
CMMC 2.0: A Practical Path for Contractors Handling CUI
Scoping the enclave, the System Security Plan, and the assessment route. What a mid-sized contractor should actually do first.
GuardsArm Team
Security Experts

CMMC exists because self-attestation did not work. Contractors asserted compliance with NIST SP 800-171, assessments found otherwise, and the department moved to verified certification for contracts involving controlled unclassified information.
For a contractor, the practical question is not what the model says. It is how to get certified without putting the entire business in scope.
Step one: find your CUI
Everything downstream depends on this, and most contractors have never done it properly.
CUI arrives in ways that bypass whatever process you think governs it: an attachment from a prime contractor, a drawing in an email thread, a specification shared through a portal and then saved locally, a file copied to a laptop for a site visit.
Practical discovery steps:
- Read your contract clauses. They tell you whether CUI is contemplated.
- Ask your primes what they consider CUI in your deliverables.
- Search your own environment for the markings, and for the document types most likely to carry it.
- Interview the engineers, who know where the drawings actually live better than any register does.
Step two: decide the boundary before you remediate
This is the decision that determines the cost of everything else.
| Approach | Consequence |
|---|---|
| CUI spread across the general environment | The whole organisation is in scope |
| A defined enclave holding all CUI | Only the enclave is assessed |
| Enclave plus strict transfer controls | Smallest assessable footprint |
An enclave is a bounded environment — a separate cloud tenancy, a segregated network zone, a dedicated virtual desktop estate — where CUI lives and from which it does not casually escape. Building one is work. Assessing an entire company against 800-171 is considerably more work, and it never stops, because every new system in the business becomes in scope.
Contractors who remediate before scoping routinely redo the remediation.
Step three: the control work
Level 2 aligns with NIST SP 800-171. The families are familiar; the common gaps for a mid-sized contractor are consistent:
Multi-factor authentication and audit logging are the two that most often require real investment. MFA for all remote and privileged access is straightforward in principle and awkward where legacy engineering applications are involved. Centralised logging with sufficient retention is a genuine project if you have never done it. See logging strategy — the reasoning transfers directly.
The two documents that carry the programme
The System Security Plan describes the boundary, the environment and how each requirement is met. Assessors work from it. An SSP that is vague, generic or inconsistent with reality makes the assessment longer and worse.
The Plan of Action and Milestones records unmet requirements with owners and dates. Note two constraints: certain requirements cannot be deferred to a POA&M at all, and open items are subject to limits on how long they may remain open. The POA&M is a mechanism for finishing, not for postponing.
Flow-down to your own suppliers
If you pass CUI to subcontractors, the requirements flow down. That makes your supply chain part of your compliance position, and it is the part contractors address last.
Start by identifying which suppliers actually receive CUI — usually far fewer than the total supplier list — and address those. See third-party risk management.
A realistic sequence
- Identify CUI and where it currently is
- Design the enclave and the transfer controls around it
- Gap assessment of the enclave against 800-171
- Remediate, writing the SSP as you go rather than afterwards
- Flow down to the suppliers who receive CUI
- Pre-assessment, then the formal assessment
Steps one and two are where the leverage is. Everything after them is proportional to how well they were done.
Where to start
Spend a week finding out what CUI you hold and where it sits. It is the cheapest week in the programme and it determines the cost of every week that follows. See also CMMC Level 1 versus Level 2.
GuardsArm supports contractors through scoping, enclave design and assessment readiness. See CMMC compliance or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “CMMC 2.0: A Practical Path for Contractors Handling CUI”
Talk to the GuardsArm team about how these services apply to your environment.


