If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Who Is Exempt from CMMC, and Why “We Only Make Parts” Usually Isn’t
A CMMC exemption is a real thing, and a much narrower thing than most contractors hope. This article covers the exemptions that actually exist, then works through the four arguments contractors make most often — the ones that feel obviously correct and don’t hold. For the underlying clause mechanics, see DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires.
The honest framing: some of you genuinely are exempt. If that’s you, this page will tell you so and you can stop spending money on this. But the reasoning has to be right, because “we assumed it didn’t apply” is not a position that survives a prime’s questionnaire or a government assessment.
The exemptions that are real
You have no federal contracts and no federal data
Straightforward. The obligations flow from contract clauses. No contract, no clause. Companies selling exclusively commercial-to-commercial have nothing here.
Worth checking honestly, though — a single subcontract to a prime counts, and companies sometimes have one buried in a division nobody thinks about.
Your contracts contain no cybersecurity clauses
Also real, and worth verifying rather than assuming. Pull your active contracts and search for the clause numbers. Some contract types genuinely don’t carry them.
Note that FAR 52.204-21 has very broad application — if you hold a federal contract and exchange working documents with the government, you likely have Federal Contract Information and therefore that clause. See FAR 52.204-21 and the 15 basic safeguarding requirements. It’s a light obligation, but it isn’t zero.
You handle FCI but never CUI
This is the most common legitimate position, and it’s a good one. It means fifteen basic safeguarding requirements rather than 110, no government cloud, no SPRS score, no third-party assessment.
The catch is that it’s a scoping conclusion, not an assumption. It has to be based on knowing what data you actually receive — which is exactly where the “we only make parts” argument falls apart.
Certain commercial-item and COTS acquisitions
There is a genuine carve-out here, and it is routinely over-read. It turns on the specific acquisition type and on whether services attach to the product. Commercial-item and COTS contracts covers where the exception actually stops.
Argument 1: “We only make parts”
This is the most common and the most consistently wrong.
The reasoning goes: we’re a machine shop, we don’t have CUI, we just make what the drawing says. But the drawing is the CUI.
Controlled Technical Information is a defined CUI category covering technical data with military or space application — engineering drawings, specifications, standards, process sheets, test reports, and manufacturing instructions. If a prime sent you a drawing to make a part for a defense program, that drawing is very likely CTI.
The part isn’t the issue. The information you needed in order to make it is.
This catches machine shops, fabricators, PCB assemblers, and specialty manufacturers constantly — precisely the companies least likely to have thought of themselves as handling controlled information. If a drawing arrived by email and sits on a shared drive, the obligation attached the moment it landed.
Argument 2: “We’re too small”
There is no size threshold. None of these clauses contain an employee count, a revenue floor, or a small business carve-out.
The reason this argument feels right is that the requirements were clearly written with larger organizations in mind, and the burden on a twelve-person shop is genuinely disproportionate. That’s a fair criticism of the policy. It is not an exemption.
DoD’s own CIO has acknowledged the cost problem — Small Business Administration data cited during the CMMC review suggested future phases could cost small and midsize businesses billions annually, and reducing that burden is an explicit goal of the reform work. But the obligations as written today apply regardless of headcount.
Argument 3: “We’re a subcontractor, not a prime”
Flowdown is the entire mechanism by which these requirements reach the supply chain. Being a sub is not an exemption; it is the normal case.
DFARS 252.204-7012, 7020, and 7021 all flow down to subcontractors whose performance involves the covered information, as does FAR 52.204-21 where FCI is involved. Your obligations arrive through your subcontract rather than directly from the government, but they arrive.
Two wrinkles worth knowing. Your prime should tell you what data you’ll receive and whether it’s CUI — many don’t, and it’s worth asking in writing before award. And since the July 2026 CMMC suspension, note that the suspension binds DoD, not primes — a prime may keep certification requirements in subcontract terms regardless. Flowdown: which clauses you must pass to your subcontractors covers both directions.
Argument 4: “We don’t store it, we just look at it”
The clause language is process, store, or transmit. All three, not just storage.
Opening a drawing in an email client processes it. Viewing it on a laptop puts it in memory and usually in a temp file. Forwarding it transmits it. A cloud drive that syncs it to a workstation stores it in two places.
Variants of this argument that also fail:
- “We delete it after.” The obligation attached while you had it, and deletion doesn’t undo the exposure window.
- “It’s on the prime’s system, we just log in.” Better than most alternatives, and it can genuinely reduce scope — but the endpoint you log in from is usually in scope, and the arrangement needs documenting.
- “Only one person sees it.” Scope can be reduced to one person and one machine. That’s a good outcome. It is not zero.
What the CMMC suspension did not exempt
Since July 2026 this argument has appeared in a new form: “CMMC is suspended, so we’re fine.”
The July 13, 2026 suspension paused CMMC Phase 2 — the mandatory third-party C3PAO assessments scheduled to begin that November. DoD stated explicitly that contractors remain contractually obligated to safeguard covered defense information.
Unaffected and still in force: DFARS 252.204-7012 in full, Phase 1 Level 1 and Level 2 self-assessments, SPRS score posting under 7019, the government’s assessment authority under 7020, and annual affirmations. DIBCAC can still assess you. See DFARS 252.204-7019 vs 7020 vs 7021 for what each clause still triggers.
What the suspension removed was the deadline. The obligations, and the False Claims Act exposure attached to misrepresenting them, are unchanged.
How to actually determine whether you’re exempt
Four questions, in order. Answer honestly.
- Do we hold any federal contract or subcontract? If no, you’re done.
- Do any of them contain FAR 52.204-21, DFARS 252.204-7012, 7019, 7020, or 7021? Search the documents rather than relying on memory.
- What information do we actually receive under those contracts? Look at real deliverables and real email — drawings, specifications, technical data, test reports, program details. Not what you think you receive.
- Does any of it fall in a CUI category? Controlled Technical Information is the one that catches manufacturers. Export-controlled data under ITAR or EAR is the other.
If you get to question four and the answer is genuinely no, you have an FCI-only obligation and this is a much smaller project than you feared.
If the answer is yes, or if you can’t tell, the useful next move is scoping — establishing which systems and people actually touch the data, so the boundary is as small as it can defensibly be. That’s also the input to vendor and partner selection, since your suppliers inherit whatever you conclude.
A new contract, a new prime, or a change in what a prime sends you are all trigger events that can move you from exempt to not. This is a question to revisit, not answer once.
Frequently asked
Questions about this topic
Is there a small business exemption from CMMC or DFARS cybersecurity clauses?
Does a machine shop that only makes parts handle CUI?
Are subcontractors exempt from CMMC and DFARS requirements?
Does the CMMC suspension mean we are exempt now?
If we only view CUI and never store it, are we in scope?
Keep reading
More in Contract Clauses & Flowdown
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers →
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires →
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors →
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements →
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements →
- Flowdown: Which Clauses You Must Pass to Your Subcontractors →
- What DFARS 252.204-7012 Requires, in Plain English →
- What to Do When a DFARS Clause Appears in a Contract You Already Signed →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5