Articles

CMMC 2.0 Compliance for Suppliers

Devon Smibert CD, MBA, BSc, CISSP
CMMC 2.0 Compliance for Suppliers

For defense suppliers, CMMC 2.0 is no longer a policy discussion. It is a revenue filter.

If your company touches Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), the question is not whether security matters. The question is whether your controls, evidence, and governance can survive procurement scrutiny, prime contractor flow-downs, and a formal assessment when the contract requires it.

CMMC 2.0 changed the buying motion for suppliers

The Cybersecurity Maturity Model Certification (CMMC) was simplified under CMMC 2.0 into three levels. That sounds easier on paper. For suppliers, it sharpened the commercial line between companies that can prove control performance and companies still managing compliance in spreadsheets.

Level 1 maps to 15 basic safeguarding requirements drawn from Federal Acquisition Regulation (FAR) clause 52.204-21. Level 2 maps to the 110 security requirements in National Institute of Standards and Technology (NIST) Special Publication 800-171 Rev 2. Level 3 is intended for the highest-priority programs and builds on Level 2 with additional requirements tied to NIST SP 800-172.

Most suppliers care about Level 2, because that is where CUI handling lives. It is also where the operational burden rises fast. A supplier may have endpoint protection, multifactor authentication, and a security policy library, yet still be unable to produce audit-grade evidence across access control, configuration management, incident response, media protection, and system security plans.

CMMC is not a documentation project with a security appendix. It is a proof problem.

Suppliers lose bids on evidence quality before they fail controls

Prime contractors and assessors do not only look for whether a control exists. They look for whether it is implemented, repeated, governed, and evidenced in a way that matches the assessment objectives in NIST SP 800-171A.

NIST SP 800-171A is the assessment guide used to evaluate the 110 requirements in NIST 800-171. It breaks each requirement into objectives and tells assessors what to examine, interview, and test. If your team says “we do vulnerability scans” but cannot show scan cadence, remediation workflow, asset scope, exception handling, and management oversight, the control is weak even if the tool is present.

For small and mid-sized suppliers, this creates a predictable failure pattern. Security tools exist. Policies exist. Ownership does not. Evidence is scattered, and nobody can tie technical activity back to the system security plan, the plan of action and milestones, and the exact control statement under review. It has been our experience that often organizations that have very MATURE cybersecurity programs may have some of the largest gaps in EFFECTIVENESS. This usually stems from the comfort derived from relying on the latest tools and familiar processes that lull teams into a false sense of security.

CMMC 2.0 compliance is now an operating model decision

A supplier can approach CMMC in two ways. The old model treats it as a pre-audit event. The better model treats it as a continuous assurance program tied to contract growth, subcontractor oversight, and procurement response.

The difference is not philosophical. It changes cost, speed, and risk.

Operating modelWhat it looks likeWhat usually happens
Annual audit scrambleSeparate tools, manual screenshots, policy updates near deadline, consultant-led readiness burstHigh internal disruption, stale evidence, expensive remediation late in the cycle
Continuous assurance programOngoing control testing, centralized evidence, governed exceptions, workflows mapped to NIST 800-171A and CMMC practicesFaster readiness, cleaner assessor experience, less rework when contracts or questionnaires arrive

This is the compliance market’s Next-Gen Firewall moment. Point tools and annual advisory projects do not hold up when buyers, primes, and regulators expect continuous proof.

The hard part is not the 110 requirements. It is scope.

Executives often ask how long CMMC Level 2 takes. The honest answer: it depends on scope discipline more than policy writing. If your CUI environment is undefined, the program sprawls. If your boundary is engineered carefully, the path gets shorter.

Scope starts with three questions:

  1. What information do you receive or create that qualifies as CUI?
  2. Where does it live, move, and get backed up?
  3. Which users, systems, service providers, and subsidiaries can touch it?

Suppliers get into trouble when they answer those questions too loosely or too late. Microsoft 365 tenants, engineering file shares, managed service providers, remote admin tools, and ticketing platforms often become hidden scope multipliers. Every extra system adds evidence obligations, access reviews, configuration baselines, and incident response dependencies.

A narrower, defensible enclave can be the right move. But it only works if the boundary is real, documented, and enforced. A paper enclave with uncontrolled data spill defeats the purpose and creates assessment risk.

Self-assessment is allowed in some cases, but it is not a shortcut

Under CMMC 2.0, a narrow subset of Level 2 programs may permit annual self-assessment, while prioritized acquisitions require a triennial third-party assessment by a Certified Third-Party Assessment Organization (C3PAO). For most suppliers handling CUI, the C3PAO assessment is the path to certification. Procurement teams should treat self-assessment with caution.

Self-assessment still requires the same underlying discipline. You need a Supplier Performance Risk System (SPRS) score where applicable, a current system security plan, documented plans of action, and evidence strong enough to support customer scrutiny. If a prime asks follow-up questions or a contract shifts into a higher-assurance category, weak self-attestation becomes a commercial liability fast.

There is also a governance issue. Many suppliers treat plans of action and milestones as a parking lot for unfinished controls. That is dangerous. Some requirements cannot remain open if they materially affect protection of CUI. The nuance matters, and contract expectations matter even more.

Technology alone will not get suppliers through CMMC

Buying a scanner, an endpoint suite, and a policy pack does not create compliance. CMMC requires an evidence chain that connects people, process, and technology.

Take access control. The technical side may include identity provider settings, multifactor authentication logs, and privileged access restrictions. The governance side includes joiner-mover-leaver workflows, periodic access reviews, approval records, and defined exceptions. The assessment side requires that all of this align to the stated control implementation in your documentation.

That is why fragmented tooling drags on supplier readiness. One team owns vulnerability data, another owns tickets, another owns HR offboarding, and none of it lands in a single control narrative. When assessors ask how a specific requirement is actually performed, the answer cannot be “we use several tools.” It needs to be operational and provable.

Primes are pushing requirements downhill faster than many suppliers expected

Even before every rule is fully enforced across all contracts, prime contractors are already tightening supplier expectations. Some are formalizing cyber flow-down clauses. Others are expanding due diligence questionnaires, requiring architecture explanations, or asking for evidence that a supplier’s NIST 800-171 program is active rather than aspirational. As a downstream supplier in the defence supply chain, unfortunately “no news” is NOT “good news”. Many organizations in the supply chain often have tunnel vision focused on their own compliance journey and may not look downstream until after the deadline has passed which pushes the time pressures (and corresponding additional costs) downstream to their suppliers and sub-contractors.

Procurement pressure arrives before regulatory deadlines feel real. A supplier can lose work in the pre-award phase without ever reaching a formal CMMC assessment. That is one reason the best operators treat CMMC readiness as part of revenue operations, not just security operations.

For executive teams, the practical question is simple: can your organization answer a buyer, a prime, and an assessor with the same control story and the same evidence set? If not, the issue is not maturity theater. It is sales friction.

What smart suppliers are doing now

The strongest supplier programs usually start with a boundary decision, then move into a control-by-control implementation review against NIST 800-171 and NIST 800-171A. After that, they build repeatable evidence collection, identify inherited controls from cloud and managed providers, and establish a standing internal review cycle rather than waiting for an annual panic window.

That sequence sounds obvious. It is still rare. Many teams begin with templates and only later discover they cannot substantiate half the statements in the system security plan.

A more effective approach engineers readiness around continuous control testing and evidence generation. That is where a platform model changes the economics. Instead of treating compliance as a consultant memo plus an audit binder, suppliers can run it as an operating system for governance, technical validation, and buyer-facing proof. RESTIV was built around that exact gap — as a platform layer beneath independent assessors, not as an assessor.

CMMC 2.0 rewards discipline, not theater

There will be plenty of noise in this market: readiness workshops, checklists, accelerated packages, and policy bundles that promise confidence in 30 days. Some can help. None replace control ownership, scoped architecture, and evidence that survives questions.

Suppliers that win under CMMC will not necessarily be the biggest. They will be the ones that can show how CUI is protected, how exceptions are governed, how controls are tested, and how that proof stays current between audits.

That is the real shift. Compliance is moving out of the annual project plan and into daily operations. For suppliers that depend on defense revenue, treating it any other way is the expensive option.

If your team is still preparing for CMMC with disconnected tools and deadline-driven evidence collection, fix the operating model before the contract forces the issue.


Devon Smibert CD, MBA, BSc, CISSP