post-img
  • Home >
  • Resources >
  • Simplify CMMC Level 2 for Midsize DoD Contractors: Changes, Scenarios & Steps
AI and automation CMMC AI and automation CMMC

Simplify CMMC Level 2 for Midsize DoD Contractors: Changes, Scenarios & Steps

  • copy-link-icon

    Copy URL

  • linkedin-icon
Midsize DoD contractors face possible CMMC policy changes, but they can still simplify their Level 2 compliance. Learn the related federal requirements, different policy scenarios, and simplification steps. Try our interactive scenario planner.

In this article:

Executive summary:

CMMC Level 2 requires midsize DoD contractors handling CUI to implement all 110 NIST SP 800-171 Rev 2 controls. DoD has paused Phase 2 third-party assessments, but the underlying obligation is unchanged: DFARS 252.204-7012 still requires those controls, and you still self-assess and maintain your SPRS score. Scoping CUI into an enclave, prioritizing high-impact controls, and keeping your SSP current are the fastest ways to simplify the work.

What CMMC Level 2 now requires for midsize DoD contractors

CMMC Level 2, set out in 32 CFR Part 170  (CMMC Program rule), requires midsize defense contractors who handle Controlled Unclassified Information (CUI) to meet all 110 security controls in NIST SP 800-171 Rev 2. While Level 1 covers basic protections for Federal Contract Information (FCI), Level 2 is for systems that process or store CUI.

Even though the DoD has paused mandatory CMMC audits by Certified Third-Party Assessment Organizations (C3PAOs) during Phase 2, organizations still need to do self-assessments and keep their compliance records up to date.

Midsize contractors need to document their security measures in a System Security Plan (SSP) and record any gaps in a Plan of Action and Milestones (POA&M). Because they handle more sensitive defense data than many smaller firms, they face unique challenges. This makes it important to map controls and collect evidence regularly as part of daily compliance.

CMMC Level 2 covers 14 security areas, including access control, incident response, and configuration management. Executives need to clearly understand each technical safeguard. By checking how each requirement fits your systems, your team can make sure the right people are responsible for every safeguard. For more details, see our full guide on CMMC Level 2 requirements.

How midsize DoD contractors should approach CMMC changes

Leaders in the Defense Industrial Base should stay aware of possible program updates but continue their own work. The Department of Defense is collecting feedback and could extend the pause, change the assessment rules, end the CMMC framework, or move ahead with Phase 2.

Whatever regulators decide, your main responsibilities do not change. DFARS 252.204-7012 still requires you to fully apply NIST SP 800-171 controls to any system that stores or handles defense data. You also need to keep your Supplier Performance Risk System (SPRS) scores current, because incorrect CMMC self-assessments can cause serious legal and regulatory issues under federal contracting rules.

Federal agency decisions also affect the whole supply chain. Prime contractors often need strict cybersecurity checks to keep their contracts, and they may ask subcontractors for third-party proof that controls are in place. To learn how top defense companies apply these rules to their suppliers, see our section below on DFARS flow-down requirements for midsize DoD contractors.

Logan Therrien, Chief Strategy Officer, Kieri SolutionsLogan Therrien, Chief Strategy Officer and Lead CMMC Assessor at Kieri Solutions, cautions against reading the pause as relief during the Secure Talk episode “CMMC Phase 2 SUSPENDED.”

"DFARS 7021 was not repealed. What's been suspended is phase two of the rollout plan and how the contractors implement that,” Therrien says. "The expensive part is implementing security. That part has been around for eight years. That part did not go away."

Lance ArnoldLance Arnold, who has 30 years of industry experience and who led a previous organization through the CMMC Level 2 process, says on the same podcast that contractors already working toward compliance shouldn't treat the suspension as a reason to stop.

“I would say keep using it, keep pressing forward,” Arnold says. “Don't stop what you're doing, because this is the best framework that we know of. Maybe next year or maybe 60 days down the line, something will be clearer and smoother and more streamlined. But for now, this is the best of what we have.”

This interactive tool lets midsize DoD contractors see how the July 2026 CMMC pause affects them. Pick your role — prime or subcontractor — and a possible DoD decision to see your next move. Under every outcome, the core requirement holds: implement NIST 800-171, self-assess, and maintain your SPRS score.

Your role

What DoD does next

Pick a role and a scenario

Your next move appears here.

Notice your next move barely changes. That's the point — implementing NIST 800-171 is required no matter what DoD decides.


How NIST and DFARS overlap with CMMC Level 2

NIST SP 800-171 sets the technical security controls, while DFARS 252.204-7012 makes these controls a legal requirement in contracts. DFARS 252.204-7021, known as the CMMC acquisition clause, adds CMMC Level 2 verification to contract solicitations. Changes in CMMC assessment policies do not change your core compliance responsibilities.

Since December 2017, DFARS 252.204-7012 has required defense contractors that handle Controlled Unclassified Information to protect such data in accordance with NIST SP 800-171. CMMC did not add new technical safeguards. Instead, it created a formal mechanism to verify that companies are following the rules.

If C3PAO audits are paused, the DFARS contract requirements still apply. Not following these rules is still a serious risk, and falsely claiming compliance can lead to False Claims Act liability, no matter what CMMC verification model is in place.

Right now, DFARS 252.204-7012 uses the version of NIST SP 800-171 that is current when the contract is offered, which is usually Rev. 2. This is also the version used in NIST SP 800-171A, the evaluation guide, and in the CMMC final rule.

Contractors should prepare for a future switch to Rev. 3 as defense standards evolve. Keeping your System Security Plan current and your Supplier Performance Risk System score accurate will help your organization stay compliant now and in the future.

DFARS flow-down requirements for midsize DoD contractors

The Federal Acquisition Regulations set rules for both prime contractors and subcontractors in defense supply chains. Prime contractors have to pass down DFARS 252.204-7012 requirements to any subcontractor that handles Controlled Unclassified Information.

This means large prime contractors cannot just secure their own networks. They also need to make sure your organization has put all the required NIST SP 800-171 security controls in place before they share sensitive defense data with you.

Since prime contractors risk heavy financial penalties and False Claims Act issues if there are supply chain problems, they often use stricter checks than the government requires. Even though the Department of Defense has paused mandatory third-party audits for CMMC, your enterprise customers might still ask for a C3PAO certification or do detailed evidence reviews to protect themselves. In the end, your timeline will mostly depend on what your prime contractor expects.

Brian Hubbard, President of Evolved Cyber SolutionsAs Brian Hubbard, President of Evolved Cyber Solutions, says on the SecureTalk podcast, “It's up to the prime. It's not a government thing. They can flow down the requirement exactly how it comes through the contract, or they might add to it."

 

Achieving compliance without a dedicated security team requires treating CMMC Level 2 as an operational sequence rather than a large IT project. Midsize contractors can streamline this process by isolating sensitive data, focusing on high-impact remediation, and leveraging automation tools to reduce the administrative burden of maintaining 110 controls.

Micah Spieler, Chief Product Officer at Strike GraphMicah Spieler, Chief Product Officer for Strike Graph, notes that reframing NIST requirements is key to making compliance manageable.

"Midsize companies get overwhelmed because they look at CMMC as 110 separate investigations," Spieler says. "But controls aren't 110 unique tasks—they're mostly queries against a smaller handful of data objects: assets, identities, configurations, and data flows."

He emphasizes that while control ownership remains with the contractor, maintaining live data transforms daily operations. "Even with an asset repository, you'll still own controls. But the difference between a chaotic IT project and a manageable daily workflow is whether you're managing compliance operations against live data in a repository, or trying to reconstruct historical reality from scratch every time your auditor has an ask."

Midsize contractors can follow these steps to simplify their CMMC Level 2 compliance:

  • Scope the CUI environment and isolate data.

Map exactly where Controlled Unclassified Information enters, travels, and rests within your infrastructure, categorizing data against the official CUI Registry. Instead of attempting to secure your entire corporate network, deploy a dedicated CUI enclave to isolate this sensitive data. Containing the footprint reduces your CMMC assessment scope, which dramatically lowers implementation costs, simplifies administrative overhead for internal IT teams, and accelerates your overall project timeline significantly.

  • Conduct a targeted gap assessment.

With your assessment boundary strictly defined, evaluate your technical safeguards and documented policies against the 110 security requirements. Internal IT teams should utilize the NIST SP 800-171A assessment procedures to verify actual operational practices rather than relying on assumptions. Identifying specific deficiencies early prevents wasted spending on unnecessary software tools and provides a realistic, objective baseline for an accurate CMMC Level 2 self-assessment.

  • Remediate gaps and log a POA&M.

Address your most critical security vulnerabilities immediately, focusing heavily on access control mechanisms and incident response protocols. For any non-critical requirements you cannot resolve right away, create a formal CMMC Plan of Action and Milestones. Keep in mind that certain highly weighted controls cannot be deferred, and regulators require all documented action items to be fully resolved within a strict 180-day window.

  • Finalize the System Security Plan.

Consolidate your security policies, system architecture diagrams, and specific control implementations into a comprehensive System Security Plan. This core document serves as the primary evidence during any compliance review and must accurately reflect your daily operational reality. A midsize organization should explicitly detail how each of the 14 NIST control families functions within the defined boundary, linking directly to verified technical evidence.

  • Submit the SPRS score and maintain compliance.

Calculate your final assessment score and submit it to the federal registry alongside an annual affirmation signed by a senior corporate executive. Compliance requires persistent ongoing maintenance once this baseline is firmly established. Implement continuous monitoring processes, conduct routine internal reviews, and update your security documentation regularly to ensure your operational posture remains audit-ready whenever enterprise prime contractors request verification.

Before taking action, executive leaders should make key decisions that help reduce compliance overhead. Setting assessment boundaries, deciding whether to manage compliance internally or work with outside partners, and focusing on remediation efforts that most affect your score will shape your program’s cost and timeline.

Midsize contractors can try these strategies to simplify CMMC Level 2 compliance:

  • Use a CUI enclave instead of applying controls across your whole company: A Controlled Unclassified Information (CUI) enclave is a secure IT environment, separate from your main network, designed to store and handle sensitive defense data. By focusing on this area, you limit your CMMC assessment scope, protect important information, and keep regular business running smoothly. This also makes audits much simpler.
  • Work with a Managed Service Provider (MSP) or External Service Provider (ESP) if you have limited staff: Building a strong cybersecurity program on your own means hiring experts and buying costly equipment. By partnering with an MSP or ESP, you can share the responsibility and avoid large upfront investments.
  • Prioritize remediation based on how much it affects your SPRS score: If you treat all 110 security requirements the same, you may run out of budget and slow down progress. Focus first on controls that have the biggest impact on your score. Fixing the most important issues early helps you qualify for conditional certification, while less critical problems can be added to a Plan of Action and Milestones (POA&M).
  • Use a GRC or compliance automation platform to continuously collect evidence: Manually gathering screenshots, logs, and documents for all 110 requirements takes a lot of time, especially for small IT teams. GRC tools designed for CMMC can automatically collect technical evidence and link it to NIST control families. This keeps your SSP and POA&M up to date all year, so you don’t have to rush before each assessment.
  • Do a mock assessment with a Registered Practitioner Organization (RPO) or Certified CMMC Professional (CCP) before your official self-assessment: Getting outside help for a readiness review helps you find important gaps early, especially in the requirements that carry the most points and cannot be deferred. Catching these issues ahead of time can mean the difference between passing and failing your assessment.

    Arnold found this during his own CMMC Level 2 assessment. "I thought my SSP was perfect. I thought I covered everything," he says. But going through the process surfaced things he hadn't seen or thought of.

    He adds: “Even all my knowledge, all my expertise, I would not go into a network, build it all myself and say I'm good to go self-assessment without someone else coming in to check my work."

Overcoming CMMC Level 2 challenges for midsize contractors

Many midsize organizations struggle with compliance because they treat important administrative steps as minor technical tasks. To avoid common mistakes like scope creep, unrealistic plans, and inaccurate reporting, approach these requirements with discipline.

Here are common CMMC Level 2 compliance challenges and practical strategies to address them:

  • Misdrawn CUI boundaries: If you do not clearly map where Controlled Unclassified Information comes in, moves, and is stored, you risk leaving important systems unprotected. To prevent this, start with a detailed data flow analysis before choosing security tools. Make sure you know every server, device, and user that handles sensitive defense information.
  • Scope creep: If you cannot properly separate sensitive data, you might end up trying to secure your whole network, which is costly and unnecessary. Avoid this by setting up a dedicated CUI enclave that keeps defense data separate from your regular business systems. This approach helps lower your assessment boundary and reduces software costs.
  • POA&M items that cannot realistically close: Some teams use the Plan of Action and Milestones to keep putting off tough problems. To avoid this, focus on fixing the most important issues right away. Only list minor gaps that have funding, assigned staff, and clear timelines so you can meet the 180-day deadline.
  • An inflated SPRS self-score: Reporting a Supplier Performance Risk System score that is not accurate can lead to serious legal trouble, especially if it is done knowingly or carelessly. To avoid this, carefully follow NIST assessment steps and use exact numbers. Make sure your score matches what is actually happening, not what you hope to achieve in the future.
  • Thin or missing evidence: If you do not have proof that your controls are followed every day, assessors will mark them as NOT MET, even if you are doing the right thing. Fix this by using continuous monitoring software that automatically records settings, access logs, and alerts. This way, your System Security Plan will use up-to-date, reliable data instead of old spreadsheets.

CMMC Level 2 requires implementing the 110 NIST SP 800-171 controls, proving each with concrete evidence, and maintaining continuous operational readiness. Managing this complex lifecycle manually through spreadsheets quickly consumes hundreds of internal engineering hours and creates severe vulnerabilities during federal or prime contractor audits.

Spieler explains that shifting from manual tracking to a centralized platform changes the entire compliance dynamic. "When you centralize those (data objects) into a single source of truth, the scope almost inverts and becomes deterministic instead of full of guesswork," Spieler says. "Technical controls become derived properties you evaluate continuously, and evidence becomes a byproduct of normal operations. It shrinks your daily job from re-proving the entire environment to triaging the handful of assets or configs that drifted."

Strike Graph’s AI-native compliance management platform consolidates this entire workflow into a single operational hub well-suited for midsize organizations. Instead of organizing files manually, teams execute guided self-assessments directly within the system, tracking identified deficiencies through integrated Plan of Action and Milestones ticketing. The platform connects directly with existing enterprise systems to automate ongoing evidence collection efficiently.

Beyond mere tracking, Strike Graph dynamically generates your essential System Security Plan while its Verify AI technology constantly validates evidence against active NIST requirements. This automated validation helps reduce compliance drift and supports ongoing audit readiness.

Visit the Strike Graph CMMC compliance platform to streamline your assessment process, eliminate redundant manual work, and protect your defense supply chain revenue.

AI-and-automation-tag-banner
ebook-image
AI-and-automation-tag-banner

Keep up to date with Strike Graph.

The security landscape is ever changing. Sign up for our newsletter to make sure you stay abreast of the latest regulations and requirements.