CMMC stands for Cybersecurity Maturity Model Certification. If you work with the Department of Defense – directly or as a subcontractor – it’s the framework that determines whether you’re allowed to handle government contracts involving sensitive information.

Here’s what you need to know in plain English.

Who Needs CMMC?

Any company in the Defense Industrial Base (DIB) that handles:

  • Federal Contract Information (FCI) – Information provided by or generated for the government under contract (Level 1)
  • Controlled Unclassified Information (CUI) – Sensitive but unclassified government information that requires protection (Level 2)

This includes manufacturers, suppliers, IT providers, consultants – anyone in the DoD supply chain.

The Levels

Level 1 (Foundational)

17 practices covering basic cyber hygiene. Self-assessment. Required for contracts with FCI. Most small suppliers start here.

Level 2 (Advanced)

110 practices aligned with NIST SP 800-171. Third-party assessment required for most contracts with CUI. This is where most of the compliance work lives.

Level 3 (Expert)

Additional practices beyond NIST 800-171. Government-led assessment. Rare for small businesses.

What Level 1 Requires (The Basics)

  • Access controls (unique user accounts, limit access to authorized users)
  • Authentication (verify user identities, enforce MFA)
  • Media protection (sanitize storage before disposal)
  • Physical protection (control physical access, escort visitors)
  • System protection (monitor network boundaries, segment public systems)
  • Integrity (patch systems, run antivirus, scan for threats)

What Most Small Companies Get Wrong

  1. They only do the technical controls – CMMC also requires documentation (SSPs, policies, procedures) and training. Assessors want proof.
  2. They over-scope – Not every system needs to be in scope. Define your CUI boundary tightly to reduce the compliance footprint.
  3. They wait too long – Level 1 takes 4-8 weeks. Level 2 takes 3-6 months. Starting the month before a contract deadline isn’t realistic.

Getting Started

First step: gap assessment. Understand where you are today vs. where you need to be. From there, build a remediation plan with timelines and costs. At Seashore IT, we’re CyberAB registered and handle the full lifecycle – technical controls, documentation, training, and ongoing maintenance.


Need IT help? Seashore IT provides flat-rate managed IT for businesses with 5-250 computers across the Western US – from auto shops and contractors to law firms and healthcare practices. Call (833) 997-6886 or email info@seashoreit.com.

Seashore IT – Your transparent IT partner, aligned to your goals, embedded in your success.

top
Simplifying IT
for a complex world.
Platform partnerships