Back to Home

    CMMC Level 1 to Level 2 Roadmap for Small Aerospace Suppliers (2026 Guide)

    A practical roadmap for small CNC shops navigating the jump from CMMC Level 1 to Level 2. Covers the 17 L1 practices, the 110 L2 controls, real cost estimates, a 12–18 month timeline, and an honest framework for deciding whether Level 2 is worth the investment.

    Last reviewed: May 12, 2026

    TL;DR — The Level 1 vs Level 2 Decision

    • Level 1: 17 practices, annual self-assessment via SPRS, sufficient for FCI-only contracts.
    • Level 2: 110 controls aligned with NIST SP 800-171, third-party (C3PAO) assessment every 3 years, required for CUI handling.
    • L2 project cost, 5–15 employee shop: $32,000–$92,000 first cycle, $12,000–$30,000 per year ongoing.
    • Timeline: 12–18 months for L1 to L2 with mature groundwork; 6–9 months if ISO 27001 or NIST 800-171 posture already exists.
    • Decision rule: Pursue L2 only when the pipeline of CUI-required contracts justifies $30k+/year overhead. Otherwise stay at L1 with a documented L2 readiness plan.

    What CMMC Actually Is (and Why It Replaced DFARS Self-Attestation)

    The Cybersecurity Maturity Model Certification (CMMC) program is the DoD's framework for verifying that defense contractors and their subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 has three levels: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). For essentially all small CNC shops, only Levels 1 and 2 are relevant.

    Before CMMC, DoD contractors self-attested to compliance with DFARS 252.204-7012 and NIST SP 800-171. In practice, that self-attestation regime was under-enforced and produced inconsistent security postures across the defense industrial base. CMMC replaces the honor system with verifiable annual (Level 1) and triennial third-party (Level 2) assessments recorded in the Supplier Performance Risk System (SPRS).

    Enforcement follows a phased rollout beginning in 2025, with full contract inclusion by 2028. Shops with active DoD pursuits should treat CMMC as an immediate strategic priority rather than a future consideration.

    Level 1 — The 17 Practices Across 6 Domains

    Domain Practices Typical Implementation
    Access Control 4 Role-based accounts, no shared logins, external system policy
    Identification & Authentication 2 Unique user IDs, strong password policy
    Media Protection 1 Documented media sanitization / destruction procedure
    Physical Protection 4 Locked shop, visitor log, escorted access, device inventory
    System & Communications Protection 2 Firewall, guest Wi-Fi separation
    System & Information Integrity 4 Endpoint AV, patch policy, automatic updates, security alert monitoring
    Total 17

    Level 1 verification is a self-attestation submitted annually into SPRS by a senior company official. For most small shops, achieving Level 1 is a 2–6 week project with $2,000–$8,000 of tooling and consulting.

    Level 2 — The 110 Controls (Grouped by Domain)

    Level 2 mirrors NIST SP 800-171 Revision 2 and covers 110 controls across 14 domains. The heaviest lifts for a small shop are almost always in these six areas:

    • Access Control (22 controls): role-based access, least privilege, session lock, wireless restrictions, remote access controls.
    • Audit & Accountability (9 controls): centralized logging (SIEM), audit review, retention, protected audit records.
    • Configuration Management (9 controls): baseline configurations, hardening, change control, approved software.
    • Incident Response (3 controls): documented IR plan, testing, external reporting (72-hour incident reporting to DoD).
    • System & Communications Protection (16 controls): boundary defense, encrypted transmission, DNS filtering, CUI-specific enclave separation.
    • System & Information Integrity (7 controls): vulnerability management, endpoint security, spam and email filtering, security alert monitoring.

    Cost Breakdown — Level 1 vs Level 2

    Line Item Level 1 Level 2
    Third-party assessment $0 (self) $15,000–$40,000
    Consultant / vCISO $1,000–$3,000 $10,000–$30,000
    Technology upgrades (Y1) $1,000–$3,000 $5,000–$15,000
    Documentation labor $500–$2,000 $2,000–$7,000
    First-cycle total $2,500–$8,000 $32,000–$92,000
    Ongoing annual cost $1,000–$3,000 $12,000–$30,000

    The 12–18 Month Level 2 Roadmap

    1. Months 1–3: Gap assessment against all 110 controls, CUI data-flow mapping, enclave design decision (GCC High vs on-prem).
    2. Months 4–6: GCC High tenant provisioning, migration of CUI systems, network re-architecture (VLAN segmentation, boundary firewall upgrade).
    3. Months 7–9: Policy authoring across all 14 domains, SIEM deployment, endpoint security rollout, IR plan and tabletop exercise.
    4. Months 10–12: Internal assessment against all 110 controls, remediation of gaps, evidence collection.
    5. Months 13–15: C3PAO third-party assessment window (typically 3–8 weeks on-site plus documentation review).
    6. Months 16–18: Remediation of C3PAO findings, final certification, SPRS submission.

    The Honest Decision Framework

    Every small shop asks the same question: should we pursue Level 2, or stay at Level 1? The honest answer is driven entirely by pipeline. Ask three questions:

    1. Do current or imminent contracts flow CUI down? Read every prime contract carefully. If DFARS 252.204-7012 is in the flow-down and the SOW references CUI, Level 2 is not optional.
    2. Is there a named DoD pursuit with a projected award date in the next 18 months? If yes, start L2 work now — the timeline requires it. If no, L2 is speculative overhead.
    3. Can the shop absorb $30,000/year in ongoing security overhead? If the additional gross margin from CUI-eligible contracts doesn't cover that overhead within 24 months, L2 is a bad investment regardless of pipeline.

    For most small aerospace shops with a commercial-heavy pipeline, the right answer is: certify to Level 1 now, maintain a documented Level 2 readiness plan, and re-evaluate every 6 months as the pipeline evolves. That posture keeps the shop credible with DoD primes while avoiding $30k/year in unrecouped overhead.

    Frequently Asked Questions

    What is the difference between CMMC Level 1 and Level 2?

    CMMC Level 1 covers 17 basic cybersecurity practices for handling Federal Contract Information (FCI), verified by annual self-assessment. Level 2 covers 110 security controls aligned with NIST SP 800-171 for handling Controlled Unclassified Information (CUI), verified by a third-party assessment (C3PAO) every 3 years. In practice: Level 1 is achievable in a few weeks with mostly configuration and policy work. Level 2 is a 12 to 18 month undertaking that typically requires network re-architecture, dedicated CUI enclaves, and $32,000–$92,000 in project cost.

    How much does CMMC Level 2 certification cost for a small shop?

    For a 5–15 employee shop, CMMC Level 2 typically costs $32,000 to $92,000 all-in for the first assessment cycle. That breaks down as: C3PAO third-party assessment ($15,000–$40,000), consultant or vCISO support ($10,000–$30,000), technology upgrades — GCC High tenant, endpoint security, SIEM, etc. — ($5,000–$15,000 first year), and internal labor for documentation and remediation ($2,000–$7,000 loaded cost). Ongoing costs run $12,000–$30,000 per year after certification, driven mostly by GCC High licensing and managed security services.

    Do I need CMMC Level 2 if I don't handle CUI?

    No. CMMC Level 1 is sufficient for contracts and subcontracts that only involve Federal Contract Information (FCI) — which covers most commercial off-the-shelf work and non-sensitive machining. Level 2 is required only when the contract flows down CUI, which is typical for direct DoD work, ITAR technical data packages, and some prime contractor subcontracts. Read every prime contract flow-down carefully — some contain a DFARS 252.204-7012 clause that triggers CUI handling and, therefore, Level 2 requirements.

    What are the 17 CMMC Level 1 practices?

    CMMC Level 1 has 17 practices across 6 domains: Access Control (limit system access, transaction limits, external system controls), Identification and Authentication (identify users, authenticate identities), Media Protection (sanitize media before disposal), Physical Protection (limit physical access, escort visitors, maintain logs, control devices), System and Communications Protection (monitor communications, implement subnetworks), and System and Information Integrity (identify and correct flaws, protect from malicious code, update protection, monitor security alerts). Every practice must be implemented and self-attested annually via SPRS.

    Is Microsoft 365 GCC High required for CMMC Level 2?

    Not strictly required, but it's the most practical path for small shops handling CUI. GCC High is DFARS 7012-compliant, ITAR-compliant, and FedRAMP High Moderate authorized. Alternatives — Microsoft 365 GCC (not sufficient for ITAR), on-prem infrastructure with FedRAMP-authorized cloud enclaves, or Google Workspace Assured Controls — are all more expensive, more complex, or less mature. For a 5–15 employee shop with ITAR-registered work, GCC High is nearly always the correct answer. Expect $40–$65 per user per month.

    How long does CMMC Level 2 certification take?

    A realistic timeline for a small shop starting from Level 1 is 12 to 18 months. Roughly: months 1–3 gap assessment and CUI enclave design, months 4–6 GCC High migration and network re-architecture, months 7–9 policy authoring and control implementation across all 110 controls, months 10–12 internal assessment and remediation, months 13–15 C3PAO assessment window, and months 16–18 remediation of assessment findings and final certification. Shops that already run a mature ISO 27001 or NIST 800-171 posture can compress this to 6–9 months.

    Should a small CNC shop pursue CMMC Level 2 or focus on Level 1?

    The honest answer depends on pipeline. If the shop has active pursuits with DoD primes that require CUI flow-down, or if the shop already holds ITAR-registered contracts with sensitive technical data, Level 2 is a strategic requirement. If current customers are commercial aerospace primes and DoD subcontracts are speculative, Level 1 (plus a documented Level 2 readiness plan) is often the better use of $50,000 in the first year. Level 2 without a matching revenue pipeline is a $30,000–$40,000 per year overhead line item with no ROI.

    Navigating CMMC as a small shop?

    Olympus Machining is an ITAR-registered, CMMC Level 1 CNC shop in Hanover, PA. We don't offer CMMC consulting — but we're happy to compare notes with other small shops working through the same decisions.

    Get in Touch

    Related Reading