The SBIR-to-CMMC question lands the same way every time. A founder gets the award letter, the contracting officer introduces the cybersecurity flow-downs, and the founder, who is two months out of a PhD lab or three years deep into a startup, opens a Google search and falls into a Slack channel arguing about “NIST 800-171” and “Level 2” and panics that they need a $150K third- party assessment to begin Phase I.
You probably don't. Here's the actual timeline.
TL;DR, your CMMC timeline
- Day 1 of Phase I:Read your award for the clauses. FAR 52.204-21 only → Level 1. DFARS 252.204-7012 present → Level 2 from day one.
- Month 1 to 2 of Phase I (Level 1 path): Knock out the 15 requirements and post the annual affirmation in SPRS. Most SBIR teams finish in 1 to 3 weeks of focused founder time.
- Month 2 to 3 of Phase I: If your topic anticipates a Phase II with CUI, start Level 2 readiness (implementation of NIST 800-171, SSP draft, evidence collection).
- Phase II award:Be ready to either affirm Level 2 readiness or be on a credible POA&M.
- Phase III: Sustain whichever level applies. Re-affirm annually for Level 1. For Level 2, keep your NIST 800-171 posture current; the triennial C3PAO reassessment is part of the suspended Phase 2.
Phase I: which level applies?
Open your award letter and search for two things:
- The clause “FAR 52.204-21” (Basic Safeguarding of Covered Contractor Information Systems), almost certainly present.
- The clause “DFARS 252.204-7012” (Safeguarding Covered Defense Information and Cyber Incident Reporting), present only if the agency anticipates CUI.
What you find determines your tier:
| Found in your award | Your CMMC tier | What you owe |
|---|---|---|
| Only FAR 52.204-21 | Level 1 | 15 safeguarding requirements + annual SPRS affirmation |
| DFARS 252.204-7012 (with or without 52.204-21) | Level 2 | 110 NIST 800-171 controls + a Level 2 self assessment under Phase 1 (the C3PAO stage is suspended as of July 2026) |
| Neither (rare for DoD) | Likely none | Confirm with your contracting officer in writing |
Phase II: when Level 2 enters the picture
Phase II is where the SBIR program shifts from feasibility study to prototype development. For many DoD topics, that's also where the agency starts handing you the kind of technical data that meets the CUI definition, export- controlled drawings, threat intelligence, sensor-system specifications, weapon-adjacent R&D, designated technical data packages.
Two things drive your obligation at Phase II:
- What clauses appear in the Phase II contract. DFARS 252.204-7012 + DFARS 252.204-7021 (the CMMC clause) = Level 2. Under Phase 1, which is in force today, that means a Level 2 self assessment. The Phase 2 stage that would have added a third party C3PAO assessment was suspended on July 13, 2026.
- The 48 CFR rollout status. The final DFARS rule (90 Fed. Reg. 41,765 from September 10, 2025) took effect November 10, 2025 and began phasing the CMMC clause into new solicitations. On July 13, 2026, DoD suspended Phase 2 and stood up a CMMC Reform Task Force to report findings within 60 days, so the rest of the phase-in schedule is under review. The rule itself is still on the books and Phase II awards can still carry the clause. Read the contract, not the calendar.
Phase III: commercialization and sustainment
Phase III is open-ended, it can run for years as the SBIR-developed technology gets commercialized through full contracts. Whatever level you carried into Phase III is the level you sustain. The Level 1 annual affirmation doesn't pause because the work is going well. For Level 2, the triennial C3PAO reassessment is part of the suspended Phase 2, but the self assessment, DFARS 252.204-7012, and your NIST SP 800-171 posture still bind you for as long as the CUI keeps flowing.
The Phase I → Phase II readiness milestones
If your topic anticipates a Phase II with CUI, the practical sequence is:
| When | Milestone | Why |
|---|---|---|
| Month 1 | Complete CMMC Level 1 self-assessment & affirmation | Required for Phase I performance under FAR 52.204-21. |
| Month 2 to 3 | Boundary diagram + SSP shell for Level 2 | Hardest piece to get right; easiest to start early. |
| Month 4 to 6 | Implement the NIST 800-171 control gaps | MFA, audit logging, encryption-at-rest, vulnerability scanning, incident response plan. |
| Month 6 to 9 | Internal NIST 800-171 Basic Assessment (score in SPRS) | Required by DFARS 252.204-7019 as soon as 7012 is in a contract. |
| Month 9 to 12 | Hold a defensible Level 2 self assessment and keep the evidence current | Phase 2 (C3PAO) is suspended as of July 2026, so there's no assessor to book right now. Primes and program offices still ask for your Level 2 posture, and a knowingly false affirmation is still False Claims Act exposure. |
What this actually costs an SBIR team
For a typical small SBIR team (1 to 10 people), planning ranges:
- Level 1, DIY: 1 to 3 weeks of founder time. Out-of-pocket cost: low hundreds (mostly tooling like MFA, password manager, endpoint security).
- Level 1, guided platform:Few hours of founder time. Platform fee under $1K per year. Useful when you want a defensible paper trail and don't want to be the one drafting the SSP from scratch.
- Level 2, full readiness: $50K, $250K+ in the first cycle including implementation work, plus 6 to 12 months of calendar time. With the C3PAO stage suspended as of July 2026, the assessment fee is off the table for now, but the NIST 800-171 implementation work behind that number is what DFARS 252.204-7012 still obligates.
For most SBIR teams the right move is to land Level 1 cheaply in month 1 and decide about Level 2 once the Phase II topic and clauses are visible.
Four mistakes SBIR founders make
- Assuming Phase I = Level 2.You've been scared into thinking the worst case is the only case. Read your award.
- Waiting until the Phase II award letter to start. By the time you read “DFARS 252.204-7021” in the PWS, the clause is already in your contract, and the NIST 800-171 implementation behind it takes months, not days. The Phase 2 suspension bought calendar room. It did not remove the obligation.
- Posting a fabricated SPRS score to satisfy a PM. Federal false statement under 18 U.S.C. § 1001. Read our response template instead.
- Choosing “use my personal laptop” as the scope.That puts your spouse's tax returns inside the assessment boundary. Separate work and personal environments before you scope.
What to do this week
- Open your Phase I award. Search for “52.204-21” and “7012.” Confirm your tier.
- Take the free CMMC check (5 minutes, no signup) to confirm independently.
- If you're Level 1, plan a one-week sprint with a guided platform, most SBIR teams finish in 5 working days.
- Subscribe to the Monday Bid Digest , we surface follow-on opportunities that align with common Phase I topic areas.
FAQ
Does SBIR Phase I require CMMC?
Usually Level 1 (not Level 2). Phase I awards typically include FAR 52.204-21 but not DFARS 252.204-7012, putting you at Level 1.
When does SBIR Phase II require Level 2?
When the Phase II contract flows down DFARS 252.204-7012, or when the agency starts transmitting CUI. Many DoD topics hit this at Phase II; some never do.
How long does Level 2 readiness take from a Phase I baseline?
6 to 12 months for a 3 to 10-person team. The C3PAO stage is suspended as of July 2026, so there's no assessor queue to sit in right now, but DFARS 252.204-7012 and NIST 800-171 still apply.
Can I use a platform or MSP for SBIR CMMC?
Yes, usually the right move for small teams. A guided platform handles Level 1 end-to-end; for Level 2 it carries the NIST 800-171 implementation and evidence work.
Does Phase I include CUI?
Usually not. Phase I is feasibility study. Check your award for CUI banner markings or DFARS 252.204-7012 to be sure.