Compliance — CMMC
CMMC 2.0 compliance for Tri-State defense suppliers
Since November 10, 2025, CMMC requirements have been entering DoD solicitations, and primes are flowing them down to every subcontractor that touches controlled information. Remediation honestly takes six to twelve months. If a 2026 or 2027 award matters to you, the work starts now — calmly.
What CMMC 2.0 actually requires
CMMC is the Department of Defense’s mechanism for verifying that contractors protect the information they handle. The level your contracts demand depends on what reaches you.
| Level | Who it applies to | Assessment |
|---|---|---|
| Level 1 | Contractors handling Federal Contract Information (FCI) only | Annual self-assessment |
| Level 2 | Contractors handling Controlled Unclassified Information (CUI) — the 110 controls of NIST SP 800-171 | Third-party assessment by a C3PAO for most awards; self-assessment for a subset |
| Level 3 | A small set of programs handling the most sensitive CUI | Government-led assessment, building on Level 2 plus NIST SP 800-172 controls |
Requirements phase into contracts through November 2028, but two forces move faster than the calendar. First, primes flow requirements down to subcontractors on their own schedules — your effective deadline is whenever your prime’s letter arrives. Second, your NIST 800-171 self-assessment score is already posted to SPRS under DFARS 252.204-7019 and -7020, which means your current posture is already speaking for you in source selection.
The timeline, realistically
Six to twelve months of remediation is typical for a shop starting from ordinary commercial IT, and C3PAO assessor waitlists have run six to eight months — so the real distance from a standing start to a certificate is often more than a year. New Jersey alone has roughly 900 manufacturers in the DoD supply chain (per NJMEP), Long Island carries its aerospace legacy, and Connecticut feeds the Electric Boat, Sikorsky, and Pratt & Whitney chains — a lot of firms will want the same assessors at the same time. Assessor capacity is the one part of the timeline you cannot buy back later.
- Scoping CUI — finding where it actually lives, and shrinking that footprint into a defensible enclave — usually takes longer than anyone expects
- MFA everywhere, and FIPS-validated encryption wherever cryptography protects CUI
- Logging, monitoring, and access control built out to 800-171’s expectations
- A System Security Plan and policies that describe reality, with a POA&M for what remains — and CMMC’s tolerance for open POA&M items is narrow, with a 180-day closeout clock
What Stedholm does
Remediation and operation, sequenced so assessment readiness is a byproduct of running the environment properly.
Scoping and enclave design
Shrink the CUI boundary before hardening it — a well-designed enclave, built on properly engineered infrastructure, can cut the scope of the entire effort.
Gap assessment against 800-171
Control by control, producing an honest SPRS score and a sequenced remediation plan with pricing in writing.
Remediation
Identity, MFA, encryption, logging, and endpoint hardening delivered through our security practice.
Documentation
A System Security Plan and POA&M that describe what actually runs — assessors check operation against paper, and mismatches are findings.
Ongoing operation
Controls kept running between assessments through managed IT, with monitoring around the clock by our tooling and escalation to an engineer.
Assessment preparation
Evidence organized the way assessors ask for it, and we sit with you during the assessment itself.
Prime pressure is the real deadline
The phase-in schedule runs to 2028, but flow-down letters and supplier questionnaires are circulating now, and primes are consolidating supplier lists around who can demonstrate readiness. For a Tri-State machine shop or engineering firm, the commercial risk is not an enforcement action — it is quietly not being on the next bid list. More on the vertical at defense and manufacturing.
We remediate and operate controls; we are not a C3PAO, a law firm, or an auditor. We do not certify you — and we would not want to grade our own work. We prepare you for the organization that does. Suppliers who also sell commercially often pair this with SOC 2 readiness, since the control overlap is substantial; other regimes live at the compliance hub.
Good fit if
NJ, Long Island, or CT manufacturer or engineering firm in a DoD supply chain
A prime’s flow-down letter or questionnaire is sitting in your inbox
Your SPRS score is posted and you would rather it were not
CUI currently lives on everyone’s laptops and the shared drive
IT is one capable, overloaded admin
Common questions
We only make one small part. Are we really in scope?
If FCI or CUI reaches you — drawings, specs, contract data — some CMMC level applies, because primes must flow requirements down. The question worth answering precisely is which level, and whether you can restructure how data reaches you to keep the scope small. That is a scoping exercise, and it is where we start.
Can we just self-assess?
Level 1 is self-assessed, and a subset of Level 2 awards permit it, but most Level 2 CUI work expects a C3PAO assessment. Your contracts and your prime’s flow-downs say which applies — read them with your counsel or contracting officer, and we will build to the answer.
What is a good SPRS score?
Scores on the 800-171 methodology range from −203 to 110, and a fresh honest assessment at a typical commercial shop often lands low — that is normal and fixable. What matters is posting an accurate score and moving it with real remediation, because misrepresenting it is a far worse problem than a low number.
Can you host our CUI enclave?
We design and operate enclave environments — commonly on Microsoft’s government cloud offerings — sized to your actual CUI footprint, so the rest of the business keeps running on ordinary commercial IT. Where a contract imposes specific hosting requirements, those govern the design.
How much of this is paperwork?
Less than the industry pretends and more than engineers wish. The SSP and POA&M matter, but assessors verify that controls operate — screenshots, logs, and configuration, not binders. Our bias is to build the operating reality first and let the documentation describe it.
Start before the waitlist starts for you.
An 800-171 gap assessment gives you an honest score, a scoped boundary, and a sequenced plan — findings are yours to keep.