Cyberuptive

DFARS · CMMC · small U.S. defense contractors

Small Defense Contractor
90-Day Cybersecurity Playbook

A practical 90-day plan for 25–100 employee U.S. defense contractors to establish a defensible DFARS baseline, prepare for CMMC, and build the evidence to prove it.

Executive summary

Cybersecurity is now a contract-readiness function.

For a 25–100 employee DoD subcontractor, cybersecurity has three practical drivers: DFARS 252.204-7012, CMMC Level 2 readiness where the contract requires it, and downstream requirements from the prime. The clause is already present in many defense contracts. It requires adequate security for covered defense information, cyber-incident reporting within 72 hours, and 90-day preservation of specified data. This playbook gets you from uncertain to defensible in 90 days on a small-business budget.

The objective is not to buy every security product. It is to create a small, known system boundary; put accountable controls around it; document how they operate; and retain evidence that the implementation is real. Level 2 maps to the 110 requirements in NIST SP 800-171 Rev. 2. That makes scoping, identity, endpoints, logging, backups, policies, and evidence the early work—not a documentation exercise reserved for the last month.

Who this is for

Small U.S. defense contractors that need a repeatable operating baseline

25–100 employees

Teams with limited IT capacity that need a focused sequence, not a multi-year transformation program.

FCI or CUI in scope

Organizations that handle Federal Contract Information only, or process, store, or transmit Controlled Unclassified Information.

Any contract stage

Pre-award firms preparing to bid, in-award teams responding to prime requests, and post-award organizations closing gaps.

Use the contract, solicitation, and prime flowdowns to determine the required CMMC level and assessment path. The DoD CMMC program page and the Cyber AB explain the program and ecosystem roles; they do not replace legal or contracting advice for a specific award.

Non-negotiable baseline

What you must have regardless of CMMC phase

These are contract and operating fundamentals. A later assessment date does not make them optional.

1. DFARS 252.204-7012 baseline

Identify where the clause appears, which systems handle covered defense information, and who owns the response path. Read the incorporated clause, not a vendor summary.

2. A current SPRS self-assessment

DFARS 7019 and 7020 connect NIST SP 800-171 DoD Assessments to contract actions. Retrieve the current record, underlying calculation, assessment date, and expiration assumptions.

3. An SSP and POA&M

Your System Security Plan must describe the actual boundary and implementation. Your POA&M should identify real remaining work, owners, milestones, and risk—not paper over missing basics.

4. Incident reporting capability

Practice the decision path for a covered cyber incident, including the 72-hour report through DIBNet, evidence preservation, executive notification, and prime coordination.

Days 1–30 · Foundation phase

Find the boundary before you buy the stack.

The first month produces the decisions that make every later dollar useful: what is in scope, what the contract requires, and what must be true in the identity and endpoint layers.

Task 1

Scope CUI

Map the data, repositories, endpoints, email, cloud services, users, admins, and suppliers that touch CUI. Mark excluded systems too.

Artifact: CUI data-flow diagram and asset list

Task 2

Inventory contracts

Pull all prime flowdowns and DFARS 7012, 7019, 7020, and 7021 clauses. Assign a contracting owner for interpretations.

Artifact: Clause register and owner list

Task 3

Check SPRS

Pull the existing score, assessment date, and evidence. Understand the delta from the 110-point maximum before making claims to a prime.

Artifact: Score worksheet and gap list

Task 4

Set the identity foundation

Evaluate Microsoft 365 GCC High or a Commercial tenant with a strict, enforced CUI boundary. Each choice has licensing, administration, data-flow, and assurance trade-offs.

Artifact: Approved identity and tenant decision

Task 5

Baseline endpoints

Create an authoritative device inventory and select EDR. Trellix, CrowdStrike, and Microsoft Defender are neutral platform options; validate fit against your boundary and operations.

Artifact: Device inventory and EDR rollout plan

Foundation budget estimate

$15K–$40K

Typical estimate for scope, assessment, architecture choices, initial endpoint work, and targeted advisory help. Major migrations are additional.

Days 31–60 · Controls phase

Turn the boundary into controls people can operate.

This month makes the small environment measurable. Assign an owner and evidence source for each task. Security tooling is useful only when alerts, access changes, backups, and user behavior create an operating record.

Task 6: MFA on all accounts

Cover users, administrators, remote access, cloud applications, and service-provider portals. Maintain a documented exception process; do not leave legacy protocols as the workaround.

Artifact: MFA coverage report and exception register

Task 7: Basic privileged access management

Use individual, separate administrator accounts. Eliminate shared credentials, remove stale elevated access, and review privileged roles on a defined cadence.

Artifact: Privileged-access roster and review record

Task 8: Logging and monitoring

Centralize identity, endpoint, firewall, and critical cloud logs. A SIEM or managed SOC can help if responsibilities, access paths, alert escalation, and retention are documented. See SOC as a Service.

Artifact: Log-source inventory and escalation runbook

Task 9: Harden email

Use Proofpoint, Microsoft Defender for Office 365, or comparable protection. Configure phishing and malware defenses, mail authentication, mailbox auditing, forwarding limits, and CUI handling rules.

Artifact: Email security configuration and test results

Task 10: Backups that restore

Apply the 3-2-1 rule: three copies, two media types, one offsite copy. Add immutable or otherwise protected copies and test a representative restore, including the time and owner.

Artifact: Backup map and restore-test record

Task 11: Train the workforce

Use KnowBe4, Proofpoint Security Awareness, or comparable training. Track completion, campaign results, role-specific follow-up, and how personnel report suspicious messages.

Artifact: Training completion and campaign records

Task 12: Approve five essential policies

Start with Acceptable Use, Access Control, Incident Response, Data Handling, and Remote Work. Policies should name actual systems, roles, escalation paths, and review frequency. A copied template is useful only after it is tailored to the way your team works.

Artifact: Approved policy set, version history, and acknowledgement record

Controls budget estimate: $25K–$70K

Estimate includes licenses, rollout support, hardening, monitoring, backup improvements, training, and policy development. Costs move most when the endpoint count, tenant choice, log-retention requirements, and unmanaged legacy systems change.

Days 61–90 · Assessment prep

Make the implementation explainable.

The last month is where documented statements meet operating evidence. Do not wait for an assessor to find a difference between the SSP and the environment.

  1. Task 13

    Final self-assessment

    Assess all 110 requirements against the scoped system, record the result, and challenge unsupported “met” answers.

  2. Task 14

    Write the SSP

    Document the boundary and a control-by-control implementation statement with owners, services, and evidence references.

  3. Task 15

    Maintain the POA&M

    Create a clear record for valid remaining gaps, owners, milestones, dependencies, and management decisions.

  4. Task 16

    Build the evidence library

    File screenshots, logs, policies, training, access reviews, tickets, test results, and management approvals by control.

  5. Task 17

    Submit SPRS status

    Submit or update your assessment score through SPRS, and retain the underlying math and source material.

  6. Task 18

    Engage an RPO review

    Ask a qualified RPO or CMMC advisor to test scope, implementation statements, and evidence quality. Review the CMMC MSSP buyer guide.

  7. Task 19

    Schedule a C3PAO

    If certification is required for your award, schedule an independent C3PAO after readiness review. A C3PAO performs the assessment; an RPO helps prepare.

  8. Assessment-prep budget estimate

    $20K–$50K

    Estimate for final assessment work, SSP and POA&M support, evidence organization, readiness review, and certification scheduling support. Independent assessment and significant remediation may be separate.

For a deeper cost and scheduling model, see the CMMC Level 2 timeline and cost guide and the CMMC readiness checklist.

Total 90-day investment

$60K–$160K

Estimated total, depending on current posture, CUI boundary, technical debt, Microsoft tenant decision, endpoint count, log retention, remediation, internal labor, and assessment path.

Review managed SOC pricing

After 90 days

Operate, review, and affirm.

A defensible environment needs continuous monitoring, quarterly evidence updates, annual affirmation activity where required, and incident tabletop exercises. Make control ownership a management routine: review privileged access, device coverage, backup restores, security training, POA&M milestones, and significant changes to the CUI boundary. CMMC is an operating model, not a binder.

Outside help vs. DIY

Choose help based on complexity, not optimism.

Below 25 employees and with no CUI, a disciplined internal team may handle much of the work using official guidance and a narrow scope. At 25 or more employees, or with any CUI, engage an RPO and/or MSSP for scoping, hardening, documentation, and ongoing operations. The right outside team should make responsibilities and evidence clearer—not make the organization dependent on a black box.

Avoidable failures

The five mistakes that make small contractors harder to defend

  1. 01

    Assuming Commercial M365 is enough for CUI

    Treat the tenant as a scope and assurance decision, not a product label.

  2. 02

    Waiting for a prime to ask for SPRS

    Know the current score, date, and supporting record before a bid or supplier review.

  3. 03

    Buying tools before scoping CUI

    An expensive tool cannot correct an undefined system boundary or data flow.

  4. 04

    Copying a peer’s SSP

    The plan must describe your environment, owners, services, and evidence—not someone else’s.

  5. 05

    Treating CMMC as a one-time project

    The assessment only tests whether controls are operating. Build the operating model first.

Grants and cost mitigation

Use public resources without budgeting against an unverified grant.

The DoD DIB Cybersecurity Program is a useful starting point for program context and defense-industry resources. For general cyber hygiene and planning, CISA maintains small-business cybersecurity resources that can support internal awareness and baseline work. If your cyber investment also advances a product or technical R&D roadmap, review the official SBIR/STTR program for relevant solicitations and eligibility.

State cybersecurity assistance changes frequently in availability, location, eligibility, and reimbursable costs. Check your state economic-development office, manufacturing extension partnership, and defense-industry office for current DoD-contractor cyber grants before assuming external funding. Keep applications, awards, invoices, and scope statements separate from the evidence that proves control implementation.

FAQ

Questions small defense contractors ask before starting

How much does CMMC cost a small defense contractor?

As a planning estimate, this 90-day playbook budgets $60,000–$160,000 depending on the current environment, scope, remediation work, licensing, and outside support. Treat that as an estimate, not a certification quote.

Can a 20-person defense contractor become CMMC certified?

Yes. Size does not prevent certification. The decisive questions are the CMMC level required by the contract, the systems in scope, the CUI data flow, and whether the organization can implement and sustain the required practices.

What is DFARS 252.204-7012?

It is the DFARS safeguarding and cyber-incident reporting clause. It requires contractors to provide adequate security for covered defense information, report covered cyber incidents within 72 hours, and preserve specified data for 90 days.

Do I need GCC High as a small subcontractor?

Not automatically. GCC High is a platform decision informed by CUI scope, contract requirements, cloud service eligibility, administration model, and data flows. A commercial Microsoft 365 tenant needs a deliberately enforced boundary if it is outside the CUI environment.

How do I submit my SPRS score?

Complete a NIST SP 800-171 DoD Assessment, calculate the score against the 110 requirements, and submit the score and assessment date in the Supplier Performance Risk System using the access and process DoD provides. Keep the underlying assessment, SSP, and POA&M.

What's the minimum SPRS score to bid?

There is no single universal minimum score that makes every contractor eligible to bid. Solicitation terms, DFARS clauses, and prime requirements control. The practical requirement is often a current, supportable score and a credible plan for gaps—not a number chosen from a generic checklist.

Can I DIY CMMC or do I need an MSSP?

A very small FCI-only organization may complete much of the work internally. At 25 or more employees, or with any CUI, outside readiness and managed-security help is usually more economical than trying to create a durable operating model from scratch.

How long does small-business CMMC take?

Ninety days can establish a scoped, documented, defensible baseline when leadership commits resources. Certification timing can take longer because remediation depth, evidence maturity, contract requirements, and C3PAO availability vary.

What tools do I need at minimum?

At minimum, establish managed identity with MFA, device inventory and endpoint protection, secure email, backups with tested restore, central logging or monitoring, vulnerability and patch management, and a controlled evidence repository. Tools support controls; they are not the control set by themselves.

Is Microsoft 365 Commercial enough for CUI?

Not by default. Some organizations deliberately keep Commercial outside the CUI boundary, but they must enforce that boundary and document it. Do not assume a commercial tenant is an approved CUI location merely because it has good security features.

How do I handle CUI in email?

Use the approved CUI system boundary for sending, receiving, storing, and protecting the message and attachments. Restrict auto-forwarding, monitor mailbox access, train users to recognize CUI, and do not route it into unapproved shared mailboxes, ticketing systems, or consumer file-sharing tools.

What if we don't handle CUI — just FCI?

You may be in a different requirement set. Confirm the contract and prime flowdowns, then implement the safeguarding requirements that apply to FCI. Do not self-classify solely from an informal email; obtain a written determination from the contracting and program teams.

Do we need a formal Incident Response plan?

Yes. A short, tested incident response plan is a baseline operational control. It should name decision-makers, escalation contacts, evidence-preservation steps, legal and contract notifications, and the 72-hour reporting decision path when DFARS 252.204-7012 applies.

How do I get financing or grants for CMMC?

Start with DoD DIB Cybersecurity Program resources, SBIR/STTR opportunities related to your technology roadmap, and your state economic-development office. State programs change frequently; verify current eligibility and eligible costs before building them into a budget.

What happens if our prime audits us?

Expect requests for current SPRS status, an SSP, POA&M, CUI boundary narrative, policy set, evidence samples, and incident process. Provide accurate, scoped material. Do not substitute a generic attestation or another company’s templates for evidence of your own environment.

For current program and clause details, review DFARS 252.204-7012, the SPRS portal, NIST SP 800-171 Rev. 2, the Cyber AB, and CISA. Contract language and incorporated requirements control.

Small-business CMMC readiness

Start with a defendable scope, then build the evidence.

Cyberuptive helps U.S. defense contractors translate contracts, CUI data flows, controls, and operating evidence into an executable cybersecurity program.