You run a machine shop that supplies the defense sector. A prime asked about CMMC, or you saw the clause in a contract, and now your inbox is full of vendors promising to make it painless. Every one of them sounds confident. Every proposal has a number on it. And you're stuck nodding along to words like "enclave" and "GCC High" and "FIPS boundary," hoping the person across the table actually knows what they mean for a shop that runs Mastercam and pushes G-code to the floor every day.
One thing just shifted in your favor. On July 13, 2026, the Department of War (DoW) suspended the mandatory third-party certification step (CMMC Phase II) pending a review aimed at cutting cost and burden for shops like yours. The clock that vendors have been using to rush you is gone for now. You still have to meet the controls and stand behind your own score, but the pressure to buy a big, expensive, C3PAO-ready package this year just eased. That makes this the right moment to slow down and ask hard questions, not to get talked into the biggest solution on the shelf.
Here's the truth. A confident answer isn't the same as a correct one. The gap between the two is where shops lose money, overbuy, and end up with a score they can't defend.
So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what CMMC Level 2 actually asks for, in plain English, including what the July suspension did and didn't change. Then we give you a ten-minute exercise to map your own CUI so you walk into vendor calls already knowing your rough scope. Then the ten questions we'd ask if we were sitting in your chair, each one with what a strong answer sounds like, what a weak one sounds like, and a real number or requirement to hold the vendor to.
Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague, changes the subject, or waves it off as "we'll sort that out later." How a vendor handles these ten tells you more than any proposal ever will.
One note on us, so you know where this is coming from. We're a CyberAB-authorized Registered Practitioner Organization, so we do CMMC readiness work: a gap analysis, a roadmap, standing up the controls, building the documentation, and getting your self-assessment to a place you can defend. We deliver that as an add-on to our managed IT, on one agreement, with the readiness labor included rather than billed by the hour. We also build our own PCs and servers on our own line in Wichita, and we've done that since 1997. That's why this guide is written from the shop floor, not a whiteboard. Use it, keep it, and bring it to every sales call you take.
Before the questions, here's the lay of the land. If you already live this every day, skip ahead. If you're newer to it, ten minutes here saves you from getting talked in circles later.
What CMMC is. CMMC stands for Cybersecurity Maturity Model Certification. It's the DoW's way of checking that the companies in its supply chain actually protect the sensitive information they handle. It isn't a new set of security rules. It's a verification layer on top of rules that have existed for years.
The three levels. Level 1 covers Federal Contract Information (FCI) and is a yearly self-assessment against 15 basic safeguards. Level 2 covers Controlled Unclassified Information (CUI) and is the one most defense machine shops are heading for. Level 3 is for the highest-sensitivity programs and is assessed by the government directly. This guide is about Level 2, because that's where the cost and the work live.
What Level 2 actually requires. Level 2 is built on a security standard called NIST SP 800-171, which has 110 individual controls spread across 14 families (things like access control, physical protection, and incident response). To meet it, you need three things working together. First, the 110 controls in place in your actual environment. Second, a System Security Plan (SSP), which is the written document describing exactly how each control is met at your shop. Third, a Plan of Action and Milestones (POA&M) for anything that isn't fully done yet, because a plan for the gaps is normal and expected.
How you're scored. You self-score against NIST 800-171 on a scale that tops out at 110. Each control is worth 1, 3, or 5 points, and missing a control subtracts its weight, so you can end up well below zero. That score gets posted in a DoW system called SPRS, along with a senior official's affirmation that it's accurate. Until the July 2026 suspension, contracts involving CUI were headed toward a mandatory check of that score by an accredited third-party assessor called a C3PAO. That third-party step is the part that's now paused (more just below).
Where things stand now, and why the pressure just eased. Here's the important update. On July 13, 2026, the DoW suspended CMMC Phase II, the mandatory third-party (C3PAO) certification that was set to become a condition of contract award on November 10, 2026. It's suspended pending a top-to-bottom review meant to lower cost and burden for small and mid-size contractors, not cancelled, so the third-party requirement could return or change. Two things did not change. Phase I self-assessment requirements, in force since November 2025, still apply. And Level 2 itself still stands, with all 110 NIST 800-171 controls. For now, you demonstrate Level 2 by doing the self-assessment and having a senior official affirm your score in SPRS, instead of hiring an accredited third-party assessor. That affirmation is a legally binding statement, so a score you can't back up carries real exposure, including under the False Claims Act. And the duty to protect CUI under DFARS 252.204-7012 has applied since 2017 regardless of any of this. The takeaway: you still have to meet the same controls and stand behind your number, but the pressure to buy a rushed, expensive C3PAO-ready enclave this year just eased. That's room to do it right, not a reason to do nothing. (Verify the current status at build time against the DoW CMMC page, since this is under active review.)
Where CybertronIT sits in that. We're an RPO, a Registered Practitioner Organization. We do the readiness work that gets you to the point where you'd meet the controls and could defend your score. We are not the C3PAO, and by design the same firm can't both prepare you and run the third-party assessment on the same engagement. That line matters even with the third-party step paused, because it could come back. Any vendor who blurs it is worth a second look.
Vendors hide behind these words. Here's what each one means, so nobody can fog you with it.
Here are the ten questions, with why each one matters on a real shop floor. Ask all ten, and watch the reactions as closely as the answers. The full checklist below adds, for every question, exactly what a strong answer sounds like, what a weak one sounds like, and the specific number or requirement to hold each vendor to.
Mastercam, GibbsCAM, Fusion, Esprit. These aren't email. They're graphics-heavy applications that lean on a real GPU and a real workstation to run without dragging. When a vendor proposes to move you into a secured cloud or a virtual desktop to protect CUI, ask exactly how your CAM seat performs in that setup, who tested it, and what it costs. With the third-party deadline paused, you have time to get this right instead of accepting whatever design a vendor can stand up fastest.
That cost is the part that quietly wrecks budgets. A regular office user in a compliant cloud is cheap by comparison. A GPU-backed virtual workstation that can actually run CAM is a different animal. A GPU-capable virtual machine in a government cloud can run from several hundred dollars a month per seat into four figures per seat per month depending on the GPU size and how many hours it runs, and Azure Government carries roughly a 15 percent premium over commercial Azure on top of that. Those are ballpark figures to frame the question, not a quote. Make the vendor price your seats, your way.
Moving a CAM seat into a virtual or cloud environment isn't always a clean lift. Some CAM licenses are tied to a physical dongle or a specific machine. Some vendors' license terms treat a virtual desktop as a different kind of install, which can mean a different license, an added cost, or a call to your CAM reseller before anything activates. Find this out before you sign, not the week you go live.
This is the question that separates people who understand shops from people who understand servers. It's one thing to lock CUI inside a secure enclave. It's another to get a program out to a machine that has no idea what CMMC is, and do it without breaking your compliance.
How does the post get to the control? USB stick? Network share? A DNC box in the corner running Windows 7? Every one of those is a real answer with real consequences. NIST 800-171 has a whole media protection family, and control 3.8.7 is specifically about controlling removable media like USB drives. So "we'll just sneakernet it on a thumb drive" isn't a shrug, it's a control you now have to account for.
Follow the part. The moment CUI leaves the protected boundary, whatever it touches can get pulled into scope. The workstation at the machine. The USB drive. The shared printer. The traveler printed on paper and clipped to the job. The old PC nobody's logged into since 2019 that still has a network cable in it.
This isn't guesswork. The official CMMC Level 2 scoping guidance sorts every asset into categories, including assets that handle CUI, assets that protect the environment, and specialized assets like the machine controls themselves. A vendor who knows the work talks in those terms and sorts your gear honestly. Scope also drives cost, so a vendor who oversizes your scope is oversizing your bill.
Your CUI doesn't sit still. A print lands from a customer portal. An engineer opens it in CAM. That becomes a program. The program becomes G-code. The G-code goes to a machine, and the finished part ships. Compliance has to hold at every handoff, not just where the data sits at rest.
There's a trap here worth knowing. Information derived from CUI is usually still CUI. So the toolpath and the G-code your team generates from a controlled drawing can carry the same protection requirement as the drawing itself. A vendor who thinks only the original PDF is sensitive, and treats the G-code as just machine data, has a hole in their plan.
Every proposal rests on assumptions. You use these machines. Your data flows this way. You have this many CUI users. Your CAM works like this. When an assumption is wrong, the fix costs money, and it usually surfaces after you've signed.
Here's a concrete one. Compliant cloud seats are priced per user, so the headcount in the proposal drives the bill. At roughly $60 per user per month for a Level 2-capable GCC High seat, guessing 10 users when the real number is 25 isn't a rounding error, it's about $900 a month the proposal didn't show. Ask what their user count is and where it came from. And ask how the labor is billed, because a low headline price with hourly remediation on top is a different deal than one with the work included.
CMMC Level 2 is built on 110 controls, and a large share of them have nothing to do with software. Whole families are about people and buildings: physical protection, personnel security, awareness and training, media handling. Who's screened before they touch CUI. Who can walk up to a machine or a server. What happens to accounts when someone quits. How visitors are logged. How you dispose of a drive or a stack of printed travelers.
Here's where you want an honest vendor, not a flattering one. A good partner will tell you plainly which of these they handle and which stay with you. The technical and administrative controls, the policies, the procedures, the account and access side, those are things a readiness partner should stand up and document. But the physical safeguards themselves, the locks on the door, the alarm, the fireproofing, the camera at the dock, those live with you, the building owner. No IT vendor installs your deadbolts. The right answer is a clear division of labor, in writing, so nothing falls in the crack between "we assumed you had it" and "we thought you did that."
Doing a control isn't enough. You have to prove it. Whoever asks, a prime, an auditor, or a future assessor, wants to see the written policy, the training records, the visitor log, the screening process, the media disposal procedure. Talk without documentation is a weak spot in your self-assessment. Your score runs on evidence, and evidence means documents that match reality.
The SSP is the backbone document of your Level 2 compliance. NIST 800-171 requires it (control 3.12.4), and it has to describe exactly how each of the 110 controls is met in your environment. A real SSP names your systems, your CAM setup, your network, your machines, your data flow. A template SSP describes a generic company that doesn't exist, and anyone who reads it against your floor spots the difference fast, because the document won't match what they see. That's true whether the reader is a prime today or a third-party assessor if that requirement comes back.
Here's what the July 2026 change means for this question. The mandatory third-party assessment (the C3PAO step) is suspended pending the DoW's review, so for now you're not hiring an outside assessor. You demonstrate Level 2 by self-assessing against the 110 controls and having a senior official affirm your score in SPRS. A single-site third-party assessment commonly ran $30,000 to $60,000 in fees for a small shop, and that expense is off your plate for now. That's real money the suspension just saved you this year.
But self-certifying is not a free pass, and any vendor who sells it that way is setting you up. The SPRS affirmation is a legally binding statement, and a score you can't back up with evidence carries False Claims Act exposure. Primes can still ask to see your number and your SSP before they hand you work. And the duty to protect CUI under DFARS 252.204-7012 has applied since 2017 no matter what CMMC does. The review could also bring the third-party step back in some form, so a defensible self-assessment now is also insurance against a rushed scramble later.
You're not just collecting answers. You're watching how a vendor reacts to hard questions. These are the patterns that should give you pause. One on its own might be a vendor having an off day. A cluster of them is a vendor who'll leave you exposed or oversold.
Everything above is the map. The full checklist is the tool you bring into the room.
The free PDF adds, for every one of the ten questions, exactly what a strong answer sounds like, what a weak one sounds like, and the specific number or requirement to hold each vendor to. It also includes a ten-minute exercise to map your own CUI before you take a single sales call, so you walk in already knowing your rough scope. It is built to print and carry.
Give us an email and it is yours. We will send the PDF to your inbox and start it downloading right away. No cost, no obligation.
Comments