← Custodia
Custodia Research · 2026 Edition

The State of CMMC for Small Defense Contractors

How ready the small business defense base really is for the Cybersecurity Maturity Model Certification, in plain business English.

By David Fuentes III · Custodia · Updated July 15, 2026
Readiness Index
33/100
Early and exposed

The Custodia Small Business CMMC Readiness Index

The small business defense base scores 33 out of 100 on CMMC readiness in this inaugural edition. The mandate is sized, the Phase 2 clock is suspended, and the floor is low. Phase 1 self assessment has been in force since November 2025, and most firms are not where the rule already requires them to be.

61
Self-assessment score health
12
Certification readiness
26
Assessor capacity
How this number is calculated

The index is an equal weight mean of three public indicators, computed by Custodia from the cited sources. This inaugural edition uses defense base wide proxies. Future editions add Custodia platform telemetry specific to small business Level 1 readiness. Methodology is published so the number is reproducible.

  • Self-assessment score health (61/100): The average self reported NIST 800-171 score sits near negative 12 on a scale that runs from negative 203 to positive 110. Normalized to a 0 to 100 scale, that is 61. Source: U.S. Department of Defense.
  • Certification readiness (12/100): Roughly 1,000 organizations have reached Level 2 certification against an estimated 8,350 that will need a third party assessment. That is about 12 percent. Source: The Cyber AB.
  • Assessor capacity (26/100): Current certification run rate is near 2,100 per year against 8,350 organizations that need an assessment, roughly 26 percent of annual demand. Source: The Cyber AB.
Section 01

The universe

How many of us does this actually hit?

337,000+
Contractors and subcontractors affected
230,000
Small entities in scope
8,350
Firms pushed to Level 2 third party assessment

The Department of Defense sized this itself. Its Regulatory Impact Analysis for the CMMC program estimates that more than 337,000 contractors and subcontractors are affected, and roughly 230,000 of them are small entities. About two thirds of the entire affected population is small business.

Most of that population sits at Level 1, the basic safeguarding tier for Federal Contract Information. Only an estimated 8,350 medium and large entities are pushed to Level 2, where an outside assessor is required. In other words, the rule is overwhelmingly a small business event, and it is overwhelmingly a Level 1 event.

For context, the defense industrial base is roughly 59,678 companies and 1.1 million workers, and small businesses won more than 183 billion dollars in federal prime contracts in FY2024. The base that this rule touches is not a niche. It is the backbone of how the government buys.

The takeaway

CMMC is not a big business problem with a small business footnote. It is a small business problem at Level 1, by the government's own numbers.

Section 02

The gap

How far behind is everyone, really?

−12
Average self reported NIST 800-171 score
110
Score required for full compliance

The single most revealing number in federal cybersecurity is the average self reported score. On a scale that tops out at 110, the average sits near negative 12. The bar is a perfect score. The base is starting deep in the hole.

Worse, the self reported numbers tend to be optimistic. When the Defense Industrial Base Cybersecurity Assessment Center validated scores that contractors reported themselves, it found many self reported perfect scores were not accurate. That gap between what firms claim and what they can prove is exactly what the move to third party assessment is meant to close.

Level 1 does not produce a 0 to 110 score. It is a binary check of 15 requirements, pass or fail. But the same readiness gap shows up: most small firms have never run a real self assessment, and they discover the gaps only when a prime asks for proof.

The takeaway

The floor is low and the self reporting is generous. The affirmation you sign is what turns that from a paperwork problem into a contract problem.

Section 03

Who is exposed

Is my industry actually in the blast radius?

$75.7M
FY2025 federal obligations, machine shops alone
Default
FCI is present in almost every federal contract

Exposure is not about whether you feel like a cybersecurity company. It is about whether you touch Federal Contract Information, and almost every federal contract creates it. A statement of work, a delivery schedule, a non public email from a contracting officer: that is all FCI, and FCI triggers Level 1.

The dollars make the reach concrete. Custodia analysis of USAspending shows a single trade, machine shops, drawing more than 75 million dollars in federal obligations in FY2025, spread across thousands of awards to mostly small firms. Repeat that across metal fabrication, construction and facilities, IT services, logistics, and professional services, and the in scope population is most of the small business base.

The firms most surprised to be in scope are the ones who do not think of themselves as defense companies at all: the welder, the parts supplier, the facilities contractor, the staffing firm. The rule does not care about your self image. It cares about your data.

The takeaway

If you hold a federal contract, assume you hold FCI, and assume Level 1 applies until you can prove it does not.

Section 04

The readiness curve

Is anyone actually getting certified?

~1,000
Organizations Level 2 certified, early 2026
~1%
Share of the defense base that is certified
103
Authorized third party assessor organizations

After years of warning, actual readiness is tiny. By early 2026 roughly 1,000 organizations had reached Level 2 certification, about 1 percent of the defense base. The assessor side is thin too: around 103 authorized assessor organizations and several hundred certified assessors to serve thousands of companies.

That math creates a queue. Certificates are being issued at a rate in the low hundreds per month against a Level 2 population in the thousands. The Department of Defense named that shortfall itself when it suspended Phase 2 in July 2026, citing severe shortages in third party assessment capacity as one reason the program needed a review.

Level 1 firms self assess, so they are not in the assessor queue. Their risk is different and quieter: they can wait until a prime or a solicitation asks for proof, and then have days, not months, to produce it.

The takeaway

Readiness is a single digit percentage and the assessor pipeline is narrow. Being early is a competitive advantage, not just a compliance checkbox.

Section 05

The cost of compliance

What is this going to cost me, in time and money?

~$6,000
DoD estimate, Level 1 self-assessment for a small entity
15
Safeguarding requirements at Level 1

The good news for the small business base is that Level 1 is the affordable tier. The Department of Defense estimates a Level 1 self assessment near 6,000 dollars for a small entity and near 4,000 dollars for a larger one, and most of that is internal time, not vendor fees.

Level 1 is 15 requirements, self assessed, with no outside assessor required. The expensive path is letting a vendor reframe a 15 requirement self assessment as a full Level 2 rebuild when your contracts only involve FCI. That mismatch, paying for Level 2 infrastructure to solve a Level 1 problem, is the most common way small firms overspend.

Ongoing maintenance, the annual affirmation and keeping evidence current, is a modest recurring cost when the work is done once and kept up, and a painful one when it is rebuilt from scratch every year.

The takeaway

Level 1 is cheap if you scope it correctly and do it once. The cost risk is buying the wrong level, not the right one.

Section 06

The risk

What happens if I get it wrong?

$9M
Aerojet Rocketdyne cyber settlement, 2022
$1.25M
Penn State cyber settlement, 2024

The affirmation a senior official signs is not a formality. Under the Department of Justice Civil Cyber-Fraud Initiative, knowingly misrepresenting your cybersecurity posture to win or keep federal work is treated as fraud. Aerojet Rocketdyne settled for 9 million dollars in 2022 and Penn State for 1.25 million dollars in 2024, both over false cybersecurity representations.

Once the acquisition rule made the CMMC affirmation a condition of award in November 2025, that affirmation became material to payment, which is the exact element these cases turn on. The exposure is real, but it is also specific: it attaches to knowingly signing something you cannot back up, not to honest gaps you are working to close.

The practical guardrail is boring and effective. Run a real self assessment, write down the result for each requirement, keep the evidence, and only sign once it is true.

The takeaway

The risk is not honest mistakes. It is signing an affirmation you cannot defend. Documentation is the defense.

Section 07

The small business squeeze

Are small firms getting pushed out?

$183B
Federal prime contracts to small business, FY2024
51 to 5
Aerospace primes after decades of consolidation

The defense base has been consolidating for thirty years. The Congressional Research Service documents the aerospace and defense prime field shrinking from 51 companies to 5, and the Department of Defense has flagged a decline in small business prime contractors as a national security concern.

Compliance burden is a consolidation force. Every requirement that is easy for a large firm with a security team and hard for a three person shop pushes work up the chain. CMMC done badly accelerates that squeeze. CMMC done simply, at the right level, is how a small firm stays in the game.

Small businesses still won more than 183 billion dollars in federal prime contracts in FY2024. The opportunity is enormous. The question is whether the small firms that can do the work can also clear the compliance bar to bid for it.

The takeaway

Compliance is becoming a gate on who gets to compete. Clearing it cheaply is a small business survival skill.

Section 08

The forecast

Where is this going next year?

Nov 2025
Phase 1 self-assessment, still in force
Suspended
Phase 2 third party assessment, paused July 13, 2026
~Sep 2026
CMMC Reform Task Force findings due

The rollout changed direction in July 2026. On July 13 the Department of Defense suspended Phase 2 and launched a 60 day top to bottom review of the CMMC program, in a memo signed by DoD Chief Information Officer Kirsten Davies. A CMMC Reform Task Force will deliver findings and recommendations within 60 days, so around September 11, 2026. The memo cites prohibitive compliance costs, severe shortages in third party assessment capacity, and complex regulatory timelines that were forcing new entrants and small businesses to opt out of defense contracts and freezing critical suppliers out of the market. Responses to the associated request for information are due by 12pm Eastern on Friday, August 14, 2026.

Phase 2 would have required third party assessment across contracts involving sensitive but unclassified information starting November 10, 2026. That date is suspended and is no longer an operative deadline. Almost nothing else moved. Phase 1 remains in force, so applicable contracts have required a CMMC self assessment since November 2025. DFARS 252.204-7012 is unaffected. NIST SP 800-171 Rev 2 baseline compliance, self assessments across the defense base, and select government led assessments are still enforced. False Claims Act exposure for a knowingly false affirmation is unchanged. The 32 CFR Part 170 program rule from December 2024 and the 48 CFR acquisition rule from November 2025 are both still on the books.

So Phase 2 is paused, not cancelled. What the suspension removed is the deadline pressure, not the requirement. For a small firm the job in front of you is the one that has been live since November 2025: run a real self assessment, keep the evidence, and sign an affirmation you can defend. Primes still ask, solicitations still carry the clause, and for firms that touch CUI the obligations underneath Level 2, DFARS 7012 and NIST SP 800-171, still apply, so readiness work keeps its value.

The takeaway

Phase 2 is paused, not cancelled. The suspension took away the deadline, not the requirement, and Phase 1 self assessment is live today.

Section 09

What to do about it

If you hold or want federal work, the move is the same: confirm whether Federal Contract Information touches your business, then meet the 15 Level 1 requirements and post your annual affirmation. Do it during the quiet phase, not the week a contract demands it.

Start with the free CMMC qualifier to see where you stand, read the plain English Level 1 guide, and check the real cost of Level 1 and the False Claims Act risk so you scope it correctly the first time.

Reviewed July 5, 2026

CMMC news and key dates

The dates that decide when CMMC starts costing you contracts. We keep this timeline current as the rules move.

Breaking, July 13, 2026
CMMC Phase 2 is suspended, pending a 60 day review

DoD suspended Phase 2 and opened a top to bottom review of the CMMC program, per a memo signed by DoD Chief Information Officer Kirsten Davies. A CMMC Reform Task Force will report findings and recommendations within 60 days. Responses to the associated RFI are due August 14, 2026. The memo cites prohibitive compliance costs, severe shortages in C3PAO assessment capacity, and complex regulatory timelines that were pushing small businesses and new entrants out of DoD contracts.

November 10, 2026 is no longer an operative deadline. Third party C3PAO certification is not phasing into applicable solicitations on that date as previously scheduled.

What did not change
Phase 2 is paused, not cancelled

Phase 1 self assessment requirements on applicable contracts remain in force. DFARS 252.204-7012 is unaffected. NIST SP 800-171 Rev 2 baseline compliance, DIB self assessments, and select government led assessments continue to be enforced, and knowingly false affirmations remain False Claims Act exposure. If your contracts carry CMMC Level 1 today, nothing about your obligation moved. If you handle CUI, the underlying Level 2 obligations still apply. What the suspension removed is the deadline pressure, not the requirement.

  1. Sep 11, 2026
    CMMC Reform Task Force report due

    The 60 day top to bottom review of the CMMC program is due to report findings and recommendations. This is the date that decides what CMMC looks like next. We will update this timeline when it lands.

  2. Aug 14, 2026
    RFI responses due

    Responses to the CMMC reform Request for Information are due by 12pm ET. This is the window for contractors to tell DoD what the program should become.

  3. Jul 13, 2026
    Phase 2 suspended, 60 day review opened

    DoD suspended CMMC Phase 2 and launched a top to bottom program review, per a memo signed by DoD CIO Kirsten Davies, citing prohibitive compliance costs, C3PAO capacity shortages, and complex timelines forcing small businesses out of DoD contracts. The November 10, 2026 Phase 2 date is suspended. Phase 1 self assessments and DFARS 252.204-7012 remain in force.

  4. Nov 10, 2025
    DFARS acquisition rule effective (Phase 1)

    The 48 CFR rule that puts CMMC into contracts took effect, beginning the phased rollout with Level 1 and Level 2 self assessment requirements.

  5. Dec 16, 2024
    CMMC Program Rule effective

    32 CFR Part 170, the rule that establishes the CMMC program, its levels, and its assessment structure, became effective.

  6. Oct 15, 2024
    Final CMMC program rule published

    The final rule published in the Federal Register (89 FR 83092), locking in the 3-level model and the scoring for Level 2.

Want the plain-English version of what changed and when it hits you? Read what CMMC is, the 32 CFR Part 170 rule, and the 48 CFR acquisition rule.

See where your business stands in 4 minutes.

The free Custodia qualifier checks your exposure against all 15 Level 1 requirements. No card, no jargon.

Methodology and sources

This report compiles primary U.S. government data, defense ecosystem figures, and Custodia analysis of public contract data. Every figure above links to its source. The readiness index is computed by Custodia from the cited indicators, with the method shown in the index panel. Figures are current as of the publication date and will be updated in the next edition. This is the inaugural 2026 edition; the report is published annually.

  1. U.S. Department of Defense. Regulatory Impact Analysis, CMMC Program (32 CFR Part 170). https://downloads.regulations.gov/DOD-2023-OS-0063-0003/content.pdf
  2. Office of the Federal Register. 32 CFR Part 170, CMMC Program. https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
  3. Federal Register. CMMC Program final rule. https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program
  4. Federal Register. DFARS CMMC acquisition rule (48 CFR), effective November 10, 2025. https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
  5. U.S. Department of Defense. CMMC Phase 2 suspension and program review memorandum, Office of the DoD Chief Information Officer, July 13, 2026. https://dodcio.defense.gov/CMMC/
  6. U.S. Department of Defense. Supplier Performance Risk System, NIST SP 800-171 assessments. https://www.sprs.csd.disa.mil/nistsp.htm
  7. The Cyber AB. CMMC ecosystem marketplace and town hall figures. https://cyberab.org/marketplace
  8. Congressional Research Service. The U.S. Defense Industrial Base, Background and Issues for Congress (R47751). https://www.congress.gov/crs-product/R47751
  9. U.S. Small Business Administration. Small Business Procurement Scorecard, FY2024. https://www.sba.gov/federal-contracting/contracting-data/small-business-procurement-scorecard
  10. National Defense Industrial Association. Vital Signs, the health of the defense industrial base. https://www.ndia.org/policy/publications/vital-signs
  11. U.S. Department of Justice. Civil Cyber-Fraud Initiative. https://www.justice.gov/civil/cyber-fraud-initiative
  12. Custodia analysis of USAspending.gov. Federal contract obligations by industry, FY2025. https://www.usaspending.gov/

Cite this report: Custodia. The State of CMMC for Small Defense Contractors (2026). https://bidfedcmmc.com/state-of-cmmc

Free · Every Monday

Get the federal bids a small business can win, in your inbox.

The Monday Bid Digest: brand-new SAM.gov solicitations matched to your NAICS, pre-filtered to Level 1 fit, with the CMMC gate called out on every one. Two minutes, no spam.

Get the Monday Bid Digest
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements, no signup, no card. If you like what you see, the 30 day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

30 day free trial · No credit card required · $499/mo with a Custodia Officer included ($4,990/yr on annual, two months free)