CMMC Level 2 for Small Defense Manufacturers: What You Actually Need to Do

A practical guide to CMMC Level 2 certification for small defense manufacturers. 110 controls, common gaps, and concrete next steps before November 2026.

If you're a small defense manufacturer with 10 to 200 employees, you've probably heard that CMMC Level 2 certification is coming. The deadline is November 2026. Here's what that actually means for your business and what you need to do about it.

What CMMC Level 2 Requires

CMMC Level 2 maps directly to NIST SP 800-171, which defines 110 security controls across 14 families. These controls cover everything from access control and audit logging to incident response and system integrity. You need to implement all 110 controls and prove it to a certified third-party assessor (C3PAO).

This is not a checkbox exercise. The assessor will verify that controls are not just documented but actually operating. If your access control policy says "multi-factor authentication required" but your VPN still accepts password-only login, that control fails.

Why Most Small Manufacturers Are Not Ready

The typical small manufacturer scores between 40 and 60 on the SPRS (Supplier Performance Risk System) scale, out of a maximum 110. That gap represents dozens of controls that are either not implemented or only partially in place. The most common reason is that these companies have IT infrastructure that grew organically over years without a security framework guiding decisions.

The Three Biggest Gaps

Access Control (AC): This family has the most controls (22) and the most failures. Common issues: shared admin accounts, no MFA on critical systems, excessive privileges, and no access review process.

Audit and Accountability (AU): You need to log security-relevant events across all systems, retain those logs, and review them. Most small manufacturers have no centralized logging.

Incident Response (IR): You need a documented incident response plan, trained staff, and evidence of testing. This is often the easiest gap to close because it is primarily documentation and training.

What Automation Can Do

Automation can handle gap analysis, evidence collection, and continuous monitoring. What automation cannot do is make the process changes for you. The tool identifies the gap; your team closes it.

Concrete Next Steps

First, get an honest gap assessment against all 110 controls with evidence requirements. Second, prioritize the 20 controls that fail most often. Third, build a remediation timeline. Most small manufacturers need 6 to 12 months.

Check your compliance readiness with our free gap assessment tool at compliance.aegisos.ai.