Home / Guides / CMMC for Small Business

CMMC for Small Business: How to Break Into DoD Contracting

Focus: cmmc for small business Veteran-run · practitioner guide Updated Jul 19, 2026 ~12 min read
Verified · Jul 19, 2026 CMMC Phase 2 is suspended (DoD, July 13, 2026) pending a 60-day review — no C3PAO third-party certification can be required right now. Self-assessment against NIST 800-171, an SPRS score, and DFARS 252.204-7012 remain the law. This guide reflects the current, post-suspension reality. Full breakdown →
The short answer

A small business absolutely can break into DoD contracting — most start as a subcontractor, register in SAM.gov for free, and meet cybersecurity with a self-assessment, not a five-figure audit. As of July 2026, the C3PAO third-party certification is suspended, so today you need an honest NIST 800-171 self-assessment, an SSP, and a posted SPRS score — the security work — without the certification cost that scared people off. The certification is paused; the standard is not.

The federal government is the largest buyer on earth, and it is required to steer a meaningful share of that spending to small businesses. The catch that stops most owners isn't the paperwork to bid — it's the wall of cybersecurity acronyms (CMMC, CUI, SPRS, DFARS) and a rumor that compliance costs half a million dollars. Here's the honest map: how a small shop actually gets in, what the cybersecurity really requires right now, and what the July 2026 suspension changed in your favor.

The July 2026 reality: what changed, what didn't

On July 13, 2026, DoD suspended CMMC Phase 2 — the requirement that many contractors pass a third-party C3PAO certification — and launched a 60-day review, citing exactly the problem small businesses have been shouting about: roughly 100,000 defense firms would need audits from only about 100 approved assessors, at costs the SBA said could exceed half a million dollars. The math didn't work for small business, so DoD hit pause.

Read this part carefully, because a lot of older advice online is now wrong:

Still fully in force today NIST SP 800-171 (the security standard), DFARS 252.204-7012 (safeguarding + 72-hour incident reporting), your SPRS self-assessment score, and CMMC Level 1 and Level 2 self-assessments. If you handle government data, you must still do the security work and self-attest to it. A false score still carries False Claims Act liability — the suspension did not lower that.
Paused (not repealed) The Level 2 C3PAO third-party certification and Level 3 government assessments. During the pause a contracting officer cannot require you to get certified — only to self-assess. This removes the biggest single cost, but it could return, modified, after the review (a report is expected around late September 2026). Build the standard now and you're ready either way.

The strategic takeaway for a small business is genuinely good news: this is the cheapest window in years to get in. You do the real security work and self-attest, without paying $30k–$100k for a certification audit that isn't currently required.

The 7-step on-ramp, in order

Becoming a DoD contractor is a sequence, not a leap. Do them in this order — each step unlocks the next.

  1. Register in SAM.gov — free.Get your Unique Entity ID (UEI), complete entity registration, pick your NAICS codes, and finish your reps & certifications. It's free at SAM.gov and renews annually. Never pay a third party to "register" you — that's the first scam every new contractor meets.
  2. Figure out what data you'll touch: FCI vs CUI.This one decision drives everything downstream. FCI (Federal Contract Information) is basic non-public contract info → CMMC Level 1, 15 safeguards. CUI (Controlled Unclassified Information — drawings, specs, technical data) → CMMC Level 2, the 110 controls of NIST 800-171. Almost everyone handles at least FCI; if CUI flows to you, you're Level 2.
  3. Do the right self-assessment.Only FCI → a Level 1 self-assessment (15 practices). CUI → implement NIST 800-171 Rev. 2 (110 controls) and perform a Level 2 self-assessment. During the suspension, self-assessment is all that can be required.
  4. Write the two documents assessors live by.A System Security Plan (SSP) describing how you meet each control, and a POA&M (Plan of Action & Milestones) listing gaps with dated fixes. A missing SSP is itself an automatic finding — this is not optional paperwork.
  5. Compute and post your SPRS score.Score your 110 controls with the DoD Assessment Methodology (start at 110, subtract weighted points; range −203 to +110) and post it in SPRS via the PIEE portal. Required under DFARS 252.204-7019/-7020, must be under three years old. Primes will ask for it before they'll sub to you.
  6. Handle DFARS 7012 flowdown.If your contract carries DFARS 252.204-7012, you must flow it down to any subcontractors touching covered data and meet the 72-hour incident-reporting and safeguarding duties yourself.
  7. Find and win the work.Start as a subcontractor to an existing prime, then grow into prime bids. Details below — including the SBA set-asides that put a thumb on the scale for small firms.

Where do you stand today? Estimate your NIST 800-171 self-assessment score across all 14 control families in about two minutes — free, no consultant.

Check my SPRS score →

Where the contracts actually are (and set-asides)

Two doors into the building, and most small firms come through the first one:

SBA socioeconomic programs are the small-business advantage — each is a certification that opens contracts set aside just for firms like yours:

Free help exists — use it APEX Accelerators (formerly PTACs) provide free, government-funded counseling on registration, certifications, and finding opportunities. There's one near you. Pair that with the SBA's Procurement Center Representatives and you have expert help at no cost — before you spend a dollar on a consultant.

What it really costs a small business now

Ignore the scariest headline number until you know which tier you're actually in. Cost tracks your data and scope, and the suspension just removed the most expensive line for most shops.

PathRealistic costWho it's for
Level 1 (FCI) self-assessmentMostly internal laborHandle only basic contract info
Level 2 self-assessment, in-house~$20k–$60kHandle CUI, DIY the prep + tooling
Level 2 with consultant help$50k–$300k+Outsourcing the documentation work
C3PAO assessment fee$30k–$100k+Suspended — not required now

For context, DoD's own worst-case three-year estimate for a representative small business running full Level 2 certification was around $488,000 — and that number is a big reason the program got paused. But the assessment fee, which the suspension removes, was only 25–40% of a total program; the rest is remediation, tooling, and your own time. The honest near-term picture: most small shops today are looking at the self-assessment and tooling tier, not the six-figure certification total. For the full line-item breakdown and the biggest cost lever (scoping), see our CMMC cost guide and the CUI enclave method.

The mistakes that sink small businesses

Do the standard, skip the consultant markup

The self-assessment is doable. This is the paperwork that proves it.

The security work is yours to do — but the documents an assessor grades don't have to cost $40k–$90k. The CMMC Level 2 DIY Compliance Kit gives a small shop the pre-written System Security Plan, all 20 required policies, a POA&M template, an evidence checklist, and a per-control SPRS scorer. Editable, one-time, built for a business doing this itself.

$2,995
one-time · lifetime updates · a fraction of a consultant's retainer
Audit-ready preparation for a fraction of consultant fees — not a substitute for a formal assessment if one is later required. Not legal advice.

Frequently asked questions

Is CMMC cancelled?

No. On July 13, 2026, DoD suspended CMMC Phase 2 (the third-party certification mandate) and launched a 60-day review. It's paused, not repealed. NIST 800-171 self-assessment, DFARS 252.204-7012, and SPRS scoring all remain in effect — the certification is suspended, the standard is not.

Do I still need a CMMC assessment to win a DoD contract right now?

Yes — a self-assessment. Level 1 (self) if you handle only FCI, or Level 2 (self) if you handle CUI. A third-party C3PAO certification is not currently required while Phase 2 is suspended, and it cannot be designated during the pause.

How much does it cost a small business to get compliant?

It depends on your data and scope. Level 1 for FCI can be largely internal. A full Level 2 program has run roughly $75k–$300k in the market (small-business average near $138k); DoD's own worst-case three-year estimate is about $488k. The suspension removes the C3PAO assessment fee ($30k–$100k+) from near-term costs, so most small shops today face the preparation-and-tooling tier.

What's the difference between CMMC Level 1 and Level 2?

Level 1 covers FCI with 15 basic safeguarding controls (FAR 52.204-21), self-assessed. Level 2 covers CUI with the 110 controls of NIST SP 800-171 Rev. 2. During the suspension both are self-assessed.

How does a small business actually find DoD contracts?

Most start as a subcontractor to a prime. Register in SAM.gov, search and set alerts there, use SubNet and primes' small-business liaison offices, and pursue SBA set-asides you qualify for — 8(a), SDVOSB, WOSB, HUBZone. APEX Accelerators offer free help.

When will CMMC come back or change?

DoD's reform task force has ~60 days to gather feedback plus 15 to write recommendations, and a public RFI closed in mid-August 2026, so a report is expected around late September 2026. Outcomes could range from minor tweaks to an overhaul, likely followed by a revised rule. Until then, self-assessment is the requirement.