CMMC 2.0 has three levels and most Texas defense subcontractors are confused about which they need. The wrong scope decision costs $30K-$300K and 6-12 months. Here is the decision framework.
CMMC 2.0 has three certification levels and most Texas defense subcontractors we engage with are confused about which level applies to their organization. The decision matters: a wrong scope determination can cost between $30,000 and $300,000 in unnecessary assessment, deployment, and operational overhead — or expose the contractor to compliance failure on the contracts they actually need to satisfy.
This guide is the scoping decision framework for Texas defense subcontractors evaluating their CMMC posture in 2026. It covers what each level requires, the CUI boundary determination that drives level selection, and enclave strategies that minimize Level 2 scope without sacrificing contract eligibility.
Required for contractors handling Federal Contract Information (FCI) only — basic information not intended for public release that you receive from or generate for the federal government in the course of contract performance. 17 controls drawn from FAR 52.204-21. Self-assessment, annual self-attestation. No third-party assessment required. Estimated cost: $5,000-$25,000 for initial deployment + annual attestation.
Required for contractors handling Controlled Unclassified Information (CUI). 110 controls drawn from NIST SP 800-171. Most contractors require third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO); a small subset of "non-prioritized" CUI contracts allow self-assessment. Three-year certification cycle with annual affirmation. Estimated cost: $50,000-$300,000 for initial deployment + $30,000-$80,000 per assessment cycle.
Required for contractors handling CUI on the highest-risk contracts. Adds ~24 enhanced controls drawn from NIST SP 800-172. DIBCAC government-led assessment. Currently affects a small minority of contractors — mostly those handling export-controlled technical data, weapons system design, or critical infrastructure CUI. Estimated cost: $200,000-$1M+.
The single most important question for any Texas defense subcontractor scoping CMMC is: does our organization receive, store, process, or transmit Controlled Unclassified Information?
Indicators you handle CUI:
Indicators you handle FCI only:
If you cannot definitively answer "no CUI" with documented evidence, assume CUI and scope for Level 2.
Most Texas defense subcontractors handle CUI in only a small portion of their environment — specific projects, specific teams, specific systems. Applying Level 2 controls to the entire enterprise dramatically inflates cost and complexity. The mature approach is the CUI enclave: scope Level 2 controls to a defined, isolated enclave that handles all CUI, and exclude the rest of the enterprise.
An effective CUI enclave includes:
The enclave reduces CMMC scope from "your whole company" to "the CUI enclave plus the supporting security/admin infrastructure." For most Texas SMB defense subcontractors, this is the difference between a $300K assessment and a $80K assessment.
CMMC 2.0 final rule implementation is now actively flowing into DoD solicitations. Texas defense primes have begun explicit flow-down requirements to subcontractors. Solicitations issued in late 2026 increasingly require certification within 12-18 months of contract start — meaning subcontractors need to be in active assessment now to maintain eligibility on new awards.
For most Texas SMB defense subcontractors handling CUI: the runway to Level 2 certification is 8-12 months from formal start to assessment. Working backward from the next major contract recompete is the right planning anchor.
For Texas defense subcontractors uncertain of their CMMC scope: pull every active DoD-related contract, scan for DFARS 252.204-7012, document what data you actually receive from each prime, and produce a written CUI determination. This single exercise typically clarifies the scoping question definitively. Then engage a CMMC Registered Practitioner or RP Organization for the formal gap assessment.
For broader CMMC context: CMMC 2.0 compliance service, Texas defense contractor CMMC preparation, CMMC Self-Assessment Tool, CMMC self-assessment guide.
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.