CMMC compliance services built for small manufacturers.
VJNetworks helps small manufacturers and defense subcontractors across the Tri-State area meet CMMC and NIST SP 800-171 requirements without pulling anyone off the shop floor for months.
VJNetworks provides CMMC compliance and NIST SP 800-171 readiness services to small manufacturers and defense subcontractors across Rockland County NY, Westchester County NY, and Bergen County NJ. A lot of subcontractors handle Controlled Unclassified Information or Federal Contract Information without realizing it, and that puts a signed government contract at risk the moment a prime checks compliance status in the Supplier Performance Risk System.
You can be on the hook for CMMC and not know it yet.
A drawing that’s already CUI.
A machine shop building one bracket for a prime contractor gets a technical drawing marked with a distribution statement nobody reads twice. That drawing is Controlled Unclassified Information. The subcontract almost certainly already has DFARS 252.204-7012 flowed down into it, whether anyone signed something that said “CMMC” on it or not.
An affirmation you can’t back up.
Contractors self-affirm CMMC compliance annually in the Supplier Performance Risk System. Signing that affirmation when the controls genuinely aren’t in place isn’t a paperwork problem. It’s a False Claims Act exposure, and that statute carries treble damages. Losing the contract is the smaller risk.
None of this means panic. It means finding out, in plain language, whether your shop actually handles CUI or FCI, and if so, exactly which of the 110 NIST SP 800-171 controls apply to your specific network and workflow.
That’s the gap assessment. It takes days, not months, and it tells you where you actually stand.
The rules changed in July 2026. Most of what you’ll read online hasn’t caught up.
CMMC clauses started showing up in DoD contracts on November 10, 2025, requiring Level 1 self-assessment for FCI and Level 2 self-assessment for CUI. That part never changed and it’s still fully in force today.
What was supposed to happen next was Phase 2: starting November 10, 2026, contracts involving CUI would start requiring an actual third-party C3PAO assessment instead of self-attestation. On July 13, 2026, the Department of Defense suspended that transition. A 60-day CMMC Reform Task Force is reviewing the program, with public comments accepted through August 14, 2026.
Worth being precise about what actually changed. It’s a policy pause, not a repeal. NIST SP 800-171 implementation is still required, DFARS clauses 252.204-7012, 7019, and 7020 are still enforceable, annual SPRS affirmation is still mandatory, and flowdown obligations to subcontractors haven’t gone anywhere. What’s paused is the requirement for a paid third-party assessor to sign off on Level 2. Self-assessment against the same 110 controls is still exactly as real an obligation as it was in June.
Not every contractor needs the same level.
Protects Federal Contract Information. 15 basic safeguarding requirements. Annual self-assessment, no third party involved. Most subcontractors that only touch FCI land here.
Protects Controlled Unclassified Information. 110 requirements pulled from NIST SP 800-171 Revision 2 across 14 domains. Self-assessment or C3PAO third-party assessment, depending on what the contract designates. This is where most manufacturers handling drawings and specs land.
Reserved for CUI facing the most sophisticated threats. Builds on Level 2 plus NIST SP 800-172 enhanced controls. Assessed directly by the government’s own DIBCAC team. A small slice of the highest-risk contractors, not a typical small manufacturer.
Eight pieces of work, scoped to your contract.
Not every shop needs every item on this list. A gap assessment tells us which ones actually apply before we quote anything.
NIST SP 800-171 Gap Assessment
We check your environment against all 110 controls and tell you exactly what’s already covered and what isn’t, in plain language.
CUI & FCI Data Flow Mapping
We trace exactly where sensitive government data lands on your network, whose laptop it touches, and where it shouldn’t be sitting.
SSP & POA&M Documentation
The System Security Plan and Plan of Action & Milestones a real assessor or auditor will actually ask to see, written and kept current.
MFA, EDR & Logging Buildout
The technical controls that make up most of the 110 requirements, implemented without ripping out what already works on your shop floor.
SPRS Score Management
Your Supplier Performance Risk System score kept accurate and current, so the annual affirmation is something you can actually stand behind.
C3PAO Assessment Readiness
If your contract ends up requiring third-party certification, we get your evidence and documentation ready before an assessor ever shows up.
Employee Security Awareness Training
CUI handling procedures your floor supervisors and office staff can actually follow, not a slideshow nobody remembers a week later.
Ongoing Compliance Monitoring
Controls drift after go-live. We keep watching so next year’s affirmation is a five-minute check-in, not a scramble.
Not sure which of these apply to you?
That’s exactly what the free assessment answers. We’ll tell you honestly.
GET YOUR GAP ASSESSMENT ↗︎Is CMMC actually your problem right now?
Your business has no federal or defense supply chain exposure at all. That’s regular cybersecurity work, a different and simpler conversation.
You’re a large prime with an in-house compliance or GRC team already running this. That’s a bigger engagement than what we’re describing here.
You’re looking for the cheapest possible checkbox. Real CMMC compliance produces documentation an assessor can actually verify, not a certificate for a drawer.
The same track record, applied to a federal requirement.
Four steps from unsure to documented.
Free Gap Assessment
We review your current environment against all 110 NIST SP 800-171 controls and tell you exactly where you stand.
Scoped Remediation Plan
Your SSP and POA&M, written in plain language and prioritized by what’s actually exploitable first.
Implementation
MFA, EDR, logging, and CUI handling procedures go in alongside your production schedule, not instead of it.
Ongoing Monitoring
SPRS score kept current, controls monitored for drift, so next year’s affirmation isn’t a scramble.
About CMMC compliance.
What company helps small manufacturers become CMMC compliant?
VJNetworks provides CMMC compliance and NIST SP 800-171 readiness services for small manufacturers and defense subcontractors across Rockland County NY, Westchester County NY, and Bergen County NJ. We run the gap assessment, build the SSP and POA&M, put the required technical controls in place, and keep your SPRS score current, with 22 years of experience and a 97% client retention rate behind that work.
How do I know if I even need CMMC certification?
Check your subcontract for DFARS clause 252.204-7012 or 252.204-7021, and check any drawings or specs you’ve received for a distribution statement. If either shows up, you’re already in scope whether you knew it or not. A free gap assessment settles it either way in a matter of days.
What’s the difference between CMMC Level 1 and Level 2?
Level 1 covers Federal Contract Information with 15 basic requirements and a yearly self-assessment. Level 2 covers Controlled Unclassified Information with 110 requirements pulled from NIST SP 800-171, and can call for either self-assessment or a third-party C3PAO assessment. Most manufacturers handling technical drawings or specs land at Level 2, not Level 1.
Is CMMC Level 2 third-party certification actually required right now?
As of August 2026, no. The DoD suspended that requirement on July 13, 2026, pending a Reform Task Force review, and public comments are open through August 14, 2026. Level 1 and Level 2 self-assessment are still required in applicable contracts. Third-party assessment could come back once the review closes, so this isn’t a reason to stop preparing.
What happens if I sign an SPRS affirmation that isn’t accurate?
It stops being a compliance question and becomes a False Claims Act question, since the statute carries treble damages and applies to false statements made to the federal government. That risk is exactly why the gap assessment matters before anyone signs anything, not after.
How much does CMMC compliance cost a small manufacturer?
It depends heavily on how far your current setup already is from the 110 controls, so industry figures vary widely and any number we gave you before looking at your environment would be a guess. The gap assessment is free and gives you a real scoped number, not an industry average that may not apply to your shop.
We’re just a small parts supplier. Does CMMC actually apply to us?
Often, yes. CMMC flows down to subcontractors at every tier who process, store, or transmit FCI or CUI, and prime contractors are required to enforce that flowdown under 32 CFR 170.23. Company size isn’t the deciding factor. What’s in the drawing or the purchase order is.
Further reading: the DFARS text of clause 252.204-7021 at Acquisition.gov, the Cyber AB’s overview of C3PAO assessors, and Federal News Network’s coverage of the July 2026 Phase 2 suspension.
Find out where you actually stand before a prime asks.
22 years in the Tri-State area. 97% client retention. A free NIST SP 800-171 gap assessment that tells you the truth about your CUI exposure, not a sales pitch.
