CMMC for Small Defense Contractors in Sacramento

If your Sacramento-area company sells into the defense supply chain — directly to the DoD or as a subcontractor to a prime — CMMC is no longer optional or theoretical. CMMC 2.0 requirements began appearing in DoD contracts in late 2025 under a phased rollout, and they flow down to subcontractors. Level 1 (15 basic practices, self-assessed) applies if you handle Federal Contract Information; Level 2 (all 110 NIST 800-171 controls, usually third-party assessed) applies if you handle Controlled Unclassified Information. If you're starting from scratch, you're 6–18 months from ready.

Here's what that means specifically for small contractors in the Sacramento region, where the defense economy is bigger than most people realize.

Why does CMMC matter so much in the Sacramento region?

Because this region is quietly full of defense work. Beale Air Force Base sits just north of the metro, Travis AFB is an hour west, and the legacy of Aerojet's decades in Rancho Cordova left a dense cluster of aerospace and defense suppliers along the Highway 50 corridor through Rancho Cordova and Folsom and El Dorado Hills. Add McClellan Park's aerospace and government tenants and you have hundreds of small machine shops, engineering firms, electronics manufacturers, and specialty service providers touching DoD data.

Most of these businesses aren't primes. They're second- and third-tier suppliers: a 20-person shop machining components to a drawing marked with distribution statements, an engineering consultancy receiving technical data packages, a logistics firm handling contract information. That drawing or data package is very likely CUI — and CUI is what triggers Level 2. Many owners in this position have never read NIST 800-171 and assume the prime "handles the cybersecurity stuff." The prime doesn't. The prime flows the requirement down to you, and increasingly asks for proof before renewing your purchase orders.

What are the CMMC 2.0 levels?

CMMC 2.0 has three levels, and the two that matter to almost every small contractor are Levels 1 and 2. Level 1 protects Federal Contract Information with 15 basic practices and an annual self-assessment. Level 2 protects Controlled Unclassified Information with the full 110 controls of NIST SP 800-171, verified by a third-party assessor for most contracts. Level 3 adds requirements from NIST 800-172 for a small set of the most sensitive programs and involves government-led assessment.

Level 1 Level 2 Level 3
Data protected Federal Contract Information (FCI) Controlled Unclassified Information (CUI) CUI on critical programs
Requirements 15 basic safeguarding practices (FAR 52.204-21) 110 controls from NIST SP 800-171 Level 2 + subset of NIST SP 800-172
Assessment Annual self-assessment + affirmation in SPRS Third-party (C3PAO) every 3 years for most contracts; self-assessment for a limited subset Government-led (DIBCAC)
Typical small contractor Handles POs, invoices, non-technical contract info Receives drawings, specs, technical data packages Rare for small businesses

The honest question to answer first is: do you actually receive CUI? Look at your contracts and the data your customers send you — DFARS 252.204-7012 clauses, distribution statements on drawings, export-control markings. If the answer is yes, Level 2 is your target, and the scoping question (which systems and people touch CUI) becomes the most important cost lever you have.

How does the phased DoD rollout work?

CMMC requirements are being inserted into contracts over a roughly three-year phase-in that began December 2025. Early phases rely mostly on self-assessments; later phases require certified third-party assessments for Level 2 before award. By the end of the rollout, CMMC will be a condition of award across applicable DoD contracts — no certification, no contract, regardless of your past performance or how good your parts are.

Two practical consequences for small Sacramento suppliers:

  • The market moves before the mandate. Primes aren't waiting for their contracts to require flow-down; supply-chain surveys asking for your SPRS score and CMMC status are already routine. A weak answer doesn't get you debarred — it gets you quietly designed out of the next program.
  • Assessor capacity is limited. There are only so many C3PAOs, and everyone's deadline clusters in the same window. Contractors who are assessment-ready early get scheduled; laggards wait in line while contracts pass them by.

There's also legal teeth behind the paperwork: your SPRS self-assessment score and annual affirmations are certifications to the government. The Department of Justice has pursued False Claims Act cases against contractors who overstated their cybersecurity compliance. "We'll round up our score" is not a strategy.

What should a small contractor actually do first?

Start with a gap assessment against NIST 800-171 and a scoping decision — before buying anything. Figure out where CUI enters your business, who touches it, and which systems store it. Then decide whether to bring your whole network up to Level 2 or build a smaller compliant enclave for CUI work. That single decision drives most of your cost, timeline, and day-to-day disruption.

A realistic sequence looks like this:

  1. Identify your data. Review contracts for DFARS 7012/7019/7020 clauses; inventory where FCI and CUI live.
  2. Scope tightly. A 40-person company where only six people touch CUI should strongly consider an enclave — a segregated, compliant environment (often built on Microsoft 365 GCC or GCC High) — instead of hardening every workstation in the building.
  3. Run the gap assessment. Score yourself against all 110 controls, honestly. Post the score to SPRS as required.
  4. Close gaps with a POA&M. MFA, encryption, logging, incident response, physical controls, policies — typically 6–18 months of work. Note that CMMC limits which controls can remain open on a Plan of Action at assessment time, and the highest-weighted ones can't.
  5. Document everything. A System Security Plan and written policies are assessed artifacts, not formalities. Assessors verify that practice matches paper.
  6. Schedule the C3PAO early if your contracts will require certification.

This is squarely the kind of work most small shops shouldn't do alone — it sits at the intersection of IT compliance and cybersecurity engineering, and mistakes in scoping or tenant selection are expensive to unwind. It's also exactly where a local partner helps: enclave builds, physical security walkthroughs, and assessment prep go smoother when your IT provider can actually drive to your shop off Highway 50 instead of advising from three time zones away.

Not sure whether your data even counts as CUI, or how far you are from a passing score? Request a free IT assessment and we'll give you a straight answer on scope and gaps.

Is CMMC worth it for a small shop?

If defense work is a meaningful slice of your revenue, yes — and it can be a competitive weapon rather than a tax. Every requirement that thins out the supplier pool raises the value of being one of the suppliers still standing. Sacramento-region primes and mid-tier integrators will need certified local suppliers, and there will be fewer of them than there are today.

The contractors who come out ahead treat CMMC as a floor for running a modern business — MFA, monitored endpoints, tested backups, and documented processes protect you from ransomware whether or not the DoD is watching. The ones who suffer are those who wait for a contracting officer to force the issue, then try to compress 18 months of work into 90 days with an assessor's calendar already full. Start with the gap assessment. Everything else follows from knowing where you stand.

Frequently asked questions

Does CMMC apply to subcontractors, not just prime contractors?
Yes. CMMC requirements flow down from primes to subcontractors at every tier. If a prime's contract requires Level 2 and your shop receives Controlled Unclassified Information — drawings, specs, technical data — you'll need Level 2 too. If you only handle Federal Contract Information, Level 1 self-assessment may suffice. Primes are already surveying their supply chains, and small machine shops and component suppliers are being asked to show compliance status now, ahead of contract requirements.
What's the difference between CMMC Level 1 and Level 2?
Level 1 covers contractors that handle only Federal Contract Information and requires 15 basic safeguards with an annual self-assessment. Level 2 applies when you handle Controlled Unclassified Information and requires all 110 security controls from NIST SP 800-171, verified in most cases by a third-party assessment from a C3PAO every three years. Level 2 is a substantially bigger lift — most small contractors need 6 to 18 months to close their gaps.
How long does it take a small contractor to get CMMC Level 2 ready?
Plan on 6 to 18 months from gap assessment to assessment-ready, depending on your starting point. Contractors already running managed IT with MFA, endpoint protection, and documented policies move faster; shops with aging servers, shared logins, and no documentation take longer. The scheduling backlog for third-party assessors adds more lead time, which is why waiting until a contract demands CMMC is the most expensive way to do this.
What does CMMC compliance typically cost a small business?
DoD's own rulemaking estimates put Level 2 certification assessment costs at roughly $100,000-plus over three years for a small entity, and industry analysts commonly cite total implementation costs ranging from tens of thousands to well over $100,000 depending on gaps. Ongoing costs include a compliant IT environment — often a Microsoft 365 GCC High enclave — monitoring, and documentation upkeep. Costs drop sharply when scope is limited to an enclave rather than the whole network.
Do I need Microsoft 365 GCC High for CMMC?
Not always, but often for Level 2. If your CUI includes export-controlled data (ITAR/EAR), GCC High is the standard answer because it guarantees US-persons support and US data residency. If your CUI is not export-controlled, commercial Microsoft 365 configured to meet NIST 800-171 — or a properly scoped enclave — can work. This is a scoping decision worth getting right early, because migrating tenants later is disruptive and expensive.
Can a small contractor self-assess for CMMC Level 2?
Only in limited cases. CMMC 2.0 allows self-assessment for a small subset of Level 2 contracts involving less sensitive CUI, but DoD has indicated the large majority of Level 2 awards will require a certified third-party assessment by a C3PAO. Even where self-assessment is allowed, a senior company official must annually affirm compliance in SPRS — a false affirmation carries False Claims Act exposure, so the work has to be real either way.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment