Start with scope, not with the list of 110 requirements. Find where Controlled Unclassified Information actually lives in your business, draw the smallest boundary you can defend, score yourself honestly against it, and fix the requirements that carry the most weight first.
Most small defense suppliers we talk to aren’t ignoring NIST SP 800-171. They started, got buried in a spreadsheet of 110 controls, and stalled. The way out is to shrink the problem before you start solving it.
The obligation didn’t pause
If your contracts include DFARS 252.204-7012, you’re already required to protect CUI on your systems using NIST SP 800-171, to report cyber incidents within 72 hours, and to use cloud services that meet FedRAMP Moderate–equivalent requirements for that data. That clause has been in defense contracts for years.
What paused in July 2026 was the next phase of CMMC, the program that verifies it. As of October 6, 2026, self-assessments, SPRS scores and annual affirmations still apply. Our CMMC status summary keeps the current picture, with sources. The pause changed who checks your work. It didn’t change the work.
Step 1: Find where CUI actually lives
Before you look at a single control, answer a narrower question: which people, systems and places touch CUI? Start with your contracts and work outward.
- Which contracts include DFARS 252.204-7012, and what information do they mark or describe as CUI?
- Where does that information arrive (email, a customer portal, a file transfer), and where does it go next?
- Who opens it, on which computers, and where is it stored, backed up and printed?
- Which systems protect or manage those computers, such as identity, endpoint management and logging?
Draw it as a simple diagram. You’ll usually find that CUI touches far fewer people and systems than the whole company. That gap is where the time and money are.
Step 2: Draw the smallest boundary you can defend
Every system inside your boundary has to meet the requirements and be assessed. If CUI flows freely across the business, the boundary is the whole business. If it’s contained, the boundary can be a small enclave: a few dedicated workstations or virtual desktops, enclave file storage, and the identity and logging that protect them.
An enclave only works if the separation is real and documented. People outside it can’t be able to open CUI, and the paths in and out need to be controlled. Our CMMC and CUI environments page walks through the difference with a diagram.
If CUI needs to live in the cloud, the service has to meet FedRAMP Moderate–equivalent requirements. Standard commercial Microsoft 365 usually doesn’t on its own. Many small contractors keep commercial Microsoft 365 for everyday work and put CUI in a separate enclave.
Step 3: Write the System Security Plan for that boundary
The System Security Plan describes the boundary, the systems inside it and how each requirement is met. It isn’t paperwork you finish at the end. Without it you can’t complete an honest assessment, and under the CMMC rule it’s one of the requirements that can never be deferred to a plan of action.
Write it for the boundary you drew in Step 2. A plan written for the whole company, when CUI only touches a corner of it, makes every later step harder.
Step 4: Score yourself honestly
The DoD Assessment Methodology starts you at 110 and subtracts 5, 3 or 1 point for each requirement that isn’t fully met. Because 42 requirements are worth five points, a score can go well below zero; the lowest possible is −203. A low number isn’t unusual for a company that’s just starting.
What matters is that the score is accurate. Your SPRS score and annual affirmations are representations to the government, and the Department of Justice has continued to pursue False Claims Act cases involving cybersecurity misrepresentations. An honest low score with a credible plan is a far better position than an optimistic one.
Step 5: Fix the heavy requirements first
Not all 110 requirements count equally, and not all of them can wait. Two of the five-point requirements trip up small companies more than any others:
- Multifactor authentication. Required for remote and network access to the systems in your boundary, and for privileged accounts.
- FIPS-validated encryption. Encryption protecting CUI has to use validated cryptographic modules. Encryption that isn’t validated earns only partial credit.
Under the CMMC rule, a conditional Level 2 status allows some requirements to be finished later on a plan of action, but only if the score is at least 88 of 110, and only for one-point requirements (plus encryption). Everything else, including the System Security Plan, has to be done first. Use that as your priority list even before an assessment is on the calendar.
Step 6: Put the rest on a dated plan
Whatever isn’t done goes into a plan of action and milestones: each gap, what will close it, who owns it and when. Under a conditional CMMC status, open items have to be closed within 180 days, so plan in months, not years.
Then work the plan. Many of the remaining items are ordinary good practice once the boundary is small: patching, account reviews, logging that someone actually looks at, and backups that have been tested.
What usually goes wrong
Scope too big
Treating the whole company as the boundary because nobody mapped where CUI goes. Everything after that costs more and takes longer.
Tools before design
Buying security products before deciding the boundary, then discovering they don’t cover the systems that matter.
Documents written last
Writing the System Security Plan after the build, from memory. The plan should drive the build.
An optimistic score
Posting a score that the evidence doesn’t support. It’s the costliest mistake on this list.
Questions we hear
How long does it take to catch up?
It depends almost entirely on scope. A tightly drawn enclave for a small team can usually be designed, built and documented in months rather than years. A company-wide boundary takes far longer.
Can we do this ourselves?
Many companies do much of it themselves. Outside help tends to pay off most in drawing the boundary, building the enclave and writing documentation that matches what was actually built.
Should we wait until CMMC Phase 2 restarts?
No. The requirement to protect CUI is already in your contracts, and self-assessments and affirmations continue. Starting now also gives you time to close gaps before a third-party assessment is required.
We already posted a score we’re not confident in. What now?
Re-assess against the methodology, correct the record with an accurate score and a plan, and talk to your counsel about your affirmations. We help with the technical side; we don’t give legal advice.
Sources: DFARS 252.204-7012; 32 CFR 170.21 (CMMC plans of action); NIST SP 800-171 Revision 2; Where CMMC stands.