Insights

Subject: CMMC Level 2 Compliance Verification Required

Written by James Reid | Jul 29, 2026, 11:00:00 AM

To many defense subcontractors, there’s an 800-pound gorilla sitting in their inbox called Cybersecurity Maturity Model Certification (CMMC) Level 2. While most subcontractors in the Defense Industrial Base (DIB) have heard of the framework, it’s another thing entirely when a customer asks how you’ll meet the November 10, 2026 compliance requirements.

What makes this email unsettling is the moment a subcontractor realizes these requirements are no longer something only their customers need to worry about. They now apply directly to them.

Welcome to Joe’s Machine Shop

There’s a machine shop owner we know, and if you’re anything like him, your stomach will probably drop the first time you get an email like this in your inbox.

In Joe’s case, it came from a long-standing customer, a contractor supporting a major U.S. defense program. His team was making components for that customer as a subcontractor. While he had heard of Level 2, has wasn’t sure what it meant for his shop or whether he should start worrying about it.

And he’s definitely not alone. Small and midsize subcontractors across the supply chain are getting emails like this every day, and most of them are wondering the same thing: What does it means for me, and where should I start?

Slowing Down the Flow-Down

If you’re a small to midsize subcontractor, you may be thinking only large defense contractors need to worry about CMMC. But come November, that’s no longer true. In November, how Controlled Unclassified Information (CUI) is handled changes everything.

If your company stores, processes, or transmits CUI as part of a defense contract, your customer may require you to prove Level 2 compliance as a condition of winning the project.2 That’s because cybersecurity requirements can now flow down through the supply chain to you.

That CUI is likely in plain sight, in design files, engineering specs, tolerances, and material certifications that you’ve moved through your systems for years. When you get CUI files by email, save them to shared drives, send them to vendors for quoting, and let employees access them during the production process, you may also need to know where that information lives, who can access it, how it’s protected, and how those protections are documented.

Level 2 Is Not Just an IT Project

The challenge of meeting Level 2 compliance goes beyond IT support. It impacts the whole organization and its people, processes, and systems. Here’s a few tips that Joe and other subcontractors are benefitting from on their way to compliance:

Your CUI footprint is bigger than you think

You might be surprised by how far CUI travels across your organization. Trace the path of just one file and you’ll probably find it moves a lot further than you thought: from an engineering workstation to a quoting system to a shared folder to a cloud storage account, to a few external vendors, and a personal laptop or two. Any of those locations could fall within the scope of an assessment.

There’s 100 ways to get it wrong

Ask your IT provider if you’re compliance-ready and they can check a few boxes: antivirus, firewalls, backups, multi-factor authentication (MFA). But Level 2 has 110 compliance requirements across 14 control families. It takes you beyond technology to knowing where your CUI lives, who has access to it, and how it moves through your environment. You’ll also need to document how each security control is implemented, maintain supporting policies and procedures, track remediation efforts, and show that security practices are being followed.

Level 2 is not one-size-fits-all

Finally some good news. First, you can tighten the scope of what needs to be covered in a dedicated area, known as a CUI enclave, where access can be limited only to the users, systems, and applications that need to touch CUI.3 Second, depending on the sensitivity of the information you handle, you may qualify for a self-assessment process instead of the Certified Third-Party Assessment Organization (C3PAO), which is more complex and has a limited number of assessors available.4

How Joe Found His Footing

As Joe learned firsthand, November 10 gets a lot less intimidating when you have a readiness partner helping you prepare. At NexusTek, we start with a CMMC readiness assessment against all 110 NIST SP 800-171 controls. We identify where CUI lives, establish your Baseline Supplier Performance Risk System (SPRS) score, and create a prioritized roadmap for closing gaps. We also help build the documentation you need, including your Security System Plan (SSP), while preparing the evidence needed for a future assessment.

It’s important to understand that a readiness partner is not the same as a C3PAO. The goal is to help your organization prepare for a formal assessment, not conduct the certification itself.

November is Just Around the Corner

When the compliance verification email lands in your inbox, that’s not the time to start figuring out where your CUI lives. November 10 is getting closer and assessment timeliness aren’t getting shorter. What you can control is when you start.

Things may seem out of control, but what you can control is whether you’re prepared before that email arrives.

A readiness assessment helps you understand where you stand today and the steps your organization needs to close any gaps to keep current contracts and pursue new business https://www.nexustek.com/cmmc-2-0-compliance-services

Sources:

  1. National Archives, Controlled Unclassified Information (CUI), accessed June 2026.

  2. FedTech, Major Contractors Close In on CMMC 2.0 Readiness, April 2025.

  3. Reuters, New cybersecurity rules for US defense industry create barrier for some small suppliers, February 2026.