QLAN
Compliance & CMMC

CMMC Level 2 Compliance for Manufacturers: A Plain-English Readiness Guide

What CMMC requires of manufacturers in the defense supply chain, how assessments work, and the practical steps to reach Level 2 readiness.

Abed Farah · Co-Founder & President · · 5 min read

Written by the team that has provided Managed IT Services to Orange County businesses since 1999.

Readiness board of the 14 NIST SP 800-171 control families assessed for CMMC Level 2, most marked in place and three flagged as open findings

If your manufacturing business supports the Department of Defense supply chain, even two or three tiers removed from the prime contractor, CMMC is not optional. It decides whether you stay eligible for the work.

This guide explains what the Cybersecurity Maturity Model Certification actually requires, how assessments work, and the order of operations we recommend to manufacturers preparing for Level 2.

Who does CMMC apply to?

CMMC applies to any company that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under a DoD contract. In practice, that includes manufacturers that:

  • Receive engineering drawings or technical specifications from government projects
  • Store or transmit CUI in email, file shares, or ERP systems
  • Work as subcontractors to defense primes
  • Plan to bid on DoD contracts

If a prime contractor has asked for your Supplier Performance Risk System (SPRS) score, you are already in scope.

What are the CMMC levels?

CMMC 2.0, the current version of the program, has three levels.

Level 1 covers 17 basic safeguarding practices for FCI and allows an annual self-assessment.

Level 2 is where most manufacturers land. It assesses the 110 security controls of NIST SP 800-171 across 14 control families, from access control and incident response to physical security. Most Level 2 contracts require a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO).

Level 3 adds controls from NIST SP 800-172 for the most sensitive programs; few SMB manufacturers need it.

What does CMMC Level 2 readiness involve?

  1. Scope your CUI. Identify exactly where CUI enters, lives, and leaves your environment. A smaller, segmented scope is dramatically cheaper to certify.
  2. Run a gap assessment against NIST SP 800-171 and calculate your SPRS score honestly. A security assessment is the quickest way to get a real baseline.
  3. Write the POA&M. Document every gap with an owner and a date. Assessors expect to see it.
  4. Close the technical gaps: multi-factor authentication, encryption, logging, access control, and network segmentation between production and business systems.
  5. Build the paper trail. Policies, system security plan, training records, and incident response plans carry as much weight as the technology. Control mapping, evidence collection, and audit liaison are the core of our managed IT compliance services.
  6. Maintain it. Compliance decays. Quarterly reviews keep your score real between assessments.

How much does CMMC Level 2 cost?

The Department of Defense published its own estimate with the CMMC final rule (32 CFR Part 170), published October 15, 2024: about $105,000 per three-year cycle for a small business to complete a Level 2 certification assessment, or roughly $35,000 a year. That figure covers the assessment, reporting, and annual affirmations only. It assumes the 110 controls are already in place, which for most small manufacturers is the expensive assumption.

Realistic year-one budgets for a small manufacturer with a well-scoped environment usually land between $75,000 and $150,000 at 2026 market rates, spread across four buckets:

  • Gap assessment and CUI scoping: $5,000 to $25,000.
  • Remediation: $25,000 to $70,000 or more, depending on what is already in place. Segmentation or a dedicated CUI enclave, multi-factor authentication, logging, and encryption live here.
  • Documentation: $8,000 to $20,000 for the system security plan, POA&M, policies, and evidence preparation.
  • The C3PAO certification assessment: $30,000 to $70,000 for a small, well-scoped enclave.

The assessor’s fee is typically only a quarter to 40 percent of the total. The rest is the work of becoming compliant, which is why the order of operations above matters: a smaller CUI scope and a completed gap assessment lower every line that follows, including the assessor’s quote. A company that keeps CUI in a dedicated enclave for ten users pays far less than one where CUI touches every workstation on the floor.

Can a small team use a CUI enclave instead?

Most small manufacturers do not need every workstation in scope. If CUI touches only a handful of people, engineering, quoting, and quality for example, a dedicated CUI enclave keeps those users and their data inside a small, defensible boundary and leaves the shop floor and the front office out of the assessment entirely. Published case studies show enclaves removing 60 to 90 percent of assets from scope and lowering total cost by 20 to 45 percent; one 40-person manufacturer went from an estimated $140,000 to $78,000 by moving CUI into an enclave.

Enclaves are priced per user per month (2026 pricing), which is what makes them work for a small team:

  • Licensing only: about $60 per user per month for a Microsoft 365 GCC High Business Premium seat, before any engineering or management. You still have to build and operate the boundary.
  • Managed enclave: $150 to $400 per user per month, including the platform, the security controls, and the monitoring and evidence the assessor will ask for.
  • A ten-user enclave therefore runs roughly $600 to $3,000 a month depending on the model, plus one-time setup and migration.

The rule of thumb: when CUI touches less than about a third of the company, the enclave usually wins. QLAN prices CMMC work per client, based on how many users need to be in scope and what the assessment finds, so drawing that boundary is the first thing we settle.

Certification lasts three years, but annual affirmations, quarterly control reviews, and keeping evidence current are ongoing work. Budget for maintenance from the start; a lapsed control found at the next assessment costs more than keeping it in place would have. For a quote based on your actual scope, schedule a readiness review.

Where do manufacturers usually stumble?

The pattern we see most often: the office network and the shop floor share one flat network, CUI lives in personal email and unmanaged file shares, and there is no system security plan. None of these are exotic problems, but each one is a finding in an assessment.

The fix is rarely buying a new tool first. It is scoping, segmentation, and documentation, done in that order.

QLAN does this work for defense-supply-chain manufacturers across Orange County, including Anaheim, Tustin, Fullerton, and Santa Ana, from the first scoping conversation through the assessment itself.

Common questions

Does CMMC apply to small manufacturers? +

Yes. Any manufacturer that receives, stores, or transmits Controlled Unclassified Information as part of a Department of Defense contract or subcontract falls under CMMC, regardless of company size.

What is the difference between CMMC Level 1 and Level 2? +

Level 1 covers 17 basic safeguarding practices for Federal Contract Information and allows annual self-assessment. Level 2 assesses the 110 controls of NIST SP 800-171 for companies that handle CUI, and most contracts require certification by an authorized third-party assessor (C3PAO).

How long does CMMC readiness take? +

For a small manufacturer starting from a typical IT environment, closing Level 2 gaps usually takes 6 to 12 months. The timeline depends on how much CUI scoping, network segmentation, and documentation work is needed.

How much does CMMC Level 2 certification cost? +

The Department of Defense estimates about $105,000 per three-year cycle for a small business for the assessment and affirmations alone. Including gap assessment, remediation, and documentation, most small manufacturers spend $75,000 to $150,000 in year one, and the C3PAO assessment fee is only a quarter to 40 percent of that total.

Can a small manufacturer lower CMMC cost with an enclave? +

Yes. A CUI enclave limits the assessment to the users and systems that actually handle Controlled Unclassified Information. Managed enclaves run roughly $150 to $400 per user per month, so a ten-user enclave costs far less than bringing every workstation in a plant into scope, and published case studies show 20 to 45 percent total savings.

Next step

Want this kind of clarity for your IT?

A senior engineer reviews your environment and outlines the highest-leverage next step. No pressure, no obligation.