Publication

You Just Got A Cybersecurity Maturity Model Certification Letter. Now What?

June 22, 2026

What defense subcontractors need to know about cybersecurity readiness, compliance misconceptions, and building a sustainable path forward.

Over the last several months, manufacturers and subcontractors across the defense industrial base (DIB) have begun receiving a familiar message from prime contractors: demonstrate cybersecurity readiness or risk falling behind in the supply chain. While the specifics vary, the questions being asked are remarkably consistent.

For some organizations, that message arrives through a formal contract requirement. For others, it comes through supplier questionnaires, cybersecurity attestations, onboarding reviews, or direct pressure from prime contractors trying to reduce risk across their supply chain.

Either way, the reality is the same:

Cybersecurity Maturity Model Certification (CMMC) is no longer a future conversation. It is an operational business requirement.

With Phase 1 underway (November 2025 – November 2026) and Phase 2 set to begin November 10, 2026 — when Level 2 C3PAO certification assessments start appearing in Department of Defense (DoD) / Department of War (DoW) contracts — the timeline for preparation is shrinking.

And for many small and mid-sized contractors, the biggest challenge right now is not just implementation—it’s separating reality from misconception.

Misconception #1: “CMMC Only Applies to Prime Contractors”

One of the most common misunderstandings is that cybersecurity obligations stop with the prime contractor.

They do not.

Under the final Defense Federal Acquisition Regulation Supplement (DFARS) rule (48 CFR, effective November 10, 2025) and 32 CFR §170.23, prime contractors carry legal responsibility for confirming that every subcontractor handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) meets the appropriate CMMC level — before work begins and before CUI is shared.

If your organization stores, processes, transmits, or supports systems connected to Controlled Unclassified Information (CUI), you are part of the defense supply chain risk equation.

That means subcontractors are increasingly being asked to demonstrate:

  • Cybersecurity maturity aligned to NIST SP 800-171
  • Operational safeguards for handling sensitive information
  • Documented processes for access control, incident response, and risk management
  • Readiness to support federal contract requirements at the appropriate CMMC level

In many cases, primes are pushing requirements downstream before formal contract language ever appears.

Why?

Because they are managing their own risk.

Misconception #2: “We’ll Wait Until It’s Officially Required”

This mindset is becoming increasingly risky.

The DoD/DoW estimates that more than 220,000 companies in the DIB are subject to CMMC requirements, and most are small and mid-sized businesses. Many require 12 to 18 months to fully implement necessary controls.

Yet, many organizations assume they can delay action until CMMC language formally appears in their contracts. But primes are not necessarily waiting for the phased rollout to mature before evaluating supplier readiness.

They are already asking questions like:

  • Can this subcontractor securely handle sensitive information? 
  • Are they a supply chain liability? 
  • Would a cyber incident at this vendor impact contract performance? 
  • What is their SPRS score — and does it reflect real readiness?

And the truth is:

Your deadline may not be the government’s deadline. Your deadline may be your prime contractor’s tolerance for risk.

Organizations that wait too long may find themselves trying to build a cybersecurity program under contract pressure, procurement deadlines, and operational stress simultaneously.

That is not the position you want to be in.

Misconception #3: “Passing the Assessment Is the Finish Line”

Many organizations are approaching CMMC like a one-time certification event. But sustainable cybersecurity maturity does not end once an assessment is complete.

The organizations struggling most are often the ones treating compliance as:

  • A checkbox exercise
  • A documentation sprint 
  • A temporary project with an end date

The organizations succeeding are building:

  • Repeatable processes that survive staff turnover and system changes
  • Operational resilience tested through tabletop exercises and incident response drills
  • Executive awareness meaning cybersecurity is a board-level priority, not just an IT concern
  • Long-term security habits embedded into daily operations, vendor management, and employee training

Because ultimately, CMMC is not just about passing an assessment.It is about reducing risk across the defense industrial base and demonstrating to your primes, your customers, and the DoD/DoW that your organization can operate securely and consistently.

So… What Should Organizations Be Doing Right Now?

If your prime contractor just sent the letter, start with the fundamentals:

Step 1: Understand Your Scope

  • Understand whether your environment handles or supports CUI 
  • Identify what level of CMMC applies to your operations (Level 1 for FCI, Level 2 for CUI)
  • Map your CUI data flows, where sensitive information enters, lives, and exits your systems

Step 2: Assess Your Current Posture

  • Honestly asess your current cybersecurity maturity where sensitive information enters, lives, and exits your systems (or get someone on the outside to do it) 
  • Review policies, procedures, and incident response capabilities 
  • Clarify responsibilities between leadership, IT, operations, and vendors

Step 3: Build Your Roadmap

  • Build a phased, realistic roadmap instead of trying to fix everything at once 
  • Clarify responsibilities between leadership, IT, operations, and vendors
  • Address Plan of Action and Milestones (POA&M) items strategically — remember, you must achieve at least 80% implementation (88/110 practices), certain controls are not POA&M-eligible, and all items must close within 180 days

Step 4: Most Importantly: Do Not Let Urgency Force Bad or Extra Expensive Decisions

The market is rapidly filling with “quick fix” promises around CMMC. Some may help. Others may create additional complexity, cost, or false confidence.

A sustainable approach matters more than a rushed one.

You Are Part of An Ecosystem

For years, cybersecurity in portions of the defense supply chain was treated as largely an IT concern. That era is ending.

CMMC is changing the conversation from:

“Do you have cybersecurity tools?”

to:

“Can your organization operate securely and consistently as part of the defense ecosystem?”

That is a much bigger question. And for many organizations, the letter from their prime contractor is the moment that reality is starting to set in.

The organizations that move now — thoughtfully, strategically, and with the right guidance — will be the ones still winning contracts in 2027 and beyond.


Frequently Asked Questions About CMMC Compliance

Does CMMC apply to subcontractors?

Yes. Under 32 CFR §170.23, CMMC requirements flow down through the supply chain to any subcontractor that processes, stores, or transmits FCI or CUI in performance of a DoD/DoW contract.

What is the CMMC Phase 2 deadline?

Phase 2 begins November 10, 2026, when the DoD/DoW will begin requiring Level 2 C3PAO certification assessments in applicable solicitations and contracts involving CUI.

How much does CMMC Level 2 compliance cost?

Industry estimates range from $120,000–$350,000 in the first year for a typical 50-person contractor, including gap assessment, remediation, documentation, and C3PAO assessment fees, with $40,000–$100,000 annually thereafter. Costs vary significantly based on current cybersecurity posture and scope.

Can I wait until CMMC appears in my contract?

You can — but many prime contractors are already requiring readiness ahead of the government's phased rollout. Waiting until CMMC appears in your RFP may mean you've already lost the bid.

What's the difference between FCI and CUI?

Federal Contract Information (FCI) is non-public information provided by or generated for the government under a contract. Controlled Unclassified Information (CUI) is more sensitive government information that requires specific safeguarding and dissemination controls. CUI triggers higher CMMC requirements (Level 2 or 3).

About the Author

Chetrice Romero is a Senior Cybersecurity Advisor at Ice Miller, where she advises organizations on cybersecurity governance, incident preparedness, operational resilience, and regulatory readiness. Her experience includes supporting critical infrastructure, public sector organizations, and defense-related environments with a focus on practical, operationally grounded cybersecurity programs. For more about her CMMC services, click here.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader’s specific circumstances.

Related People

Related Categories

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights