Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
Who Is Exempt from CMMC, and Why “We Only Make Parts” Usually Isn’t
A CMMC exemption is a real thing, and a much narrower thing than most contractors hope. This article covers the exemptions that actually exist, then works through the four arguments contractors make most often — the ones that feel obviously correct and don’t hold. For the underlying clause mechanics, see DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.
The honest framing: some of you genuinely are exempt. If that’s you, this page will tell you so and you can stop spending money on this. But the reasoning has to be right, because “we assumed it didn’t apply” is not a position that survives a prime’s questionnaire or a government assessment.
The exemptions that are real
You have no federal contracts and no federal data
Straightforward. The obligations flow from contract clauses. No contract, no clause. Companies selling exclusively commercial-to-commercial have nothing here.
Worth checking honestly, though — a single subcontract to a prime counts, and companies sometimes have one buried in a division nobody thinks about.
Your contracts contain no cybersecurity clauses
Also real, and worth verifying rather than assuming. Pull your active contracts and search for the clause numbers. Some contract types genuinely don’t carry them.
Note that FAR 52.204-21 has very broad application — if you hold a federal contract and exchange working documents with the government, you likely have Federal Contract Information and therefore that clause. See FAR 52.204-21 and the 15 basic safeguarding requirements. It’s a light obligation, but it isn’t zero.
You handle FCI but never CUI
This is the most common legitimate position, and it’s a good one. It means fifteen basic safeguarding requirements rather than 110, no government cloud, no SPRS score, no third-party assessment.
The catch is that it’s a scoping conclusion, not an assumption. It has to be based on knowing what data you actually receive — which is exactly where the “we only make parts” argument falls apart.
Certain commercial-item and COTS acquisitions
There is a genuine carve-out here, and it is routinely over-read. It turns on the specific acquisition type and on whether services attach to the product. Commercial-item and COTS contracts covers where the exception actually stops.
Argument 1: “We only make parts”
This is the most common and the most consistently wrong.
The reasoning goes: we’re a machine shop, we don’t have CUI, we just make what the drawing says. But the drawing is the CUI.
Controlled Technical Information is a defined CUI category covering technical data with military or space application — engineering drawings, specifications, standards, process sheets, test reports, and manufacturing instructions. If a prime sent you a drawing to make a part for a defense program, that drawing is very likely CTI.
The part isn’t the issue. The information you needed in order to make it is.
This catches machine shops, fabricators, PCB assemblers, and specialty manufacturers constantly — precisely the companies least likely to have thought of themselves as handling controlled information. If a drawing arrived by email and sits on a shared drive, the obligation attached the moment it landed.
Argument 2: “We’re too small”
There is no size threshold. None of these clauses contain an employee count, a revenue floor, or a small business carve-out.
The reason this argument feels right is that the requirements were clearly written with larger organizations in mind, and the burden on a twelve-person shop is genuinely disproportionate. That’s a fair criticism of the policy. It is not an exemption.
DoD’s own CIO has acknowledged the cost problem — Small Business Administration data cited during the CMMC review suggested future phases could cost small and midsize businesses billions annually, and reducing that burden is an explicit goal of the reform work. But the obligations as written today apply regardless of headcount.
Argument 3: “We’re a subcontractor, not a prime”
Flowdown is the entire mechanism by which these requirements reach the supply chain. Being a sub is not an exemption; it is the normal case.
DFARS 252.204-7012, 7020, and 7021 all flow down to subcontractors whose performance involves the covered information, as does FAR 52.204-21 where FCI is involved. Your obligations arrive through your subcontract rather than directly from the government, but they arrive.
Two wrinkles worth knowing. Your prime should tell you what data you’ll receive and whether it’s CUI — many don’t, and it’s worth asking in writing before award. And since the July 2026 CMMC suspension, note that the suspension binds DoD, not primes — a prime may keep certification requirements in subcontract terms regardless. Flowdown: which clauses you must pass to your subcontractors covers both directions.
Argument 4: “We don’t store it, we just look at it”
The clause language is process, store, or transmit. All three, not just storage.
Opening a drawing in an email client processes it. Viewing it on a laptop puts it in memory and usually in a temp file. Forwarding it transmits it. A cloud drive that syncs it to a workstation stores it in two places.
Variants of this argument that also fail:
- “We delete it after.” The obligation attached while you had it, and deletion doesn’t undo the exposure window.
- “It’s on the prime’s system, we just log in.” Better than most alternatives, and it can genuinely reduce scope — but the endpoint you log in from is usually in scope, and the arrangement needs documenting.
- “Only one person sees it.” Scope can be reduced to one person and one machine. That’s a good outcome. It is not zero.
What the CMMC suspension did not exempt
Since July 2026 this argument has appeared in a new form: “CMMC is suspended, so we’re fine.”
The July 13, 2026 suspension paused CMMC Phase 2 — the mandatory third-party C3PAO assessments scheduled to begin that November. DoD stated explicitly that contractors remain contractually obligated to safeguard covered defense information.
Unaffected and still in force: DFARS 252.204-7012 in full, Phase 1 Level 1 and Level 2 self-assessments, SPRS score posting under 7019, the government’s assessment authority under 7020, and annual affirmations. DIBCAC can still assess you. See DFARS 252.204-7019 vs 7020 vs 7021 for what each clause still triggers.
What the suspension removed was the deadline. The obligations, and the False Claims Act exposure attached to misrepresenting them, are unchanged.
How to actually determine whether you’re exempt
Four questions, in order. Answer honestly.
- Do we hold any federal contract or subcontract? If no, you’re done.
- Do any of them contain FAR 52.204-21, DFARS 252.204-7012, 7019, 7020, or 7021? Search the documents rather than relying on memory.
- What information do we actually receive under those contracts? Look at real deliverables and real email — drawings, specifications, technical data, test reports, program details. Not what you think you receive.
- Does any of it fall in a CUI category? Controlled Technical Information is the one that catches manufacturers. Export-controlled data under ITAR or EAR is the other.
If you get to question four and the answer is genuinely no, you have an FCI-only obligation and this is a much smaller project than you feared.
If the answer is yes, or if you can’t tell, the useful next move is scoping — establishing which systems and people actually touch the data, so the boundary is as small as it can defensibly be. That’s also the input to vendor and partner selection, since your suppliers inherit whatever you conclude.
A new contract, a new prime, or a change in what a prime sends you are all trigger events that can move you from exempt to not. This is a question to revisit, not answer once.
Common questions about CMMC exemption
Is there a small business exemption from CMMC or DFARS cybersecurity clauses?
No. None of these clauses contain a size threshold, employee count, or revenue floor. The requirements apply regardless of company size. Reducing the burden on small businesses is an explicit goal of the CMMC reform work, but no exemption exists today.
Does a machine shop that only makes parts handle CUI?
Usually yes. Controlled Technical Information is a CUI category covering technical data with military or space application, including engineering drawings, specifications, and manufacturing instructions. If a prime sends a drawing to make a defense part, that drawing is very likely CTI. The part is not the issue — the information needed to make it is.
Are subcontractors exempt from CMMC and DFARS requirements?
No. Flowdown is the mechanism by which these requirements reach the supply chain. DFARS 252.204-7012, 7020, and 7021 all flow down to subcontractors whose performance involves the covered information, as does FAR 52.204-21 where FCI is involved.
Does the CMMC suspension mean we are exempt now?
No. The July 2026 suspension paused CMMC Phase 2 third-party certification assessments. DFARS 252.204-7012 remains fully in force, as do Phase 1 self-assessments, SPRS score posting, annual affirmations, and the government’s assessment authority. The suspension removed a deadline, not the obligations.
If we only view CUI and never store it, are we in scope?
Yes. The clause language covers processing, storing, or transmitting. Opening a drawing processes it, viewing it typically creates temporary files, and forwarding it transmits it. Scope can often be reduced to a small number of systems and people, which is a good outcome, but it is not zero.
Next step: Question three above — what information do we actually receive — is where this gets decided, and it’s harder than it sounds. The CUI Scoping Workbook is a fillable 15-page workbook for working through it and defining the smallest defensible boundary. Free, no email required.
Last reviewed: August 2026. CMMC program status is under review; verify current requirements against official sources before acting.