There’s been a lot of noise on LinkedIn this week about the Army and Navy making CMMC a prerequisite for SBIR/STTR funding. Some of it has been accurate. Some of it has been vague enough to generate clicks without actually helping anyone understand what changed or what to do about it.

I pulled the primary source. Here’s what it says and what it means for small businesses competing for DoD innovation funding.

What the BAA Actually Says

The Navy’s DoW 2026 SBIR CSO Release 1 — published this week — contains a topic from NAVWAR (Naval Information Warfare Systems Command) for resilient wideband RF photonic architectures. It’s a serious technical topic involving assured communications and PNT in contested electromagnetic environments. ITAR-restricted. Likely to go classified in Phase II.

Inside the topic description, in plain text:

Projected CMMC Level Requirement: Level 2 (Self)

And in the proposal submission instructions section, applicable across all topics in the CSO:

“DOW has established the CMMC Program to verify that awardees have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC Level requirements are identified within each topic. Proposing SBCs should anticipate that a Projected CMMC Level for Phase II award may be higher than the Projected CMMC Level advertised in the Phase I topic.”

That last sentence is the one that matters most.

What Level 2 (Self) Actually Means

CMMC Level 2 maps to all 110 controls in NIST SP 800-171 Rev 2. For a self-assessment, there’s no third-party assessor involved — you’re conducting your own assessment, scoring it, and uploading that score to SPRS along with an annual executive affirmation.

That sounds manageable. And for a firm that has already been doing the work, maintaining an SSP, tracking a POAM, actually implementing the controls, it is manageable.

For a firm that has been ignoring 800-171 because “CMMC wasn’t enforced yet,” it’s a significant lift. All 110 controls. A documented System Security Plan. A POAM for anything not fully implemented. A score in SPRS before award.

Not before your next option period. Before award.

The Phase II Problem

Here’s where it gets harder for SBIR firms specifically.

Phase I CMMC levels are projected at the time the topic is published. The BAA is explicit that the Phase II level may be higher. For a topic like the NAVWAR one above, a jump from Level 2 Self to Level 2 C3PAO between Phase I and Phase II is essentially expected.

What does that mean practically?

A C3PAO assessment requires engaging an accredited third-party assessment organization through the Cyber AB marketplace. Lead times are currently running three to six months just to get on the schedule. The assessment itself takes weeks. Remediation of findings takes additional time. The full cycle from “we should probably get assessed” to “we have a CMMC Level 2 certification in eMASS” is realistically six to twelve months for most small businesses.

Phase I SBIR awards are typically four to six months long.

If you win a Phase I award today and wait until the Phase I Final Report is submitted to start thinking about your C3PAO assessment, you will not be certified in time for Phase II award. The math doesn’t work.

The Cost Proposal Angle

The BAA also says this:

“Proposing SBCs should carefully review and consider the CMMC requirements as compliance may impact proposed costs and technical approach.”

This is the government telling you to price it in. CMMC readiness costs are allowable on SBIR contracts. The Technical and Business Assistance (TABA) provision exists specifically to help small businesses address compliance costs — though TABA is not available for Phase I open topics under this particular CSO.

If your Phase II cost proposal doesn’t account for the cost of achieving and maintaining CMMC Level 2 certification, you’re either underbidding or you’re hoping the requirement goes away. Neither is a good position.

The SPRS Requirement

Separate from CMMC level, the BAA explicitly requires a current NIST SP 800-171 assessment score uploaded to SPRS as a condition of award. This is DFARS 252.240-7997 territory. No active SPRS entry, no award.

This isn’t new regulation… The requirement to conduct and document a 800-171 assessment has existed since 2017. What’s new is the enforcement posture. Contracting officers now have clear language in the solicitation to check SPRS before making an award. Firms that have never submitted an assessment score are now disqualifiable at award, not just technically non-compliant on paper.

What This Means for SBIR/STTR Firms Right Now

If you are a small business competing for DoD SBIR or STTR funding, here is the practical checklist:

Before you submit a proposal:

  • Check whether the topic you’re targeting has a projected CMMC level. It’s in the topic description.

  • Make sure you have an active SPRS entry with a current 800-171 self-assessment score.

  • If you don’t have an SSP, build one. This is the foundational document for any CMMC assessment.

If you win Phase I:

  • Start your C3PAO assessment process immediately if Phase II is likely to require L2 C3PAO.

  • Build CMMC readiness costs into your Phase II proposal narrative and cost volume.

  • Do not wait until Phase II selection notification to start thinking about this.

If you’re a Phase II firm today:

  • Verify your CMMC posture against the level required in your current contract.

  • If you’re on self-assessment and your contract is moving toward option periods that may require C3PAO, get in the queue now.

The Bigger Picture

This isn’t an Army-specific change or a Navy-specific change. It’s the DFARS rule that went into effect November 10, 2025 working exactly as designed. CMMC requirements are now embedded in solicitations at the topic level. The level can escalate between phases. SPRS compliance is a condition of award.

The firms that treated CMMC as a future problem are now finding it in the solicitation they’re responding to this month.

The good news is that Level 2 self-assessment is achievable for a small business that approaches it systematically. The 110 controls in NIST 800-171 are well-documented. The assessment process is straightforward if your environment is well-scoped and your documentation is in order. This is solvable. But it requires starting, and starting now.

If you’re an SBIR/STTR firm trying to figure out where you stand, feel free to reach out. This is exactly the kind of problem we help defense contractors work through at Init Cyber.