Field Guide · Controlled Unclassified Information
CUI for CMMCThe Ultimate Guide
What Controlled Unclassified Information actually is, how to mark and handle it, what CMMC really requires of you — and the traps that cost defense contractors their eligibility. Every claim below is pinned to a primary source.
196 claims independently fact-checked — 55 corrected, 1 refuted and removed.
Sources: eCFR · Federal Register · NARA CUI Registry · NIST CSRC & CMVP · DoW CIO
CMMC Phase 2 is suspended
On 13 July 2026 the Department of War suspended the November 2026 transition to Phase 2. During the suspension, program managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self), and may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). Contracting officers are directed to amend active solicitations and to remove those requirements from existing contracts by modification. No waivers will be granted during the review.
Two things this does not mean. It is executive, not regulatory — 32 CFR 170.3(e) is untouched and the schedule can restart without rulemaking. And DFARS 252.204-7012 remains fully in force, along with all 110 NIST SP 800-171 Rev 2 requirements, SPRS scoring, self-assessments, annual affirmations, government-led DIBCAC assessments and False Claims Act exposure.
Attachment 1, “Cybersecurity Maturity Model Certification Procedures,” to the 13 July 2026 implementing memorandum (DoW release no. 26-P-1023). The suspension removed the assessor, not the requirement.
Flight plan
01 · Origin
What CUI actually is
Before any control, one question: is this information legally CUI at all? Contractors routinely over-mark and under-mark because they never resolve it.
CUI was created by Executive Order 13556, signed 4 November 2010 and published at 75 FR 68675, which designated NARA as Executive Agent. The government-wide rulebook is 32 CFR Part 2002, issued at 81 FR 63324 and effective 14 November 2016 — and never amended since.
“CUI is a FOIA exemption.” It is not. EO 13556 §2(b) states designation as CUI “shall not have a bearing” on FOIA determinations. Marking something CUI neither creates nor supports a basis for withholding it. This is the single most common misuse of the marking — by government and contractors alike.
The two-prong test
Under 32 CFR 2002.4(h), information is CUI only if it satisfies both a provenance prong (who created or possesses it) and an authority prong (a law, regulation or Government-wide policy requires or permits safeguarding).
The provenance clause ends “…an executive branch agency or an entity acting for an agency.” That trailing phrase is load-bearing: it closes the loophole that data created by a subcontractor rather than by the agency escapes CUI.
32 CFR 2002.1(f) says Part 2002 does not apply directly to non-executive-branch entities. It reaches your company only indirectly, through agreements — today, DFARS 252.204-7012 and your contract terms. Your obligations come from the clause in your contract, not from the CFR standing alone.
Basic vs. Specified — not a severity ladder
The distinction turns solely on whether the underlying authority spells out specific controls — not on sensitivity. 32 CFR 2002.4(r) is explicit: Specified controls “may be more stringent than, or may simply differ from” Basic.
“Specified is the CUI equivalent of Secret.” No. A Specified category can require looser dissemination than Basic. And where a Specified authority is silent, Basic controls fill the gap — stated in four separate places: 2002.4(h), 2002.4(j), 2002.4(r) and 2002.14(b)(2)(ii).
Reading the CUI Registry
The Registry is a live resource, not a snapshot — re-pull it rather than caching it. As of 13 August 2026 the category list carries 128 categories across 20 organizational index groupings. The groupings carry no legal effect; they appear nowhere in Part 2002, and at least one assignment is counterintuitive (Agriculture sits under Intelligence).
| What people say | What the Registry actually shows |
|---|---|
| “There are 124 or 125 categories” | 128 on the category list; the separate Category Marking List carries 126 — the two disagree because they were reviewed on different dates |
| “Every category is Basic or Specified” | NATO Restricted and NATO Unclassified populate neither column. A rule set assuming a binary will mishandle them |
| “Basic banners are always the bare word CUI” | Not always — Net Worth carries the Basic banner CUI//NETW |
| “You can't validate a banner programmatically” | You can, partly: all 56 Specified banners begin CUI//SP-, without exception |
Banner arithmetic reconciles as 56 Specified + 95 Basic − 27 carrying both = 124, plus the 2 NATO rows populating neither = 126.
Legacy markings: void, but still arriving
32 CFR 2002.20(a)(2) is blunt — if legacy markings remain, they “are void and no longer indicate that the information is protected.” But that is the regulatory endpoint, not a description of reality. Discontinuation is conditioned on each agency's CUI EA implementation timeline, and the Registry still carries the banner that existing agency policy remains in effect until that agency implements. You will still receive FOUO-marked material. Protect it, and request a properly marked copy under 2002.20(a)(3).
Do not over-extend “legacy,” though: NATO markings and RD/FRD have their own regimes and are not swept away.
02 · Procedure
Marking & handling
Marking is where guides most often cite the wrong authority — and where an SSP that cites the CFR for a rule the CFR never states becomes a finding.
A banner marking is mandatory and may carry up to three elements in fixed order (32 CFR 2002.20(b)). The control marking may be either “CONTROLLED” or “CUI” at the designator's discretion.
The slash syntax — CUI//CATEGORY/SUBCATEGORY//DISSEM — exists only in the NARA CUI Marking Handbook and the Registry. 32 CFR 2002.20 is silent on separators; it merely says the Registry contains the specific instructions. Do not cite the CFR for the // and / rules.
Distribution statements and export warnings do not belong in the banner. 32 CFR 2002.20(b)(2)(iii): where law or policy requires marking, distribution-limitation or warning statements, agencies “must not include these additional indicators in the CUI banner marking or CUI portion markings.”
You apply the Government's markings — you don't originate your own
Designation authority rests with executive branch agencies. But the common shorthand “contractors never mark” is wrong in the other direction: a contractor creating new CUI under contract does apply markings — it applies the Government's designation rather than inventing one. Contractor-coined markings like CUI//SENSITIVE or COMPANY PROPRIETARY — CUI are non-conformant, because categories and dissemination controls must come from the Registry.
Before performance starts, ask the contracting officer in writing which CUI categories apply, which distribution statement, and which limited dissemination controls. Put the answer in a per-contract CUI handling annex. If the contract flows down CUI obligations but names no categories, raise it as a question — guessing produces both over-marking and under-marking findings.
Dissemination: the default is sharing
Access is governed by “lawful Government purpose,” not need-to-know (32 CFR 2002.16(a)(1)). There are exactly 10 approved Limited Dissemination Controls — and banner and portion forms differ, which breaks validation logic if mixed.
| Banner | Portion | Contractor impact |
|---|---|---|
| NOFORN | NF | No foreign national release |
| FED ONLY | FED ONLY | Excludes you |
| FEDCON | FEDCON | Expressly includes contractors |
| NOCON | NOCON | Excludes you |
| DL ONLY | DL ONLY | Named distribution list only |
| RELIDO | RELIDO | Release determined by originator |
| REL TO [USA, LIST] | REL TO [USA, LIST] | Named countries only |
| DISPLAY ONLY [USA, LIST] | DISPLAY ONLY [USA, LIST] | View, no release |
| Attorney-Client | AC | Privileged |
| Attorney-WP | AWP | Work product |
Those are the only two that categorically exclude contractors. Receiving either should trigger a call to the contracting officer — not a quiet file-save. Note also that only the designating agency may apply LDCs (2002.16(b)(4)(iii)); if you want one, you ask.
Physical handling — and the over-engineering trap
32 CFR 2002.14(c) requires “reasonable precautions,” including keeping CUI under direct control or behind at least one physical barrier. Quote (c)(3) in full and the standard becomes clear: the barrier must actually work — it must “reasonably ensure” protection from unauthorized access or observation outside a controlled environment.
“CUI needs double-wrapping, receipting and couriers.” Unlike classified material under 32 CFR 2001, Part 2002 imposes no double-wrapping, receipting or courier requirement. If double-wrapping is required, it comes from a Specified authority or your contract — not from the CUI rule.
Two package rules that look contradictory but aren't: 2002.14(d)(4) says mark packages per §2002.20, while 2002.20(i)(2) says do not put CUI markings on the outside of an envelope or package. They reconcile because 2002.20(i) is the marking rule for packages — the obligation lands on the contents and inner wrapper.
Destruction
32 CFR 2002.14(f) requires rendering information unreadable, indecipherable and irrecoverable. For paper, NIST SP 800-88 specifies cross-cut shredding to 1 mm × 5 mm particles or smaller.
The common failure
A DIN P-4 office shredder does not meet the 1 mm × 5 mm spec. “Cross-cut” alone is not enough — check the particle spec on the nameplate.
The over-buy
NSA/CSS evaluated equipment is the classified standard and is not mandated for CUI — though the particle size coincides, so one high-security shredder covers both.
Microforms must be burned, with residue reduced to white ash — a shredder is not authorized for microfiche. And destruction is gated twice: only when the agency no longer needs the information and a NARA-approved records schedule allows.
03 · Comms
CUI in email & collaboration
The most-used CUI channel, the most misconfigured, and the one where a single vendor myth drives the largest unnecessary spend in the entire program.
Two different encryption obligations
| Requirement | What it demands | Points |
|---|---|---|
| SC.L2-3.13.8 | Cryptographic mechanisms to prevent disclosure during transmission — this is the one that actually forces email in transit to be encrypted | 3 |
| SC.L2-3.13.11 | FIPS-validated cryptography when CUI leaves your protected environment | 5 |
“We use AES-256, so we're FIPS compliant.” 3.13.11 requires a validated module — an active CMVP certificate, the correct module version, and FIPS mode actually enabled. As Microsoft's own documentation puts it, “FIPS 140 compliant” is an industry term for products that merely rely on validated ones. Simply using an approved algorithm is not sufficient.
Exchange Online uses opportunistic TLS by default, which — in Microsoft's own words — “sends the message without encryption if the recipient's organization doesn't support TLS.” Worse, TLS encrypts the connection, not the message, and forced TLS does not survive the recipient auto-forwarding it onward. Leaving opportunistic TLS as your only control is a findable deficiency.
S/MIME does not encrypt the subject line
Under RFC 8551, header protection is optional (MAY), so essentially no deployment does it. Subjects, recipient lists and metadata traverse in cleartext — and are logged by every hop, including your own mail gateway, archiving system and DLP appliance. The internal logging exposure is usually larger than the wire exposure, and it is what an assessor can actually see.
Rule to enforce with DLP: subject lines may carry the marking indicator and a neutral reference number. No part numbers, no drawing numbers, no program nicknames.
GCC High is not universally required
Microsoft's own DFARS page names both GCC and GCC High/DoD as adequate for DFARS — Commercial is pointedly absent from that list. What forces GCC High is not the word “CUI”. It is a contractual or legal requirement for US-only data residency and US-person access — chiefly ITAR and certain export-controlled technical data.
In both GCC and GCC High, Microsoft support sits outside the accreditation boundary. Microsoft's GCC High page carries the same warning as GCC: support “isn't included in the service accreditation boundary and doesn't provide FedRAMP, DoD SRG, ITAR, IRS 1075, or CJIS data handling compliance assurances.” So “we're in GCC High, therefore support is cleared” is factually wrong. Write a support-ticket procedure either way: never attach CUI to a vendor support case.
The hidden cost of GCC High is external collaboration. Microsoft states GCC High users “will be able to share only with other organizations in GCC-High.” Before signing, list your top 20 external collaborators, check which cloud each is in, and pilot the actual path.
DFARS 252.204-7012(b)(2)(ii)(D) requires FedRAMP Moderate or equivalent — but it also requires the CSP to comply with paragraphs (c) through (g): 72-hour incident reporting, malicious software submission to DC3, 90-day media preservation, forensic access and damage assessment. That contractual commitment is what actually disqualifies vendors, regardless of FedRAMP status.
And the loophole readers reach for is closed: asked whether a non-FedRAMP-Moderate cloud may store encrypted CUI, DoD answers No. Encrypting it does not exempt the provider.
DFARS 252.204-7012(c)(3) requires a DoD-approved medium assurance certificate to report incidents at dibnet.dod.mil. Identity proofing takes weeks — you cannot obtain one inside the 72-hour window. Buy for two named people so a vacation doesn't blow the clock. Note the DIBNet identity certificate and S/MIME email certificates are separate products, priced and issued separately.
04 · Perimeter
Physical security for CUI
Six requirements, three of which can never go on a POA&M — and almost all of them cheap. This is also where the worst over-engineering happens.
CUI is unclassified. The standard is a “controlled environment” plus “at least one physical barrier.” Not a SCIF. Not ICD 705 slab-to-slab construction. Not TEMPEST. Not a GSA-approved container. None of it appears in NIST SP 800-171 or 32 CFR 170. When a proposal quotes it, ask for the citation — you will not get one. A locked door plus a locked cabinet satisfies 2002.14(c).
“Controlled environment” is defined at 32 CFR 2002.4(f) as any area an authorized holder deems to have adequate controls. The standard is holder-determined and risk-based, not a prescriptive hardware spec — so write your own definition into the SSP and defend it.
The six requirements
| Req | What it requires | POA&M? |
|---|---|---|
| 3.10.1 | Limit physical access — reaches the whole operating environment, and explicitly covers contractors and visitors, not just employees | 5 pts |
| 3.10.2 | Protect the facility and support infrastructure — power, distribution, transmission lines | 5 pts |
| 3.10.3 | Escort visitors and monitor visitor activity | Never |
| 3.10.4 | Maintain audit logs of physical access | Never |
| 3.10.5 | Control and manage physical access devices | Never |
| 3.10.6 | Enforce safeguarding at alternate work sites | 1 pt |
3.10.3, 3.10.4 and 3.10.5 can never go on a POA&M — they must be MET on assessment day. A written escort procedure with distinguishable visitor badges, a bound visitor log with a stated retention period, and a key/badge register showing issue, return and revocation will satisfy all three. Days of work, not dollars. Fix these first.
NIST does not require interior logs universally. The actual text: physical access points “can include facility access points, interior access points to systems or system components requiring supplemental access controls, or both.” The trigger is conditional — an interior door needs its own log only where you've determined it requires supplemental control. Don't over-read it; do document your determination.
The support-infrastructure gap
3.10.2 explicitly reaches power and transmission infrastructure, so a locked server room fed by an unlocked electrical closet is an incomplete control — and assessors are trained to catch it. Walk the power and network path, not just the room: the UPS closet, the transfer switch, and the demarc. In a leased suite the demarc is usually in a landlord-controlled closet.
Visual and acoustic exposure is a regulatory requirement, not etiquette — 32 CFR 2002.14(c)(2) requires ensuring unauthorized individuals cannot access, observe, or overhear CUI discussions. Do a sightline walk at dusk from outside the building and from every public corridor, then reorient desks (free) before buying privacy film.
05 · Hardware
Equipment fit for CUI
There is no approved-products list for CUI. There is one requirement that names a standard, and a great deal of marketing that pretends otherwise.
Of all 110 requirements, exactly one mentions FIPS — 3.13.11. There is no NSA-listed hardware mandate for CUI, no approved laptop list, and no certification a vendor can sell you that makes a device “CUI-approved.” What exists is a validated cryptographic module, verifiable by certificate number on the NIST CMVP list.
How to actually verify a product
On the CMVP Validated Modules Search, the vendor's product name is not what matters. Four fields are:
- Certificate status — Active, Historical, or Revoked
- Module version — must match what you actually run
- Tested operational environment — validation is environment-specific
- FIPS mode — a validated module used outside its security policy is not validated crypto
Build a one-page crypto inventory with a row for every place CUI is encrypted — disk, email transport, VPN, Wi-Fi, backup, file transfer, mobile, USB — and record all four fields plus the certificate number. A row with no certificate number is a finding. Treat it as one now.
Every remaining FIPS 140-2 certificate moves to the CMVP Historical List. Expect vendors to sell against that date. The accurate position is narrower: CMVP states plainly that “CMVP supports the purchase and use of these modules for existing systems.” Historical status blocks new federal procurement recommendations — it is not a kill switch. Do not rip out working 140-2 modules that day.
The genuine unresolved problem: the CMMC Assessment Guide and the DoD Assessment Methodology still say “FIPS 140-2” (the methodology even says “140-1 or -2”), and no guidance has been published on how assessors treat a Historical-List certificate afterwards. That is unresolved — plan procurement accordingly rather than assuming an outcome.
The equipment people forget
Multifunction printers
Copiers and MFPs hold hard drives. 3.13.8's discussion names printers, copiers, scanners and fax machines explicitly. Put drive retention or sanitization with a serial-numbered certificate into the lease before the next swap — cheaper than the finding.
Mobile devices
3.1.19 requires CUI encrypted on mobile, inheriting FIPS validation from 3.13.11 and key protection from 3.13.10. Document the CMVP certificate for the mobile crypto module — the step almost everyone skips, and it is the assessment objective's evidence.
Removable media
Media Protection has nine requirements (3.8.1–3.8.9), including marking media with CUI markings — but never the outside of the shipping package. Never degauss flash media; crypto-erase on a self-encrypting drive only counts with a matching CMVP certificate.
End-of-life systems
Unsupported equipment is a compliance failure, not a risk acceptance. Keep an EOL register — every OS, appliance, firmware and application in the CUI boundary with its vendor end-of-support date, refreshed quarterly.
06 · Governance
How CMMC governs CUI
The single most-botched fact in CMMC commentary is that there is one rule. There are two, with different numbers, different agencies and different dates.
| The PROGRAM rule | The ACQUISITION rule | |
|---|---|---|
| Codified | 32 CFR Part 170 | 48 CFR (DFARS) 204, 212, 217, 252 |
| Federal Register | 89 FR 83092 | 90 FR 43560 |
| Published | 15 Oct 2024 | 10 Sep 2025 |
| Effective | 16 Dec 2024 | 10 Nov 2025 |
| RIN | 0790-AL49 | 0750-AK81 |
| What it did | Created the program, levels and assessment ecosystem | Put the clause in contracts |
“CMMC became binding on 16 December 2024.” Nothing became contractually binding on any contractor that day. 10 November 2025 is when a contracting officer could first put the clause in a solicitation. Note the nuance in the other direction too: 32 CFR 170 is a legally effective rule — it simply does not attach to you absent an inserted clause.
Pin-cite carefully: 89 FR 83092 is the first page of the document (preamble); 89 FR 83214 is where the codified regulatory text begins. Citing 83092 for a specific requirement lands you in preamble discussion — persuasive, not binding.
The three levels
Foundational
1
FCI only — not CUI
- Requirements
- 15, from FAR 52.204-21(b)(1)
- Assessment
- Annual self-assessment
- POA&M
- Never permitted
- Certificate
- None — self only
Advanced
2
The CUI level
- Requirements
- 110 · NIST SP 800-171 Rev 2
- Objectives
- 320, via SP 800-171A (Jun 2018)
- Assessment
- Self or C3PAO · 3 years
- POA&M
- Conditional, 180 days
Expert
3
Layered on Level 2
- Requirements
- 24 selected from SP 800-172
- Assessment
- DCMA DIBCAC · 3 years
- Prerequisite
- Perfect 110/110 Level 2 (C3PAO)
- POA&M
- 7 requirements ineligible
There are 15 FAR safeguarding requirements. The table has 17 rows because FAR 52.204-21(b)(1)(ix) splits into three phrases mapping to objectives 3.10.3, 3.10.4 and 3.10.5. People saying “17” are counting mapped objectives, not requirements.
The withdrawn-standard anomaly
CMMC Level 2 is assessed against NIST SP 800-171 Rev 2 and SP 800-171A (June 2018). NIST withdrew both on 14 May 2024. They remain binding anyway, because a fixed-date incorporation by reference under 1 CFR part 51 freezes the edition, and 32 CFR 170.2 has never been amended. NIST's document lifecycle has no effect on the regulation.
“Rev 2 was withdrawn, so I should upgrade to Rev 3.” A contractor who “upgrades” is still assessed against Rev 2 and can fail on requirements Rev 3 dropped. Specifically, PE.L2-3.10.3, 3.10.4 and 3.10.5 map to withdrawn Rev 3 identifiers — and all three are among the six that may never go on a POA&M. You fail, with no remedy. Do a Rev 3 gap analysis if you like; do not reassess or report against Rev 3 in SPRS.
The score is not a count
Scoring starts at 110 and subtracts. Requirements are weighted 5, 3 or 1 — and the floor is −203, a range DOJ itself has recited in court filings.
| Weight | Count | Note |
|---|---|---|
| 5 points | 42 | 23 basic + 19 derived. Derived does not mean low-value — 19 derived requirements carry the maximum penalty |
| 3 points | 16 | Includes 3.5.3 (MFA) and 3.13.11 (encryption), which escalate to 5 if not implemented at all |
| 1 point | 51 | Your legitimate POA&M candidates |
| Unscored | 1 | 3.12.4 (SSP) is scored NA — only 109 of 110 are scored |
Reconciliation both ways: basic 23+7+1 = 31; derived 19+7+2+51 = 79; 31+79 = 110. Deductions 210+42+10+51 = 313, so 110 − 313 = −203. The widely-published shortcut (“42 at five, 14 at three, 1 for the rest”) yields −195 and is the most likely way a competing source disagrees.
No. The score is not a count of requirements met. A company with 95 met can easily score below 88 if the misses are five-pointers.
POA&M eligibility — three conditions, not alternatives
- Score ≥ 0.8 — at least 88 of 110.
- No POA&M item worth more than 1 point — sole exception: SC.L2-3.13.11 at 3 points where encryption is employed but not FIPS-validated.
- None of six named requirements on the POA&M: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, PE.L2-3.10.5.
You can score 95 and still be barred from Conditional status. 88 is necessary, not sufficient — and it is a floor, not a target.
The three-year validity runs from the Conditional CMMC Status Date and is not reset by POA&M closeout — close on day 179 and you have three years minus 179 days. The 180-day closeout window runs from that same date.
Separately, an annual affirmation must be current or your status is not “current.” A three-year certificate with a 13-month-old affirmation blocks award and option exercise. Nothing prompts you.
Absence of an up-to-date SSP results in a finding that the assessment could not be completed — no score, no Conditional status. And CA.L2-3.12.4 can never be POA&M'd. A stale SSP is treated the same as no SSP. Any prior DoD CIO adjudication must be written into it or it is worthless at assessment.
Flow-down tracks the prime's level, not just the information
| Sub handles | Prime's level | Sub's floor |
|---|---|---|
| FCI only | any | Level 1 (Self) |
| CUI | Level 2 (Self) | Level 2 (Self) |
| CUI | Level 2 (C3PAO) | Level 2 (C3PAO) |
| CUI | Level 3 (DIBCAC) | Level 2 (C3PAO) |
Only in the Level 2 (Self) case does the floor stay at Self. 32 CFR 170.23 reaches all tiers, and 252.204-7021(f)(2) requires verification before subcontract award.
Flowdown is paragraph (f). Paragraph (g) belongs to the superseded 2020-vintage clause — citing it marks a guide as working from the wrong version.
07 · Threat surface
Where CUI actually leaks
Mapped to the requirement each one breaks, because a vulnerability you can't tie to a control is a vulnerability you can't fund.
Building & physical
| Weakness | Why it reaches CUI | Maps to | Fix |
|---|---|---|---|
| Tailgating Critical | Defeats badge control without touching it — the highest-yield entry technique in authorized physical assessments | 3.10.1 | Put the control on the one door into the CUI area: interlocking vestibule, optical turnstile, or at minimum a held-open alarm plus a camera aimed at the badge point |
| 125 kHz prox cards Critical | HID ProxCard II, EM4100, Indala clone in seconds with a consumer device | 3.10.5 | Read the part number on a real card — don't trust the integrator. Migrate to Seos, DESFire EV3 or PIV with mutual authentication and a diversified key |
| Wiegand reader wiring Critical | An implant on the unencrypted line captures and replays credentials — the softest target in the building | 3.10.5 · 3.6.1 | Wire the tamper switch on every reader and route tamper/offline events into the SIEM as security incidents, not maintenance tickets |
| OSDP assumed safe High | Published research documents five attack classes against real deployments — encryption is optional, and install mode is often left enabled | 3.10.5 | Specify OSDP Verified hardware, refuse unencrypted reader connections, disable install mode, and verify in the controller config rather than the brochure |
| Drop ceilings & raised floors High | Most partition walls stop at the grid, not the slab — the locked server door is bypassed entirely | 3.10.1 · 3.10.2 | Push up a ceiling tile and look. Extend slab-to-slab, or fit a welded mesh barrier above the grid |
| Live jacks in public areas High | Lobby and conference-room ports reach the network. Named explicitly in Rev 3 as requiring “disconnected or locked spare jacks” | 3.10.2 · 3.13.5 | Do both halves: administratively shut the port and pull the patch cord. Keep a port-to-jack map as evidence; 802.1X on the rest |
| Unattended printouts High | Output devices are explicitly in scope — printers, monitors, copiers, scanners, fax | 3.8.1 | Badge-release pull printing on every device that can receive a CUI job; relocate CUI-capable printers out of visitor paths |
| Unescorted service staff High | Cleaners, HVAC and copier techs are visitors unless on the authorized list. “Signed in but unescorted” is a top failure | 3.10.3 | Move cleaning to business hours with the CUI area excluded from scope — employees empty their own bins into locked destruction consoles |
| Landlord access Medium | In leased space the building master key is a path into your CUI environment | 3.10.1 | Install your own reader and lock on a keyway the building master doesn't open; negotiate a lease addendum for notice of entry |
| Lock-screen previews Medium | Session lock requires a pattern-hiding display — toast notifications routinely defeat it | 3.1.10 | Enforce lock by policy, then disable lock-screen notification content — the half almost everyone misses |
Cyber, network & cloud
| Weakness | Why it reaches CUI | Maps to | Fix |
|---|---|---|---|
| Flat network Critical | Not a NIST violation per se — but it makes every workstation, server and backup a CUI Asset assessed against all 110. The single biggest lever on program cost | 3.13.1 · 3.13.5 | Draw the data flow first, then enclave: dedicated VLAN + firewall policy, or a separate tenant. Document the boundary in the SSP and network diagram |
| Unmanaged SaaS / shadow IT Critical | Breaks AC.L2-3.1.20 — one of the six that can never be POA&M'd | 3.1.20 | Publish an approved-external-services list; block unapproved cloud storage and AI tools at the egress/DNS layer; run a shadow-IT discovery pass before you book an assessment |
| MFA gaps on local privileged access Critical | 3.5.3 is a 5-point item that cannot go on a POA&M. Most contractors cover remote and cloud, then miss local console | 3.5.3 | Inventory every privileged account and prove MFA on console access — hypervisors, firewalls, switches, backup console. Break-glass needs documented compensating controls, not an exemption |
| Exposed edge devices Critical | VPN gateways, firewalls and RDP are the dominant initial-access path | 3.11.2 · 3.14.1 | Subscribe your edge models to the CISA KEV feed with an internal SLA that beats it — KEV-listed edge appliance patched or offline in 72 hours |
| Legacy Windows protocols High | SMBv1, LLMNR, NBT-NS and NTLM are the standard path from one phished workstation to domain admin | 3.4.6 · 3.4.7 · 3.5.10 | Sequence to avoid outages: disable LLMNR and NBT-NS by GPO, require LDAP signing + channel binding, then SMB signing servers-then-workstations, then remove SMBv1 |
| “FedRAMP-ready” clouds High | Ready, In Process, StateRAMP, SOC 2 and “FedRAMP-aligned” are none of them an authorization | DFARS 7012(b)(2)(ii)(D) | Record either a Marketplace authorization ID at Moderate or above, or a 3PAO equivalency body of evidence with zero open POA&Ms. Re-verify annually |
| CSP won't sign (c)–(g) High | The obligation most vendors refuse — incident reporting, malware submission, media preservation, forensic access | DFARS 7012(c)–(g) | If a vendor won't commit contractually, it is not usable for CUI regardless of FedRAMP status |
| MSP with standing access High | An ESP holding credentials to your enclave is in scope even if it never sees a CUI file — Security Protection Data expressly includes passwords granting access | 170.19(c)(2) | Get a Customer Responsibility Matrix covering all 110, technician MFA, and a named standing-access list. Their certification covers their environment, not yours |
| Backups outside the boundary Medium | Backup systems holding CUI are CUI Assets. Frequently scoped out by accident | 3.8.9 | Put backup repositories in the enclave inventory and confirm the crypto module on backup encryption has a CMVP certificate |
| Client-side-only VDI lockdown Medium | The out-of-scope carve-out requires server-side enforcement — and MFA to the VDI server must be separate from the unmanaged client | 170.19(c) | Disable drive mounting, printing, clipboard and screenshots server-side. A client-side lockdown is not what DoD describes |
Several statistics that circulate widely in CMMC content — tailgating success percentages, breach-report figures, DIBCAC “most-failed control” rankings, and authorized-assessor counts — could not be traced to a primary source, or traced back to vendor marketing. They have been left out rather than softened. The failure modes above stand on the regulation and the published research alone.
08 · Flight plan
The gameplan
Sequenced by what gates what. Durations assume 20–200 employees, one CUI-bearing business line, a functioning IT function, and an executive sponsor. The long poles are procurement lead times and evidence accumulation — not technical work.
-
Stop, verify, decide
Weeks 0–2
Read the actual clauses in every active contract and open solicitation. Which carry 252.204-7012, 252.204-7021, 252.204-7025, FAR 52.204-21 — and what level is designated? Your obligations are whatever clauses are actually in them, not what the news says.
- For any contract carrying Level 2 (C3PAO) or Level 3, request a modification in writing citing the 13 July 2026 memoranda — and keep complying until the modification actually arrives
- Ask the contracting officer in writing to identify the CUI and its categories
- Start PIEE/SPRS role provisioning now — 1–3 weeks, longer without an active administrator
- Verify your SPRS score is under three years old and reconciles to your SSP
-
Scope & data flow
Weeks 2–8 · this decision drives ~70% of program cost
Map where CUI enters, lives, leaves, and who touches it. Then inventory every asset with a category column: CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Specialized Asset, Out-of-Scope. Include paper repositories, MFPs, mobile devices and backups.
Write the exclusion justification at the time you make the decision — the rule requires you to justify the inability of an Out-of-Scope Asset to process, store or transmit CUI. Anything falling into an in-scope category cannot be Out-of-Scope.
For most contractors under ~200 people an enclave is dramatically cheaper than dragging the whole network in — but only if you can prove CUI genuinely cannot leak into the general network.
-
Start the long poles
Weeks 4–20, overlapping
These gate everything else, so start them before remediation:
- Tenant decision and migration — 6–12 weeks for GCC; 3–6 months for GCC High, expensive and effectively one-way. Pilot external collaboration with your top 20 counterparties before signing
- Medium assurance certificates for two named incident reporters — multi-week identity proofing
- Crypto inventory and CMVP verification — 4–8 weeks; save certificate pages and Security Policy PDFs
- CSP evidence — authorization IDs or 3PAO equivalency packages, plus written confirmation of 7012(c)–(g). Vendors are slow: 4–12 weeks
- MSP package — CRM for all 110, technician MFA, willingness to be interviewed by your assessor. If they won't produce it, price the switch
-
Remediate by points-per-dollar
Weeks 8–36
Day-one gates first — the six that a POA&M cannot save, five of which are cheap: the SSP, escort procedure, visitor log, key/badge register, approved-external-services list, and public information review. Then MFA and media sanitization, which are 5-point and also POA&M-ineligible.
Then the remaining 5-point items, then the 3-point partial-credit wins — moving MFA from remote-and-privileged to all users recovers 3 points, as does moving to a genuinely validated crypto module. The 1-pointers come last; they are your legitimate POA&M candidates.
✕ Don't plan to POA&M your way outIf your gap list contains any 5- or 3-point item other than the 3.13.11 carve-out, a POA&M cannot save you. Fix it before the assessment, or don't book the assessment.
-
Evidence, self-assessment, mock
Weeks 30–48
Build the evidence register at the 320-objective level, not the 110-requirement level. For each objective record three things: the artifact, the person who can be interviewed, and the test that can be demonstrated live.
One screenshot of one laptop does not prove a control across 60 endpoints — export the inventory-joined report. If you have only a policy document for an objective, you will fail it.
Use two vendors: an RPO/consultant for gap assessment and mock, and a separate C3PAO for certification. Post your score against every CAGE code in scope, not just headquarters.
-
Sustainment
Continuous
Obligation Cadence The trap Annual affirmation in SPRS Annually Nothing prompts you. A lapsed affirmation blocks award even with a valid certificate Re-assessment Within 3 years of status date Assume a practical clock of 30 months, not 36 — you must have passed before the date rolls over POA&M closeout 180 days, no extensions Get it on the assessor's calendar in writing the day the initial assessment ends — it's a separate engagement, not included in most quotes CSP / ESP re-verification Annually Authorizations lapse and package names change EOL & crypto registers Quarterly / annually Certificate statuses change; capture evidence as of your assessment date M&A note: an inherited affirmation is inherited liability. Make CMMC status and SPRS score history a diligence item.
Remediation capex/opex · readiness consulting · the assessment itself · ongoing run-rate. DoD's published figure is an assessment cost, not a compliance cost — the rule's impact analysis attributes implementation cost to the pre-existing FAR 52.204-21 and DFARS 7012 obligations rather than to CMMC. Then check allowability: for most contractors this is an allowable G&A/overhead expense, which materially changes the business case.
09 · Critical
Ten facts you can't get wrong
- There are two CMMC rules. The program rule (32 CFR 170, effective 16 Dec 2024) created the program but put nothing in a contract. The acquisition rule (DFARS, effective 10 Nov 2025) inserts the clause.
- Level 2 is assessed against NIST SP 800-171 Rev 2 and SP 800-171A (June 2018) — both withdrawn by NIST on 14 May 2024, both still binding, because the incorporation by reference freezes the edition.
- Phase 2 is suspended as of 13 July 2026. Only Level 1 (Self) and Level 2 (Self) may be designated; no waivers. It is executive, not regulatory — it can restart without rulemaking.
- DFARS 252.204-7012 remains fully in force independently of CMMC — 72-hour reporting, 90-day media preservation from submission of the report, FedRAMP Moderate equivalency, flowdown at paragraph (m).
- The SPRS floor is −203, derived as 42 at five points, 16 at three (two escalating to five), 51 at one, and 3.12.4 unscored. The shortcut formula yields −195 and will make readers distrust everything else.
- A Level 2 POA&M requires all three conditions — ≥88, no item above 1 point (except the 3.13.11 carve-out), and none of the six named requirements. They are conditions, not alternatives.
- The three-year clock runs from the Conditional Status Date and is not reset by closeout, and a separate annual affirmation must be current or your status is not “current.”
- CUI flow-down tracks the prime's level, not just the information. Prime at Level 3 → CUI subs need at least Level 2 (C3PAO). 170.23 reaches all tiers.
- A contractor may not unilaterally decontrol — request it from the designating agency. But don't overstate it as “only the designating agency may decontrol”; 2002.18(b)(1), (i) and (m) each allow otherwise.
- CUI is not a FOIA exemption, legacy markings are void but still arrive, and “Specified” is not a higher security tier.
The False Claims Act carries treble damages plus per-claim civil penalties (currently $14,308–$28,619, unchanged for 2026). Recent settlements — MORSECORP at $4.6M, Raytheon/RTX/Nightwing at $8.4M, Penn State at $1.25M, Georgia Tech Research Corporation at $875K — all arose under the pre-CMMC self-attestation regime.
The MORSECORP lesson is not the bad score. The company learned its actual score was −142 in July 2022 and did not correct it until June 2023 — three months after being served a federal subpoena. The eleven months between knowing and correcting is what turns a bad score into a scienter problem. CMMC adds attestation surface: a named affirming official making an annual personal affirmation is a cleaner target than an anonymous score upload.