TEC Communications
The phase-in is over. CMMC requirements are appearing in DoD solicitations and flowing down through prime contractors, and the companies feeling it hardest aren't the primes — they're the Tier 2 and Tier 3 suppliers who never thought of themselves as defense contractors.
If you machine parts that end up in a defense platform, you're in scope. It doesn't matter that your customer is a Michigan manufacturer and not the Pentagon. Requirements flow down the chain.
The regional manufacturing base — Grand Rapids, Holland, Zeeland, Muskegon, Kentwood — is heavy on automotive, office furniture, and precision machining. Plenty of those shops have picked up defense or aerospace work over the last decade as a diversification play. That work is now carrying compliance obligations that the shop floor was never built for.
Three patterns show up over and over:
Flat networks. The CNC machines, the office PCs, the guest Wi-Fi, and the ERP are all on the same broad network segment because that's how it was wired in 2011 and it worked. Under CMMC, that's a problem.
Legacy OT that can't be patched. A press brake controller running Windows 7 embedded, because the vendor never released anything newer and replacing the machine is a six-figure decision. This is solvable — you isolate it and compensate — but it has to be documented as such, not ignored.
Email as the file system. Drawings and specs living in Outlook inboxes and shared USB drives. If any of that is CUI, it's a problem, and for most suppliers it is.
This is the single most expensive mistake we see: companies prepping for Level 2 when they only need Level 1, or assuming Level 1 when their contract says otherwise.
Level 1 covers Federal Contract Information. Fifteen basic safeguarding practices. Annual self-assessment with an executive affirmation in SPRS. It is genuinely achievable for a small shop, and for many suppliers it's all that's required.
Level 2 covers Controlled Unclassified Information. 110 practices from NIST SP 800-171. Most contracts requiring it will require a third-party assessment by a C3PAO, not a self-attestation. This is a real program of work — typically 9–18 months from cold start for a manufacturer with no existing security program.
Your contract or your prime tells you which. Read the DFARS clauses. If it's ambiguous, ask the prime in writing.
For a 60-person manufacturer starting from a typical position:
Months 1–2 — Scope it. Where does CUI enter, where does it live, where does it leave? Draw the boundary as tightly as you legitimately can. Every system inside the boundary is a system you have to secure, document, and assess. Aggressive, honest scope reduction is the biggest cost lever available to you.
Months 2–4 — Gap assessment against all 110 controls. Score yourself in SPRS. It will be negative. Everyone's first score is negative.
Months 4–10 — Remediation. Network segmentation, MFA everywhere, EDR, centralized logging, encrypted storage for CUI, access control tied to actual job roles, an incident response plan somebody has read.
Months 8–14 — Documentation. The System Security Plan and POA&M. Assessors examine evidence, not intentions. Undocumented compliance is non-compliance.
Months 12–18 — Pre-assessment, then the C3PAO engagement.
Uncomfortable but useful ranges for a mid-size West Michigan supplier pursuing Level 2:
Level 1 is a different universe — often under $15,000 all-in if your environment is reasonably modern.
Two things make this less painful than it looks. First, scope reduction: an enclave architecture, where CUI lives in a segmented environment separate from general business operations, can cut remediation cost dramatically. Second, most of what you're buying is security you should have anyway. MFA, EDR, and backups aren't compliance theater — they're what stops the ransomware event that takes your plant down for nine days.
CMMC gets the attention because it's contractual. But the broader exposure for regional manufacturers is vendor risk. Your ERP host, your MSP, your EDI provider, the integrator with remote access to the line — each is a path into your environment.
Minimum viable vendor hygiene: know who has remote access and revoke what's stale, require MFA on every third-party connection, ask for a SOC 2 report from anyone touching your data, and put breach-notification language in contracts. Also — and this is the one nobody does — actually test whether your backups restore. Quarterly. With a stopwatch.
Ask your prime what level your contracts require. Inventory where drawings and specs actually live. Get a current SPRS score, even an ugly one. Then decide whether you're building this internally or bringing in help.
The suppliers who move now will be taking work from the ones who wait. That's the actual competitive dynamic here, and it's already underway across West Michigan.
TEC works with manufacturers across Grand Rapids, Holland, and the lakeshore on segmentation, security stack deployment, and CMMC readiness. Start with a gap assessment today!