
If your business does any work with the Department of Defense — or sits somewhere in the DoD supply chain — CMMC 2.0 (Cybersecurity Maturity Model Certification) is no longer a "someday" problem. Enforcement is rolling into new contracts, and prime contractors are already asking their vendors to prove they meet the standard.
At Boston IT Services (BITS), we've been helping SMBs quietly navigate NIST 800-171 and CMMC for years. Here's what you actually need to know — without the acronym soup.
What Is CMMC 2.0?
CMMC 2.0 is the DoD's framework for ensuring contractors and subcontractors adequately protect sensitive federal data. It has three levels:
- Level 1 (Foundational): 17 basic practices for companies handling Federal Contract Information (FCI). Annual self-assessment.
- Level 2 (Advanced): 110 controls aligned to NIST SP 800-171 for anyone touching Controlled Unclassified Information (CUI). Requires a third-party (C3PAO) assessment every 3 years for most contracts.
- Level 3 (Expert): Enhanced protections based on NIST SP 800-172 for the most sensitive programs. Government-led assessment.
Who Is Actually Affected?
Short answer: a lot more companies than you'd think. If your business — or a company you sell to — handles anything from technical drawings to manufacturing specs to research data flagged as CUI, you're in scope. That includes manufacturers, engineering firms, biotech, universities, cloud service providers, and even IT and marketing vendors serving prime contractors.
Common Misconceptions
- "We're too small to be a target." Attackers specifically target smaller subcontractors as a way into primes.
- "Our IT team says we're fine." Being fine and being assessable are very different things. CMMC requires documented evidence, not just good intentions.
- "We'll deal with it when we bid." Achieving Level 2 typically takes 6–12 months. Waiting until the RFP drops means losing the bid.
A Practical Roadmap
- Scope your environment. Identify where FCI and CUI live — endpoints, file shares, email, SaaS apps, backups.
- Run a gap assessment against NIST 800-171. Every control gets a score (0, 1, 3, or 5).
- Build a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M). These are required artifacts, not optional paperwork.
- Implement enclaves where possible. Isolating CUI to a Microsoft GCC High tenant or a similar enclave dramatically shrinks your assessment scope.
- Turn on the core technical controls — MFA everywhere, FIPS-validated encryption, centralized logging, endpoint detection, audited access reviews, and documented incident response.
- Train your people. Insider mistakes are still the #1 cause of CUI exposure.
- Get pre-assessed before your official C3PAO visit. A dry run always uncovers gaps.
How BITS Helps
We work as a co-managed IT and security partner for companies preparing for CMMC. That typically looks like:
- Full 800-171 gap assessment with a plain-English report
- SSP and POA&M authoring
- Deploying and hardening Microsoft 365 GCC / GCC High enclaves
- Managed EDR, MFA, patching, backup, and 24×7 monitoring aligned to CMMC controls
- Ongoing evidence collection so your next assessment isn't a fire drill
💬 Not sure where you stand? We offer a free 30-minute CMMC readiness call — no jargon, no scare tactics, just an honest look at what you'd need to be assessment-ready.


