CMMC Advisory for Manufacturers and Defense Contractors
Independent guidance for manufacturers, defense contractors, and subcontractors working through CMMC. DTS IT Advisors helps you understand what actually applies to your business, identify where Controlled Unclassified Information (CUI) lives, define scope, evaluate remediation and provider options, and prepare for the right assessment path, without selling you a predetermined technology stack, managed service, or enclave.
Why CMMC Gets Complicated
Most manufacturers and defense contractors do not struggle with CMMC because the rules are secret. They struggle because the practical questions do not have a single, obvious owner.
Contract and flow-down language is often vague. A prime contract, purchase order, or subcontract may reference CMMC, DFARS 252.204-7012, or NIST SP 800-171 without stating clearly what level applies, when, or to which systems.
It is not always clear whether you handle CUI. Many companies know they have Federal Contract Information (FCI). Far fewer have mapped where Controlled Unclassified Information actually enters, moves through, and leaves the business.
Scope creep is common. Without a deliberate scoping exercise, systems, users, and locations that do not need to be in scope get pulled in anyway, inflating cost and complexity.
Recommendations conflict. An MSP, a cybersecurity consultant, an enclave provider, and an assessor can each give a different answer about what you need, in part because each one is describing the piece of the problem they sell a solution for.
Tools and services get purchased before requirements are validated. Licensing a platform, an enclave, or a compliance tool before you know your real scope is one of the most common and most expensive mistakes manufacturers make.
Responsibility is unclear. Ownership of CMMC readiness is often split across company leadership, internal IT, an MSP, an MSSP, a compliance consultant, a cloud or enclave provider, and eventually a C3PAO, with no one holding the full picture.
None of this means CMMC is unmanageable. It means most companies benefit from someone who can look across the whole picture before they commit to a path.
How DTS IT Advisors Helps
DTS IT Advisors provides independent CMMC advisory services. We help you get clarity and make informed decisions. Specifically, we help with:
Contract and requirement clarification: identifying the cybersecurity and technology requirements reflected in your contracts, solicitations, and subcontract flow-downs, mapping them to your environment, and flagging ambiguous language for confirmation with your prime, contracting official, or counsel as appropriate. DTS does not provide legal advice.
CUI and information-flow review: helping you identify whether, where, and how Controlled Unclassified Information and Federal Contract Information move through your systems, people, and processes.
CMMC scope strategy: defining a scope that reflects your actual environment rather than a default assumption, so you are not protecting more (or less) than the requirement calls for.
Enclave evaluation: assessing whether an enclave is a good fit for your workflow, and if so, what kind, without steering you toward a specific enclave product.
Coordination of current-state and gap reviews: helping you scope and interpret a gap assessment against NIST SP 800-171 Rev. 2, and understand what the results actually mean for your business.
Remediation option evaluation: comparing realistic paths to close identified gaps, including cost, timeline, and operational impact.
Provider and proposal evaluation: reviewing proposals from MSPs, MSSPs, consultants, and enclave vendors side by side, so you can compare them on the same terms.
Cost and contract comparison: helping you understand what you are actually being asked to buy, and whether it matches what your contracts require.
Technology and service sequencing: helping you decide what to address first, second, and later, instead of buying everything at once.
Responsibility mapping: documenting who is responsible for implementing, operating, and providing evidence for each requirement, across your internal team and every outside provider involved.
Preparation for the appropriate assessment path: making sure your documentation, evidence, and scope are ready before you engage a C3PAO or submit a self-assessment.
DTS IT Advisors does not perform CMMC certification assessments. Level 2 certification assessments are conducted by authorized, accredited C3PAOs (CMMC Third-Party Assessment Organizations) under the Cyber AB, and Level 3 assessments are government-led through the Defense Contract Management Agency’s DIBCAC. Our role is to help you get ready for that process, and to help you know when and how to engage the right one.
Why Work With an Independent CMMC Advisor
Most organizations a manufacturer encounters during a CMMC project have something specific to sell: managed services, a security product, an enclave, or an assessment. That is not a criticism. Each of those providers solves a real part of the problem. But it means each one is answering the question from inside their own offering.
An independent advisor’s job is different. DTS IT Advisors is not an MSP, MSSP, enclave vendor, cybersecurity product vendor, or C3PAO. We do not have a predetermined stack, platform, or assessment to sell you. That means:
We can tell you when a simpler, lower-cost path meets your actual requirement, even if that means recommending less than a vendor might.
We can compare proposals from multiple MSPs, enclave providers, or consultants against your specific contract requirements, using consistent evaluation criteria.
We can help you sequence spending so you validate what you need before you commit budget to a platform or service.
We can help clarify where one provider’s responsibility ends and another’s begins, which is often where gaps and finger-pointing happen later.
The goal is not to replace your MSP, your assessor, or your existing providers. It is to make sure the decisions about scope, priorities, and provider selection are made with a clear picture of your actual requirements, before you sign a contract you may need to unwind later.
The DTS CMMC Advisory Process
A straightforward, seven-step process designed for business owners and operations leaders, not just IT staff.
Clarify: We identify the cybersecurity and technology requirements reflected in your contracts, solicitations, and flow-down language, map them to your environment, and flag ambiguous language for confirmation with your prime, contracting official, or counsel as appropriate.
Map: We help you identify where Federal Contract Information and Controlled Unclassified Information exist and how they move through your people, systems, and locations.
Scope: We help you define a CMMC scope that matches your real environment, so you are protecting the right systems, not guessing.
Assess: We help you coordinate and interpret a current-state or gap review against the applicable NIST SP 800-171 Rev. 2 requirements.
Compare: We evaluate remediation options, providers, and proposals side by side against your actual requirements and budget.
Prioritize: We help you sequence the work: what needs attention first, what can wait, and what may not be needed at all.
Prepare: We help you get documentation, evidence, and scope ready for the appropriate assessment path, whether that is a self-assessment or a certification assessment through a C3PAO.
CMMC Level 1 vs. Level 2: What You Need to Know
CMMC is built around two concepts that matter to almost every manufacturer and defense contractor: what kind of information you handle, and how rigorously you have to prove you are protecting it.
Federal Contract Information (FCI) is information the government provides or generates under a contract that is not intended for public release. If your business holds a federal contract or subcontract of almost any kind, you likely handle FCI.
Controlled Unclassified Information (CUI) is a narrower and more sensitive category: information that requires safeguarding under law, regulation, or government-wide policy, but that is not classified. The National Archives (NARA) administers the CUI program and maintains the CUI Registry that defines which categories of information qualify. Many manufacturers are surprised to learn they handle CUI, and some believe they do when they do not. This is one of the most common things to get wrong, and one of the first things worth clarifying.
A third level, CMMC Level 3 (Expert), applies to a smaller set of contracts that require enhanced protection beyond Level 2. It adds requirements drawn from NIST SP 800-172 and is assessed by the government through the Defense Contract Management Agency's DIBCAC, not by a commercial C3PAO. Level 3 is not shown as a card above since it applies to a much smaller subset of manufacturers and is not a like-for-like comparison with Levels 1 and 2.
Knowing which of these applies to you, and knowing it based on your actual contracts rather than an assumption, is usually the single highest-value first step in a CMMC project.
Current CMMC Program Update
CMMC implementation and enforcement timelines change periodically as the Department of War (formerly the Department of Defense) issues updates. For the current status of the CMMC rollout and what it means for manufacturers right now, see our CMMC Phase II Pause update. This callout is reviewed and updated as the regulatory environment changes; the guidance above it does not.
CMMC Level 1
Foundational
- Applies to
- When a covered defense contract or subcontract requires CMMC Level 1 for systems that process, store, or transmit Federal Contract Information (FCI).
- Requirements
- 15 basic safeguarding requirements.
- Source standard
- FAR 52.204-21.
- Assessment type
- Self-assessment only. No third-party assessor is involved.
- Frequency
- Annual self-assessment, with annual affirmation from a senior company official.
- Plans of Action (POA&Ms)
- Not permitted at this level.
CMMC Level 2
Advanced
- Applies to
- When a covered defense contract or subcontract requires CMMC Level 2 for systems that process, store, or transmit Controlled Unclassified Information (CUI).
- Requirements
- 110 security requirements aligned with NIST SP 800-171 Rev. 2.
- Source standard
- NIST SP 800-171 Rev. 2.
- Assessment type
- Self-assessment or a certification assessment performed by an accredited C3PAO, depending on your contract.
- Frequency
- Generally every three years, with affirmation at assessment and annually after.
- Plans of Action (POA&Ms)
- Limited POA&Ms may be permitted for eligible requirements under Conditional status, subject to CMMC scoring and control restrictions, and must be closed within 180 days.
Is a CMMC Enclave Right for You?
An enclave, a separated environment built to contain systems and data that fall inside CMMC scope, can be a genuinely useful strategy. Used well, it can reduce the number of systems and users that need to meet the full requirement, which can lower both cost and complexity.
It is not automatically the best, simplest, or least expensive option for every business, and it is not a shortcut around understanding your requirements. Before committing to an enclave, it is worth evaluating:
Workflow fit: Can your team actually get their work done inside the boundary, or will people end up moving information in and out of it to stay productive?
Scope accuracy: Does the enclave actually contain everything that needs to be in scope, and nothing that does not?
Responsibility: Which controls does the enclave provider operate, which stay with you, and who provides evidence for each one during an assessment?
Usability over time: Will the enclave still fit the business as it grows, adds customers, or takes on new contracts?
Long-term operating cost: What does the enclave cost on an ongoing basis, not just to set up, compared to alternative approaches?
How CUI actually moves: If information regularly needs to travel between engineering, production, and outside partners, a narrow enclave can create as much friction as it removes.
DTS IT Advisors can evaluate whether an enclave makes sense for your specific environment, and if so, help you compare providers, without an enclave product of our own to sell you.
Who This Service Is For
This service is a good fit if your business fits one or more of the following:
You are a manufacturer, defense contractor, or subcontractor in the Defense Industrial Base.
You have received CMMC, DFARS, or NIST SP 800-171 requirements from a customer or prime contractor.
You know you handle Controlled Unclassified Information, or you are not sure.
You are being asked to evaluate or have already been pitched a CMMC enclave.
You have received conflicting recommendations from an MSP, consultant, or assessor.
You are preparing for CMMC Level 1 or Level 2 requirements and want an independent read on your scope before you spend money.
If you are further along and already know exactly what you need, DTS IT Advisors can still be useful as a second opinion before you sign a contract for tools, an enclave, or a managed service.
Related CMMC Resources
CMMC After the Phase II Pause: What Manufacturers Still Need to Do: the current status of CMMC implementation and what has not changed.
The Manufacturer's CMMC Readiness Checklist: a free, seven-question checklist to work through with your team before you spend on tools or services.
Frequently Asked Questions
Does CMMC apply to my company?
Not every federal contract triggers CMMC, and not every company that handles FCI or CUI is automatically required to comply. Whether CMMC applies, and at what level, comes from the specific defense solicitation or contract you are working under and the requirements that flow down from it. Some contracts require CMMC Level 1, some require CMMC Level 2, and some do not reference CMMC at all. The reliable way to know is to review the actual language in your contract, solicitation, or subcontract flow-downs rather than assume based on your industry or the fact that you hold a federal contract.
How do I know whether we handle CUI?
The clearest way is to review your actual contracts, solicitations, and subcontract language for CUI-related clauses, and to trace what kind of information your customers or primes actually send you. Many companies assume they do or do not handle CUI without having checked. An independent review of your contracts and information flow is usually the fastest way to get a real answer.
Do we need CMMC Level 1 or Level 2?
Your required CMMC level is established by the applicable defense solicitation, contract, or subcontract flow-down. Level 1 is used where CMMC Level 1 is required for systems that process, store, or transmit Federal Contract Information (FCI). Level 2 is used where CMMC Level 2 is required for systems that process, store, or transmit Controlled Unclassified Information (CUI). The determination should come from your actual contract requirements, not simply from the type of information your organization possesses.
Should we use a CMMC enclave?
Sometimes. An enclave can reduce scope and simplify compliance when it fits your workflow, but it is not automatically the cheapest or easiest option, and a poor fit can create more friction than it removes. It is worth evaluating against your actual operations before committing.
Can our MSP handle CMMC?
An MSP can implement many of the technical controls CMMC requires. However, defining scope, identifying CUI, mapping responsibility across every provider involved, and preparing for an assessment are broader than what a managed services relationship typically covers. Many companies benefit from an independent review of scope and requirements, separate from whoever is implementing the technical controls.
What is the difference between an RPO and a C3PAO?
An RPO (Registered Provider Organization) and its Registered Practitioners (RPs) provide non-certified advisory and consulting services to help organizations prepare for CMMC. A C3PAO (CMMC Third-Party Assessment Organization) is authorized and accredited by the Cyber AB to conduct official Level 2 certification assessments through Certified CMMC Assessors. Advisory roles like RPOs and RPs cannot issue a certification assessment result. Level 3 assessments are handled separately: they are conducted by the government through the Defense Contract Management Agency's DIBCAC, not by a C3PAO.
Does DTS perform CMMC certification assessments?
No. DTS IT Advisors is an independent technology advisor, not a C3PAO. Level 2 certification assessments are performed by authorized, accredited C3PAOs, and Level 3 assessments are conducted by the government through the Defense Contract Management Agency's DIBCAC. DTS helps you get ready for that process by clarifying scope, coordinating gap reviews, and preparing documentation and evidence, and helps you know when and how to engage the right assessor if certification is required.
How much does CMMC readiness cost?
It depends heavily on your scope, current environment, and which assessment path applies to you. Costs can include internal time, remediation of technical or process gaps, tooling or an enclave if one is the right fit, and third-party assessment fees if certification is required. One of the most valuable things an independent advisor can do is help you avoid spending on tools or services before your actual scope and requirements are confirmed.
When should we bring in a C3PAO?
Generally, after your scope is defined, your gaps are identified, and remediation is either complete or well underway, and only if your contract requires a Level 2 certification assessment rather than a self-assessment. Bringing in a C3PAO too early, before your scope and readiness are clear, can be costly and inefficient.
What should we do before buying CMMC tools or services?
Confirm what your contracts actually require, identify where CUI exists in your business, and define your scope. Our Manufacturer's CMMC Readiness Checklist walks through the same seven questions we use with clients, in a format you can work through with your team before committing to any purchase.
Not Sure What You Actually Need?
If you are unsure about your scope, whether you handle CUI, which provider recommendation to trust, or what to spend money on next, an independent conversation is a useful first step.
Sources and Further Reading
32 CFR Part 170 (eCFR): the federal regulation establishing the CMMC Level 1, 2, and 3 structure.
NARA, About Controlled Unclassified Information: the National Archives’ official definition and background on CUI.
The Cyber AB, Ecosystem Roles: official definitions of the C3PAO, RPO, and RP roles within the CMMC ecosystem.