Executive summary

On September 16, 2026, NIST published SP 1352, Assessing Security Requirements for Controlled Unclassified Information (CUI): NIST SP 800-171A, Revision 3 — Small Business Primer. The guide is aimed directly at small-business owners and employees responsible for implementing SP 800-171 Rev. 3, performing self-assessments, or preparing to work with external assessors.

For small defense contractors, the practical value is significant: the primer explains how to think about assessment scope, evidence, assessment methods, findings, and preparation in a way that can improve the quality of a cybersecurity readiness program.

But there is an important distinction.

As of September 28, 2026, the Department's public CMMC guidance still states that CMMC Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2. The Department also announced on July 13, 2026 that CMMC Phase II requirements were suspended while Phase I self-assessment requirements remained in place.

So the new NIST primer should be treated as useful assessment guidance and a view into the direction of federal CUI assessment practice—not as permission to silently replace the current CMMC Level 2 baseline with Revision 3.

For a small defense contractor, the right move is to use the primer to improve assessment discipline while continuing to follow the requirements that actually apply to its solicitations, contracts, flow-downs, and current CMMC phase.

Why NIST SP 1352 matters to small defense contractors

NIST says the purpose of SP 1352 is to help the small-business community understand foundational SP 800-171A Rev. 3 assessment concepts and basic strategies for planning an assessment.

That matters because many small defense contractors do not fail readiness work because they have never heard of NIST SP 800-171. They struggle because implementation, evidence, ownership, scope, and assessment preparation are disconnected.

A control may exist in practice but not be documented. A policy may exist but not match the actual configuration. A managed service provider may operate a technical safeguard without the contractor being able to explain how it works. A System Security Plan may list an environment that has changed since it was written.

A good readiness process has to connect those pieces.

NIST SP 800-171A provides the assessment methodology used to evaluate whether security requirements are implemented. The new small-business primer makes that assessment mindset more accessible to organizations that do not have a large compliance or security staff.

Primary source: NIST SP 1352 — Small Business Primer

What the new primer does not change about CMMC today

The publication of a newer NIST assessment guide does not automatically rewrite a defense contractor's current contractual requirements.

The Department's current small-business cybersecurity guidance describes CMMC Level 2 as requiring protection of CUI through the 110 security requirements in NIST SP 800-171 Revision 2, with either a self-assessment or C3PAO assessment depending on the solicitation.

In addition, the Department's July 13, 2026 announcement suspended the planned Phase II expansion that had been scheduled for November 10, 2026. The announcement explicitly said Phase I self-assessment requirements remain in place and that contractors remain responsible for safeguarding covered defense information when applicable.

That means a contractor should distinguish between three things:

  1. The security and assessment guidance NIST is publishing now.
  2. The CMMC requirements currently incorporated into the program and acquisition documents.
  3. The specific clauses and flow-downs that apply to the contractor's actual work.

Blurring those categories can create expensive mistakes.

Primary sources:

What a CMMC readiness assessment should actually prove

A readiness assessment should do more than produce a spreadsheet of "met" and "not met."

It should establish whether the organization can support its security claims with evidence tied to the real environment.

NIST SP 800-171A Rev. 3 explains that assessment procedures can use different assessment methods and objects to determine whether safeguards are implemented as intended. The methodology is designed to examine implementation, not merely the existence of written policy.

For a small business, that translates into a practical question:

Could an independent person follow the evidence and reach the same conclusion you did?

A useful readiness review should therefore connect each applicable requirement to:

  • the system or service where the requirement is implemented;
  • the responsible owner;
  • the relevant policy or procedure;
  • configuration evidence;
  • logs, screenshots, exports, tickets, or other artifacts where appropriate;
  • the method used to validate implementation;
  • exceptions or limitations;
  • remediation ownership; and
  • the date the evidence was last validated.

That is the difference between an evidence package and a folder full of screenshots.

Five actions small defense contractors should take now

1. Reconfirm the assessment boundary

Before reviewing controls, determine which systems actually process, store, or transmit CUI and which systems provide security protection for those environments.

NIST's CUI assessment guidance states that the System Security Plan describes the system boundary, operating environment, implementation of requirements, and relationships or connections to other systems. The assessment scope is informed by that SSP.

For a small contractor, boundary mistakes can create unnecessary cost in either direction.

An overly broad boundary can pull ordinary corporate systems into a high-control environment. An overly narrow boundary can exclude systems, identities, administrators, external service providers, or data flows that materially affect CUI.

Start with the data flow, not the product list.

Related HostBreach guide: CMMC Enclave vs. Whole-Company Scope

2. Build evidence around assessment methods, not screenshots alone

Assessment preparation is stronger when the organization understands what an assessor may need to examine, interview, and test, rather than collecting static screenshots without context.

Evidence should answer questions such as:

  • What does this artifact prove?
  • Which requirement does it support?
  • Which system is it from?
  • Who generated it?
  • Is it current?
  • Can the implementation be reproduced or demonstrated?
  • Does the documented procedure match actual operations?

The new NIST primer is useful because it helps small organizations understand assessment mechanics before they are under assessment pressure.

3. Separate policy existence from implementation

A policy can say that access is reviewed quarterly. That does not prove the review occurred.

A procedure can say logs are retained. That does not prove the configured retention period matches the statement.

A diagram can show a secure enclave. That does not prove users, administrators, remote-support tools, backups, or integrations stay inside the intended boundary.

Readiness work should test the connection between written requirements and operating reality.

4. Keep current CMMC and contract requirements as the controlling baseline

Use newer NIST material to improve preparation and future-proof the program, but do not change the formal CMMC assessment baseline without verifying the governing rule, solicitation, contract, and official Department guidance.

The Department's current CMMC cybersecurity page still describes Level 2 around NIST SP 800-171 Revision 2.

For organizations subject to Phase I self-assessment requirements, that means the current self-assessment has to be supportable against the applicable baseline—not against whatever standard is newest in a browser search.

5. Treat readiness as an operational security exercise

A readiness project is most valuable when it improves both assessment outcomes and real resilience.

The goal should not be to create the largest possible evidence repository. It should be to make the environment understandable, defensible, and harder to compromise.

That includes validating:

  • identity and privileged access;
  • external exposure;
  • remote administration;
  • email security;
  • vulnerability management;
  • logging and alerting;
  • incident-response responsibilities;
  • backup and recovery;
  • supplier dependencies; and
  • whether security controls still operate after system changes.

This is where a threat-informed CMMC approach adds value. Compliance evidence shows what the organization says it has implemented. Outside-in intelligence can help identify which exposures an attacker could observe before authentication and where those observations should influence remediation priorities.

External intelligence does not determine CMMC compliance and does not replace an internal assessment. It is an additional risk-prioritization layer.

A practical readiness sequence for a small business

A small contractor can structure readiness work into six stages:

Stage 1 — Contract and information analysis

Identify the clauses, customer expectations, FCI/CUI obligations, and business opportunities driving the work.

Stage 2 — Scope and data flow

Map where CUI is received, created, stored, transmitted, administered, backed up, and shared.

Stage 3 — Requirement implementation review

Evaluate the applicable requirements against the real environment rather than relying only on policy statements.

Stage 4 — Evidence validation

Create an evidence index and verify that artifacts actually support the claimed implementation.

Stage 5 — Remediation and retest

Fix technical and procedural gaps, then verify the fix.

Stage 6 — Assessment rehearsal

Have someone who did not implement the control attempt to follow the SSP, evidence, and operating procedure.

That last step often exposes ambiguity before an external assessor does.

What should leadership ask before declaring itself "ready"?

A business owner, CEO, COO, CIO, or affirming official should be able to ask:

  • Can we identify exactly where CUI exists?
  • Can we explain the boundary without relying on one person's memory?
  • Do our written policies match how employees and administrators actually work?
  • Can we reproduce the evidence behind our self-assessment?
  • Have we validated inherited controls from cloud, MSP, MSSP, and other providers?
  • Are remediation items owned and dated?
  • Do we know which requirements are contractual today versus anticipated later?
  • If an assessor asks us to demonstrate a control, can we do it without building the evidence during the meeting?

If the answer to several of these is no, the organization may have implemented useful security controls but still lack assessment readiness.

Where HostBreach fits

HostBreach provides Threat-Informed CMMC Advisory for small and midsized defense contractors preparing for CMMC and related CUI security obligations.

Our approach combines internal readiness work—scope, SSP, POA&M, evidence, implementation validation, and assessment preparation—with passive outside-in intelligence that helps leadership understand what is visible from an attacker's perspective.

HostBreach is not a C3PAO, and an external exposure review does not determine CMMC compliance.

If you are trying to determine whether your current environment and evidence are actually ready for assessment, start with HostBreach CMMC Advisory or review the CMMC Cyber Snapshot.

Sources