For CMMC providers

Prospecting for CMMC compliance providers: defense suppliers on a clock

The best CMMC prospects are defense suppliers at a moment that forces the work: a new defense program, a certification push, an ownership change or a new site. Clean finds those plants and dates the reason, so you reach them while the decision is open.

Book a demo

The short answer

CMMC buyers are hard to find because nothing public shows which subcontractors carry the requirement. The fix is timing: reach a supplier when something forces the work, like a new defense program, open remediation items, a merger or a new site. Clean researches US plants for those moments and gives each supplier a dated reason, its evidence and what would prove it wrong.

Key takeaways

  • As of September 26, 2026, Phase II is suspended, but Phase 1 self-assessments and annual affirmations still apply.
  • DoD estimates a small contractor's Level 2 certification assessment at $104,670 over three years, before implementation.
  • Nothing public shows which subcontractors carry CMMC, so timing beats list size.
  • Mergers and network expansions can require a new assessment, which makes ownership changes and new sites real CMMC moments.
  • Clean dates every reason to reach out and marks what it cannot confirm as unknown.
01

Why CMMC buyers are so hard to find

The requirement travels inside contracts. DoD says contractors and subcontractors entrusted with federal contract information (FCI) or controlled unclassified information (CUI) need a specific CMMC level as a condition of award, and its rule covers how that requirement flows down to subcontractors. Nothing public shows which plants carry that flowdown and which only make commercial parts.

The count is hard even in principle: one company can be a prime on one contract and a sub on others, sometimes under more than one prime.

So CMMC prospecting tends to run on stand-ins: an AS9100 badge, a machining category in a contact database, a defense logo on a website. Those say a plant might touch defense work. They don't say when the work lands on the owner's desk. That gap is why static prospect lists and intent data burn so many first touches in this category.

02

Where CMMC stands today (checked September 26, 2026)

Phase 1 began on November 10, 2025. On July 13, 2026, the Department of War (the name DoD now uses on its own sites) suspended Phase II, which would have made third-party Level 2 certification a condition of award starting November 10, 2026. The DoD CIO site says implementation is paused in Phase 1 while a review runs, and that DoD will enforce NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments.

The implementing memo is blunt. Program offices may only ask for Level 1 (Self) or Level 2 (Self). Third-party requirements come out of active solicitations as soon as practicable, and out of existing contracts at the next option period or scheduled modification. The task force's report was due September 11 and, per a September 21 law firm update, had not been made public. On September 26, 2026 the DoD CIO site still showed the pause, so check it again before you quote any date to a prospect.

The Phase II pause at a glance

Changed by the pauseStill required
No C3PAO certification as a condition of awardLevel 2 self-assessment against 110 NIST SP 800-171 Rev 2 requirements, every three years
Later phases on holdAnnual affirmation, or the status lapses
Third-party requirements leaving contractsLevel 1 annual self-assessment for federal contract information
Whole program under reviewOpen POA&M items closed within 180 days
03

What CMMC costs a small supplier, by DoD's own math

Open the cost conversation with DoD's numbers, then show where you fit. DoD's own cost estimate puts a small contractor's Level 2 certification assessment at $104,670 over three years, including two annual affirmations. DoD models the assessor's fee at $31,234 of that. The rest is the contractor's own hours plus outside prep help. The self-assessment path, which is what Phase 1 asks for, comes to $37,196 over three years.

Neither figure includes implementation. DoD's estimate assumes the NIST controls are already in place. In our view, few small suppliers keep a full-time security team, so the distance between where they are and that assumption is your market. Size the proposal to how the plant approves spending, and see how CMMC deal sizes compare in manufacturing software sales cycles.

04

The four moments that put CMMC on a supplier's desk

Four of the 14 buying moments that Clean sorts a plant's life into match how CMMC obligations attach to a defense supplier, and each carries a clock: the flowdown arrives with a purchase order, a POA&M has 180 days, a merger has a closing date, a new site has a move-in date. A static list of defense suppliers has none of that.

A new program often lands first article and part-approval work on the quality team at the same time, so aim at the owner and IT. The wider pattern is in manufacturing buying signals and new factories and plant expansions.

CMMC buying moments at a defense supplier

Buying momentWhat happens at the plantWhy CMMC work followsWho typically owns it
New customer programWins its first defense program or a new primeThe prime flows the required CMMC level down, and the sub needs it before the subcontract awardOwner or president, plus contracts
Certification pursuitStarts a self-assessment, carries open POA&M items, or wants an outside reviewOpen items run on a 180-day clock, and some contractors still want a third-party reviewIT manager, with the owner signing
Ownership changeA merger, acquisition or add-on combines networksDoD's scoping guidance names mergers and acquisitions as changes that can require a new assessmentNew owner's finance and IT
New siteA new building, line or plant joins the network handling CUINetwork expansion is DoD's other named example of a scope changePlant manager and IT
05

How to sell to defense contractors while Phase II is paused

Sell the affirmation. The certificate can wait. Contracts that carry CMMC still require a self-assessment, and a senior official at the supplier still affirms continuing compliance every year. Skadden's July analysis put it plainly: with self-assessment now the primary enforcement mechanism, False Claims Act exposure is, "if anything, sharper." An affirmation nobody can back up with evidence is now a legal exposure for the supplier.

The work is also unfinished. One 2025 survey by a security vendor, of 364 IT practitioners at small and mid-size defense suppliers, found 71% had started CMMC work, yet just 17% described themselves as Level 2 compliant. The answers are self-reported and not every respondent was a manufacturer, but the gap between started and done is where you sell.

Pitch by role. C3PAOs: Skadden expects an assessment backlog if third-party requirements return, and Covington's September update said there may be benefits to a third-party review even now. RPOs and consultants: scoping, the system security plan, POA&M close-out and the evidence behind each affirmation. Managed security providers: in the same survey, 52% planned changes to their outsourced security provider within a year, but more of those planned to bring security in-house (38%) than to find a new provider (33%).

06

How Clean finds CMMC prospects plant by plant

Clean researches manufacturing accounts at the plant level, so a defense supplier prospect points at the site that handles the work, which is not always headquarters. The early signs Clean has catalogued across all 14 buying moments number more than 4,000, and Clean maps 140+ typical chains of events, such as a first defense contract that sets off a security build-out.

Before a supplier reaches your CMMC team, the reason to call it is dated and paired with its evidence, the rival explanations that could also fit and the finding that would show it wrong. Anything Clean can't confirm (whether a plant already holds a current assessment, for instance) is left marked unknown rather than guessed. Look-alikes such as building contractors, repair shops and one-person operations never reach your list. Under all of it, each plant's history is a dated timeline, read by a temporal graph network, because for a defense supplier the order and spacing of changes (a new program, then a new site) say more than any single one. The method is laid out in how Clean works. Book a demo, and Clean will assemble a live plant list for your CMMC practice during the call.

Common questions

How do CMMC consultants find new clients?

Referrals and broad defense contractor lists are common starting points, and the lists are the weak part: nothing public shows which subcontractors carry a CMMC flowdown. Filter by timing instead. Look for suppliers that just won defense work, are merging or being acquired, are opening a new site, or have open remediation items on a 180-day clock.

Is CMMC still required in 2026?

Partly. As of September 26, 2026, the DoD CIO site says implementation is paused in Phase 1, which began November 10, 2025. Phase II, the third-party certification step, was suspended on July 13, 2026. Self-assessments, annual affirmations and the NIST SP 800-171 Rev 2 requirements still apply to contractors handling federal contract information or controlled unclassified information.

How much does CMMC Level 2 certification cost a small business?

DoD's own cost estimate puts a small contractor's Level 2 certification assessment at $104,670 over three years, including annual affirmations, with the third-party assessor's fee at $31,234 of that. The Level 2 self-assessment path comes to $37,196 over three years. Neither figure includes implementing the controls, which DoD's estimate assumes is already done.

Who buys CMMC services at a manufacturer?

At a small shop the owner or president typically signs, since losing defense work hits the whole company. In mid-size plants an IT manager and whoever manages contracts typically drive the project, with a controller or CFO checking the cost. Small suppliers typically lean on outside service providers rather than a full-time security team.

Can you buy a list of companies that need CMMC?

Not an accurate one. The requirement flows from primes to subcontractors inside contracts, and nothing public shows which subs carry it. Even the count is hard, since one company can be a prime on one contract and a sub on others. Generic defense contractor lists mix real CUI handlers with commercial-only shops.

Sources

  1. 01Cybersecurity Maturity Model Certification, U.S. Department of War, Office of the Chief Information Officer, Accessed 2026-09-26
  2. 02About CMMC, U.S. Department of War, Office of the Chief Information Officer, Accessed 2026-09-26
  3. 03Implementing Suspension of CMMC Phase II (memo, Attachment 1: CMMC Procedures), U.S. Department of War, Office of the Chief Information Officer, 2026-07-13
  4. 04CMMC Scoping Guide, Level 2 (Version 2.13), U.S. Department of War, Office of the Chief Information Officer, Accessed 2026-09-26
  5. 05CMMC Certification Cost in 2026: DoD Estimate vs Real Budget (DoD small-entity estimates), The Defense Compliance Report, 2026-09-14
  6. 06CMMC Reform Task Force Updates September 2026, Covington & Burling, Inside Government Contracts, 2026-09-21
  7. 07DOW Suspends CMMC Phase II: What the Pause Means for Contractors Right Now, Skadden, Arps, Slate, Meagher & Flom LLP, 2026-07-23
  8. 08DIB Cybersecurity Maturity Report, 2025 Edition, RADICL, 2025

Next