The defense industrial base has a problem. Over the past decade, the number of small businesses in the DIB has declined by more than 40%. Compliance burden is a significant driver. CMMC Level 2 is the latest chapter. For a 15-person manufacturer or a 30-person engineering firm, the same 110 security requirements that apply to a 5,000-person prime contractor also apply to you. Same standard. Fraction of the resources.
This guide exists because most CMMC content on the internet is written by vendors who want to sell you something and consultants who want to bill you. What follows is an honest, specific account of what a CMMC compliance platform actually needs to do for a small defense contractor: what the 110 requirements mean in practice, how to evaluate tools, how to read pricing that vendors deliberately obscure, and what the assessment experience actually looks like from the inside.
Why 1TEN was built
The tools available to small defense contractors when CMMC began taking shape fell into two categories: general-purpose GRC platforms that required expensive configuration and compliance expertise to be useful, and consultants charging by the hour to manually produce documentation that would be outdated six months later.
Neither option reflected how small manufacturers and engineering firms actually operate. A 20-person shop doesn't have a CISO. They have an IT person who also handles the phones, and a quality manager who is already managing ISO certifications, customer audits, and production deadlines. Asking that organization to navigate a 400-page NIST framework and produce a System Security Plan from scratch is not a compliance challenge. It's an existential one.
The result is an air-gapped, on-premises appliance that walks a defense contractor through the entire CMMC Level 2 process: from first assessment interview through fully generated SSP, 14 domain policies, and ongoing compliance calendar. Every piece of output is designed to the standard that C3PAO assessors actually apply.
It is deployed on your premises because your CUI should never leave your network to achieve compliance with regulations designed to protect your CUI. The irony of uploading sensitive compliance data to a shared cloud to prove you handle sensitive data securely is not lost on us.
DIB-focused tools vs. enterprise tools not built for small contractors
The CMMC compliance software market broadly divides into three categories. Understanding what each does — and doesn't do — is essential before you spend money.
| Capability | Enterprise GRC | Content Comm. | Purpose-Built CMMC |
|---|---|---|---|
| All 110 requirements | Configurable | Partial (~90%) | ✓ All 110 |
| Automated SSP generation | With configuration | No | ✓ From your data |
| 14 domain policies auto-generated | No | No | ✓ All 14 |
| SPRS score calculation | Some products | No | ✓ Real-time |
| C3PAO assessor questions built in | No | No | ✓ Every requirement |
| Security awareness training | No | No | ✓ AT.L2 compliant |
| CUI stays on your premises | Depends | Cloud-based | ✓ Air-gapped |
| Designed for non-security staff | No | Partial | ✓ Yes |
| Implementation time | 3–12 months | Weeks (limited scope) | Days to weeks |
The content communication platform problem
Platforms like Kiteworks are built around securing file transfer, email, and content sharing. When vendors say they support "nearly 90% of CMMC Level 2 requirements," that claim requires context: they mean their platform can help satisfy some objectives for the specific use case of content communications. Your SSP, policies, training records, incident response plan, configuration baselines, and risk assessment still need to be built from scratch.
The enterprise GRC platform problem
Enterprise GRC platforms are genuinely capable — if you have the resources to configure them, the expertise to maintain them, and the staff to use them. For most small defense contractors, none of those conditions apply. Configuring them for CMMC typically requires a consultant engagement that costs more than the software itself.
Assessment readiness checklist: all 110 requirements by domain
Use this checklist to assess your current posture. For each requirement, mark status as Met, POA&M (gap with remediation plan), or Not Started. SPRS scoring deducts points for every requirement not marked Met.
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| AC.L2-3.1.1 | Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). | 5pts | |
| AC.L2-3.1.2 | Limit system access to the types of transactions and functions that authorized users are permitted to execute. | 5pts | |
| AC.L2-3.1.3 | Control the flow of CUI in accordance with approved authorizations. | 1pt | |
| AC.L2-3.1.4 | Separate the duties of individuals to reduce the risk of malevolent activity without collusion. | 1pt | |
| AC.L2-3.1.5 | Employ the principle of least privilege, including for specific security functions and privileged accounts. | 3pts | |
| AC.L2-3.1.6 | Use non-privileged accounts or roles when accessing non-security functions. | 1pt | |
| AC.L2-3.1.7 | Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. | 1pt | |
| AC.L2-3.1.8 | Limit unsuccessful logon attempts. | 1pt | |
| AC.L2-3.1.9 | Provide privacy and security notices consistent with CUI rules. | 1pt | |
| AC.L2-3.1.10 | Use session lock with pattern-hiding displays after a period of inactivity. | 1pt | |
| AC.L2-3.1.11 | Terminate sessions after a defined condition. | 1pt | |
| AC.L2-3.1.12 | Monitor and control remote access sessions. | 5pts | |
| AC.L2-3.1.13 | Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. | 5pts | |
| AC.L2-3.1.14 | Route remote access via managed access control points. | 1pt | |
| AC.L2-3.1.15 | Authorize remote execution of privileged commands and access to security-relevant information via remote access only for documented operational needs. | 1pt | |
| AC.L2-3.1.16 | Authorize wireless access prior to allowing such connections. | 5pts | |
| AC.L2-3.1.17 | Protect wireless access using authentication and encryption. | 5pts | |
| AC.L2-3.1.18 | Control connection of mobile devices. | 5pts | |
| AC.L2-3.1.19 | Encrypt CUI on mobile devices and mobile computing platforms. | 3pts | |
| AC.L2-3.1.20 | Verify and control/limit connections to external systems. | 1pt | |
| AC.L2-3.1.21 | Limit use of portable storage devices on external systems. | 1pt | |
| AC.L2-3.1.22 | Control CUI posted or processed on publicly accessible systems. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| AT.L2-3.2.1 | Ensure that personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems. | 5pts | |
| AT.L2-3.2.2 | Ensure that organizational personnel are adequately trained to carry out their assigned information security responsibilities. | 5pts | |
| AT.L2-3.2.3 | Provide security awareness training on recognizing and reporting potential threats posed by social engineering, including phishing, pretexting, and tailgating. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| AU.L2-3.3.1 | Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. | 5pts | |
| AU.L2-3.3.2 | Ensure that the actions of individual system users can be traced to those users, so they can be held accountable for their actions. | 3pts | |
| AU.L2-3.3.3 | Review and update logged events. | 1pt | |
| AU.L2-3.3.4 | Alert in the event of an audit logging process failure. | 1pt | |
| AU.L2-3.3.5 | Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. | 5pts | |
| AU.L2-3.3.6 | Provide audit record reduction and report generation to support on-demand analysis and reporting. | 1pt | |
| AU.L2-3.3.7 | Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. | 1pt | |
| AU.L2-3.3.8 | Protect audit information and audit tools from unauthorized access, modification, and deletion. | 1pt | |
| AU.L2-3.3.9 | Limit management of audit logging to a subset of privileged users. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| CA.L2-3.12.1 | Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. | 5pts | |
| CA.L2-3.12.2 | Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. | 3pts | |
| CA.L2-3.12.3 | Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. | 5pts | |
| CA.L2-3.12.4 | Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. (Not point-scored — a missing SSP invalidates the entire assessment rather than deducting points.) | 0pts |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| CM.L2-3.4.1 | Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles. | 5pts | |
| CM.L2-3.4.2 | Establish and enforce security configuration settings for information technology products employed in organizational systems. | 5pts | |
| CM.L2-3.4.3 | Track, review, approve, and log changes to organizational systems. | 1pt | |
| CM.L2-3.4.4 | Analyze the security impact of changes prior to implementation. | 1pt | |
| CM.L2-3.4.5 | Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. | 5pts | |
| CM.L2-3.4.6 | Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. | 5pts | |
| CM.L2-3.4.7 | Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. | 5pts | |
| CM.L2-3.4.8 | Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software. | 5pts | |
| CM.L2-3.4.9 | Control and monitor user-installed software. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| IA.L2-3.5.1 | Identify system users, processes acting on behalf of users, and devices. | 5pts | |
| IA.L2-3.5.2 | Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems. | 5pts | |
| IA.L2-3.5.3 | Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. | 5pts | |
| IA.L2-3.5.4 | Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. | 1pt | |
| IA.L2-3.5.5 | Employ identifier management practices for user and device identifiers. | 1pt | |
| IA.L2-3.5.6 | Disable identifiers after a defined inactivity period. | 1pt | |
| IA.L2-3.5.7 | Enforce a minimum password complexity and change of characters when new passwords are created. | 1pt | |
| IA.L2-3.5.8 | Prohibit password reuse for a specified number of generations. | 1pt | |
| IA.L2-3.5.9 | Allow temporary password use for system logons with an immediate change to a permanent password. | 1pt | |
| IA.L2-3.5.10 | Store and transmit only cryptographically-protected passwords. | 5pts | |
| IA.L2-3.5.11 | Obscure feedback of authentication information. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| IR.L2-3.6.1 | Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. | 5pts | |
| IR.L2-3.6.2 | Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. | 3pts | |
| IR.L2-3.6.3 | Test the organizational incident response capability. | 3pts |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| MA.L2-3.7.1 | Perform maintenance on organizational systems. | 3pts | |
| MA.L2-3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel for the performance of organizational system maintenance. | 5pts | |
| MA.L2-3.7.3 | Ensure equipment removed for off-site maintenance is sanitized of any CUI. | 1pt | |
| MA.L2-3.7.4 | Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. | 3pts | |
| MA.L2-3.7.5 | Require MFA to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. | 5pts | |
| MA.L2-3.7.6 | Supervise the maintenance activities of maintenance personnel without required access authorization. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| MP.L2-3.8.1 | Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. | 3pts | |
| MP.L2-3.8.2 | Limit access to CUI on system media to authorized users. | 3pts | |
| MP.L2-3.8.3 | Sanitize or destroy system media before disposal or reuse. | 5pts | |
| MP.L2-3.8.4 | Mark media with necessary CUI markings and distribution limitations. | 1pt | |
| MP.L2-3.8.5 | Control access to media containing CUI and maintain accountability for media during transport. | 1pt | |
| MP.L2-3.8.6 | Implement cryptographic mechanisms to protect the confidentiality of CUI during transport unless otherwise protected by alternative physical safeguards. | 1pt | |
| MP.L2-3.8.7 | Control the use of removable media on system components. | 5pts | |
| MP.L2-3.8.8 | Prohibit the use of portable storage devices when such devices have no identifiable owner. | 3pts | |
| MP.L2-3.8.9 | Protect the confidentiality of backup CUI at storage locations. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| PE.L2-3.10.1 | Limit physical access to organizational systems to authorized individuals. | 3pts | |
| PE.L2-3.10.2 | Protect and monitor the physical facility and support infrastructure for organizational systems. | 3pts | |
| PE.L2-3.10.3 | Escort visitors and monitor visitor activity. | 1pt | |
| PE.L2-3.10.4 | Maintain audit logs of physical access. | 3pts | |
| PE.L2-3.10.5 | Control and manage physical access devices. | 3pts | |
| PE.L2-3.10.6 | Enforce safeguarding measures for CUI at alternate work sites. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| PS.L2-3.9.1 | Screen individuals prior to authorizing access to organizational systems containing CUI. | 3pts | |
| PS.L2-3.9.2 | Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. | 5pts |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| RA.L2-3.11.1 | Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. | 3pts | |
| RA.L2-3.11.2 | Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. | 5pts | |
| RA.L2-3.11.3 | Remediate vulnerabilities in accordance with risk assessments. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| SC.L2-3.13.1 | Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems. | 5pts | |
| SC.L2-3.13.2 | Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. | 5pts | |
| SC.L2-3.13.3 | Separate user functionality from system management functionality. | 1pt | |
| SC.L2-3.13.4 | Prevent unauthorized and unintended information transfer via shared system resources. | 1pt | |
| SC.L2-3.13.5 | Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. | 5pts | |
| SC.L2-3.13.6 | Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). | 5pts | |
| SC.L2-3.13.7 | Prevent remote devices from simultaneously using remote connections with the system and communicating via some other pathway to resources in other networks (i.e., split tunneling). | 1pt | |
| SC.L2-3.13.8 | Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. | 3pts | |
| SC.L2-3.13.9 | Terminate network connections associated with communications sessions after a defined period of inactivity. | 1pt | |
| SC.L2-3.13.10 | Establish and manage cryptographic keys for cryptography employed in organizational systems. | 1pt | |
| SC.L2-3.13.11 | Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. | 5pts | |
| SC.L2-3.13.12 | Prohibit remote activation of collaborative computing devices and provide indication of use to present users. | 1pt | |
| SC.L2-3.13.13 | Control and monitor the use of mobile code. | 1pt | |
| SC.L2-3.13.14 | Control and monitor the use of VoIP technologies. | 1pt | |
| SC.L2-3.13.15 | Protect the authenticity of communications sessions. | 5pts | |
| SC.L2-3.13.16 | Protect CUI at rest. | 1pt |
| ID | Requirement | SPRS | Status |
|---|---|---|---|
| SI.L2-3.14.1 | Identify, report, and correct information and information system flaws in a timely manner. | 5pts | |
| SI.L2-3.14.2 | Provide protection from malicious code at appropriate locations within organizational systems. | 5pts | |
| SI.L2-3.14.3 | Monitor system security alerts and advisories and take action in response. | 5pts | |
| SI.L2-3.14.4 | Update malicious code protection mechanisms when new releases are available. | 5pts | |
| SI.L2-3.14.5 | Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed. | 3pts | |
| SI.L2-3.14.6 | Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. | 5pts | |
| SI.L2-3.14.7 | Identify unauthorized use of organizational systems. | 3pts |
What CMMC compliance tools actually cost
Most CMMC vendors deliberately avoid publishing pricing. The reason is not complexity — pricing comparisons favor vendors whose costs are genuinely lower, and most enterprise vendors don't want that comparison happening before a relationship is established.
The honest comparison: enterprise GRC is priced for organizations that have compliance teams. Cloud SaaS introduces a CUI scoping complication. A purpose-built air-gapped platform eliminates both problems — at a price point designed for the organizations that actually need it.
What C3PAO assessors actually look for
C3PAO assessors are not trying to fail you. They're trying to verify that your security controls actually exist and actually work — not just that you wrote down that they do. Understanding the verification standard changes how you document.
The three things assessors verify for every control
| Policy exists | — a written document that states the control is required and describes how it is implemented at your organization |
| Control is implemented | — demonstrable evidence that the control functions in your actual environment (configuration screenshots, access logs, training records) |
| Evidence supports the claim | — artifacts linked to the specific requirement that prove the policy isn't aspirational |
Interview questions you should expect
For every domain, assessors conduct structured interviews. Common questions include: "Walk me through how a new user is provisioned and what access they receive." "Show me where your audit logs are and how you review them." "What would happen if an employee's laptop were lost or stolen?" Your platform should prepare you for these — not just ask you to mark a box.
SSP and documentation: what good looks like
Your System Security Plan is the first document your C3PAO assessor reads. It is also the document that sets their expectation for everything that follows. A weak SSP creates suspicion before the assessment even begins. A strong SSP demonstrates that you understand your environment and have thought carefully about how each control is implemented.
Required SSP sections
| Executive Summary | — organization overview, scope statement, and assessment date |
| System Identification | — system name, purpose, CUI types, system boundaries |
| Roles & Responsibilities | — named personnel and their security responsibilities |
| Tools & Technologies | — all systems, software, and hardware in the CUI boundary |
| Control Implementation | — statement for each of the 110 requirements |
| Training Program | — training content, assignments, completion records |
| POA&M | — all unmet requirements with timelines, owners, and interim mitigations |
| Evidence Index | — list of all supporting artifacts with references to the requirements they satisfy |
1TEN generates all of these sections from your environment data automatically. The output reads like a document written about your organization — because it was. Full SSP guide →
After certification: ongoing compliance requirements
CMMC Level 2 certification is valid for 3 years. But the compliance obligations don't pause between assessments. Several ongoing requirements must be maintained:
| Annual affirmation | — a named senior official must affirm annually that your compliance posture has not materially changed. 1TEN's Annual Affirmation module tracks this automatically. |
| Recurring security tasks | — backup verification, audit log review, vulnerability scanning, privileged access reviews, and media sanitization logs must be performed and documented on a schedule. |
| Training renewals | — personnel security awareness training must be refreshed periodically. Completion records must be available for the annual affirmation review. |
| SSP currency | — your SSP must be updated when your environment changes. New systems in scope, personnel changes, or architecture modifications all require SSP revision. |
| POA&M closure | — any items on your POA&M at certification must be closed within the 180-day conditional window, with documentation of completion. |
Certification is the beginning of a 3-year compliance cycle, not the end of a project. The contractors who maintain strong posture between assessments are the ones who build ongoing compliance into their operations — not the ones who sprint to certification and then let their documentation go stale. POA&M guide →
Frequently asked questions
Do small defense contractors really need CMMC Level 2 certification?
Yes — if your contract involves Controlled Unclassified Information (CUI), CMMC Level 2 is a mandatory contract requirement regardless of company size. A 10-person shop supplying a prime contractor handles the same CUI protection obligations as a 500-person firm. The DoD has codified this in 48 CFR 252.204-7021.
How long does CMMC Level 2 certification take?
From initial assessment to C3PAO certification, most small contractors should plan for 6 to 18 months depending on their starting posture. Organizations with weak SPRS scores or no existing documentation typically need 12+ months of remediation. Organizations that are well-prepared with complete documentation, trained staff, and a credible POA&M can complete the process in 6 to 9 months.
What is the difference between a CMMC compliance platform and a GRC tool?
A GRC tool is general-purpose and can be configured for many standards including CMMC, SOC 2, HIPAA, and others. A CMMC-specific platform is built exclusively around the 110 NIST SP 800-171 requirements and C3PAO assessment process, with pre-built SSP templates, embedded assessor questions, SPRS scoring, and domain policies designed specifically for defense contractors. For small contractors without a dedicated compliance team, a purpose-built CMMC platform is almost always faster and more practical.
Can I use a cloud-based CMMC tool if I handle CUI?
You can, but it adds complexity to your scoping and shared responsibility picture. If your compliance documentation — SSPs, policies, evidence — lives on a vendor's cloud, that infrastructure may fall within your CUI boundary and require its own security controls. An on-premises or air-gapped deployment keeps all compliance data inside your network, simplifying your scope and eliminating cloud dependency from your assessment conversation.
What do C3PAO assessors actually look for?
C3PAO assessors verify three things for each of the 110 requirements: that a policy exists, that the policy is implemented and demonstrably functioning, and that evidence supports the claim. Generic or templated documentation fails the second and third tests. The biggest gap between self-assessments and C3PAO-verified scores is documentation that describes a control without proving it works.
What is a POA&M and when is it required?
A Plan of Action and Milestones (POA&M) documents the security gaps in your environment: requirements that are not yet fully implemented, along with remediation timelines, responsible owners, and interim mitigations. Under CMMC Level 2, a limited number of non-critical requirements may be addressed via POA&M at the time of assessment, giving you 180 days post-certification to close them. High-weight requirements and those related to CUI protection generally cannot be deferred. Full POA&M guide →