top of page

CMMC Compliance for Small Government Contractors: From Assessment to Actually Ready at Level 1 and Level 2

May 1
18 min read

Updated: Sep 1

Updated August 2026: This article has been updated to reflect the Department of War's July 2026 suspension of CMMC Phase II requirements, the ongoing review of the CMMC program and what those changes mean for small government contractors working toward CMMC Level 1 or Level 2.



CMMC compliance for small government contractors – Level 1 and Level 2 technical implementation by SNL-Tech Services

Knowing What You Need to Do and Actually Doing It Are Two Different Things

One of the biggest challenges I see for small government contractors isn't necessarily finding information about CMMC. There is plenty of information available. The harder part comes when a business has completed an assessment, identified its gaps or been told what requirements apply and somebody finally asks: Who is actually going to implement all of this?


A gap assessment can identify deficiencies. A policy can say what employees are supposed to do. A System Security Plan can describe how an environment operates. A CMMC compliance specialist can help a business understand the broader compliance requirements. But none of those things automatically configures Active Directory, hardens a server, creates Group Policies, fixes file permissions, implements MFA, segments a network, replaces equipment that can't support the required security controls, secures Microsoft 365, protects a backup system or determines whether a server actually needs unrestricted access to the internet.


Somebody still has to implement the technical controls. That's the part of CMMC compliance for small government contractors I focus on at SNL-Tech Services: implementing the technical controls inside the actual IT environment.


I work inside the company's actual IT environment to implement, harden, configure, test and document the technical controls the business needs. If the company wants me to continue managing that environment afterward, SNL-Tech Services can also provide ongoing Managed IT Services so those controls continue to be maintained as users, applications, equipment and workflows change.


First, What Does CMMC Mean for a Small Business?

For most small government contractors, the conversation begins with the information the business handles.

CMMC Level 1 applies to information systems that process, store or transmit Federal Contract Information, or FCI. Those systems are assessed against the 15 safeguarding requirements derived from FAR 52.204-21.


CMMC Level 2 comes into the picture when the business processes, stores or transmits Controlled Unclassified Information, or CUI. Level 2 is based on the 110 security requirements in NIST SP 800-171 Revision 2 under the current CMMC framework.

The size of the company doesn't determine the level. A five-person engineering company can have significant Level 2 requirements if it handles CUI. A larger contractor may have a very different scope depending on the information involved and its contractual requirements.


That's why I don't think the first CMMC question should be “What security products should we buy?” I want to know what information the business handles, where that information goes, what systems are involved and what the contract actually requires.

I've written separately about the difference between FCI and CUI and the individual Level 1 requirements, so I won't repeat all of that here. This article is about what happens after the business understands the requirements and needs to make the technology actually meet them.


CMMC Phase II Is Suspended. The Cybersecurity Requirements Didn't Disappear.

This is the biggest change since I originally published this article. On July 13, 2026, the Department of War suspended the CMMC Phase II requirements that had been scheduled to take effect on November 10, 2026. The Department also announced a comprehensive review of the CMMC program. Phase I self-assessment requirements remain in place.


For small government contractors, I think it's important to understand both sides of that announcement. The suspension changes the near-term CMMC rollout, including the planned expansion of third-party certification requirements under Phase II. It does not mean companies can stop protecting FCI and CUI or ignore the cybersecurity obligations that already apply to their contracts.


I wouldn't recommend that a small contractor spend money racing toward an assessment milestone that is currently under review simply because somebody is selling fear around a deadline. I also wouldn't recommend doing nothing.

The practical question remains: Are the technical controls your business needs actually implemented and working?

The assessment process may change. The need to protect the information entrusted to your business doesn't disappear with it.


Level 1 Is a Self-Assessment, but the Controls Still Have to Exist

Level 1 sometimes gets dismissed as the easy version of CMMC because there are 15 requirements and the business performs a self-assessment. But a self-assessment isn't the same thing as having nothing to implement.


The business still needs to look at how users access systems, how identities and permissions are managed, how devices and connections are controlled, how systems are protected from malicious software, whether updates are being maintained, how physical access is handled and whether the safeguards the company says it has are actually operating.


For a small business without internal IT, even Level 1 can raise very practical questions: Which computers are in scope? What about Microsoft 365? What needs to change on employee computers? What documentation do I need? Who configures the technical controls? How do I know whether what I already have is sufficient?

Those are legitimate questions. My role isn't to check boxes for the business. I review the technical environment, identify what is already in place, implement the technical pieces that need to change, document what I do and give the business accurate information about how its IT environment is actually configured.


Level 2 Is Where the Environment Becomes Much More Important

Once CUI enters the picture, the technical conversation gets considerably larger. Current CMMC Level 2 scoping rules include assets that process, store or transmit CUI and require CUI assets to be addressed in the asset inventory, System Security Plan and network diagram.


That sounds straightforward until you look at a real small business. The company may already have Active Directory, local servers, databases, desktops, laptops, Microsoft 365, printers, switches, wireless networks, firewalls, VPNs, backup systems and applications that have been integrated over many years. A manufacturer may also have engineering applications, CAD/CAM systems, inspection software and production systems that depend on the existing environment.


Now the question isn't simply “Where should we store CUI?” It becomes “How do we protect CUI while still allowing the company to do the work?”


Once employees need to open, modify and create CUI using local applications, engineering systems, production systems or other existing technology, a solution designed primarily around secure cloud storage can become much more complicated. This is why I don't believe there is one CMMC Level 2 architecture that fits every small contractor.


Do I Have to Replace My Entire IT Environment?

This is one of the questions I think small contractors are afraid to ask, and the answer is not necessarily.

Sometimes significant replacement or migration is necessary. If existing equipment is unsupported, can't provide required security functionality or can't be properly secured, keeping it simply because the company already owns it isn't a good technical strategy. But I also don't believe in replacing technology just to make a CMMC project look cleaner on paper.


An established company may have years invested in Active Directory, servers, databases, applications, printers and workflows. Completely rebuilding that environment could introduce enormous cost, disruption and operational risk. The first step is understanding what can stay, what can be hardened, what needs to be segmented, what needs to be upgraded and what genuinely needs to be replaced.


For some businesses, a separate enclave may make sense. For others, an appropriately secured on-premises environment may make more sense. For some established contractors, a hybrid architecture may be the practical answer—using an appropriate cloud environment for certain communication and collaboration workflows while hardening and maintaining local systems that still need to process or store CUI.

CMMC architecture should follow the information and the business workflow, not a product checklist.


CMMC Compliance for Small Government Contractors: Not Sure Where to Start?

Not every small government contractor comes to me with a completed technical assessment or a detailed understanding of its existing IT environment. Sometimes the business knows CMMC is going to matter for current or future contracts but doesn't yet have a clear picture of what technology it has, how it is configured or what would need to change.

That's where an SNL-Tech Services IT Baseline Assessment can be a practical place to start.

The IT Baseline Assessment isn't a CMMC certification or a replacement for working with a company that specializes in CMMC compliance. It gives me an opportunity to understand the technical environment the business already has before we start talking about major upgrades, migrations or new security products.

Depending on the environment, my IT Baseline Assessment can include reviewing:

  • Network and firewall configuration

  • Servers and Active Directory

  • Microsoft 365

  • Workstations and other endpoints

  • Existing switches, wireless infrastructure and other network equipment

  • Security tools and endpoint protection

  • Backup and recovery systems

  • Remote access

  • User accounts, permissions and administrative access

  • Existing hardware and infrastructure

  • Existing IT documentation and network information

I'm looking at what is already working, where the technical weaknesses are and where the environment may need additional investigation or changes based on the requirements the business is trying to meet. For a small contractor that doesn't have a well-documented IT environment, that baseline can answer an important question: What do we actually have today?


From there, the business is in a much better position to work with its CMMC compliance specialists to determine what requirements apply and for me to determine what technical work may be necessary. We may discover that some of the required technical controls are already in place. We may find systems that can be hardened rather than replaced. We may identify equipment that needs to be upgraded, access that needs to be restricted, missing documentation or areas of the network that need to be redesigned.

I would rather understand the environment first and make recommendations based on what I actually find than hand a small business a predetermined CMMC technology package.


Do I Automatically Need GCC High for Level 2?

This is another question I hear frequently, and it's an important one because GCC High can represent a significant increase in cost and complexity for a small business.

I don't think the answer should start with the Microsoft license. I want to understand what information the company handles, what contractual and other regulatory requirements apply, how employees need to communicate with primes and subcontractors, whether CUI will be processed or stored in Microsoft 365, which Microsoft services employees actually need and how the cloud environment will interact with local systems.


For some contractors, GCC High may be the right answer. But “You have CUI, therefore move everything to GCC High” isn't an architecture. It's a product recommendation. Those are two different things.


The cloud environment is only one part of the CUI workflow. If an employee receives CUI through an appropriately secured cloud environment and then downloads it onto a local workstation, saves it to a server or works with it inside a local application, the technical considerations don't magically stop at Microsoft 365.

That's why I want to understand the entire workflow before recommending the environment.


What Technical CMMC Implementation Actually Looks Like

My role at SNL-Tech Services is the technical implementation, hardening and ongoing management of the IT environment.

That work goes much deeper than installing endpoint protection or turning on MFA. I work through the environment itself—servers, Active Directory, Group Policy, file shares, networks, firewalls, endpoints, Microsoft 365, backups, remote access and the other technology the business depends on—to determine what needs to be hardened, restricted, segmented, upgraded or replaced.

Depending on the business and its applicable requirements, that can include:

  • Server hardening: Reviewing and hardening Windows servers, removing unnecessary services and protocols, restricting administrative access, maintaining supported operating systems, patching systems and reducing unnecessary exposure.

  • Active Directory hardening: Reviewing users, security groups, privileged accounts, service accounts and administrative rights; implementing least privilege; separating administrative access where appropriate; and cleaning up unnecessary accounts and permissions.

  • Group Policy: Creating and managing GPOs that enforce security configurations consistently across applicable workstations and servers.

  • File and folder security: Reviewing file shares, NTFS permissions and security groups so employees only have access to the information required for their jobs and CUI isn't unnecessarily available throughout the company.

  • Network segmentation: Designing VLANs, firewall rules and network boundaries to appropriately segment CUI systems and sensitive resources from users and devices that don't need access.

  • Internet-access controls: Determining which servers, devices and systems actually require internet access and restricting or eliminating internet access where it isn't necessary.

  • Firewall and network hardening: Configuring firewalls, switches, secure management interfaces, network services and the rules governing communication between network segments.

  • MFA and privileged access: Implementing MFA where required across cloud services, remote access and applicable local infrastructure while protecting privileged administrative access.

  • Endpoint hardening: Configuring encryption, endpoint protection, device controls, local administrator restrictions, patching and other security settings on managed workstations.

  • Hardware evaluation and replacement: Reviewing servers, firewalls, switches, printers and other infrastructure to determine whether they can support the required controls, including applicable requirements involving FIPS-validated cryptography, and upgrading or replacing equipment when necessary.

  • Virtualization: Designing and implementing local virtualization where it makes sense, including hypervisor hosts and separate virtual machines for server roles when that improves security, isolation, management, backup or recovery.

  • Microsoft 365 and cloud security: Configuring identity, permissions, MFA, administrative access and other security controls while helping determine what cloud environment makes sense for the company's requirements.

  • Remote access: Securing VPNs and other remote-access methods and restricting remote connectivity to the users and systems that actually require it.

  • RMM and device management: Deploying an RMM solution where appropriate to maintain device inventory, monitor configurations, manage operating system and software updates and maintain visibility into managed endpoints.

  • Logging and monitoring: Configuring systems to generate and retain the appropriate security logs and providing the visibility needed to understand what is happening inside the environment.

  • Backup and recovery: Securing backup systems, restricting access to backups, accounting for protected information contained in backup copies and testing recovery.

  • Technical testing: Testing controls after implementation to verify that they actually work rather than assuming a setting, policy or security product is doing what it is supposed to do.

  • IT support: Supporting the users, computers, servers and systems that have to operate inside the environment after the controls are implemented.

One of the questions I continually ask when I'm working through an environment is: Does this actually need access to that?


Does this employee need that file share? Does this workstation need to communicate with that server? Does this server need unrestricted internet access? Does that VLAN need a path into the CUI environment? Does a service account need all of the permissions it has? Does an administrator need to use a privileged account for ordinary work?


The goal isn't to make the network unusable. It's to understand what the business legitimately needs and remove unnecessary access, connectivity, services and permissions while properly protecting the pathways the business actually requires.


What About Switches, Printers and Other Hardware?

CMMC isn't just a Microsoft 365 and Windows workstation project. Network equipment, printers and other devices need to be evaluated based on the role they play in the environment. This becomes particularly important at Level 2 when equipment may process, store or transmit CUI or provide security protection for the CUI environment.


I review existing hardware to determine whether it can support the technical controls required for the role it performs. That can mean changing configurations, updating firmware, restricting management access, changing how devices communicate, segmenting them differently or replacing equipment that can't appropriately support the required security configuration.


Where cryptography is relied upon to protect the confidentiality of CUI, I also need to evaluate whether the cryptographic technology being used meets the applicable FIPS-validation requirements.


This is particularly important because a small business may have equipment that has been operating reliably for years. Reliable doesn't necessarily mean appropriate for the new security requirements. At the same time, I don't assume every piece of hardware needs to be replaced simply because CMMC entered the conversation. I evaluate what the device does, where it sits in the environment and what requirements actually apply.


I Document What I Build

Technical implementation isn't complete if nobody can explain afterward how the environment was built or what was changed. Documentation is part of my technical work.

When I make changes to a CMMC environment, I document the technical work I perform and the systems I'm responsible for. I also create a full network diagram of the environment showing the relevant infrastructure and how those systems connect.


Depending on the engagement, that documentation can include the network architecture, firewalls, switches, VLANs, servers, hypervisors and virtual machines, endpoints, wireless networks, identity systems, Microsoft 365, remote-access paths, backup systems, security tools and other components that make up or interact with the environment.


For a Level 2 environment, that technical documentation becomes particularly important because CUI assets need to be accurately identified and represented as part of the company's CMMC scope and documentation.


The documentation I produce also gives the company's CMMC compliance specialists accurate technical information they can use when developing or updating the SSP, policies, procedures and broader compliance documentation.


The compliance documentation should describe the environment that actually exists. My job is to build and document that technical environment accurately so the people responsible for the broader CMMC documentation aren't trying to document controls based on assumptions.


Do I Need an IT Company or a CMMC Compliance Company?

I think the answer for many small contractors is both kinds of expertise, because they're different specialties.

A company that specializes in CMMC compliance can help the business with policies, procedures, organizational requirements, CUI-handling processes, SSP development and the broader compliance program. I focus on the technology underneath those requirements.


If a requirement says access must be restricted, somebody has to configure the systems that restrict it. If MFA is required, somebody has to implement it in the appropriate systems. If CUI needs to be segmented, somebody has to design and configure the network. If encryption is being relied upon to protect CUI, somebody has to verify and configure the technology. If a policy says only certain employees can access a file location, the permissions in Active Directory and on the file server need to actually enforce that.


Those technical and compliance functions need to communicate, even when they're being provided by different companies. I can provide the network diagrams, configurations, implementation records and other technical documentation from the work I perform to the company's CMMC compliance specialists so they have accurate information about the environment.


What If I Already Have an IT Person or MSP?

You don't necessarily need to replace them. If your internal IT person or existing MSP knows the environment and the company wants to keep that relationship, I can work alongside them on the technical implementation.


The important question is whether someone involved has the technical knowledge and capacity to implement the CMMC technical requirements correctly and whether everyone understands their responsibilities. I don't think a good existing IT relationship should be discarded just because a specialized project comes along.


If I perform the technical implementation and the company wants its existing IT provider to manage the environment afterward, I can document what I've implemented and work with them so they understand the technical environment they'll be responsible for maintaining.


What Happens After the Controls Are Implemented?

This is one of the questions I think deserves much more attention because CMMC isn't a one-time IT project.

A company's environment keeps changing. Employees are hired and leave. Permissions change. Computers are replaced. Applications are installed. Microsoft changes its services. Vendors change. Servers are upgraded. New cloud applications appear. Someone creates a new workflow. A department starts storing information somewhere it didn't before. A control that worked correctly when it was implemented can become ineffective later because something around it changed.


For businesses that want me to continue managing the environment after the initial technical implementation, SNL-Tech Services also provides Managed IT Services. That can include user support, account management, RMM monitoring, patching, device inventory, endpoint security, server management, Active Directory and Group Policy management, network and firewall management, Microsoft 365 administration, backups, documentation, hardware replacement and reviewing changes that could affect the technical controls.

Because I already understand the environment and why the controls were configured the way they were, I can evaluate future changes in the context of that architecture instead of treating every IT request as an isolated ticket.


A business doesn't have to become an ongoing Managed IT client for me to perform the initial CMMC technical implementation. But somebody needs to own the technical environment after implementation because security controls don't maintain themselves.


What If I Don't Have Internal IT That Can Do This?

This is exactly where I think many small government contractors get stuck. Some have no internal IT department. Others have one employee trying to manage everything. Some have an MSP that handles everyday support but doesn't have the resources or experience to implement the technical side of a CMMC environment.

That's a business I can help.


SNL-Tech Services can work directly with a small contractor that doesn't have internal IT, alongside an existing IT provider that needs additional technical expertise or with the company's specialized CMMC compliance resources.


For CMMC technical implementation projects, I am also willing to travel outside my normal Maryland service area when onsite work is necessary. Some environments need to be seen. If the business has local servers, manufacturing systems, multiple network segments, specialized equipment or years of infrastructure that has grown with the company, being onsite can be important to understanding how everything actually works before deciding how it should be changed.


The Most Secure Environment Still Has to Let the Business Work

This is one of the biggest lessons I think small businesses need to hear. A company still has to operate after the CMMC project is finished.

Employees need to quote work. Engineers need to open drawings. Production needs to manufacture things. Accounting needs to function. Employees may need remote access. Prime contractors need information. Subcontractors may need information. Applications still need to communicate with servers.


Security controls that make legitimate work nearly impossible can create another problem: employees start looking for ways around them. At the same time, “that's how we've always done it” isn't a reason to leave an insecure process in place.

The technical work is finding the balance between the requirement, the risk and the legitimate operational needs of the company.

“The most secure architecture in the world isn't particularly useful if the business can't operate inside it. The goal is to meet the requirements while designing around the way the company actually has to work.”SNL-Tech Services

Frequently Asked Questions

Is CMMC Phase II canceled?

No. The Department of War suspended the Phase II requirements in July 2026 while it conducts a comprehensive review of the CMMC program. Phase I self-assessment requirements remain in place.


Does the Phase II suspension mean I can stop working on CMMC?

No. The suspension changed the rollout of Phase II. It did not eliminate the underlying need to safeguard government information or comply with the cybersecurity requirements that currently apply to your contracts.


Is CMMC Level 1 really something a small business can do?

Yes, but don't confuse a self-assessment with having nothing to implement. If your systems process, store or transmit FCI, you still need to understand the applicable scope and make sure the required safeguards are actually implemented.


Do I have to move my whole company to GCC High for Level 2?

Not automatically. The appropriate architecture depends on the information you handle, your contractual and other regulatory requirements, the services you use and where CUI actually needs to go. GCC High may be the right solution for some businesses, but the architecture should be designed around the requirements and workflow rather than starting with a product.


Can I keep my existing servers and Active Directory?

Potentially. Existing systems aren't automatically prohibited simply because a company needs Level 2. They do, however, need to be evaluated against the applicable requirements if they're part of the CUI environment. In some cases, hardening and segmenting the existing environment may make sense. In others, replacement or a different architecture may be necessary.


Does all of my hardware have to be replaced for CMMC Level 2?

No. Hardware should be evaluated based on what it does, where it sits in the environment and which requirements apply to it. Some equipment may be perfectly capable of supporting the required configuration. Other equipment may need firmware updates, configuration changes, additional segmentation or replacement because it can't provide the security functionality required for its role.


Can SNL-Tech Services implement the technical controls without doing all of my CMMC compliance documentation?

Yes. That's how I define my role. I focus on the technical implementation, hardening, testing and documentation of the IT environment. I can provide the technical documentation and evidence from my work to the business and its CMMC compliance specialists so the broader compliance documentation accurately reflects the technology.


Do I need both an IT company and a CMMC compliance company?

For many small contractors, I think having both kinds of expertise makes sense. A CMMC compliance specialist can focus on the broader compliance program, policies, procedures, organizational requirements and documentation. I focus on implementing and maintaining the technology underneath those requirements. The important part is making sure both sides are working from accurate information about the same environment.


Do I have to replace my current MSP?

No. I can work alongside an existing MSP or internal IT person if the business wants to keep them. I can also provide ongoing Managed IT Services after implementation if the company needs someone to manage the technical environment moving forward.


Do you travel for CMMC projects?

Yes. SNL-Tech Services is based in Maryland, but I am willing to travel outside my normal service area for CMMC technical implementation projects when onsite work is necessary to properly understand, build or harden the environment.


What should I do first if I'm told my business needs CMMC?

Start with the contract and the information. Determine what requirements apply, whether you're handling FCI or CUI and where that information enters, moves through and leaves the business.

If you don't already have a clear understanding of your existing IT environment, an SNL-Tech Services IT Baseline Assessment can be a good technical starting point. It allows me to look at what you already have, how it is configured and where technical weaknesses or potential CMMC concerns may exist before recommending major changes.

From there, the business can determine what can stay, what can be hardened, what needs to be upgraded and where additional technical or specialized CMMC compliance work is needed.

I wouldn't start with a shopping cart. I'd start with the environment.


From Assessment to Actually Ready

A business can have an assessment, a gap report, policies and a plan and still not have the technical controls implemented.

Eventually somebody has to configure the firewall, harden Active Directory and build the Group Policies.

Somebody has to fix the permissions, segment the network and configure MFA.

Somebody has to secure the servers and endpoints, document the network and test that the controls actually work.

And somebody has to continue managing those systems after the project is finished.

That's what I do.

SNL-Tech Services focuses on the technical implementation, hardening, documentation and ongoing management of IT controls for small government contractors. I can work with businesses that don't have internal IT, alongside an existing IT provider that needs additional technical expertise, or with the company's CMMC compliance specialists so the technical environment and the broader compliance program accurately reflect one another.

If you're trying to figure out what CMMC Level 1 or Level 2 means for the technology you already have, I don't think the first answer should automatically be replacing everything.

Start by understanding what you have, what information you handle, how the business actually works and what truly needs to change.


Additional Information & Resources

For businesses that want to read the official requirements and guidance directly, these are the resources I recommend:

Department of War — CMMC Phase II Suspension AnnouncementThe July 13, 2026 announcement suspending CMMC Phase II requirements, confirming that Phase I self-assessment requirements remain in place and announcing the comprehensive CMMC program review.

Department of War — CMMC Program Changes and Cybersecurity RequirementsAdditional Department of War information explaining the Phase II suspension and emphasizing that contractors still need to comply with applicable cybersecurity requirements and safeguard government information.

32 CFR Part 170 — Cybersecurity Maturity Model Certification ProgramThe federal regulation governing the CMMC program, including assessment levels, scoping, asset categories, POA&Ms and affirmation requirements.

NIST SP 800-171 — Protecting Controlled Unclassified InformationThe NIST publication containing the security requirements currently underlying CMMC Level 2.

FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information SystemsThe federal contract clause containing the 15 basic safeguarding requirements associated with protecting Federal Contract Information (FCI).

DFARS — Defense Federal Acquisition Regulation SupplementThe Defense Federal Acquisition Regulation Supplement, including cybersecurity requirements applicable to Defense Industrial Base contractors.

Comments


bottom of page