Back to Blog
Compliance
4 min read

CMMC 2.0: A Practical Path for Contractors Handling CUI

Scoping the enclave, the System Security Plan, and the assessment route. What a mid-sized contractor should actually do first.

GuardsArm Team

Security Experts

September 25, 2026

CMMC 2.0 compliance path for defense contractors

CMMC exists because self-attestation did not work. Contractors asserted compliance with NIST SP 800-171, assessments found otherwise, and the department moved to verified certification for contracts involving controlled unclassified information.

For a contractor, the practical question is not what the model says. It is how to get certified without putting the entire business in scope.

Scope before you remediate
The order that decides the whole cost
An enclave shrinks the assessment
Scattered CUI puts the business in scope
Flow-down is yours too
Suppliers receiving CUI inherit the requirements

Step one: find your CUI

Everything downstream depends on this, and most contractors have never done it properly.

CUI arrives in ways that bypass whatever process you think governs it: an attachment from a prime contractor, a drawing in an email thread, a specification shared through a portal and then saved locally, a file copied to a laptop for a site visit.

CUI rarely arrives through the process you designed
It comes as an email attachment, a drawing saved to a laptop, or a file pulled from a prime contractor portal. Any scoping exercise that only examines approved systems will miss most of it, which is why interviewing engineers finds more than reading the asset register does.

Practical discovery steps:

  • Read your contract clauses. They tell you whether CUI is contemplated.
  • Ask your primes what they consider CUI in your deliverables.
  • Search your own environment for the markings, and for the document types most likely to carry it.
  • Interview the engineers, who know where the drawings actually live better than any register does.

Step two: decide the boundary before you remediate

This is the decision that determines the cost of everything else.

ApproachConsequence
CUI spread across the general environmentThe whole organisation is in scope
A defined enclave holding all CUIOnly the enclave is assessed
Enclave plus strict transfer controlsSmallest assessable footprint

An enclave is a bounded environment — a separate cloud tenancy, a segregated network zone, a dedicated virtual desktop estate — where CUI lives and from which it does not casually escape. Building one is work. Assessing an entire company against 800-171 is considerably more work, and it never stops, because every new system in the business becomes in scope.

Contractors who remediate before scoping routinely redo the remediation.


Step three: the control work

Level 2 aligns with NIST SP 800-171. The families are familiar; the common gaps for a mid-sized contractor are consistent:

Where mid-sized contractors typically fall shortAccess control, multi-factor authentication and audit logging are the biggest gaps, followed by configuration management, media protection and incident response.Access control and least privilegeShared accounts and broad access are the normMulti-factor authenticationIncomplete, especially for legacy engineering toolsAudit and accountabilityLogging not centralised or not retained long enoughConfiguration managementNo baselines, informal change controlMedia protectionRemovable media largely uncontrolledIncident responseA plan exists on paper, never exercised
The first three usually require budget, not just policy.

Multi-factor authentication and audit logging are the two that most often require real investment. MFA for all remote and privileged access is straightforward in principle and awkward where legacy engineering applications are involved. Centralised logging with sufficient retention is a genuine project if you have never done it. See logging strategy — the reasoning transfers directly.


The two documents that carry the programme

The System Security Plan describes the boundary, the environment and how each requirement is met. Assessors work from it. An SSP that is vague, generic or inconsistent with reality makes the assessment longer and worse.

The Plan of Action and Milestones records unmet requirements with owners and dates. Note two constraints: certain requirements cannot be deferred to a POA&M at all, and open items are subject to limits on how long they may remain open. The POA&M is a mechanism for finishing, not for postponing.

Write the SSP during remediation, not after
Teams that remediate first and document later produce an SSP reconstructed from memory, with gaps and inconsistencies the assessor finds. Writing each section as the control goes in costs almost nothing extra and produces a document that matches reality.

Flow-down to your own suppliers

If you pass CUI to subcontractors, the requirements flow down. That makes your supply chain part of your compliance position, and it is the part contractors address last.

Start by identifying which suppliers actually receive CUI — usually far fewer than the total supplier list — and address those. See third-party risk management.


A realistic sequence

  1. Identify CUI and where it currently is
  2. Design the enclave and the transfer controls around it
  3. Gap assessment of the enclave against 800-171
  4. Remediate, writing the SSP as you go rather than afterwards
  5. Flow down to the suppliers who receive CUI
  6. Pre-assessment, then the formal assessment

Steps one and two are where the leverage is. Everything after them is proportional to how well they were done.


Where to start

Spend a week finding out what CUI you hold and where it sits. It is the cheapest week in the programme and it determines the cost of every week that follows. See also CMMC Level 1 versus Level 2.

GuardsArm supports contractors through scoping, enclave design and assessment readiness. See CMMC compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “CMMC 2.0: A Practical Path for Contractors Handling CUI”

Talk to the GuardsArm team about how these services apply to your environment.