Login / My Account772-224-8118Free Consultation →
    Back to Blog

    CMMC for Small Business: What to Do Right Now

    Tatem Web DesignAugust 24, 202614 min read2,615 words

    CMMC for Small Business: What to Do Right Now

    Decorative CMMC compliance title card illustration

    Don’t pause your cybersecurity work. Confirm whether you handle Controlled Unclassified Information (CUI), update your Supplier Performance Risk System (SPRS) entry, and start a gap assessment against NIST SP 800-171 Rev 2. The Department of Defense suspended the Phase II third-party assessment requirement for CMMC on July 13, 2026, but DFARS 252.204-7012 obligations and your existing NIST 800-171 responsibilities never went away.

    Most small businesses fall into Level 1 (basic federal contract information) or Level 2 (CUI handling), and the suspension changes only when a third-party assessor shows up, not what you’re required to protect.

    Three things to do today:

    • Pull your active DoD contracts and search for DFARS 252.204-7012 or FAR 52.204-21 clauses.
    • Do a quick inventory of where CUI or federal contract information lives on your network, laptops, and email.
    • Schedule a gap assessment now, before the review period ends and assessor calendars fill up again.

    Key Takeaways

    CMMC compliance for small business now hinges on continuing NIST SP 800-171 work despite the Phase II suspension, not waiting for certification rules to fully resume.

    Point Details
    Phase II is suspended, not gone DFARS 252.204-7012 and NIST SP 800-171 obligations remain active regardless of certification timelines.
    Know your level first Level 1 covers about 15 FAR practices; Level 2 covers 110 NIST SP 800-171 requirements.
    Scope reduction cuts cost A CUI enclave or segmented network shrinks the systems that need full remediation and documentation.
    Use free resources early Project Spectrum, SBA, MEP centers, and SBDCs offer no-cost or low-cost help before you hire a consultant.
    Get expert help when needed Tatem Web Design offers gap assessments, SSP drafting, and managed security services for Florida small businesses.

    Table of Contents

    CMMC Status for Small Business: What Changed and What Didn’t

    The Department of Defense suspended the CMMC Phase II third-party assessment requirement on July 13, 2026, announcing a program review before certification requirements resume. Phase I self-assessment requirements stayed in place the entire time.

    What paused, what didn’t: The suspension covers the timeline for mandatory C3PAO certification. It does not touch DFARS 252.204-7012, your obligation to implement NIST SP 800-171 controls, or your existing SPRS score.

    The DoD CIO’s own guidance confirms CMMC remains a program in active reform, not a program on ice. Contractors who assume “suspended” means “skip it” are misreading the announcement. Watch for updates through DoD CIO communications and Federal Register notices over the coming months. Some contractors who certified early before the pause are stuck with sunk costs and no immediate benefit, a caution other businesses should heed rather than repeat by doing nothing at all.

    Does Your Business Handle FCI or CUI?

    Federal Contract Information (FCI) is the information you generate or receive under a government contract that isn’t intended for public release: an invoice, a delivery schedule, a basic purchase order. Controlled Unclassified Information (CUI) is a narrower, higher-sensitivity category: technical drawings marked with distribution statements, export-controlled specs, or unclassified defense data that requires safeguarding under a specific law or regulation. Handling FCI alone generally points you toward Level 1. Handling CUI points you toward Level 2.

    To find out which applies to you:

    1. Search every active solicitation and contract for DFARS 252.204-7012, FAR 52.204-21, and DFARS 252.204-7021 flow-down language.
    2. Ask your prime contractor directly whether the statement of work or any deliverable contains CUI, and get the answer in writing.
    3. Read the statement of work line by line for markings like “CUI,” “export controlled,” or “distribution statement,” and log every location where that data touches your systems.

    What Level 1 and Level 2 Actually Require

    Level 1 rests on FAR 52.204-21, about 15 basic safeguarding practices covering things like access control and media disposal. Level 2 maps directly to NIST SP 800-171 Rev 2, which contains 110 security requirements spanning access control, incident response, system monitoring, and more.

    Which assessment path applies depends on your contract. Some Level 2 work qualifies for self-assessment; other contracts require a Certified Third-Party Assessment Organization (C3PAO) review. Either way, you need:

    • A System Security Plan (SSP) describing how each requirement is met.
    • A Plan of Action and Milestones (POA&M) for anything not yet fully implemented.
    • Evidence logs, screenshots, and configuration records that back up every claim in the SSP.
    • A current SPRS score entry, since an inaccurate score is a legal representation, not a formality, according to DoD CIO guidance.

    NIST SP 800-171 Rev 2 remains the governing baseline for current Level 2 assessments. Build your evidence against Rev 2 first; layer in Rev 3 mapping later if you want to future-proof the work.

    How Much Does CMMC Cost a Small Business?

    Level 1 compliance is comparatively cheap since you’re implementing around 15 practices, often achievable with existing IT staff and a few hundred dollars in tooling. Level 2 costs far more because 110 requirements touch nearly every system you run.

    The SBA cited compliance costs approaching $593,800 for small firms pursuing full third-party certification, the exact burden that drove the Phase II suspension in the first place.

    Your actual number will land far below that ceiling if you control the biggest cost drivers:

    • Gap assessment and documentation labor (often the single biggest line item for a business with no existing SSP).
    • Technical remediation: multifactor authentication, encryption, centralized logging.
    • Managed security services versus building an internal team from scratch.
    • Assessor fees, which only apply if your contract requires third-party certification.

    Reducing your CUI footprint before you spend on remediation is the fastest way to shrink that bill.

    A Step-by-Step CMMC Readiness Roadmap

    Getting assessment-ready doesn’t require doing everything at once. Work through it in order:

    1. Confirm your boundary. Decide exactly where CUI touches your network, and draw a line around it.
    2. Run a gap assessment. Options include a Registered Provider Organization (RPO), your local Manufacturing Extension Partnership (MEP) center, an independent consultant, or a structured self-assessment.
    3. Shrink the scope. Moving CUI into a managed enclave, a segmented network, or a virtual desktop infrastructure (VDI) setup can cut the number of systems that need full remediation, one of the most effective cost levers available to a small contractor.
    4. Write the SSP and POA&M, then close gaps with MFA, patch management, encryption, and logging.
    5. Choose your assessment path (self-assessment or C3PAO) and update your SPRS entry accordingly.
    6. Maintain the program with ongoing monitoring, staff training, and annual affirmation.

    Pro Tip: Outsource the technical controls (firewalls, logging, patching) to a managed provider while keeping organizational controls, like policy documents and training records, in-house. It’s usually the fastest way to close gaps without hiring a full security team.

    For the website and hosting side of this work, a cybersecurity compliance checklist built for small business systems overlaps heavily with what an assessor will want to see.

    Where to Find Free or Low-Cost CMMC Help

    You don’t have to build this alone or pay full consulting rates for every step.

    • DoD CIO’s CMMC pages carry the official rule text, FAQ resources, and program updates as they’re released.
    • Project Spectrum offers free assessment tools, training modules, and expert guidance built specifically for small and medium defense contractors.
    • SBA, MEP centers, and Small Business Development Centers (SBDCs) provide funding guidance and hands-on assistance for smaller firms navigating compliance costs.
    • The Cyber AB maintains the marketplace of authorized C3PAOs and RPOs if you need a formal assessment or professional support.

    Use Project Spectrum for self-service gap tools, your SBDC for funding conversations, and the Cyber AB marketplace when you’re ready to hire a professional.

    Who’s Behind This Guidance

    This guidance comes from Matt at Tatem Web Design, a Stuart, Florida digital agency with 26+ years of experience that now runs CMMC Level 2 compliance consulting alongside its web design and cybersecurity practice.

    Tatem’s team maps directly to the roadmap above: gap assessments, SSP and POA&M drafting, managed enclave setup, and staff training.

    Who's Behind This Guidance — overview diagram

    The Phase II Suspension Is a Reprieve, Not a Reset

    Most of the advice floating around right now treats the Phase II suspension like a green light to slow down. That’s backwards. The suspension gives small businesses a limited window to fix problems before assessor demand and pricing spike again once the reform review wraps up.

    The conventional wisdom oversells “CMMC certification” as a single finish line. In practice, right-sizing your target level matters more than any other decision you’ll make. Plenty of small contractors qualify for Level 1 or a self-assessment path at Level 2, depending on contract language, and chasing a higher level than your contracts require is the single most expensive mistake in this space.

    If you handle CUI, prioritize shrinking your boundary before you spend a dollar on remediation tools. A smaller enclave means fewer systems to document, fewer controls to maintain, and a cheaper path to an accurate SPRS score. Free resources like Project Spectrum exist for exactly this reason. Use them before you write a check to anyone.

    Hands adjusting network cables in small IT enclave

    How Tatem Web Design Helps You Get CMMC Ready

    Tatem Web Design gives Florida small businesses a single point of contact for CMMC prep instead of juggling separate vendors for documentation, technical fixes, and training. That matters most when a gap assessment turns up a dozen scattered issues across your network, website, and email systems, and you need one team that can prioritize and fix them in the right order.

    Tatemweb

    The team handles the parts that eat the most hours: a structured gap assessment against NIST SP 800-171 Rev 2, SSP and POA&M drafting, managed enclave and network segmentation to shrink your CUI boundary, and staff training that covers the organizational controls assessors actually check. Every engagement is built around your specific contracts, not a generic template.

    If you’re staring down a DFARS clause and don’t know where to start, call Tatem Web Design at 772-224-8118 or visit the CMMC compliance consulting page to schedule a consultation and get a gap assessment on the calendar.

    Sources

    FAQ

    What Do Small Businesses Need for CMMC Certification?

    Small businesses need a documented System Security Plan, a Plan of Action and Milestones for open gaps, and an accurate SPRS score reflecting either Level 1 practices (FAR 52.204-21) or Level 2 requirements (NIST SP 800-171 Rev 2), depending on their contracts.

    How Much Does CMMC Compliance Cost?

    Level 1 compliance typically costs far less since it covers around 15 basic practices, while full Level 2 third-party certification can run toward the $593,800 upper estimate the SBA cited for small firms, though scope reduction brings that number down substantially.

    Which Companies Need CMMC Certification?

    Any company holding a DoD contract or subcontract that includes DFARS 252.204-7012 or FAR 52.204-21 clauses needs to meet the corresponding CMMC level, determined by whether the work involves Federal Contract Information or Controlled Unclassified Information.

    Is It Difficult to Get CMMC Certified?

    Level 1 is manageable for most small businesses with existing IT support, while Level 2’s 110 requirements demand real technical remediation and documentation, which is why scope reduction and professional gap assessments make the process considerably more manageable.

    Should I Pause CMMC Prep During the Phase II Suspension?

    No. DFARS and NIST SP 800-171 obligations remain in force, and businesses that keep preparing now avoid the assessor backlog and pricing pressure expected once the DoD’s program review concludes.

    Share:
    M

    Tatem Web Design

    26+ Years

    Web Design & SEO Specialist · Tatem Web Design

    Matt Tatem has been designing websites professionally since 1999, making Tatem Web Design one of Florida's longest-running web agencies. Based in Stuart, FL, he specializes in WordPress, local SEO, Shopify e-commerce, and cybersecurity consulting for small businesses.

    More Articles
    Let's Work Together

    Ready to Transform Your
    Online Presence?

    Let's create a stunning website that drives real results for your Florida business. Free consultation, no obligations.

    Get Free Quote 772-224-8118

    Stuart, FL · No contracts required · Results guaranteed