CMMC and NIST 800-171 Compliance: A Plain-English Guide for Small Businesses

A small business owner reviewing compliance documents at a laptop, representing CMMC and NIST 800-171 compliance for defense contractors

A bigger customer, a prime contractor, or a government contract just told you that you need to be “CMMC compliant,” or maybe “NIST 800-171 compliant,” and your stomach did a small, unhappy flip. Perhaps there were clause numbers involved. Perhaps someone said the word “audit.” Here is the short, calming version: this is a real requirement, it is not a scam, and it is far more manageable than the acronym soup makes it look. Let us translate it into plain English so you can figure out whether it applies to you and what to actually do next.

Quick takeaway: NIST 800-171 is a checklist of 110 security practices for protecting sensitive government information. CMMC is the Department of Defense program that verifies you actually follow it. If your business handles government contract information, even as a small subcontractor, you likely need one of three levels. Many companies can begin with a self-assessment; some contracts require a certified outside assessor. The earlier you scope it, the cheaper and calmer the whole thing is.

What This Actually Means in Plain English

You are really dealing with two things wearing two different hats. Once you can tell them apart, most of the confusion falls away.

NIST 800-171 is the recipe. It is a published set of 110 security requirements, written by the National Institute of Standards and Technology, that describe how to protect sensitive but unclassified government information on your own computers. The requirements are grouped into 14 everyday categories such as access control, training, backups, and keeping software updated. Most of them are things a well-run business should be doing anyway.

CMMC is the health inspector. CMMC stands for Cybersecurity Maturity Model Certification. It is the Department of Defense program that checks whether you actually meet those requirements before you are allowed to win or keep the work. You cannot simply say “trust me, we are careful.” Depending on the contract, you either assess yourself and formally attest to it, or an accredited outside assessor comes in and verifies it.

So NIST 800-171 is what good security looks like, and CMMC is how the Defense Department confirms you have it. They travel together, which is why people use the two names almost interchangeably.

First Question: Do You Even Need This?

This is the most important question, and a surprising number of small businesses get it wrong in both directions, some panicking when they do not need to, and others assuming they are too small to matter.

You most likely need CMMC if you do work for the Department of Defense, directly or as a subcontractor several tiers down the supply chain, and your computers store, process, or send certain government information. That information comes in two flavors:

  • FCI (Federal Contract Information): basic information provided by or generated for the government under a contract that is not meant to be released publicly, such as certain emails, delivery schedules, or process details. This maps to the lowest CMMC level.
  • CUI (Controlled Unclassified Information): more sensitive material such as technical drawings, specifications, and controlled technical data. It is not classified, but the government still requires it to be safeguarded. This pushes you up to Level 2 or higher.

How to tell for sure: the solicitation or contract itself will state the required CMMC level. Look for DFARS clauses 252.204-7012 (which covers protecting this kind of information) and 252.204-7021 (the CMMC clause). A quick heads-up: the government reorganized some of these clause numbers in early 2026, so do not get too attached to any single number. The durable truth is simple, the required CMMC level is written right in the solicitation, and your prime contractor can tell you what data will flow to you.

The most expensive misconception is “we are just a small subcontractor, so this does not apply to us.” CMMC requirements flow down the supply chain. Prime contractors are required to pass them along to their subcontractors, and those subcontractors pass them to theirs. Being small does not remove the obligation. The main exception is work solely for commercial off-the-shelf products.

The Three Levels, Briefly

CMMC has three levels. Which one applies depends entirely on how sensitive the information is that you handle. Most small businesses land at Level 1 or Level 2.

  • Level 1 (Foundational): for companies that handle only FCI. It covers basic cyber hygiene, the security equivalent of locking your doors and not taping the key to the frame. You assess yourself once a year and post a score and an annual affirmation in a Defense Department system called SPRS.
  • Level 2 (Advanced): for companies that handle CUI. This is the full set of all 110 NIST 800-171 requirements. There are two possible paths, a self-assessment or a formal assessment by an accredited third party called a C3PAO, and the contract tells you which one you need. The Defense Department expects that most companies handling real CUI will need the third-party route.
  • Level 3 (Expert): for the most sensitive national-security work. It adds an extra layer of requirements from a companion standard, NIST 800-172, and involves a government-led assessment. Most small businesses will never touch this level.

“Self-Assessment” vs. “Getting Certified” (and Where We Fit)

This is where the process gets real, and where a few key documents show up. None of them are as scary as they sound.

Your SPRS score. SPRS is the Supplier Performance Risk System, the government portal where your assessment results live. Your score starts at 110 and drops as requirements go unmet, with some worth more than others. Multi-factor authentication, for example, is a heavy hitter. Each contract can set a minimum score you have to clear.

Your SSP (System Security Plan). This is the document where you write down how you meet each requirement, what systems are in scope, and how they are protected. Assessors essentially grade you against your own plan, so a clear, honest SSP is the backbone of the whole effort.

Your POA&M (Plan of Action and Milestones). This is your honest list of the gaps you have not closed yet and the dates you will close them by. At Level 2 there are limits on what can stay open, and outstanding items generally have to be fixed within about 180 days.

On the self-assessment path, you assess your own systems and a senior official in your company formally affirms the result in SPRS. On the certification path, an accredited outside assessor, the C3PAO, verifies everything in a formal audit.

Here is where we will be straight with you. Technology Ronin is not a C3PAO and not a certified assessor. What we do is get you genuinely ready, scope your environment, run a gap assessment, help you implement the NIST 800-171 controls, write your SSP and POA&M, calculate your score, and help you complete your self-assessment and SPRS submission. When your contract requires a formal Level 2 certification, we get you audit-ready and connect you with an accredited C3PAO to perform it. And a word to the wise, if anyone who is not a C3PAO offers to personally “certify” you, that is your cue to walk away.

A Few Things People Get Wrong

The same handful of misunderstandings trip up small businesses over and over. A quick reality check saves a lot of pain:

  • “It is just an IT problem.” It is a contractual and legal obligation. A senior official personally signs the affirmation, which means leadership has real skin in the game, not just the IT person.
  • “We are too small to be in scope.” Requirements flow down to subcontractors of every size. A three-person shop can absolutely be on the hook.
  • “We will deal with it if we win the bid.” The required level often has to be in place before award, not after. Waiting can cost you the contract.
  • “The right software will make us compliant.” Tools help, but compliance is mostly documented process and consistent habits. No product is “CMMC compliant” on your behalf.

A Real-World Example

Picture a twelve-person machine shop that supplies parts to a larger defense contractor. One morning a new subcontract lands in the inbox, and buried in it is a CUI flow-down requirement. The owner’s first reaction is quiet panic.

It turns out the shop routinely emails technical drawings back and forth, and those drawings are CUI. A gap assessment paints an honest picture, there is no multi-factor authentication, no written security plan, and backups that nobody has ever tested. The starting SPRS score is low.

So they get to work. They write a System Security Plan, start a POA&M for the gaps, turn on multi-factor authentication, tighten up who can access what, and fix their backups. They re-check the score, and it climbs above the contract’s minimum. A senior official affirms it in SPRS, and the shop keeps the work. The whole thing took about six weeks of steady effort, not a catastrophe, because they started before the deadline instead of after losing a contract.

Ronin Tip: Before you buy a single “CMMC-in-a-box” product, draw the smallest honest boundary you can around exactly where sensitive government data lives, which laptops, which people, which cloud apps. Shrinking that boundary is the cheapest and most powerful move in the entire process. Most of compliance is documentation and habits, not gadgets.

The Clock Is Real (Why “Later” Gets Expensive)

As of mid-2026, CMMC is no longer a someday problem. It is actively rolling into real contracts, phased in over several years:

  • The self-assessment phase is already live. Since late 2025, applicable contracts have been requiring Level 1 and Level 2 self-assessments as a condition of award.
  • The bigger shift lands around November 2026, when many CUI contracts begin requiring that formal third-party C3PAO certification instead of a self-assessment.
  • Full phase-in continues through 2028, as higher levels and more contracts are pulled in.

Here is the catch that makes timing matter. There are only a small number of accredited assessors, fewer than a hundred, serving tens of thousands of defense contractors, and the wait for an assessment is already running many months. Translation: even though the final deadlines are a year or two out, the smart, low-stress move is to scope and start now, while you can still choose your own pace instead of scrambling against a contract deadline.

What You Can Do This Week

You do not have to solve all of this at once. A few concrete first steps will tell you most of what you need to know:

  • Ask the direct question: contact your prime contractor or contracting officer and ask, in writing, whether you will handle FCI or CUI and what CMMC level the work requires.
  • Read the contract: look for the stated CMMC level and DFARS clauses 252.204-7012 and 252.204-7021.
  • Map your data: list where that information actually lives, email, laptops, phones, cloud apps, and that one shared drive everyone forgets about.
  • Do not guess your score: the SPRS affirmation is a legal statement signed by a senior official. An inflated score can become a False Claims Act problem, not just an audit note, so score conservatively and back it with evidence.
  • Get a real gap assessment before buying anything: understand your scope and your gaps first, then spend money on the things that actually move your score.

When to Get Help

You do not have to become a compliance expert overnight, and you should not have to. A few genuinely useful, free, government-backed resources can get you oriented: Project Spectrum, which is Defense Department-sponsored help aimed at small businesses; your local APEX Accelerator, which offers free government-contracting guidance and has offices in Colorado; and the NIST Manufacturing Extension Partnership network, known in Colorado as Manufacturer’s Edge. The official Defense Department CMMC pages, linked below, are always the source of truth.

And if you would rather have a calm human translate all of this for your specific situation, that is exactly what we do. More on that just below.

The Bottom Line

CMMC and NIST 800-171 are real, they are not going away, and they are absolutely survivable, especially if you scope tightly and start early. The companies that struggle are almost always the ones who waited until a contract was already on the line. The ones who breeze through treated it as a project, not an emergency. It is a checklist and some paperwork, backed by good security habits, not a mountain. And you do not have to figure it out alone.

Want a Hand Making Sense of This?

Not sure whether CMMC even applies to you? That is the most common, and most important, first question, and we are happy to answer it. Technology Ronin is a Colorado-based IT partner serving small businesses and defense contractors across the Front Range and, remotely, throughout the U.S. and Canada. We will take you as far as we can go together, figuring out your scope, closing the gaps in NIST 800-171, and completing your self-assessment and SPRS submission, and when your contract calls for a formal Level 2 certification, we get you audit-ready and connect you with an accredited C3PAO. We are not a certified assessor ourselves, and we will always tell you exactly where that line is.

Book a free 20-minute CMMC scoping call and we will help you understand what you are dealing with and what it would take to get compliant. Get in touch or call (970) 387-TECH.

Quick Questions

Is NIST 800-171 the same as CMMC?

They are two halves of the same coin. NIST 800-171 is the list of 110 security requirements; CMMC is the Department of Defense program that verifies you actually meet them before you win the work.

I am just a small subcontractor. Do I really need this?

Very likely, if you handle government contract information. CMMC requirements flow down from primes to subcontractors of every size, so being small does not remove the obligation. The main exception is work solely for commercial off-the-shelf products.

Can Technology Ronin certify us?

No. A formal CMMC Level 2 certification can only be performed by an accredited third-party assessor, a C3PAO. What we do is get you fully ready, handle your self-assessment and SPRS submission, and connect you with a certified assessor when your contract requires one. If anyone who is not a C3PAO offers to “certify” you, be cautious.


Helpful Resources

For readers who want to go straight to the source, these official and trusted resources are the best place to start:

Scroll to Top