Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

Who Is Exempt from CMMC, and Why “We Only Make Parts” Usually Isn’t

CMMC exemption is a real thing, and a much narrower thing than most contractors hope. This article covers the exemptions that actually exist, then works through the four arguments contractors make most often — the ones that feel obviously correct and don’t hold. For the underlying clause mechanics, see DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.

The honest framing: some of you genuinely are exempt. If that’s you, this page will tell you so and you can stop spending money on this. But the reasoning has to be right, because “we assumed it didn’t apply” is not a position that survives a prime’s questionnaire or a government assessment.

The exemptions that are real

You have no federal contracts and no federal data

Straightforward. The obligations flow from contract clauses. No contract, no clause. Companies selling exclusively commercial-to-commercial have nothing here.

Worth checking honestly, though — a single subcontract to a prime counts, and companies sometimes have one buried in a division nobody thinks about.

Your contracts contain no cybersecurity clauses

Also real, and worth verifying rather than assuming. Pull your active contracts and search for the clause numbers. Some contract types genuinely don’t carry them.

Note that FAR 52.204-21 has very broad application — if you hold a federal contract and exchange working documents with the government, you likely have Federal Contract Information and therefore that clause. See FAR 52.204-21 and the 15 basic safeguarding requirements. It’s a light obligation, but it isn’t zero.

You handle FCI but never CUI

This is the most common legitimate position, and it’s a good one. It means fifteen basic safeguarding requirements rather than 110, no government cloud, no SPRS score, no third-party assessment.

The catch is that it’s a scoping conclusion, not an assumption. It has to be based on knowing what data you actually receive — which is exactly where the “we only make parts” argument falls apart.

Certain commercial-item and COTS acquisitions

There is a genuine carve-out here, and it is routinely over-read. It turns on the specific acquisition type and on whether services attach to the product. Commercial-item and COTS contracts covers where the exception actually stops.

Argument 1: “We only make parts”

This is the most common and the most consistently wrong.

The reasoning goes: we’re a machine shop, we don’t have CUI, we just make what the drawing says. But the drawing is the CUI.

Controlled Technical Information is a defined CUI category covering technical data with military or space application — engineering drawings, specifications, standards, process sheets, test reports, and manufacturing instructions. If a prime sent you a drawing to make a part for a defense program, that drawing is very likely CTI.

The part isn’t the issue. The information you needed in order to make it is.

This catches machine shops, fabricators, PCB assemblers, and specialty manufacturers constantly — precisely the companies least likely to have thought of themselves as handling controlled information. If a drawing arrived by email and sits on a shared drive, the obligation attached the moment it landed.

Argument 2: “We’re too small”

There is no size threshold. None of these clauses contain an employee count, a revenue floor, or a small business carve-out.

The reason this argument feels right is that the requirements were clearly written with larger organizations in mind, and the burden on a twelve-person shop is genuinely disproportionate. That’s a fair criticism of the policy. It is not an exemption.

DoD’s own CIO has acknowledged the cost problem — Small Business Administration data cited during the CMMC review suggested future phases could cost small and midsize businesses billions annually, and reducing that burden is an explicit goal of the reform work. But the obligations as written today apply regardless of headcount.

Argument 3: “We’re a subcontractor, not a prime”

Flowdown is the entire mechanism by which these requirements reach the supply chain. Being a sub is not an exemption; it is the normal case.

DFARS 252.204-7012, 7020, and 7021 all flow down to subcontractors whose performance involves the covered information, as does FAR 52.204-21 where FCI is involved. Your obligations arrive through your subcontract rather than directly from the government, but they arrive.

Two wrinkles worth knowing. Your prime should tell you what data you’ll receive and whether it’s CUI — many don’t, and it’s worth asking in writing before award. And since the July 2026 CMMC suspension, note that the suspension binds DoD, not primes — a prime may keep certification requirements in subcontract terms regardless. Flowdown: which clauses you must pass to your subcontractors covers both directions.

Argument 4: “We don’t store it, we just look at it”

The clause language is process, store, or transmit. All three, not just storage.

Opening a drawing in an email client processes it. Viewing it on a laptop puts it in memory and usually in a temp file. Forwarding it transmits it. A cloud drive that syncs it to a workstation stores it in two places.

Variants of this argument that also fail:

  • “We delete it after.” The obligation attached while you had it, and deletion doesn’t undo the exposure window.
  • “It’s on the prime’s system, we just log in.” Better than most alternatives, and it can genuinely reduce scope — but the endpoint you log in from is usually in scope, and the arrangement needs documenting.
  • “Only one person sees it.” Scope can be reduced to one person and one machine. That’s a good outcome. It is not zero.

What the CMMC suspension did not exempt

Since July 2026 this argument has appeared in a new form: “CMMC is suspended, so we’re fine.”

The July 13, 2026 suspension paused CMMC Phase 2 — the mandatory third-party C3PAO assessments scheduled to begin that November. DoD stated explicitly that contractors remain contractually obligated to safeguard covered defense information.

Unaffected and still in force: DFARS 252.204-7012 in full, Phase 1 Level 1 and Level 2 self-assessments, SPRS score posting under 7019, the government’s assessment authority under 7020, and annual affirmations. DIBCAC can still assess you. See DFARS 252.204-7019 vs 7020 vs 7021 for what each clause still triggers.

What the suspension removed was the deadline. The obligations, and the False Claims Act exposure attached to misrepresenting them, are unchanged.

How to actually determine whether you’re exempt

Four questions, in order. Answer honestly.

  1. Do we hold any federal contract or subcontract? If no, you’re done.
  2. Do any of them contain FAR 52.204-21, DFARS 252.204-7012, 7019, 7020, or 7021? Search the documents rather than relying on memory.
  3. What information do we actually receive under those contracts? Look at real deliverables and real email — drawings, specifications, technical data, test reports, program details. Not what you think you receive.
  4. Does any of it fall in a CUI category? Controlled Technical Information is the one that catches manufacturers. Export-controlled data under ITAR or EAR is the other.

If you get to question four and the answer is genuinely no, you have an FCI-only obligation and this is a much smaller project than you feared.

If the answer is yes, or if you can’t tell, the useful next move is scoping — establishing which systems and people actually touch the data, so the boundary is as small as it can defensibly be. That’s also the input to vendor and partner selection, since your suppliers inherit whatever you conclude.

A new contract, a new prime, or a change in what a prime sends you are all trigger events that can move you from exempt to not. This is a question to revisit, not answer once.

Common questions about CMMC exemption

Is there a small business exemption from CMMC or DFARS cybersecurity clauses?

No. None of these clauses contain a size threshold, employee count, or revenue floor. The requirements apply regardless of company size. Reducing the burden on small businesses is an explicit goal of the CMMC reform work, but no exemption exists today.

Does a machine shop that only makes parts handle CUI?

Usually yes. Controlled Technical Information is a CUI category covering technical data with military or space application, including engineering drawings, specifications, and manufacturing instructions. If a prime sends a drawing to make a defense part, that drawing is very likely CTI. The part is not the issue — the information needed to make it is.

Are subcontractors exempt from CMMC and DFARS requirements?

No. Flowdown is the mechanism by which these requirements reach the supply chain. DFARS 252.204-7012, 7020, and 7021 all flow down to subcontractors whose performance involves the covered information, as does FAR 52.204-21 where FCI is involved.

Does the CMMC suspension mean we are exempt now?

No. The July 2026 suspension paused CMMC Phase 2 third-party certification assessments. DFARS 252.204-7012 remains fully in force, as do Phase 1 self-assessments, SPRS score posting, annual affirmations, and the government’s assessment authority. The suspension removed a deadline, not the obligations.

If we only view CUI and never store it, are we in scope?

Yes. The clause language covers processing, storing, or transmitting. Opening a drawing processes it, viewing it typically creates temporary files, and forwarding it transmits it. Scope can often be reduced to a small number of systems and people, which is a good outcome, but it is not zero.


Next step: Question three above — what information do we actually receive — is where this gets decided, and it’s harder than it sounds. The CUI Scoping Workbook is a fillable 15-page workbook for working through it and defining the smallest defensible boundary. Free, no email required.

Last reviewed: August 2026. CMMC program status is under review; verify current requirements against official sources before acting.

Table of Contents