Skip to content
INDUSTRY 4.0 & DIGITAL

CMMC 2.0 Compliance: What Defense Manufacturers Need to Know Before Certification

CMMC 2.0 has three levels, and most manufacturers guess wrong about which one applies to them — it's not about company size, it's about whether you handle Controlled Unclassified Information. The three levels explained, and why CUI can show up several tiers down the supply chain.

July 22, 2026 Updated July 22, 2026 4 min read SCMEP Training Team 4 views
Defense manufacturing facility with precision machinery

CMMC 2.0 has three levels, and most manufacturers guess wrong about
which one applies to them. The level isn’t about company size — it’s
about whether you handle Controlled Unclassified Information (CUI), and
a small subcontractor holding CUI can land in a higher tier than a much
larger company that never touches it.

What CMMC 2.0 actually requires

Cybersecurity analyst reviewing a CMMC compliance checklist

The Cybersecurity Maturity Model Certification (CMMC) is the
Department of Defense’s framework for verifying that contractors and
subcontractors handling defense information actually have adequate
cybersecurity controls in place — not just a policy stating that they
do. CMMC 2.0 simplified an earlier, more complex version down to three
levels, each tied to the sensitivity of information a company handles
rather than to company size or contract value.

The three levels

CMMC 2.0 levels and what they require
Level Protects Assessment
Level 1 — Foundational Federal Contract Information (FCI) Annual self-assessment, 15 practices
Level 2 — Advanced Controlled Unclassified Information (CUI) Maps to NIST SP 800-171’s 110 controls; third-party assessment for most contracts
Level 3 — Expert CUI at highest risk of advanced persistent threats Adds NIST SP 800-172 controls; government-led assessment
IT specialist reviewing cybersecurity controls on a monitor

Why this affects South Carolina manufacturers specifically

South Carolina’s defense and aerospace subcontractor base — much of
it feeding Boeing’s North Charleston operations and other DoD prime
contractors — means CUI can show up several tiers down the supply
chain, not just at the prime contractor. A small machine shop making a
bracket for a subassembly can be handling CUI (drawings, specifications,
technical data) without fully realizing their CMMC obligations extend
that far down the chain. Full enforcement requires both a DoD program
rule and a separate acquisition rule to be finalized — this is an area
where the exact enforcement timeline has moved multiple times, so
manufacturers should confirm current status directly at
dodcio.defense.gov/cmmc rather than relying on any single article,
including this one.

Getting ready before it’s contractually required

Team assessing network infrastructure equipment

The practical starting point for most manufacturers is figuring out
whether they actually handle CUI at all — a surprising number don’t,
and can stay at the simpler Level 1 self-assessment. For those that do,
the NIST SP 800-171 controls underneath Level 2 cover things like access
control, incident response, and system monitoring that many shops
haven’t formally documented even if they’re informally doing some of it
already. Waiting until a contract requires certification to start this
work is the most common — and most expensive — mistake.

Where training fits

Consultant explaining a compliance roadmap to manufacturing leadership

CMMC compliance itself isn’t a standalone course in SCMEP’s current
catalog, but it connects directly to the broader digital readiness work
covered in our Digital Transformation —
Are You Ready?
course. As a NIST Manufacturing
Extension Partnership affiliate serving South Carolina manufacturers
since 1989
, our focus is helping manufacturers understand where they
actually stand before a defense customer forces the question.

If your company is assessing CMMC readiness, you can
browse the Industry 4.0 and Digital
training catalog
or email the training team.

CMMC compliance depends heavily on the plant-floor systems that touch
sensitive data. See our related guide on
SCADA systems for why
industrial control system security is its own discipline, distinct from
typical office IT security.

Frequently asked questions

What is CMMC 2.0?

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense’s framework verifying that defense contractors and subcontractors have adequate cybersecurity controls. Version 2.0 simplified the framework to three levels tied to the sensitivity of information handled.

What are the three CMMC levels?

Level 1 (Foundational) protects Federal Contract Information with an annual self-assessment. Level 2 (Advanced) protects Controlled Unclassified Information and maps to NIST SP 800-171’s 110 controls. Level 3 (Expert) adds NIST SP 800-172 controls for the highest-risk information.

Does CMMC only apply to large defense contractors?

No. CMMC requirements are based on what type of information a company handles, not its size. A small subcontractor several tiers down the supply chain that handles Controlled Unclassified Information can face the same Level 2 requirements as a much larger prime contractor.

Is CMMC fully enforced yet?

Enforcement timelines have shifted as the DoD finalizes both a program rule and a separate acquisition rule. Manufacturers should verify current enforcement status directly at the DoD’s official CMMC site rather than relying on any single secondary source.

SCMEP Training Team

NIST Manufacturing Extension Partnership affiliate

South Carolina Manufacturing Extension Partnership has delivered manufacturing training to South Carolina manufacturers since 1989. Articles are produced and reviewed by SCMEP's training team.

Ready to build this capability on your floor?

Explore SCMEP's manufacturing training catalog, or talk to the training team about what your plant needs.

Leave a Reply

Your email address will not be published. Required fields are marked *