CMMC and CUI Environments

If your company handles Controlled Unclassified Information on Department of Defense contracts, the obligation to protect it is already in your contracts. We help you get there: we design, build and document the environment that supports it, scoped to the work that actually touches CUI.

Security & compliance
CMMC and CUI Environments
Covers
CUI scoping, environment design and build, documentation support, operations
Serves
Onsite in New Mexico; remote engineering nationwide

Four Directions helps design and implement technology that supports security and compliance objectives. We do not provide legal advice, and we do not assess or certify compliance.

Where CMMC stands

As of October 5, 2026

  • Phase 1 is in effect. Since November 10, 2025, DoD solicitations can require CMMC Level 1 or Level 2 self-assessments, with results and annual affirmations posted in SPRS.
  • Phase 2 is suspended. In a memo announced July 13, 2026, the DoD Chief Information Officer suspended all pending CMMC implementation milestones, including Phase 2, which would have begun requiring third-party (C3PAO) Level 2 certifications on November 10, 2026. Class Deviation 2026-O0025, Revision 3 (September 3, 2026) carries the pause into contract language.
  • No restart date has been announced. A CMMC Reform Task Force review is under way; its report had not been published as of this update.
  • The safeguarding obligation hasn’t changed. Where DFARS 252.204-7012 is in your contract, you must still implement the 110 security requirements of NIST SP 800-171 Revision 2 and report cyber incidents within 72 hours.
  • Beyond DoD: a proposed FAR rule published in June 2026 would extend CUI safeguarding requirements, based on NIST SP 800-171 Revision 3, to contracts across federal agencies. It isn’t final.

Program timelines change; the requirements written into your contracts and solicitations are what govern.

Sources: DoD CIO: CMMC program; Class Deviation 2026-O0025, Revision 3; 32 CFR Part 170 (CMMC program rule); NIST SP 800-171 Revision 2.

FCI, CUI and the three levels

CMMC sorts contractors by the kind of information they handle. Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn’t intended for public release. Controlled Unclassified Information (CUI) is a narrower category that law, regulation or policy requires to be safeguarded, such as controlled technical information.

LevelProtectsRequirementsHow it’s assessed
Level 1FCI15 basic safeguarding requirements (FAR 52.204-21)Annual self-assessment
Level 2CUI110 requirements of NIST SP 800-171 Revision 2Self-assessment, or a third-party (C3PAO) assessment every three years, as the contract specifies. Third-party requirements are currently paused.
Level 3CUI in DoD’s highest-priority programsLevel 2, plus 24 requirements from NIST SP 800-172Government (DIBCAC) assessment
Under 32 CFR Part 170. A senior official affirms compliance annually at every level.

Start with the boundary

The biggest cost decision in a CUI program is scope: which people, systems and facilities touch CUI and therefore have to meet the requirements. Draw that boundary tightly, and the work, the cost and the assessment all get smaller.

Two ways to scope a CUI environmentDiagram with two panels. Left panel, 'Whole company in scope': a single hatched boundary surrounds office laptops, shop and production computers, the business file server, email and collaboration, engineering workstations and the network, so every system must meet all 110 requirements. Right panel, 'CUI enclave': a small boundary surrounds only CUI workstations, enclave file storage, and enclave identity and multifactor authentication. Office laptops, shop computers, email and the business file server sit outside the boundary, and data crosses into the enclave only through a controlled transfer.Whole company in scopeOffice laptopsShop and production PCsBusiness file serverEmail and collaborationEngineering workstationsNetwork and Wi-FiEvery system must meet all 110 requirements,and every one of them is assessed.CUI enclaveCUI boundaryCUI workstationsEnclave file storageEnclave identity and MFAOffice laptopsShop and production PCsEmail and collaborationBusiness file serverControlled transferOnly the enclave carries the full requirement set; therest of the business can sit outside it if properly separated.
Two ways to scope a CUI environmentDiagram with two panels. Left panel, 'Whole company in scope': a single hatched boundary surrounds office laptops, shop and production computers, the business file server, email and collaboration, engineering workstations and the network, so every system must meet all 110 requirements. Right panel, 'CUI enclave': a small boundary surrounds only CUI workstations, enclave file storage, and enclave identity and multifactor authentication. Office laptops, shop computers, email and the business file server sit outside the boundary, and data crosses into the enclave only through a controlled transfer.Whole company in scopeOffice laptopsShop andproduction PCsBusinessfile serverEmail andcollaborationEngineeringworkstationsNetworkand Wi-FiEvery system must meet all 110requirements and is assessed.CUI enclaveCUI boundaryCUI workstationsEnclave file storageEnclave identity and MFAControlled transferOffice laptopsShop & production PCsEmail & collaborationBusiness file serverOnly the enclave carries the full set;the rest can sit outside if separated.
Scope drives cost. A tightly drawn enclave means fewer systems to secure, document and assess, but it only works if the separation is real and documented.

CMMC’s scoping guidance sorts assets into CUI assets, security protection assets, contractor risk managed assets, specialized assets and out-of-scope assets. We map yours, document the boundary and the data flows across it, and design so the boundary is easy to defend.

What the environment has to do

NIST SP 800-171 has 110 requirements across 14 families. In technical terms, most of them come down to a handful of capabilities:

  • Identity and access. Unique accounts, multifactor authentication, least privilege and controlled remote access.
  • Endpoints. Managed, hardened and encrypted devices, with removable media under control.
  • Encryption. FIPS-validated cryptography protecting CUI in storage and in transit.
  • Boundaries and segmentation. Network and system boundaries that keep CUI where it belongs and monitor what crosses.
  • Logging and monitoring. Audit records collected centrally, protected and actually reviewed.
  • Configuration and change control. Secure baselines, timely patching and documented changes.
  • Incident response. The ability to detect an incident, report it within 72 hours and preserve evidence.
  • Backup and recovery. Protected copies of CUI and restores that have been tested.

Technology is only part of it. Policies, procedures, training and your System Security Plan matter just as much. We document the technical design and configuration so they support your plan, rather than leaving you to reverse-engineer it before an assessment.

Cloud, on-premises or a mix

There’s no single right architecture for CUI. The choice depends on how many people need access, what kinds of CUI you handle, whether any of it is export-controlled, and what you already run.

Government cloud suite

Government versions of Microsoft 365 (GCC and GCC High) are built for regulated workloads. They change the licensing and administration model, and they’re purchased through authorized channels; we help you choose, plan and configure them.

On-premises enclave

A small, dedicated environment for CUI work: a few workstations, file storage and identity, separated from the rest of the business. Often the most economical choice for small teams.

Virtual desktop enclave

People reach CUI only through managed virtual desktops, which keeps CUI off everyday laptops.

Hybrid

Everyday work stays in commercial cloud services; CUI lives in a separate enclave or government tenant, with controlled ways to move data between them.

Cloud services that store or process CUI generally must meet FedRAMP Moderate (or equivalent) requirements and support the contract’s incident-reporting obligations. We check current authorizations and terms for the specific services before recommending them.

How we work

  1. Scope Identify where CUI lives and flows, and draw the smallest defensible boundary.
  2. Design Choose the platform and controls, and produce diagrams and a build plan.
  3. Build Implement identity, endpoints, network, logging and backup to the design.
  4. Document Configuration records, diagrams and data flows that support your System Security Plan.
  5. Maintain If you want ongoing help: patching, monitoring, account reviews and evidence, done inside your environment under accounts you control.

CMMC is your requirement, and the environment, controls and certification are yours. We’re not a C3PAO and don’t conduct certification assessments; assessors must be independent of the people who help you implement, so we stay on the implementation side.

Questions we hear

Is CMMC paused?

Partly. As of October 5, 2026, the move to required third-party (C3PAO) certifications is suspended, but Level 1 and Level 2 self-assessments, SPRS reporting and annual affirmations continue, and DFARS 252.204-7012 still requires NIST SP 800-171. The requirements in your actual contracts are what count.

Do we still need NIST SP 800-171 while Phase 2 is paused?

Yes, if your contracts include DFARS 252.204-7012. The pause changed who assesses you, not what you’re required to protect or how.

Your SPRS score and affirmations also need to reflect reality. The Department of Justice has continued to pursue False Claims Act cases involving cybersecurity misrepresentations.

What’s an enclave?

A separate, tightly scoped environment where CUI work happens, isolated from the rest of the business. A smaller scope means fewer systems to secure, document and assess.

Can we use regular Microsoft 365 for CUI?

Usually not on its own. DFARS 252.204-7012 requires cloud services that hold CUI to meet FedRAMP Moderate-equivalent requirements, and Microsoft offers government versions of Microsoft 365 for regulated data. Which offering fits depends on your data, including whether any of it is export-controlled. Many small contractors keep commercial Microsoft 365 for everyday work and put CUI in a separate enclave.

Can you certify us?

No. Certification assessments are performed by authorized third-party assessment organizations (C3PAOs) or, for Level 3, by the government. We help you prepare: we design, build and document the environment you’re assessed on.

Is Four Directions CMMC certified?

No, and it doesn’t need to be for this work. CMMC applies to the contractor that handles the information, which is you. We help you meet it, working inside your environment, so your CUI stays there and the controls being assessed are yours. If we have ongoing administrative access, it’s set up under your accounts and documented in your System Security Plan, as the CMMC rule expects for outside service providers.

What’s an SPRS score?

The result of your self-assessment against NIST SP 800-171 using DoD’s assessment methodology, posted in the Supplier Performance Risk System. It starts at 110 and goes down for each requirement not met, so it can be negative.

Start with scope

Tell us in general terms what CUI you handle and where it lives today. Please don’t send any CUI through the form.