Few places in America have more businesses affected by CMMC than the corridor between Baltimore and Washington. Fort Meade is home to NSA, U.S. Cyber Command, and the Defense Information Systems Agency, and thousands of Maryland companies feed that ecosystem: software shops in Columbia and Annapolis Junction, engineering firms in Hanover and Linthicum, machine shops and logistics companies across Anne Arundel and Howard counties. If any part of your revenue flows from the Department of Defense, directly or through a prime, CMMC is no longer something to watch. It is appearing in contracts now, and the companies that treat it as an IT project with a deadline are winning work from the companies that treated it as paperwork.
What CMMC actually is, in one paragraph
The Cybersecurity Maturity Model Certification is the Department of Defense's way of verifying that contractors protect government information on their own networks. Contractors have been contractually obligated to follow the underlying security rules for years; what CMMC changes is verification. Instead of every vendor promising compliance on the honor system, contracts now specify a CMMC level, and you must prove you meet it, through a formal self-assessment or a third-party audit, before award. No certification at the required level means you are ineligible for that contract, no matter how good your product is.
Two kinds of information decide everything
Your required level depends on what government information touches your systems, so start by learning two acronyms:
- FCI (Federal Contract Information): information provided by or generated for the government under contract that is not intended for public release. If you hold any DoD contract, you almost certainly handle FCI. It is that broad.
- CUI (Controlled Unclassified Information): sensitive but unclassified information the government requires safeguarding for, such as technical drawings, specifications, export-controlled data, and certain program details. CUI is what pushes you into the serious tier.
Before you buy anything or hire anyone, answer one question honestly: where does CUI enter, live, and leave your business? Email inboxes, file shares, a CAD workstation, an engineer's laptop, a subcontractor portal. This mapping exercise drives your level, your scope, and most of your cost.
The three levels, practically
Level 1: basic hygiene for FCI
Level 1 applies when you handle FCI but no CUI. It requires 15 basic security practices, things like limiting system access to authorized users, using antivirus, and changing default passwords, and it is verified by an annual self-assessment with an executive affirmation entered into the government's SPRS database. For a small business with reasonably managed IT, Level 1 is achievable in weeks, not months. Do not let anyone sell you a six-figure Level 1 project. But do take the affirmation seriously: a company officer is signing a statement to the federal government, and false claims have already produced enforcement actions against contractors.
Level 2: the real work, for CUI
Level 2 applies when you handle CUI, and it is where most Fort Meade corridor contractors land. It requires implementing all 110 security controls of NIST SP 800-171, covering access control, encryption, logging, incident response, physical security, personnel security, and more. Depending on the contract, verification is either a triennial self-assessment or, for most CUI-bearing contracts, a triennial third-party audit by a certified assessment organization (a C3PAO), with annual affirmations in between.
What the 110 controls mean in practice for a typical 20 to 100 person contractor:
- A defined enclave. Most companies do not bring their whole network to Level 2. They build a bounded environment where all CUI lives, often Microsoft 365 GCC High plus hardened endpoints, and keep everything else out of scope. Scoping well is the single biggest cost lever.
- MFA everywhere, FIPS-validated encryption, and controlled removable media. The technical controls overlap heavily with what cyber insurers now demand; our guide to cyber insurance IT requirements covers that shared ground, and money spent here counts twice.
- Documentation with teeth. A System Security Plan (SSP) describing how each control is met, and a POA&M (plan of action and milestones) for gaps. Assessors read these first. A control that works but is undocumented scores as a failure.
- Operational discipline. Log review, access reviews when people join and leave, incident response exercises, patch cadence. Controls are behaviors, not purchases.
Realistic numbers, stated as typical market ranges rather than promises: a Level 2 readiness effort usually runs 9 to 18 months from a standing start, and small contractors commonly spend in the tens of thousands to low six figures across tooling, migration, consulting, and the assessment itself, with ongoing annual costs after that. Companies that already run tight, well-documented IT land at the low end. Companies starting from a peer-to-peer network and personal Gmail land at the high end.
Level 3: for the most sensitive programs
Level 3 adds a further set of enhanced controls from NIST SP 800-172 on top of Level 2 and is assessed by the government itself. It applies to a small slice of contractors on the most sensitive programs. If you need Level 3, you will know from your contracting officer; do not plan for it speculatively.
Why the corridor context matters
Three local realities shape how Maryland contractors should approach this:
- Primes are flowing requirements down early. The large integrators around Fort Meade and along the Route 32 and BW Parkway corridor are asking subcontractors for SPRS scores and certification status now, ahead of contractual deadlines, because a non-compliant sub is a risk to the prime's own award. Expect your certification status to become a line item in teaming decisions.
- Certified talent is nearby but in demand. The region has an unusual density of assessors, consultants, and MSPs with clearances and CMMC practices. That is good news for choice and bad news for wait times: C3PAO assessment calendars book out months ahead. If your window is 2027, your assessment should be scheduled in 2026.
- Small shops carry the same rules as big ones. A 12-person machine shop in Glen Burnie holding CUI drawings faces the same 110 controls as a 500-person integrator. The difference is that scoping, shared enclaves, and outsourced security operations matter far more when you cannot amortize compliance across a large headcount.
A sane roadmap
- Determine your level. Read your contracts and DFARS clauses, ask your primes in writing, and map where CUI actually flows. Many companies discover they can eliminate CUI from most of their systems entirely.
- Score yourself against NIST 800-171. An honest gap assessment produces your SPRS score and your real to-do list. Expect the first score to be humbling; that is normal.
- Scope an enclave. Decide what is in and out. Smaller scope, smaller cost, smaller audit.
- Remediate in dependency order. Identity and MFA first, then the CUI environment migration, then logging and monitoring, then documentation, then the behavioral controls, with evidence collected as you go.
- Run a mock assessment, then book the real one. A dry run against the official assessment guide catches documentation gaps while they are cheap to fix.
Choosing IT help without getting burned
CMMC has attracted both excellent providers and opportunists, and telling them apart is the buying decision that determines everything downstream. Questions that separate them: How many clients have you taken through a Level 2 assessment, and can we speak to one? Do you run your own environment at the standard you sell (an MSP touching your CUI environment has compliance obligations of its own)? Will you commit in writing to which of the 110 controls you own, which we own, and which are shared? Vague answers to that last question are the classic failure mode: responsibility gaps between contractor and provider are among the most common findings in failed assessments.
This is also a procurement problem, not just a technical one, and it rewards structure. A written requirements document and a competitive process surface the pretenders quickly; that is exactly what our RFP service exists for, and our IT project management service can carry the remediation plan through to the assessment date. Commitments on response times and responsibilities belong in the contract itself, and our guide to MSP SLAs covers what to demand there. The one thing not to do is wait: every quarter of delay narrows your assessment options and hands bids to competitors who started earlier.
Find an MSP that has done CMMC before
We match Maryland defense contractors with vetted providers who have real Level 1 and Level 2 track records, and the matching service is free to you.
Start Your Free Match