Ditch Microsoft & Google Today!

CMMC Compliance for Small Defense Contractors: What Level 2 Actually Asks For

CMMC compliance is the Department of Defense’s requirement that contractors prove they protect federal contract information and controlled unclassified information before they are awarded work. Since the acquisition rule took effect on 10 November 2025, CMMC requirements began appearing in DoD solicitations on a phased schedule — which means for many small contractors the question is no longer whether it applies, but when it lands in a contract you want.

CMMC compliance
CMMC compliance from LiberationTek

This is an explainer, not a sales page. We are not a CMMC assessor and we do not sell a certification. What we do is run the infrastructure around the work — email, hosting, backups, networks — and small contractors keep asking us the same questions. Here are the honest answers.

The Three Levels, Briefly

  • Level 1 covers federal contract information and a short list of basic safeguarding practices, met by annual self-assessment.
  • Level 2 covers controlled unclassified information and aligns with the 110 security requirements in NIST SP 800-171. Depending on the contract, it is met either by self-assessment or by certification from an accredited third-party assessor.
  • Level 3 applies to the highest-priority programs and adds selected requirements from NIST SP 800-172, assessed by the government.

Which level applies to you is written into the contract, not chosen by you. Your contracting officer is the authority, and if a solicitation is ambiguous, ask in writing before you bid.

What CMMC Compliance Actually Asks A Small Shop To Do

Strip away the acronyms and Level 2 is asking whether you can answer these questions with evidence rather than opinion:

  • Do you know which systems touch CUI, and can you draw that boundary on a page?
  • Is access limited to named people who need it, with multi-factor authentication?
  • Is CUI encrypted in transit and at rest, using validated cryptography?
  • Are logs kept, and does somebody look at them?
  • Are media, laptops and backups controlled when they leave the building?
  • Do you train the people who handle it, and can you prove you did?
  • Do you have an incident response plan with reporting timelines you can actually meet?

Most small contractors fail on scope and evidence rather than on technology. The tooling exists; the documentation and the discipline are what is missing.

Scope Is The Whole Game

The single most expensive mistake is letting CUI spread across every system you own. A shop that keeps CUI inside a defined enclave — a small set of systems, accounts and storage — has a far smaller, cheaper assessment than one where a drawing has been emailed to three personal accounts and a shared drive.

Practical version: decide where CUI lives before you start buying tools. Then keep everything else — the marketing site, the general staff mailboxes, the public file sharing — deliberately out of scope.

Where Email And Hosting Fit

This is where we are careful. Handling CUI in email imposes requirements that most standard business mail platforms do not meet, including validated encryption and constraints on who can access the system. That is why the market for compliant email is narrow and why products like Microsoft’s GCC High exist.

So the honest split is this. Your CUI enclave needs a platform built and contracted for that purpose, and we will tell you when what we run is not it. Your everything else — the public website, the general business mailboxes, the backups of non-CUI systems, the network and workstation management around the enclave — is ordinary infrastructure, and that is the part we can take off your plate.

Anyone who tells you a standard hosting plan makes you CMMC compliant is either confused or selling something. Compliance is a property of your whole system and your evidence, not of a product you bought.

A Sensible Order Of Operations

  1. Read the contract and confirm the level with your contracting officer.
  2. Inventory where CUI is today, honestly, including inboxes and personal devices.
  3. Draw the enclave and shrink it until it is boring.
  4. Assess against NIST SP 800-171, record a score and a plan for the gaps.
  5. Fix the gaps in priority order, keeping evidence as you go.
  6. Book the assessment when the evidence is real, not when the calendar says so.

Talk To Us About The Parts We Run

If you are working through CMMC compliance and want a straight conversation about which of your systems are genuinely in scope and which are not — and who should run the ones that are not — book a call. We will not sell you a certification, and we will say plainly where you need a specialist instead.

CMMC Compliance FAQ

What is CMMC compliance?

It is the Department of Defense’s requirement that contractors demonstrate specified cybersecurity practices before award, at Level 1, 2 or 3 depending on the information involved and what the contract says.

When does CMMC apply to my contract?

The acquisition rule took effect on 10 November 2025 and CMMC requirements are being phased into DoD solicitations. The requirement applies when it appears in your specific contract, so confirm it with your contracting officer.

Is CMMC Level 2 the same as NIST SP 800-171?

Level 2 aligns with the 110 security requirements of NIST SP 800-171. Whether you can self-assess or need a third-party assessment depends on the contract.

Does buying compliant software make us compliant?

No. Compliance covers your whole system, your processes and your evidence. A product can help you meet specific requirements; it cannot make you compliant on its own.

Can LiberationTek make us CMMC compliant?

No, and we will not claim otherwise. We are not an assessor and we do not sell a CUI enclave. We can run the infrastructure outside your enclave and help you keep that boundary clean.

Related reading