Small Business Cybersecurity Act of 2024 proposed a 30% tax credit for qualified CMMC expenditures, capped at $50,000 annually, for firms with 50 or fewer employees. Neither has been enacted. In the meantime, free assistance from APEX Accelerators, Project Spectrum, and SBDCs is available now.

Will CMMC get easier for small businesses after the reform review?

Possibly for verification, but the security requirements are unlikely to disappear. The CMMC Reform Task Force was directed to recommend a framework that lowers barriers for small, medium, and non-traditional businesses and replaces prohibitive third-party compliance models with scalable, realistic security measures. The RFI supporting that review asked about streamlining self-assessment, accepting existing commercial cybersecurity capabilities, and identifying which controls impose the greatest burden for the least security benefit. Every one of those directions still assumes a NIST SP 800-171-based standard. The Task Force's recommendations were due to the DoW CIO in mid-September 2026.

How long does it take a small business to get CMMC-ready?

Level 1 takes roughly two to four weeks for small businesses with basic controls already in place. Level 2 takes three to nine months depending on your current cybersecurity posture. If you're starting from scratch with minimal controls, plan on six to nine months minimum. An end-to-end platform like Secureframe Defense can compress that substantially by automating gap analysis, documentation, and evidence collection.

Do I need a consultant?

Not necessarily. Many small businesses can handle Level 1 entirely internally. For Level 2, a compliance platform covering gap analysis, documentation, and evidence collection can replace much of what a consultant provides at a fraction of the cost. Where consultants add the most value is in specific technical gaps you can't resolve internally, scoping decisions on complex environments, and pre-assessment readiness reviews. Engaging a CMMC Registered Practitioner or RPO for targeted support, rather than a full-service engagement, is often the more cost-effective approach. Your local APEX Accelerator can make referrals at no cost.

Which CMMC level do most small businesses need?

Most small subcontractors fall into Level 1 or Level 2. Level 1 applies if you only handle FCI. Level 2 applies if you handle CUI, which is common for subcontractors who receive technical data, specifications, or other sensitive program information from primes. If you're uncertain, review your contract's DFARS clauses and confirm with your prime whether CUI is being flowed down to your organization.

What proactive steps can small businesses take today?

Start with scoping: determine whether you handle FCI or CUI and where that data lives. Run a gap analysis against NIST 800-171 Rev 2 to understand your current posture. Calculate your SPRS score and make sure you're registered to submit it. Develop or update your SSP so it reflects your actual environment. Identify your highest-priority remediation items and begin closing them. And consider how an enclave approach could reduce your compliance scope and cost.

Anna Fitzgerald

Senior Content Marketing Manager

Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.