CMMC Level 2 Self-Assessment: The Practical Path for a Small Defense Contractor

The direct answer: if you are a small defense contractor today, the requirement that is actually enforceable is a self-assessment against the 110 requirements of NIST SP 800-171 Revision 2, with a score posted in SPRS and an annual affirmation from a senior official. Phase 1 of the CMMC rollout went live on July 13, 2026. Phases 2 through 4, including the expansion of third-party C3PAO assessment as a condition of award, are on hold. The 110 requirements did not change when the phases were suspended.
That distinction matters more than it sounds. A great deal of published commentary reads the suspension as "CMMC is paused." It is not. The 48 CFR acquisition rule took effect on November 10, 2025, and CMMC obligations flow through contracts now. What is paused is the escalation to third-party assessment, not the obligation itself.
Scope before controls
The single highest-leverage decision is not a control. It is the boundary. Every system that stores, processes, or transmits Controlled Unclassified Information inherits all 110 requirements. Every system that does not, does not.
Small contractors routinely treat the entire company network as in scope by default, then discover that CMMC Level 2 implementation across a general-purpose corporate environment is a far larger project than the contract value justifies. The alternative is to define a deliberate enclave: a bounded environment where CUI lives, with controlled entry and exit, and to keep the rest of the business outside it.
This is a business architecture decision as much as a security one, and it is the point at which outside help pays for itself most clearly. It is also reversible only at significant cost, which is why it belongs first rather than after a year of control work.
Where the 110 usually stall
Across the 14 families, a predictable handful of requirements consume disproportionate effort for organizations under roughly 50 people:
- Multifactor authentication for local and network access to privileged accounts, applied consistently rather than to the obvious systems only.
- Audit and accountability. Generating logs is straightforward. Retaining them, protecting them from modification, and demonstrating that someone reviews them is where small teams fall down.
- Configuration management. Establishing baseline configurations and then showing that deviations are tracked, which presumes an accurate asset inventory that many organizations do not have.
- FIPS-validated cryptography for CUI at rest and in transit. Encryption being present is not the requirement. Validated modules are.
- Incident response. A written plan is necessary and not sufficient. The requirement contemplates a capability that has been exercised.
- Security awareness training tied to role, with records that survive scrutiny.
None of these are conceptually hard. What makes them hard at 15 people is that no one owns them full time, and the evidence trail is what an assessor examines. For a fuller treatment of why documented policy and operating evidence are different things, see Security Control Evidence: Policy vs Implementation.
Self-assessment does not mean unassisted
A self-assessment is an attestation your company makes about its own environment. The score goes into SPRS under your name, and the annual affirmation is signed by a named senior official at your company. That person carries the attestation, so the underlying work needs to hold up.
The failure mode we see most often is a self-assessment scored optimistically against an SSP that describes an intended environment rather than the operating one. That gap is invisible until it is not, and it is precisely what a later third-party assessment surfaces.
Watch November 10, 2026
Phase 2 was scheduled to begin on November 10, 2026 before it was placed on hold. If it resumes on or near that date, contractors whose awards depend on Level 2 will need a C3PAO assessment rather than a self-assessment, and C3PAO capacity is finite. The organizations that fare well in that transition will be the ones whose self-assessment was honest, because the delta between a defensible self-assessment and a third-party assessment is mostly evidence organization rather than new control work.
Related reading: NIST 800-171 vs CMMC: Key Differences Explained, CMMC Level 2 Requirements for Small Business, and CMMC Paused, HIPAA Delayed: The Compliance Floor Is Moving.
How Z Cyber approaches this
Z Cyber works as a cybersecurity operating partner rather than a report vendor. For CMMC engagements that means a named Executive Security Advisor leads the scoping decision, the program state lives in Glance so the SSP reflects the environment as it actually is, and remediation is delivered rather than handed over as a list. We recommend and we implement. The contractor accepts the risk, signs the affirmation, and owns the decision. See Defense and Government and Compliance Advisory.
Frequently Asked Questions
Can a small business self-assess for CMMC Level 2, or does it need a C3PAO?
It depends on what the contract says, and right now most awards are landing on self-assessment. Phase 1 of the CMMC rollout is live as of July 13, 2026, and during it program managers may designate Level 1 (Self) or Level 2 (Self). Phase 2, which would expand the Level 2 requirement to third-party assessment by a C3PAO as a condition of award, was scheduled for November 10, 2026 but is currently on hold along with Phases 3 and 4. The controlling answer is always the solicitation. Read the DFARS clauses in the specific contract rather than assuming a level, because a prime can flow down a stricter requirement than the government imposed on it.
How many controls are in CMMC Level 2?
110. CMMC Level 2 maps to the 110 security requirements in NIST SP 800-171 Revision 2, organized across 14 families from Access Control through System and Information Integrity. That count did not change when Phases 2 through 4 were suspended in July 2026. Level 1 is a much smaller set, the 15 basic safeguarding requirements drawn from FAR 52.204-21, and it applies to Federal Contract Information rather than Controlled Unclassified Information.
What is the practical order of work for a 15-person defense contractor?
Scope first, then architecture, then controls, then evidence. Identify precisely where CUI lives and moves, then shrink that boundary as far as the business allows, because every system inside it inherits all 110 requirements. Many small contractors cut their assessment surface substantially by moving CUI into a single enclave rather than treating the whole company network as in scope. Only after the boundary is settled does control implementation become a bounded project instead of an open-ended one.
Does a POA&M satisfy CMMC Level 2?
Only partially, and only temporarily. A Plan of Action and Milestones can cover a limited subset of requirements for a limited window, and certain requirements cannot be deferred to a POA&M at all. Treating a POA&M as a substitute for implementation is one of the more common ways a contractor arrives at an assessment believing it is ready and is not. Confirm the current POA&M rules against the contract and the applicable DFARS clause before relying on one.
What has to be submitted, and how often?
A self-assessment score has to be posted in the Supplier Performance Risk System (SPRS), supported by a current System Security Plan, and a senior company official has to affirm continued compliance annually. The affirmation is a named individual attesting on the company's behalf, so the assessment work needs to be defensible to whoever signs it. Scores are not static: they change as the environment changes, which is why the SSP has to reflect the environment as it actually is rather than as it was at the time of the last review.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.

