Task 1
Scope CUI
Map the data, repositories, endpoints, email, cloud services, users, admins, and suppliers that touch CUI. Mark excluded systems too.
Artifact: CUI data-flow diagram and asset list
DFARS · CMMC · small U.S. defense contractors
A practical 90-day plan for 25–100 employee U.S. defense contractors to establish a defensible DFARS baseline, prepare for CMMC, and build the evidence to prove it.
Executive summary
For a 25–100 employee DoD subcontractor, cybersecurity has three practical drivers: DFARS 252.204-7012, CMMC Level 2 readiness where the contract requires it, and downstream requirements from the prime. The clause is already present in many defense contracts. It requires adequate security for covered defense information, cyber-incident reporting within 72 hours, and 90-day preservation of specified data. This playbook gets you from uncertain to defensible in 90 days on a small-business budget.
The objective is not to buy every security product. It is to create a small, known system boundary; put accountable controls around it; document how they operate; and retain evidence that the implementation is real. Level 2 maps to the 110 requirements in NIST SP 800-171 Rev. 2. That makes scoping, identity, endpoints, logging, backups, policies, and evidence the early work—not a documentation exercise reserved for the last month.
Who this is for
Teams with limited IT capacity that need a focused sequence, not a multi-year transformation program.
Organizations that handle Federal Contract Information only, or process, store, or transmit Controlled Unclassified Information.
Pre-award firms preparing to bid, in-award teams responding to prime requests, and post-award organizations closing gaps.
Use the contract, solicitation, and prime flowdowns to determine the required CMMC level and assessment path. The DoD CMMC program page and the Cyber AB explain the program and ecosystem roles; they do not replace legal or contracting advice for a specific award.
Non-negotiable baseline
These are contract and operating fundamentals. A later assessment date does not make them optional.
Identify where the clause appears, which systems handle covered defense information, and who owns the response path. Read the incorporated clause, not a vendor summary.
DFARS 7019 and 7020 connect NIST SP 800-171 DoD Assessments to contract actions. Retrieve the current record, underlying calculation, assessment date, and expiration assumptions.
Your System Security Plan must describe the actual boundary and implementation. Your POA&M should identify real remaining work, owners, milestones, and risk—not paper over missing basics.
Practice the decision path for a covered cyber incident, including the 72-hour report through DIBNet, evidence preservation, executive notification, and prime coordination.
Days 1–30 · Foundation phase
The first month produces the decisions that make every later dollar useful: what is in scope, what the contract requires, and what must be true in the identity and endpoint layers.
Task 1
Map the data, repositories, endpoints, email, cloud services, users, admins, and suppliers that touch CUI. Mark excluded systems too.
Artifact: CUI data-flow diagram and asset list
Task 2
Pull all prime flowdowns and DFARS 7012, 7019, 7020, and 7021 clauses. Assign a contracting owner for interpretations.
Artifact: Clause register and owner list
Task 3
Pull the existing score, assessment date, and evidence. Understand the delta from the 110-point maximum before making claims to a prime.
Artifact: Score worksheet and gap list
Task 4
Evaluate Microsoft 365 GCC High or a Commercial tenant with a strict, enforced CUI boundary. Each choice has licensing, administration, data-flow, and assurance trade-offs.
Artifact: Approved identity and tenant decision
Task 5
Create an authoritative device inventory and select EDR. Trellix, CrowdStrike, and Microsoft Defender are neutral platform options; validate fit against your boundary and operations.
Artifact: Device inventory and EDR rollout plan
Foundation budget estimate
$15K–$40K
Typical estimate for scope, assessment, architecture choices, initial endpoint work, and targeted advisory help. Major migrations are additional.
Days 31–60 · Controls phase
This month makes the small environment measurable. Assign an owner and evidence source for each task. Security tooling is useful only when alerts, access changes, backups, and user behavior create an operating record.
Cover users, administrators, remote access, cloud applications, and service-provider portals. Maintain a documented exception process; do not leave legacy protocols as the workaround.
Artifact: MFA coverage report and exception register
Use individual, separate administrator accounts. Eliminate shared credentials, remove stale elevated access, and review privileged roles on a defined cadence.
Artifact: Privileged-access roster and review record
Centralize identity, endpoint, firewall, and critical cloud logs. A SIEM or managed SOC can help if responsibilities, access paths, alert escalation, and retention are documented. See SOC as a Service.
Artifact: Log-source inventory and escalation runbook
Use Proofpoint, Microsoft Defender for Office 365, or comparable protection. Configure phishing and malware defenses, mail authentication, mailbox auditing, forwarding limits, and CUI handling rules.
Artifact: Email security configuration and test results
Apply the 3-2-1 rule: three copies, two media types, one offsite copy. Add immutable or otherwise protected copies and test a representative restore, including the time and owner.
Artifact: Backup map and restore-test record
Use KnowBe4, Proofpoint Security Awareness, or comparable training. Track completion, campaign results, role-specific follow-up, and how personnel report suspicious messages.
Artifact: Training completion and campaign records
Start with Acceptable Use, Access Control, Incident Response, Data Handling, and Remote Work. Policies should name actual systems, roles, escalation paths, and review frequency. A copied template is useful only after it is tailored to the way your team works.
Artifact: Approved policy set, version history, and acknowledgement record
Controls budget estimate: $25K–$70K
Estimate includes licenses, rollout support, hardening, monitoring, backup improvements, training, and policy development. Costs move most when the endpoint count, tenant choice, log-retention requirements, and unmanaged legacy systems change.
Days 61–90 · Assessment prep
The last month is where documented statements meet operating evidence. Do not wait for an assessor to find a difference between the SSP and the environment.
Assess all 110 requirements against the scoped system, record the result, and challenge unsupported “met” answers.
Document the boundary and a control-by-control implementation statement with owners, services, and evidence references.
Create a clear record for valid remaining gaps, owners, milestones, dependencies, and management decisions.
File screenshots, logs, policies, training, access reviews, tickets, test results, and management approvals by control.
Submit or update your assessment score through SPRS, and retain the underlying math and source material.
Ask a qualified RPO or CMMC advisor to test scope, implementation statements, and evidence quality. Review the CMMC MSSP buyer guide.
If certification is required for your award, schedule an independent C3PAO after readiness review. A C3PAO performs the assessment; an RPO helps prepare.
Assessment-prep budget estimate
$20K–$50K
Estimate for final assessment work, SSP and POA&M support, evidence organization, readiness review, and certification scheduling support. Independent assessment and significant remediation may be separate.
For a deeper cost and scheduling model, see the CMMC Level 2 timeline and cost guide and the CMMC readiness checklist.
Total 90-day investment
Estimated total, depending on current posture, CUI boundary, technical debt, Microsoft tenant decision, endpoint count, log retention, remediation, internal labor, and assessment path.
After 90 days
A defensible environment needs continuous monitoring, quarterly evidence updates, annual affirmation activity where required, and incident tabletop exercises. Make control ownership a management routine: review privileged access, device coverage, backup restores, security training, POA&M milestones, and significant changes to the CUI boundary. CMMC is an operating model, not a binder.
Outside help vs. DIY
Below 25 employees and with no CUI, a disciplined internal team may handle much of the work using official guidance and a narrow scope. At 25 or more employees, or with any CUI, engage an RPO and/or MSSP for scoping, hardening, documentation, and ongoing operations. The right outside team should make responsibilities and evidence clearer—not make the organization dependent on a black box.
Avoidable failures
Treat the tenant as a scope and assurance decision, not a product label.
Know the current score, date, and supporting record before a bid or supplier review.
An expensive tool cannot correct an undefined system boundary or data flow.
The plan must describe your environment, owners, services, and evidence—not someone else’s.
The assessment only tests whether controls are operating. Build the operating model first.
Grants and cost mitigation
The DoD DIB Cybersecurity Program is a useful starting point for program context and defense-industry resources. For general cyber hygiene and planning, CISA maintains small-business cybersecurity resources that can support internal awareness and baseline work. If your cyber investment also advances a product or technical R&D roadmap, review the official SBIR/STTR program for relevant solicitations and eligibility.
State cybersecurity assistance changes frequently in availability, location, eligibility, and reimbursable costs. Check your state economic-development office, manufacturing extension partnership, and defense-industry office for current DoD-contractor cyber grants before assuming external funding. Keep applications, awards, invoices, and scope statements separate from the evidence that proves control implementation.
FAQ
As a planning estimate, this 90-day playbook budgets $60,000–$160,000 depending on the current environment, scope, remediation work, licensing, and outside support. Treat that as an estimate, not a certification quote.
Yes. Size does not prevent certification. The decisive questions are the CMMC level required by the contract, the systems in scope, the CUI data flow, and whether the organization can implement and sustain the required practices.
It is the DFARS safeguarding and cyber-incident reporting clause. It requires contractors to provide adequate security for covered defense information, report covered cyber incidents within 72 hours, and preserve specified data for 90 days.
Not automatically. GCC High is a platform decision informed by CUI scope, contract requirements, cloud service eligibility, administration model, and data flows. A commercial Microsoft 365 tenant needs a deliberately enforced boundary if it is outside the CUI environment.
Complete a NIST SP 800-171 DoD Assessment, calculate the score against the 110 requirements, and submit the score and assessment date in the Supplier Performance Risk System using the access and process DoD provides. Keep the underlying assessment, SSP, and POA&M.
There is no single universal minimum score that makes every contractor eligible to bid. Solicitation terms, DFARS clauses, and prime requirements control. The practical requirement is often a current, supportable score and a credible plan for gaps—not a number chosen from a generic checklist.
A very small FCI-only organization may complete much of the work internally. At 25 or more employees, or with any CUI, outside readiness and managed-security help is usually more economical than trying to create a durable operating model from scratch.
Ninety days can establish a scoped, documented, defensible baseline when leadership commits resources. Certification timing can take longer because remediation depth, evidence maturity, contract requirements, and C3PAO availability vary.
At minimum, establish managed identity with MFA, device inventory and endpoint protection, secure email, backups with tested restore, central logging or monitoring, vulnerability and patch management, and a controlled evidence repository. Tools support controls; they are not the control set by themselves.
Not by default. Some organizations deliberately keep Commercial outside the CUI boundary, but they must enforce that boundary and document it. Do not assume a commercial tenant is an approved CUI location merely because it has good security features.
Use the approved CUI system boundary for sending, receiving, storing, and protecting the message and attachments. Restrict auto-forwarding, monitor mailbox access, train users to recognize CUI, and do not route it into unapproved shared mailboxes, ticketing systems, or consumer file-sharing tools.
You may be in a different requirement set. Confirm the contract and prime flowdowns, then implement the safeguarding requirements that apply to FCI. Do not self-classify solely from an informal email; obtain a written determination from the contracting and program teams.
Yes. A short, tested incident response plan is a baseline operational control. It should name decision-makers, escalation contacts, evidence-preservation steps, legal and contract notifications, and the 72-hour reporting decision path when DFARS 252.204-7012 applies.
Start with DoD DIB Cybersecurity Program resources, SBIR/STTR opportunities related to your technology roadmap, and your state economic-development office. State programs change frequently; verify current eligibility and eligible costs before building them into a budget.
Expect requests for current SPRS status, an SSP, POA&M, CUI boundary narrative, policy set, evidence samples, and incident process. Provide accurate, scoped material. Do not substitute a generic attestation or another company’s templates for evidence of your own environment.
For current program and clause details, review DFARS 252.204-7012, the SPRS portal, NIST SP 800-171 Rev. 2, the Cyber AB, and CISA. Contract language and incorporated requirements control.
Small-business CMMC readiness
Cyberuptive helps U.S. defense contractors translate contracts, CUI data flows, controls, and operating evidence into an executable cybersecurity program.