CMMC exists because self-attestation did not work. Defence contractors had been required to implement NIST SP 800-171 for years and asserted compliance in order to win contracts; assessments found the assertions frequently overstated. The Cybersecurity Maturity Model Certification adds the missing part - independent verification, tied to eligibility for award.
The core distinction: FCI and CUI
Everything in CMMC follows from what information you handle:
- Federal Contract Information (FCI) - information provided by or generated for the government under a contract, not intended for public release. Most defence-related suppliers hold some.
- Controlled Unclassified Information (CUI) - sensitive but unclassified information requiring safeguarding, including a great deal of technical data, drawings and specifications. This is where the substantial obligations begin.
The practical difficulty is that CUI is frequently not marked, or is marked inconsistently by the government customer. Suppliers routinely discover CUI sitting in engineering shares, email attachments and a CAD system nobody considered in scope. Identifying where CUI actually lives is the single largest task in a CMMC programme, and it precedes every control decision.
The levels
- Level 1 (Foundational) - basic safeguarding of FCI, a short set of practices, annual self-assessment with senior official affirmation.
- Level 2 (Advanced) - the NIST SP 800-171 control set, for organisations handling CUI. This is where most of the supply chain lands, and the majority of contracts requiring it call for a third-party assessment by a certified assessment organisation rather than self-assessment.
- Level 3 (Expert) - additional controls drawn from NIST SP 800-172 for the highest-priority programmes, assessed by the government.
If you handle CUI, plan for Level 2 with a third-party assessment. Requirements are being phased into contracts over time, so the operative question is not whether it applies but which of your contracts carry it first - check the clauses in your current awards and your pipeline.
Assess against 800-171 without building a spreadsheet
GRC Copilot scores you against the control set, tracks evidence per requirement, and produces the gap list your System Security Plan and POA&M depend on.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Two documents that carry the whole programme
- System Security Plan (SSP) - describes the system boundary and how each requirement is met. It is not a policy document; it is a detailed statement of implementation, and an assessor works directly from it. A thin SSP produces a difficult assessment regardless of how good your controls are.
- Plan of Action and Milestones (POA&M) - what is not yet met, with dates and owners. Historically POA&Ms were used to defer indefinitely; under CMMC their use is constrained, certain requirements cannot be deferred at all, and open items must close within a limited window. Treat the POA&M as a short bridge, not a parking area.
Scoping: the enclave decision
Applying the full control set to your entire corporate network is expensive and usually unnecessary. The alternative is a CUI enclave - a defined, segmented environment where CUI is processed and stored, with everything outside it kept demonstrably CUI-free.
An enclave narrows assessment scope dramatically, and the trade-off is discipline: it only works if CUI genuinely cannot leave. That means controlling email, file sharing, endpoints and the habit of engineers copying drawings to a local drive. The enclave fails on user behaviour far more often than on technical design, so plan the workflow and the training alongside the architecture.
Cloud services in scope must meet the government's authorisation expectations, which is why several major providers offer dedicated government-community environments. Verify the specific service you intend to use rather than assuming a provider-wide claim covers it.
The requirements suppliers most often fail
- Multifactor authentication across all in-scope access, including local and privileged.
- FIPS-validated cryptography - not merely "encryption", but validated modules. This trips up organisations using otherwise-strong tooling.
- Audit logging and review with retention and evidence that logs are actually examined.
- Media protection and sanitisation, including marking.
- Incident reporting to the government within the required window - a contractual obligation with a tight clock.
- Flow-down to subcontractors who also touch CUI. Your suppliers' status becomes your problem.
Preparing
- Determine what contract clauses currently bind you, and what your pipeline requires.
- Locate all FCI and CUI - interviews plus discovery tooling, not assumption.
- Decide the boundary: enclave or enterprise-wide.
- Gap assess against the control set, honestly.
- Write the SSP as you remediate, not afterwards.
- Remediate, prioritising anything that cannot be deferred.
- Engage a certified assessment organisation early - capacity is limited and lead times are real.
Frequently asked questions
Does CMMC apply if we only hold FCI?
Then Level 1 and self-assessment apply. The obligation escalates sharply the moment CUI enters, which is why identifying CUI accurately matters so much.
How does it relate to ISO 27001?
An ISO-certified organisation has a strong foundation - governance, risk and many overlapping controls - but CMMC prescribes specific requirements that ISO does not, notably FIPS-validated cryptography and government incident reporting. Expect overlap, not substitution.
Can we use a POA&M to pass?
Only within limits. Some requirements must be fully met, and open items carry a closure deadline. It is not the deferral mechanism it once was.
What about non-US suppliers?
If you hold CUI under a defence contract or subcontract, the obligations follow the information, not your location - and data residency requirements may constrain where it can be processed.
Key takeaways
- Finding where CUI actually lives is the largest and most underestimated task.
- Level 2 with third-party assessment is the realistic target for CUI handlers.
- An enclave cuts scope sharply but only holds if user workflow supports it.
- The SSP is what the assessor works from - write it as you remediate.