Comprehensive Guide · 2026

CMMC Level 2 Compliance Platform for Small Defense Contractors.

What to look for, what to avoid, and what no one else will tell you about tools, pricing, and C3PAO assessment readiness. Written by people who have been inside both sides of the process.

Last updated: February 26, 2026

Origin Tool comparison 110-req checklist Pricing Assessors SSP & docs Ongoing compliance FAQ

The defense industrial base has a problem. Over the past decade, the number of small businesses in the DIB has declined by more than 40%. Compliance burden is a significant driver. CMMC Level 2 is the latest chapter. For a 15-person manufacturer or a 30-person engineering firm, the same 110 security requirements that apply to a 5,000-person prime contractor also apply to you. Same standard. Fraction of the resources.

This guide exists because most CMMC content on the internet is written by vendors who want to sell you something and consultants who want to bill you. What follows is an honest, specific account of what a CMMC compliance platform actually needs to do for a small defense contractor: what the 110 requirements mean in practice, how to evaluate tools, how to read pricing that vendors deliberately obscure, and what the assessment experience actually looks like from the inside.

About this guide
1TEN was built by people who lived this problem. The perspective here is earned, not theoretical. We'll mention 1TEN where relevant, but this guide is designed to be useful regardless of what platform you ultimately choose.

Why 1TEN was built

The tools available to small defense contractors when CMMC began taking shape fell into two categories: general-purpose GRC platforms that required expensive configuration and compliance expertise to be useful, and consultants charging by the hour to manually produce documentation that would be outdated six months later.

Neither option reflected how small manufacturers and engineering firms actually operate. A 20-person shop doesn't have a CISO. They have an IT person who also handles the phones, and a quality manager who is already managing ISO certifications, customer audits, and production deadlines. Asking that organization to navigate a 400-page NIST framework and produce a System Security Plan from scratch is not a compliance challenge. It's an existential one.

The core insight
"The assessment isn't designed to trick you. But it is designed to verify. Verification is a different standard than documentation." The gap between self-reported SPRS scores and C3PAO-verified scores is real, consistent, and predictable. 1TEN exists to close it.

The result is an air-gapped, on-premises appliance that walks a defense contractor through the entire CMMC Level 2 process: from first assessment interview through fully generated SSP, 14 domain policies, and ongoing compliance calendar. Every piece of output is designed to the standard that C3PAO assessors actually apply.

It is deployed on your premises because your CUI should never leave your network to achieve compliance with regulations designed to protect your CUI. The irony of uploading sensitive compliance data to a shared cloud to prove you handle sensitive data securely is not lost on us.

DIB-focused tools vs. enterprise tools not built for small contractors

The CMMC compliance software market broadly divides into three categories. Understanding what each does — and doesn't do — is essential before you spend money.

Capability Enterprise GRC Content Comm. Purpose-Built CMMC
All 110 requirementsConfigurablePartial (~90%)✓ All 110
Automated SSP generationWith configurationNo✓ From your data
14 domain policies auto-generatedNoNo✓ All 14
SPRS score calculationSome productsNo✓ Real-time
C3PAO assessor questions built inNoNo✓ Every requirement
Security awareness trainingNoNo✓ AT.L2 compliant
CUI stays on your premisesDependsCloud-based✓ Air-gapped
Designed for non-security staffNoPartial✓ Yes
Implementation time3–12 monthsWeeks (limited scope)Days to weeks

The content communication platform problem

Platforms like Kiteworks are built around securing file transfer, email, and content sharing. When vendors say they support "nearly 90% of CMMC Level 2 requirements," that claim requires context: they mean their platform can help satisfy some objectives for the specific use case of content communications. Your SSP, policies, training records, incident response plan, configuration baselines, and risk assessment still need to be built from scratch.

The enterprise GRC platform problem

Enterprise GRC platforms are genuinely capable — if you have the resources to configure them, the expertise to maintain them, and the staff to use them. For most small defense contractors, none of those conditions apply. Configuring them for CMMC typically requires a consultant engagement that costs more than the software itself.

Assessment readiness checklist: all 110 requirements by domain

Use this checklist to assess your current posture. For each requirement, mark status as Met, POA&M (gap with remediation plan), or Not Started. SPRS scoring deducts points for every requirement not marked Met.

SPRS Scoring Note
Your score starts at 110 and each unmet requirement deducts its point value. Requirements worth 5 points cannot be deferred to a POA&M and must be fully implemented for certification. Full SPRS scoring guide →
AC Access Control 22 requirements · 54 SPRS pts · View domain →
ID Requirement SPRS Status
AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). 5pts
AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute. 5pts
AC.L2-3.1.3 Control the flow of CUI in accordance with approved authorizations. 1pt
AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion. 1pt
AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts. 3pts
AC.L2-3.1.6 Use non-privileged accounts or roles when accessing non-security functions. 1pt
AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. 1pt
AC.L2-3.1.8 Limit unsuccessful logon attempts. 1pt
AC.L2-3.1.9 Provide privacy and security notices consistent with CUI rules. 1pt
AC.L2-3.1.10 Use session lock with pattern-hiding displays after a period of inactivity. 1pt
AC.L2-3.1.11 Terminate sessions after a defined condition. 1pt
AC.L2-3.1.12 Monitor and control remote access sessions. 5pts
AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. 5pts
AC.L2-3.1.14 Route remote access via managed access control points. 1pt
AC.L2-3.1.15 Authorize remote execution of privileged commands and access to security-relevant information via remote access only for documented operational needs. 1pt
AC.L2-3.1.16 Authorize wireless access prior to allowing such connections. 5pts
AC.L2-3.1.17 Protect wireless access using authentication and encryption. 5pts
AC.L2-3.1.18 Control connection of mobile devices. 5pts
AC.L2-3.1.19 Encrypt CUI on mobile devices and mobile computing platforms. 3pts
AC.L2-3.1.20 Verify and control/limit connections to external systems. 1pt
AC.L2-3.1.21 Limit use of portable storage devices on external systems. 1pt
AC.L2-3.1.22 Control CUI posted or processed on publicly accessible systems. 1pt
AT Awareness & Training 3 requirements · 11 SPRS pts · View domain →
ID Requirement SPRS Status
AT.L2-3.2.1 Ensure that personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational systems. 5pts
AT.L2-3.2.2 Ensure that organizational personnel are adequately trained to carry out their assigned information security responsibilities. 5pts
AT.L2-3.2.3 Provide security awareness training on recognizing and reporting potential threats posed by social engineering, including phishing, pretexting, and tailgating. 1pt
AU Audit & Accountability 9 requirements · 19 SPRS pts · View domain →
ID Requirement SPRS Status
AU.L2-3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. 5pts
AU.L2-3.3.2 Ensure that the actions of individual system users can be traced to those users, so they can be held accountable for their actions. 3pts
AU.L2-3.3.3 Review and update logged events. 1pt
AU.L2-3.3.4 Alert in the event of an audit logging process failure. 1pt
AU.L2-3.3.5 Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. 5pts
AU.L2-3.3.6 Provide audit record reduction and report generation to support on-demand analysis and reporting. 1pt
AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. 1pt
AU.L2-3.3.8 Protect audit information and audit tools from unauthorized access, modification, and deletion. 1pt
AU.L2-3.3.9 Limit management of audit logging to a subset of privileged users. 1pt
CA Security Assessment 4 requirements · 13 SPRS pts · View domain →
ID Requirement SPRS Status
CA.L2-3.12.1 Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. 5pts
CA.L2-3.12.2 Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. 3pts
CA.L2-3.12.3 Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. 5pts
CA.L2-3.12.4 Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. (Not point-scored — a missing SSP invalidates the entire assessment rather than deducting points.) 0pts
CM Configuration Management 9 requirements · 33 SPRS pts · View domain →
ID Requirement SPRS Status
CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles. 5pts
CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems. 5pts
CM.L2-3.4.3 Track, review, approve, and log changes to organizational systems. 1pt
CM.L2-3.4.4 Analyze the security impact of changes prior to implementation. 1pt
CM.L2-3.4.5 Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. 5pts
CM.L2-3.4.6 Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. 5pts
CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. 5pts
CM.L2-3.4.8 Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software. 5pts
CM.L2-3.4.9 Control and monitor user-installed software. 1pt
IA Identification & Authentication 11 requirements · 27 SPRS pts · View domain →
ID Requirement SPRS Status
IA.L2-3.5.1 Identify system users, processes acting on behalf of users, and devices. 5pts
IA.L2-3.5.2 Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems. 5pts
IA.L2-3.5.3 Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. 5pts
IA.L2-3.5.4 Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. 1pt
IA.L2-3.5.5 Employ identifier management practices for user and device identifiers. 1pt
IA.L2-3.5.6 Disable identifiers after a defined inactivity period. 1pt
IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created. 1pt
IA.L2-3.5.8 Prohibit password reuse for a specified number of generations. 1pt
IA.L2-3.5.9 Allow temporary password use for system logons with an immediate change to a permanent password. 1pt
IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords. 5pts
IA.L2-3.5.11 Obscure feedback of authentication information. 1pt
IR Incident Response 3 requirements · 11 SPRS pts · View domain →
ID Requirement SPRS Status
IR.L2-3.6.1 Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. 5pts
IR.L2-3.6.2 Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. 3pts
IR.L2-3.6.3 Test the organizational incident response capability. 3pts
MA Maintenance 6 requirements · 18 SPRS pts · View domain →
ID Requirement SPRS Status
MA.L2-3.7.1 Perform maintenance on organizational systems. 3pts
MA.L2-3.7.2 Provide controls on the tools, techniques, mechanisms, and personnel for the performance of organizational system maintenance. 5pts
MA.L2-3.7.3 Ensure equipment removed for off-site maintenance is sanitized of any CUI. 1pt
MA.L2-3.7.4 Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. 3pts
MA.L2-3.7.5 Require MFA to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. 5pts
MA.L2-3.7.6 Supervise the maintenance activities of maintenance personnel without required access authorization. 1pt
MP Media Protection 9 requirements · 23 SPRS pts · View domain →
ID Requirement SPRS Status
MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. 3pts
MP.L2-3.8.2 Limit access to CUI on system media to authorized users. 3pts
MP.L2-3.8.3 Sanitize or destroy system media before disposal or reuse. 5pts
MP.L2-3.8.4 Mark media with necessary CUI markings and distribution limitations. 1pt
MP.L2-3.8.5 Control access to media containing CUI and maintain accountability for media during transport. 1pt
MP.L2-3.8.6 Implement cryptographic mechanisms to protect the confidentiality of CUI during transport unless otherwise protected by alternative physical safeguards. 1pt
MP.L2-3.8.7 Control the use of removable media on system components. 5pts
MP.L2-3.8.8 Prohibit the use of portable storage devices when such devices have no identifiable owner. 3pts
MP.L2-3.8.9 Protect the confidentiality of backup CUI at storage locations. 1pt
PE Physical Protection 6 requirements · 14 SPRS pts · View domain →
ID Requirement SPRS Status
PE.L2-3.10.1 Limit physical access to organizational systems to authorized individuals. 3pts
PE.L2-3.10.2 Protect and monitor the physical facility and support infrastructure for organizational systems. 3pts
PE.L2-3.10.3 Escort visitors and monitor visitor activity. 1pt
PE.L2-3.10.4 Maintain audit logs of physical access. 3pts
PE.L2-3.10.5 Control and manage physical access devices. 3pts
PE.L2-3.10.6 Enforce safeguarding measures for CUI at alternate work sites. 1pt
PS Personnel Security 2 requirements · 8 SPRS pts · View domain →
ID Requirement SPRS Status
PS.L2-3.9.1 Screen individuals prior to authorizing access to organizational systems containing CUI. 3pts
PS.L2-3.9.2 Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. 5pts
RA Risk Assessment 3 requirements · 9 SPRS pts · View domain →
ID Requirement SPRS Status
RA.L2-3.11.1 Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. 3pts
RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. 5pts
RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments. 1pt
SC System & Comms Protection 16 requirements · 42 SPRS pts · View domain →
ID Requirement SPRS Status
SC.L2-3.13.1 Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems. 5pts
SC.L2-3.13.2 Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. 5pts
SC.L2-3.13.3 Separate user functionality from system management functionality. 1pt
SC.L2-3.13.4 Prevent unauthorized and unintended information transfer via shared system resources. 1pt
SC.L2-3.13.5 Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. 5pts
SC.L2-3.13.6 Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). 5pts
SC.L2-3.13.7 Prevent remote devices from simultaneously using remote connections with the system and communicating via some other pathway to resources in other networks (i.e., split tunneling). 1pt
SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. 3pts
SC.L2-3.13.9 Terminate network connections associated with communications sessions after a defined period of inactivity. 1pt
SC.L2-3.13.10 Establish and manage cryptographic keys for cryptography employed in organizational systems. 1pt
SC.L2-3.13.11 Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. 5pts
SC.L2-3.13.12 Prohibit remote activation of collaborative computing devices and provide indication of use to present users. 1pt
SC.L2-3.13.13 Control and monitor the use of mobile code. 1pt
SC.L2-3.13.14 Control and monitor the use of VoIP technologies. 1pt
SC.L2-3.13.15 Protect the authenticity of communications sessions. 5pts
SC.L2-3.13.16 Protect CUI at rest. 1pt
SI System & Info Integrity 7 requirements · 31 SPRS pts · View domain →
ID Requirement SPRS Status
SI.L2-3.14.1 Identify, report, and correct information and information system flaws in a timely manner. 5pts
SI.L2-3.14.2 Provide protection from malicious code at appropriate locations within organizational systems. 5pts
SI.L2-3.14.3 Monitor system security alerts and advisories and take action in response. 5pts
SI.L2-3.14.4 Update malicious code protection mechanisms when new releases are available. 5pts
SI.L2-3.14.5 Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed. 3pts
SI.L2-3.14.6 Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. 5pts
SI.L2-3.14.7 Identify unauthorized use of organizational systems. 3pts
Live SPRS Score Estimate
110
Mark requirements Met or POA&M above to see your estimated score. Track live in 1TEN →
Want this tracked automatically?
1TEN maps your responses to all 110 requirements, calculates your live SPRS score, and generates your SSP and POA&M from your answers. No spreadsheet. No manual tracking. Request a demo →

What CMMC compliance tools actually cost

Most CMMC vendors deliberately avoid publishing pricing. The reason is not complexity — pricing comparisons favor vendors whose costs are genuinely lower, and most enterprise vendors don't want that comparison happening before a relationship is established.

Enterprise GRC
ServiceNow, RSA Archer, OneTrust
$15K–$80K/yr
⚠ Not built for small DIB contractors
Plus $20K–$100K+ in implementation and configuration costs. Requires ongoing consultant support. Total first-year cost frequently exceeds $100,000.
Cloud CMMC SaaS
Compyl, Drata (CMMC module), Scrut
$3K–$25K/yr
⚠ Review CUI scoping implications
Per-user pricing typical. Does not include consulting fees for SSP writing or policy development. Your compliance data lives on their cloud infrastructure.

The honest comparison: enterprise GRC is priced for organizations that have compliance teams. Cloud SaaS introduces a CUI scoping complication. A purpose-built air-gapped platform eliminates both problems — at a price point designed for the organizations that actually need it.

What C3PAO assessors actually look for

C3PAO assessors are not trying to fail you. They're trying to verify that your security controls actually exist and actually work — not just that you wrote down that they do. Understanding the verification standard changes how you document.

The three things assessors verify for every control

Policy exists— a written document that states the control is required and describes how it is implemented at your organization
Control is implemented— demonstrable evidence that the control functions in your actual environment (configuration screenshots, access logs, training records)
Evidence supports the claim— artifacts linked to the specific requirement that prove the policy isn't aspirational
The gap most contractors miss
Generic or templated documentation fails the second and third tests. Assessors will ask to see your specific environment reflected in your SSP, will interview personnel to verify training, and will observe system configurations. The biggest gap between self-assessments and C3PAO-verified scores is documentation that describes a control without proving it works.

Interview questions you should expect

For every domain, assessors conduct structured interviews. Common questions include: "Walk me through how a new user is provisioned and what access they receive." "Show me where your audit logs are and how you review them." "What would happen if an employee's laptop were lost or stolen?" Your platform should prepare you for these — not just ask you to mark a box.

SSP and documentation: what good looks like

Your System Security Plan is the first document your C3PAO assessor reads. It is also the document that sets their expectation for everything that follows. A weak SSP creates suspicion before the assessment even begins. A strong SSP demonstrates that you understand your environment and have thought carefully about how each control is implemented.

Required SSP sections

Executive Summary— organization overview, scope statement, and assessment date
System Identification— system name, purpose, CUI types, system boundaries
Roles & Responsibilities— named personnel and their security responsibilities
Tools & Technologies— all systems, software, and hardware in the CUI boundary
Control Implementation— statement for each of the 110 requirements
Training Program— training content, assignments, completion records
POA&M— all unmet requirements with timelines, owners, and interim mitigations
Evidence Index— list of all supporting artifacts with references to the requirements they satisfy

1TEN generates all of these sections from your environment data automatically. The output reads like a document written about your organization — because it was. Full SSP guide →

After certification: ongoing compliance requirements

CMMC Level 2 certification is valid for 3 years. But the compliance obligations don't pause between assessments. Several ongoing requirements must be maintained:

Annual affirmation— a named senior official must affirm annually that your compliance posture has not materially changed. 1TEN's Annual Affirmation module tracks this automatically.
Recurring security tasks— backup verification, audit log review, vulnerability scanning, privileged access reviews, and media sanitization logs must be performed and documented on a schedule.
Training renewals— personnel security awareness training must be refreshed periodically. Completion records must be available for the annual affirmation review.
SSP currency— your SSP must be updated when your environment changes. New systems in scope, personnel changes, or architecture modifications all require SSP revision.
POA&M closure— any items on your POA&M at certification must be closed within the 180-day conditional window, with documentation of completion.

Certification is the beginning of a 3-year compliance cycle, not the end of a project. The contractors who maintain strong posture between assessments are the ones who build ongoing compliance into their operations — not the ones who sprint to certification and then let their documentation go stale. POA&M guide →

Frequently asked questions

Do small defense contractors really need CMMC Level 2 certification?

Yes — if your contract involves Controlled Unclassified Information (CUI), CMMC Level 2 is a mandatory contract requirement regardless of company size. A 10-person shop supplying a prime contractor handles the same CUI protection obligations as a 500-person firm. The DoD has codified this in 48 CFR 252.204-7021.

How long does CMMC Level 2 certification take?

From initial assessment to C3PAO certification, most small contractors should plan for 6 to 18 months depending on their starting posture. Organizations with weak SPRS scores or no existing documentation typically need 12+ months of remediation. Organizations that are well-prepared with complete documentation, trained staff, and a credible POA&M can complete the process in 6 to 9 months.

What is the difference between a CMMC compliance platform and a GRC tool?

A GRC tool is general-purpose and can be configured for many standards including CMMC, SOC 2, HIPAA, and others. A CMMC-specific platform is built exclusively around the 110 NIST SP 800-171 requirements and C3PAO assessment process, with pre-built SSP templates, embedded assessor questions, SPRS scoring, and domain policies designed specifically for defense contractors. For small contractors without a dedicated compliance team, a purpose-built CMMC platform is almost always faster and more practical.

Can I use a cloud-based CMMC tool if I handle CUI?

You can, but it adds complexity to your scoping and shared responsibility picture. If your compliance documentation — SSPs, policies, evidence — lives on a vendor's cloud, that infrastructure may fall within your CUI boundary and require its own security controls. An on-premises or air-gapped deployment keeps all compliance data inside your network, simplifying your scope and eliminating cloud dependency from your assessment conversation.

What do C3PAO assessors actually look for?

C3PAO assessors verify three things for each of the 110 requirements: that a policy exists, that the policy is implemented and demonstrably functioning, and that evidence supports the claim. Generic or templated documentation fails the second and third tests. The biggest gap between self-assessments and C3PAO-verified scores is documentation that describes a control without proving it works.

What is a POA&M and when is it required?

A Plan of Action and Milestones (POA&M) documents the security gaps in your environment: requirements that are not yet fully implemented, along with remediation timelines, responsible owners, and interim mitigations. Under CMMC Level 2, a limited number of non-critical requirements may be addressed via POA&M at the time of assessment, giving you 180 days post-certification to close them. High-weight requirements and those related to CUI protection generally cannot be deferred. Full POA&M guide →

Miss nothing.

1TEN gives your team the structure to govern CMMC compliance without building a compliance department around it.

Request a Demo