CMMC Compliance Consulting Hero Banner
CMMC Compliance

CMMC Compliance Consulting for Small Defense Subcontractors

CMMC compliance means meeting the Cybersecurity Maturity Model Certification level in your DoD contract: Level 1 self-assessment for FCI or Level 2 against NIST SP 800-171 for CUI. IRM scopes, assesses, and prepares you, led by a CMMC Registered Practitioner.

  • CMMC Registered Practitioner
  • Level 1 and Level 2, US and Canada (CPCSC)
  • From $2,000 per month

What is CMMC Compliance?

CMMC compliance means a US defense contractor or subcontractor has met the Cybersecurity Maturity Model Certification level written into its contract. CMMC 2.0 has three levels: Level 1 covers 15 basic safeguarding requirements for Federal Contract Information and is met by an annual self-assessment; Level 2 covers the 110 security requirements of NIST SP 800-171 for Controlled Unclassified Information and, for most contracts, requires a third-party assessment by a C3PAO every three years; Level 3 adds requirements from NIST SP 800-172 and is assessed by the Department of Defense. The CMMC program rule took effect in December 2024 and the requirement is being phased into contracts from November 2025.

IRM's CMMC compliance service is led by a CMMC Registered Practitioner and takes a subcontractor from "our prime just asked for our SPRS score" to assessment-ready. We scope where FCI and CUI actually flow, run the gap assessment at the level your contracts demand, write the System Security Plan and Plan of Action and Milestones, close the gaps that matter, and prepare you for the self-assessment affirmation or the C3PAO visit.

Canadian suppliers to the US defense industrial base face the same requirement, and Canada's own Canadian Program for Cyber Security Certification (CPCSC) is being phased in alongside it. Because both programs map to NIST SP 800-171, we build one control set that satisfies both, and we do it from Toronto with the same Virtual CISO who then keeps the controls operating between assessments.

What the Engagement Includes

  • CUI and FCI data-flow scoping and enclave boundary decision
  • Level 1 (15 requirements) or Level 2 (110 requirements) gap assessment with a scored, prioritized plan
  • System Security Plan (SSP) and Plan of Action and Milestones (POA&M) written to assessor expectations
  • NIST SP 800-171 DoD Assessment score calculated and submitted to SPRS
  • Policies, procedures, and evidence for all 14 control families
  • Enclave design guidance for Microsoft 365 GCC High or an equivalent CUI environment
  • Mock assessment and objective evidence review before the C3PAO engagement
  • Annual affirmation support and continuous monitoring after certification

When you do not need CMMC Yet

If you have no DoD prime or subcontract in your pipeline, and none of your customers handle CUI, CMMC is not your framework. A general baseline such as CIS Controls or the Canadian CAN/DGSI 104 will give you better security for the money.

If you handle only FCI and no CUI, you need Level 1, which is a self-assessment against 15 requirements and does not need a C3PAO. Many small suppliers are quoted Level 2 programs they do not need. Scoping comes first; it determines the level, the cost, and the timeline.

Who CMMC Compliance is for, by Revenue Stage

Defense subcontractors are sized by contract revenue rather than ARR. This is how we size CMMC engagements for the suppliers we work with.

Who CMMC Compliance is for, by Revenue Stage
StageTypical ARRWhat You NeedIRM Engagement
Small supplier, FCI onlyUnder $2M revenueCMMC Level 1 self-assessment and affirmation, and a defensible answer when a prime asks for your status.Free CMMC Level 1 assessment at cmmc.irmcon.com, then a Crawling tier sprint to close the 15 requirements and file the affirmation.
Growing subcontractor, first CUI contract$2M to $10M revenueCMMC Level 2 readiness, an SSP and POA&M, and an SPRS score you can stand behind.Walking tier, 90 days to SSP, POA&M, and SPRS submission, then a remediation runway to C3PAO.
Established subcontractor, multiple CUI programs$10M to $50M revenueLevel 2 C3PAO certification, a CUI enclave, and controls that hold across sites and product lines.Walking or Running tier, mock assessment in month 3, C3PAO engagement in months 4 to 9.
Canadian supplier to US primesAny sizeCMMC for US flow-downs and CPCSC for Canadian contracts, from one control set.Same tiers, with the CAN/DGSI 104 baseline and CPCSC mapping included.

The 90-Day CMMC Plan

This is the sequence we run to get a subcontractor from first contact to a submitted SPRS score and a clear runway to assessment. Level 1 suppliers finish inside the 90 days; Level 2 suppliers leave day 90 with the remediation plan a C3PAO expects to see.

Days 1 to 30

Scope and Assess

  • Map where FCI and CUI enter, live, and leave, and decide the enclave boundary
  • Confirm the level your contracts require, Level 1 or Level 2
  • Gap assessment against all in-scope requirements, scored to the DoD assessment methodology
  • Asset inventory across people, technology, facilities, and external service providers
Days 31 to 60

Document and Remediate

  • System Security Plan drafted for every requirement, with implementation statements
  • POA&M built for open items with owners and dates
  • Close the highest-weighted gaps first: MFA, FIPS-validated encryption, audit logging, CUI marking
  • Policies and procedures issued for all 14 control families
Days 61 to 90

Score and Prove

  • NIST SP 800-171 self-assessment score calculated and submitted to SPRS
  • Level 1: annual affirmation completed and evidence archived
  • Level 2: mock assessment against objective evidence and C3PAO shortlisted
  • Continuous monitoring cadence set: vulnerability scans, access reviews, incident reporting

CMMC Compliance Pricing

CMMC work is delivered as a monthly Virtual CISO subscription led by a CMMC Registered Practitioner, so small suppliers get a scoped program rather than an enterprise-sized quote.

Crawling tier, Level 1 and scoping

From $2,000 per month

15 to 20 hours per month, sprint package. Excludes C3PAO assessment fees and any enclave licensing such as Microsoft 365 GCC High.

Level 2 readiness programs, including the SSP, POA&M, and SPRS submission, run on the Walking tier from $4,250 per month (20 to 40 hours). Multi-site Level 2 programs through C3PAO certification sit on the Running tier from $6,950 per month. Pre-packaged Cyber and AI bundles start at $4,950.

See all Pricing Tiers

Check your CMMC Level 1 Readiness first for Free

Free CMMC assessment platform

Free CMMC Level 1 Readiness Assessment

Assess your organization against the CMMC Level 1 safeguarding requirements, score each gap, and generate a readiness report you can hand to your prime, on IRM's dedicated CMMC assessment platform at cmmc.irmcon.com.

Run the CMMC Level 1 AssessmentBook a Free Consultation

Related: the free Cybersecurity Baseline Assessment (CAN/DGSI 104) covers the Canadian baseline for CPCSC, and Fractional CISO services keep the program running between assessments.

floating circle
Frequently Asked Questions

Frequently Asked Questions about CMMC Compliance

CMMC compliance means a defense contractor or subcontractor has met the Cybersecurity Maturity Model Certification level required by its Department of Defense contract. CMMC 2.0 has three levels: Level 1 for Federal Contract Information (15 requirements, annual self-assessment), Level 2 for Controlled Unclassified Information (the 110 requirements of NIST SP 800-171, third-party assessment for most contracts), and Level 3 for the most sensitive programs (additional NIST SP 800-172 requirements, government-led assessment).

The CMMC program rule took effect in December 2024 and the acquisition rule began phasing CMMC requirements into new DoD solicitations and contracts from November 2025, starting with self-assessments and moving to third-party Level 2 certification requirements over the following years. If a prime contractor has asked for your SPRS score or your CMMC status, the requirement has already reached you through flow-down.

Level 1 applies when you handle only Federal Contract Information and covers 15 basic safeguarding requirements from FAR 52.204-21, verified by an annual self-assessment and affirmation. Level 2 applies when you handle Controlled Unclassified Information and covers all 110 NIST SP 800-171 requirements; most Level 2 contracts require a certification assessment by a C3PAO every three years, with annual affirmations in between. Scoping which data you actually hold decides which level applies.

IRM delivers CMMC readiness as a monthly Virtual CISO subscription led by a CMMC Registered Practitioner: Level 1 and scoping from $2,000 per month on the Crawling tier, Level 2 readiness including the SSP, POA&M, and SPRS submission from $4,250 per month on the Walking tier, and multi-site Level 2 programs through C3PAO certification from $6,950 per month. C3PAO assessment fees and enclave licensing such as Microsoft 365 GCC High are additional and depend on your scope.

IRM's 90-day plan gets a subcontractor to a scoped boundary, a complete System Security Plan, a POA&M, and a submitted SPRS score. Remediation of the remaining gaps typically takes another 3 to 6 months depending on how much of the 110 requirements is already in place, after which a mock assessment and the C3PAO engagement follow. A realistic first-time Level 2 certification timeline is 6 to 12 months.

It is the NIST SP 800-171 self-assessment score, from minus 203 to 110, that contractors handling CUI must calculate using the DoD Assessment Methodology and submit to the Supplier Performance Risk System. Each unimplemented requirement subtracts 1, 3, or 5 points depending on its weight. Primes check it before awarding subcontracts, and IRM calculates and submits it as part of the 90-day plan.

The System Security Plan describes your CUI environment and how each of the 110 requirements is implemented; the Plan of Action and Milestones lists the requirements not yet met, with owners and dates. Both are mandatory for Level 2, and both are the first documents a C3PAO reads. IRM writes them to the level of detail an assessor expects, with implementation statements tied to objective evidence.

Not always. An enclave that isolates CUI to a smaller, controlled environment reduces the scope you must assess and is often the most economical route for a small supplier, and GCC High is one common choice for it. Whether you need one depends on where CUI flows today; that is why scoping comes first in the IRM plan, before any licensing decision.

Yes, when a Canadian supplier holds CUI under a subcontract to a US DoD prime, the CMMC requirement flows down regardless of location. Separately, Canada is phasing in its own Canadian Program for Cyber Security Certification (CPCSC), which is modeled on CMMC and NIST SP 800-171. IRM works with Canadian defense suppliers from Toronto and builds one control set that satisfies both programs.

A CMMC Registered Practitioner (CMMC-RP) is an individual trained and registered with the Cyber AB, the CMMC accreditation body, to provide CMMC consulting and readiness advice. Registered Practitioners cannot conduct certification assessments; that is the role of C3PAOs and their certified assessors. IRM's founder is a CMMC-RP, so readiness work is done by someone trained on the assessment process itself.

A subset of Level 2 contracts allows a self-assessment with annual affirmation instead of a C3PAO certification, but the DoD has indicated most Level 2 contracts will require the third-party route. Whether your contract allows self-assessment is specified in the solicitation. Either way the requirements, the SSP, and the SPRS score are the same, so the readiness work is identical.

Yes. IRM's free CMMC Level 1 Readiness Assessment at cmmc.irmcon.com assesses your organization against the Level 1 safeguarding requirements, scores each gap, and generates a readiness report you can share with your prime. Canadian suppliers can also run the free Cybersecurity Baseline Assessment at irmcon.com/products/cybersecurity-baseline-assessment/ for the CAN/DGSI 104 baseline behind CPCSC.
Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.