Posted by Shane Morris | Reading time: 9 minutes.
If your business holds — or wants to hold — a Department of Defense contract, CMMC 2.0 isn’t optional paperwork. It’s a hard gate. No certification, no contract, regardless of how strong your proposal is otherwise.
The problem most defense contractors run into isn’t disagreement about whether CMMC matters. It’s not knowing exactly what “compliant” actually requires in practice, level by level, control by control. This post breaks that down clearly, so you know precisely where your business stands before an assessor tells you.
What CMMC 2.0 Actually Is
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that contractors and subcontractors handling sensitive information actually have the cybersecurity controls they claim to have. CMMC 2.0 streamlined the original five-level model down to three:
- Level 1 (Foundational) — basic safeguarding of Federal Contract Information (FCI), self-assessed annually
- Level 2 (Advanced) — protection of Controlled Unclassified Information (CUI), aligned to NIST SP 800-171, requiring either self-assessment or third-party certification depending on contract requirements
- Level 3 (Expert) — the highest tier, for the most sensitive programs, requiring government-led assessment
Most small and mid-sized defense contractors and subcontractors fall into Level 2 — which is also where the real complexity lives, since it maps to 110 specific security controls across 14 domains under NIST SP 800-171.
Why This Matters More in 2026
CMMC requirements have moved from “coming soon” to active contract language. DoD is incorporating CMMC requirements directly into solicitations, which means primes are increasingly required to verify their subcontractors’ compliance before subcontracts are even awarded. If you’re in the defense supply chain at any tier, the assumption that “we’ll deal with it when it’s actually enforced” is no longer a safe one to operate on.
The Core Domains You’ll Be Assessed Against
CMMC Level 2 assessments evaluate your environment across 14 control domains. Here’s what each one actually requires in practice:
Access Control — Are user accounts limited to only what each person needs? Is multi-factor authentication enforced on remote and privileged access?
Awareness and Training — Can you prove your staff receives regular, documented security awareness training — not just a one-time onboarding mention?
Audit and Accountability — Are your systems logging security-relevant events, and are those logs actually reviewed, not just collected?
Configuration Management — Do you have documented baseline configurations for your systems, and a controlled process for changes?
Identification and Authentication — Are users uniquely identified, and are authentication mechanisms strong enough to meet the standard?
Incident Response — Do you have a documented, tested incident response plan — not a plan that exists only in someone’s head?
Maintenance — Is system maintenance controlled and logged, including remote maintenance sessions?
Media Protection — Is CUI on removable media properly marked, controlled, and sanitized before disposal or reuse?
Personnel Security — Are screening procedures in place for personnel with access to CUI, and is access revoked promptly when someone leaves?
Physical Protection — Are physical access controls in place for facilities and systems that process CUI?
Risk Assessment — Do you conduct and document periodic risk assessments, not just at audit time?
Security Assessment — Are your security controls periodically assessed for effectiveness, with a documented plan of action for gaps?
System and Communications Protection — Are network boundaries protected, and is CUI encrypted in transit and at rest where required?
System and Information Integrity — Are systems monitored for malicious code, and are flaws remediated in a timely, documented manner?
The Documents You Need Before an Assessor Ever Shows Up
Controls in place but undocumented is one of the most common failure points in CMMC assessments. You need:
- A System Security Plan (SSP) describing how each of the 110 controls is implemented in your specific environment
- A Plan of Action and Milestones (POA&M) for any control gaps, with realistic remediation timelines
- Incident response documentation, including evidence it’s been tested, not just written
- Configuration baselines for systems handling CUI
- Access control policies with evidence of enforcement, not just a written policy sitting in a drawer
If an assessor asks “show me,” and the answer is “we do that, we just don’t have it written down,” that’s a finding, not a pass.
Common Gaps We See in Real Environments
After working with defense contractors and subcontractors across multiple CMMC engagements, the same gaps show up again and again:
Multi-factor authentication isn’t fully enforced. Often it’s on for email but not for VPN access, privileged accounts, or remote administration — which is a partial implementation, not a complete one.
Logging exists, but nobody’s watching it. Systems generate logs, but there’s no defined process or responsible party actually reviewing them for anomalies.
CUI isn’t clearly identified or marked. If your team doesn’t know which specific data is CUI, they can’t consistently protect it the way the standard requires.
The incident response plan has never been tested. A plan that’s never been run through a tabletop exercise is a document, not a capability — and assessors increasingly ask for evidence of testing, not just the plan itself.
Subcontractor flow-down isn’t tracked. If you’re a prime with subcontractors handling CUI, you’re responsible for verifying their compliance too — many primes haven’t built that verification process yet.
What to Do With This Checklist
Walk through each domain above honestly. For every item where your honest answer is “not really” or “I think so, but I’m not sure,” that’s a gap that needs a documented remediation plan before an actual assessment — self-assessed or third-party.
This isn’t a one-afternoon project for most organizations. Real CMMC Level 2 readiness usually takes months of deliberate work across documentation, technical controls, and staff training. The earlier you start closing the real gaps, the less it costs you in both time and risk when a contract requirement lands with a hard deadline attached.
Get the Full Checklist
We’ve built a complete, downloadable CMMC 2.0 Compliance Checklist that walks through every domain and control area in detail, so you can assess your own environment against the actual standard — not a simplified summary of it.
[Download the CMMC 2.0 Compliance Checklist →]
No commitment. No sales pressure. Just clarity on where your compliance stands.
Silotech Services holds CMMC Level 2 certification and provides compliance-aligned managed IT services for defense contractors and subcontractors nationwide.
Sources: DoD CMMC 2.0 Program Documentation · NIST SP 800-171 Rev 2
ABOUT SILOTECH
National IT. Local Engineers. One Standard.
Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.
WHAT WE DO
Business Operations
Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →
IT Infrastructure
Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →
Employee Support
Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →
INDUSTRIES WE SERVE
RECENT POSTS
-
The Difference Between Co-Managed and Fully Managed IT: How to Know Which One Your Business Needs
Posted by Shane Morris | Reading time: 6 minutes. Once a business decides outside IT support makes sense, the next question is rarely asked clearly enough: fully managed, or co-managed? The two models solve different…
-
What Is a vCIO — and Why Growing SMBs Can’t Afford to Not Have One
Posted by Shane Morris | Reading time: 6 minutes. Most growing businesses eventually hit a point where their technology decisions stop being simple. What started as “buy a few laptops and a server” becomes a…
Posted by Shane Morris | Reading time: 9 minutes.
If your business holds — or wants to hold — a Department of Defense contract, CMMC 2.0 isn’t optional paperwork. It’s a hard gate. No certification, no contract, regardless of how strong your proposal is otherwise.
The problem most defense contractors run into isn’t disagreement about whether CMMC matters. It’s not knowing exactly what “compliant” actually requires in practice, level by level, control by control. This post breaks that down clearly, so you know precisely where your business stands before an assessor tells you.
What CMMC 2.0 Actually Is
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that contractors and subcontractors handling sensitive information actually have the cybersecurity controls they claim to have. CMMC 2.0 streamlined the original five-level model down to three:
- Level 1 (Foundational) — basic safeguarding of Federal Contract Information (FCI), self-assessed annually
- Level 2 (Advanced) — protection of Controlled Unclassified Information (CUI), aligned to NIST SP 800-171, requiring either self-assessment or third-party certification depending on contract requirements
- Level 3 (Expert) — the highest tier, for the most sensitive programs, requiring government-led assessment
Most small and mid-sized defense contractors and subcontractors fall into Level 2 — which is also where the real complexity lives, since it maps to 110 specific security controls across 14 domains under NIST SP 800-171.
Why This Matters More in 2026
CMMC requirements have moved from “coming soon” to active contract language. DoD is incorporating CMMC requirements directly into solicitations, which means primes are increasingly required to verify their subcontractors’ compliance before subcontracts are even awarded. If you’re in the defense supply chain at any tier, the assumption that “we’ll deal with it when it’s actually enforced” is no longer a safe one to operate on.
The Core Domains You’ll Be Assessed Against
CMMC Level 2 assessments evaluate your environment across 14 control domains. Here’s what each one actually requires in practice:
Access Control — Are user accounts limited to only what each person needs? Is multi-factor authentication enforced on remote and privileged access?
Awareness and Training — Can you prove your staff receives regular, documented security awareness training — not just a one-time onboarding mention?
Audit and Accountability — Are your systems logging security-relevant events, and are those logs actually reviewed, not just collected?
Configuration Management — Do you have documented baseline configurations for your systems, and a controlled process for changes?
Identification and Authentication — Are users uniquely identified, and are authentication mechanisms strong enough to meet the standard?
Incident Response — Do you have a documented, tested incident response plan — not a plan that exists only in someone’s head?
Maintenance — Is system maintenance controlled and logged, including remote maintenance sessions?
Media Protection — Is CUI on removable media properly marked, controlled, and sanitized before disposal or reuse?
Personnel Security — Are screening procedures in place for personnel with access to CUI, and is access revoked promptly when someone leaves?
Physical Protection — Are physical access controls in place for facilities and systems that process CUI?
Risk Assessment — Do you conduct and document periodic risk assessments, not just at audit time?
Security Assessment — Are your security controls periodically assessed for effectiveness, with a documented plan of action for gaps?
System and Communications Protection — Are network boundaries protected, and is CUI encrypted in transit and at rest where required?
System and Information Integrity — Are systems monitored for malicious code, and are flaws remediated in a timely, documented manner?
The Documents You Need Before an Assessor Ever Shows Up
Controls in place but undocumented is one of the most common failure points in CMMC assessments. You need:
- A System Security Plan (SSP) describing how each of the 110 controls is implemented in your specific environment
- A Plan of Action and Milestones (POA&M) for any control gaps, with realistic remediation timelines
- Incident response documentation, including evidence it’s been tested, not just written
- Configuration baselines for systems handling CUI
- Access control policies with evidence of enforcement, not just a written policy sitting in a drawer
If an assessor asks “show me,” and the answer is “we do that, we just don’t have it written down,” that’s a finding, not a pass.
Common Gaps We See in Real Environments
After working with defense contractors and subcontractors across multiple CMMC engagements, the same gaps show up again and again:
Multi-factor authentication isn’t fully enforced. Often it’s on for email but not for VPN access, privileged accounts, or remote administration — which is a partial implementation, not a complete one.
Logging exists, but nobody’s watching it. Systems generate logs, but there’s no defined process or responsible party actually reviewing them for anomalies.
CUI isn’t clearly identified or marked. If your team doesn’t know which specific data is CUI, they can’t consistently protect it the way the standard requires.
The incident response plan has never been tested. A plan that’s never been run through a tabletop exercise is a document, not a capability — and assessors increasingly ask for evidence of testing, not just the plan itself.
Subcontractor flow-down isn’t tracked. If you’re a prime with subcontractors handling CUI, you’re responsible for verifying their compliance too — many primes haven’t built that verification process yet.
What to Do With This Checklist
Walk through each domain above honestly. For every item where your honest answer is “not really” or “I think so, but I’m not sure,” that’s a gap that needs a documented remediation plan before an actual assessment — self-assessed or third-party.
This isn’t a one-afternoon project for most organizations. Real CMMC Level 2 readiness usually takes months of deliberate work across documentation, technical controls, and staff training. The earlier you start closing the real gaps, the less it costs you in both time and risk when a contract requirement lands with a hard deadline attached.
Get the Full Checklist
We’ve built a complete, downloadable CMMC 2.0 Compliance Checklist that walks through every domain and control area in detail, so you can assess your own environment against the actual standard — not a simplified summary of it.
[Download the CMMC 2.0 Compliance Checklist →]
No commitment. No sales pressure. Just clarity on where your compliance stands.
Silotech Services holds CMMC Level 2 certification and provides compliance-aligned managed IT services for defense contractors and subcontractors nationwide.
Sources: DoD CMMC 2.0 Program Documentation · NIST SP 800-171 Rev 2
ABOUT SILOTECH
National IT. Local Engineers. One Standard.
Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.
WHAT WE DO
Business Operations
Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →
IT Infrastructure
Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →
Employee Support
Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →
INDUSTRIES WE SERVE
RECENT POSTS
-
The Difference Between Co-Managed and Fully Managed IT: How to Know Which One Your Business Needs
Posted by Shane Morris | Reading time: 6 minutes. Once a business decides outside IT support makes sense, the next question is rarely asked clearly enough: fully managed, or co-managed? The two models solve different…
-
What Is a vCIO — and Why Growing SMBs Can’t Afford to Not Have One
Posted by Shane Morris | Reading time: 6 minutes. Most growing businesses eventually hit a point where their technology decisions stop being simple. What started as “buy a few laptops and a server” becomes a…
-
Is Your IT Provider Actually Securing Your Business — or Just Managing It?
Posted by Shane Morris | Reading time: 7 minutes. If you already have an IT provider, this post isn’t trying to convince you that you need one — you’ve already made that decision. The real…
-
Cloud Migration Gone Wrong: 7 Mistakes SMBs Make and How to Avoid Them
Posted by Shane Morris | Reading time: 7 minutes. Cloud migration sounds simple in a sales pitch: move your systems to the cloud, cut your hardware costs, gain flexibility. In practice, it’s one of the…


