Defense Logistics Agency suppliers got a special Christmas gift: detailed estimates of CMMC requirements by DLA supply class! The Defense Department buys a lot of different products and services and the estimates make it clear that different types of contractors will experience CMMC requirements in very different ways. If only we could get every agency and mega prime to put out info like this.
Transcript
[Music]
All right, folks. Merry Christmas. It’s that time of year. It’s the big special day. And Santa has left a present for Defense Logistics Agency suppliers: a breakdown of estimated CMMC requirements by level for each DLA supply class. Depending on the type of work you do, your odds of needing CMMC Level 2 certification instead of a self-assessment might be very low—but they are never going to be zero. Nonzero, if you will. And that’s what we’re going to talk about this week. I don’t think that you were the bearded man and I was the elf that people were looking forward to seeing today, Jacob, but here we are talking about things that are super important. And what kind of gift is this? It’s a great gift. It’s a great gift that’s level-setting expectations for an entire base. It’s saying this is what’s going to happen and this is what you can expect. No surprises here. Let’s talk about it.
For the diehards watching this on Christmas, amazing. We’re happy that you’re checking this out. Probably one of the more insightful episodes we had all year. Honestly, I wish every DoD component and program would put out breakdowns and information the way that DLA has. It’s super cool. They’re setting the model for how I wish the other components would put out this information. Depending on what type of work you do for DLA, this might be a good gift. It might be coal in your stocking. We’ll talk about it when we get to their breakdown.
For those of you who don’t know, the Defense Logistics Agency is the nation’s combat logistics support agency. This is directly from the “What DLA Buys” webpage. If you’re not familiar, they manage the global defense supply chain—everything from raw materials to the items end users actually need for the Army, Navy, Air Force, Marine Corps, Coast Guard, 11 different combatant commands, federal agencies, and partner and allied nations. They manage 86% of the military’s spare parts. They manage 100% of fuel and troop-support consumables. They handle reutilization of military equipment, catalogs, and logistics information for all the products the military buys. They offer document automation and production services for a wide range of military and federal agencies. It’s a big deal. We’re talking hundreds of billions of dollars and tons of material, all managed by DLA. So when DLA says things about CMMC, a lot of people are going to listen. It feels like they touch just about everything. In some way, shape, or form, the seven degrees of separation in the Defense Industrial Base might as well be seven degrees to DLA. Between the Army Corps of Engineers and DLA, we’re talking about an absolute ton of people who are going to be wrestling with CMMC based on how they zig or how they zag.
Let’s talk about supply classes. Supply classes are the way the U.S. military categorizes the goods it procures. Everything from food, water, and condiments like ketchup and mayonnaise—those are Class I. Clothing and cleaning supplies fall into Class II. Jet fuel, jet engines, construction materials, ammunition, missiles, medical supplies, maintenance kits—everything the military buys falls into these supply classes. At a high level, this gets very detailed. Each class has many subclasses, and each subclass has its own distribution requirements and corresponding DoD policies. The DoD buys a lot of stuff. There’s tons of detailed policy about all of it. For our purposes, the takeaway is simple: the Defense Department buys a lot of different kinds of goods. That means a lot of different contractors are doing different kinds of work involving different kinds of data. Some of that data might be controlled. Some of it might be highly controlled. Some of it might not be controlled at all. That means different DLA suppliers will experience CMMC in very different ways depending on the type of work they perform. Even though CMMC gets talked about as this monolithic requirement for all of DoD, even within individual agencies or programs, one company’s experience could be wildly different from another’s in terms of requirements, timelines, self-assessment versus certification, or having requirements at all.
The DLA Small Business website is excellent. They’ve done a very good job of putting everything in one place. Under the DLA Small Business Resource Center, there’s a cybersecurity resource page full of helpful information. It covers foundations of CMMC, the three levels of the model, steps to achieving CMMC, how CMMC applies to automatic versus manual awards, an overview of the phased rollout, external links to training resources like DAU and Project Spectrum, and most importantly, an expected CMMC level breakdown by individual supply class. This is how the program applies to DLA. It’s all on one page. Clear as day. If you need help understanding it, they’ve provided useful links right there. That’s setting your supply chain up for success. You can’t say they didn’t give you the fishing rod, the hook, and the bait.
Definitely check out the chart. Study the supply class that applies to you or your clients. DLA anticipates that 25% of its total procurements will require CMMC. That’s a lot of commercial off-the-shelf procurements that are exempt. DLA buys all kinds of stuff, and a lot of that is commercial. COTS items are exempt from CMMC and DFARS 7012 requirements. But 25% of $150 billion or more annually is still a lot of contracts that will require CMMC. That 25% doesn’t mean you personally have a 25% chance of needing CMMC. It depends entirely on your supply class. Among the supply classes, most requirements are for Level 2 self-assessments, but certification requirements vary widely.
For example, in Class I—food and water—DLA estimates 95% Level 2 self-assessment, 5% Level 2 C3PAO certification, and 0% Level 1. If you’re a Class I vendor, everyone’s going to need Level 2. You might be able to self-assess, but nobody is getting just Level 1. That’s interesting. When you dig into subclasses, there’s a lot more complexity than “CUI ketchup,” but even here, no Level 1-only requirements.
In Class II—clothing and tools—DLA anticipates 70% Level 2 self-assessment, 30% Level 2 C3PAO certification, and 0% Level 1. If you’re familiar with specialized gear—high-speed clothing, specialized materials, even reflective tape—some of that can be sensitive. So it’s not surprising that controlled information may be involved. When we say 0% Level 1, that means no contracts where Level 1 is the highest requirement. If you’re at Level 2, you still must meet Level 1 controls first.
In Class III—fuel and chemicals—DLA estimates 95% Level 1, 4% Level 2, and 1% Level 3. That 1% Level 3 is fascinating. Within one class, you could have Level 1 on one contract and Level 3 on another. The difference between Level 1 and Level 3 is enormous—almost like operating on different planets in terms of cybersecurity obligations.
At the bottom of the chart are service contracts—medical, transportation, logistics, equipment support, and similar services. DLA estimates 1% Level 1, 12% Level 2 self-assessment, 73% Level 2 C3PAO certification, and 10% Level 3. That 10% Level 3 requirement for services is significant. Service contracts often touch multiple systems, data flows, and sensitive operations, so it makes sense. But it’s a big deal.
If you’re a DLA supplier, check out the DLA Small Business cybersecurity page. Study the supply class that applies to you. Understand that your CMMC experience may be very different from others—even within the same agency. Some classes are mostly self-assessment. Some are mostly Level 1. Some have significant Level 3 exposure. CMMC rollout is not monolithic. It is not uniform across agencies, programs, or contractors. It is impossible to predict your specific situation from high-level policy alone. You have to go to your customer—in this case, DLA—and get the specifics. Preparation is the best prevention. There’s no substitute for being ready. Merry Christmas, everybody. I hope you got what you wanted. I hope this information was helpful. And next week, we’ll see you for our prediction show in the new year. See you next week.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.



