Yes. If your construction or architecture firm handles Controlled Unclassified Information (CUI) as part of a DoD contract or subcontract, CMMC applies to you, typically at Level 2. CMMC requirements now affect an estimated 300,000+ organizations across the defense supply chain, and there is no small-business exception. Even firms with as few as 15-20 computers can fall under the same 110 NIST SP 800-171 controls as a large manufacturer. The requirement is based on the data you touch, not your company size or industry.

How to Know If Your Project Involves CUI

Most standard construction and architecture work only requires CMMC Level 1, which covers 17 basic controls focused on who can access your systems and data. But the moment your project touches CUI, you're in Level 2 territory. Common examples in construction and architecture include:

  • Design files, blueprints, or specifications for secure or restricted-access facilities
  • Site plans or infrastructure details for active military installations
  • Technical data tied to a specific DoD program, even if the building itself is unclassified

If none of the above applies and you're only handling Federal Contract Information (FCI), such as basic project schedules or invoices, Level 1 self-assessment is likely sufficient.

CMMC Level 1 vs. Level 2 for Construction & Architecture Firms

Level 1 (17 controls): Self-assessed. Covers basic cyber hygiene, controlling system access, using antivirus, and backing up data. Achievable in weeks for a reasonably run IT environment.

Level 2 (110 controls): Applies when you handle CUI, such as sensitive facility blueprints or classified specs. This is the same standard manufacturers face, and it typically takes 12-18 months to implement from a standing start.

This is where many architecture firms get caught off guard: they assume they're Level 1 because "we're not IT people," when the specific project they're bidding on actually requires Level 2.

The 3-Step Path to Compliance for Non-Manufacturing DoD Contractors

Step 1: Scope your CUI. Identify exactly which projects, files, and systems touch CUI versus FCI. This determines your required level.

Step 2: Gap assessment against NIST 800-171. A qualified assessor compares your current environment to the 110 controls (if Level 2 applies) and documents where you stand.

Step 3: Remediate and document. Close the gaps, then formalize everything in a System Security Plan (SSP) and Plan of Action & Milestones (POA&M).

Common Mistakes Construction & Architecture Firms Make with CMMC

  • Assuming CMMC is "just an IT thing" rather than a contractual and legal requirement tied to the award itself
  • Missing subcontractor flow-down clauses buried in prime contract language
  • Overlooking physical security controls for job-site laptops, tablets, and printed drawings
  • Waiting until a solicitation demands compliance instead of starting during the bid process, when assessor capacity is already booked months out

What This Means for Your Next Bid Cycle

One important 2026 development: on July 13, 2026, the Department of War suspended the CMMC Phase 2 requirement that would have made third-party C3PAO certification mandatory starting November 10, 2026. A CMMC Reform Task Force is now reviewing the program. That pause does not remove your underlying obligation to implement NIST 800-171 controls and self-assess. It simply pauses the requirement for outside verification while the review runs. Firms that keep building toward Level 2 now will be positioned to win bids regardless of how the review concludes.

Why Construction & Architecture Firms Work With Justice IT Consulting

  • Registered Practitioner Organization (RPO) with Certified CMMC Professionals (CCPs) and Registered Practitioners (RPs) on staff
  • We hold our own CMMC Level 2 certification
  • 4-time Top 250 MSSP in the world, 3-time Top 500 MSP in the world
  • Our team includes an Amazon Best-Selling Author on CMMC compliance and hosts The CMMC Compliance Guide Podcast
  • Family-owned, DFW-based, 60+ five-star Google reviews

Not sure whether your next DoD project puts you in Level 1 or Level 2 territory? Contact Justice IT Consulting for a scope review. We'll tell you plainly where you stand.