CMMC and CUI Environments
If your company handles Controlled Unclassified Information on Department of Defense contracts, the obligation to protect it is already in your contracts. We help you get there: we design, build and document the environment that supports it, scoped to the work that actually touches CUI.
- Security & compliance
- CMMC and CUI Environments
- Covers
- CUI scoping, environment design and build, documentation support, operations
- Serves
- Onsite in New Mexico; remote engineering nationwide
Four Directions helps design and implement technology that supports security and compliance objectives. We do not provide legal advice, and we do not assess or certify compliance.
Where CMMC stands
As of October 5, 2026
- Phase 1 is in effect. Since November 10, 2025, DoD solicitations can require CMMC Level 1 or Level 2 self-assessments, with results and annual affirmations posted in SPRS.
- Phase 2 is suspended. In a memo announced July 13, 2026, the DoD Chief Information Officer suspended all pending CMMC implementation milestones, including Phase 2, which would have begun requiring third-party (C3PAO) Level 2 certifications on November 10, 2026. Class Deviation 2026-O0025, Revision 3 (September 3, 2026) carries the pause into contract language.
- No restart date has been announced. A CMMC Reform Task Force review is under way; its report had not been published as of this update.
- The safeguarding obligation hasn’t changed. Where DFARS 252.204-7012 is in your contract, you must still implement the 110 security requirements of NIST SP 800-171 Revision 2 and report cyber incidents within 72 hours.
- Beyond DoD: a proposed FAR rule published in June 2026 would extend CUI safeguarding requirements, based on NIST SP 800-171 Revision 3, to contracts across federal agencies. It isn’t final.
Program timelines change; the requirements written into your contracts and solicitations are what govern.
Sources: DoD CIO: CMMC program; Class Deviation 2026-O0025, Revision 3; 32 CFR Part 170 (CMMC program rule); NIST SP 800-171 Revision 2.
FCI, CUI and the three levels
CMMC sorts contractors by the kind of information they handle. Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn’t intended for public release. Controlled Unclassified Information (CUI) is a narrower category that law, regulation or policy requires to be safeguarded, such as controlled technical information.
| Level | Protects | Requirements | How it’s assessed |
|---|---|---|---|
| Level 1 | FCI | 15 basic safeguarding requirements (FAR 52.204-21) | Annual self-assessment |
| Level 2 | CUI | 110 requirements of NIST SP 800-171 Revision 2 | Self-assessment, or a third-party (C3PAO) assessment every three years, as the contract specifies. Third-party requirements are currently paused. |
| Level 3 | CUI in DoD’s highest-priority programs | Level 2, plus 24 requirements from NIST SP 800-172 | Government (DIBCAC) assessment |
Start with the boundary
The biggest cost decision in a CUI program is scope: which people, systems and facilities touch CUI and therefore have to meet the requirements. Draw that boundary tightly, and the work, the cost and the assessment all get smaller.
CMMC’s scoping guidance sorts assets into CUI assets, security protection assets, contractor risk managed assets, specialized assets and out-of-scope assets. We map yours, document the boundary and the data flows across it, and design so the boundary is easy to defend.
What the environment has to do
NIST SP 800-171 has 110 requirements across 14 families. In technical terms, most of them come down to a handful of capabilities:
- Identity and access. Unique accounts, multifactor authentication, least privilege and controlled remote access.
- Endpoints. Managed, hardened and encrypted devices, with removable media under control.
- Encryption. FIPS-validated cryptography protecting CUI in storage and in transit.
- Boundaries and segmentation. Network and system boundaries that keep CUI where it belongs and monitor what crosses.
- Logging and monitoring. Audit records collected centrally, protected and actually reviewed.
- Configuration and change control. Secure baselines, timely patching and documented changes.
- Incident response. The ability to detect an incident, report it within 72 hours and preserve evidence.
- Backup and recovery. Protected copies of CUI and restores that have been tested.
Technology is only part of it. Policies, procedures, training and your System Security Plan matter just as much. We document the technical design and configuration so they support your plan, rather than leaving you to reverse-engineer it before an assessment.
Cloud, on-premises or a mix
There’s no single right architecture for CUI. The choice depends on how many people need access, what kinds of CUI you handle, whether any of it is export-controlled, and what you already run.
Government cloud suite
Government versions of Microsoft 365 (GCC and GCC High) are built for regulated workloads. They change the licensing and administration model, and they’re purchased through authorized channels; we help you choose, plan and configure them.
On-premises enclave
A small, dedicated environment for CUI work: a few workstations, file storage and identity, separated from the rest of the business. Often the most economical choice for small teams.
Virtual desktop enclave
People reach CUI only through managed virtual desktops, which keeps CUI off everyday laptops.
Hybrid
Everyday work stays in commercial cloud services; CUI lives in a separate enclave or government tenant, with controlled ways to move data between them.
Cloud services that store or process CUI generally must meet FedRAMP Moderate (or equivalent) requirements and support the contract’s incident-reporting obligations. We check current authorizations and terms for the specific services before recommending them.
How we work
- Scope Identify where CUI lives and flows, and draw the smallest defensible boundary.
- Design Choose the platform and controls, and produce diagrams and a build plan.
- Build Implement identity, endpoints, network, logging and backup to the design.
- Document Configuration records, diagrams and data flows that support your System Security Plan.
- Maintain If you want ongoing help: patching, monitoring, account reviews and evidence, done inside your environment under accounts you control.
CMMC is your requirement, and the environment, controls and certification are yours. We’re not a C3PAO and don’t conduct certification assessments; assessors must be independent of the people who help you implement, so we stay on the implementation side.
Questions we hear
Is CMMC paused?
Partly. As of October 5, 2026, the move to required third-party (C3PAO) certifications is suspended, but Level 1 and Level 2 self-assessments, SPRS reporting and annual affirmations continue, and DFARS 252.204-7012 still requires NIST SP 800-171. The requirements in your actual contracts are what count.
Do we still need NIST SP 800-171 while Phase 2 is paused?
Yes, if your contracts include DFARS 252.204-7012. The pause changed who assesses you, not what you’re required to protect or how.
Your SPRS score and affirmations also need to reflect reality. The Department of Justice has continued to pursue False Claims Act cases involving cybersecurity misrepresentations.
What’s an enclave?
A separate, tightly scoped environment where CUI work happens, isolated from the rest of the business. A smaller scope means fewer systems to secure, document and assess.
Can we use regular Microsoft 365 for CUI?
Usually not on its own. DFARS 252.204-7012 requires cloud services that hold CUI to meet FedRAMP Moderate-equivalent requirements, and Microsoft offers government versions of Microsoft 365 for regulated data. Which offering fits depends on your data, including whether any of it is export-controlled. Many small contractors keep commercial Microsoft 365 for everyday work and put CUI in a separate enclave.
Can you certify us?
No. Certification assessments are performed by authorized third-party assessment organizations (C3PAOs) or, for Level 3, by the government. We help you prepare: we design, build and document the environment you’re assessed on.
Is Four Directions CMMC certified?
No, and it doesn’t need to be for this work. CMMC applies to the contractor that handles the information, which is you. We help you meet it, working inside your environment, so your CUI stays there and the controls being assessed are yours. If we have ongoing administrative access, it’s set up under your accounts and documented in your System Security Plan, as the CMMC rule expects for outside service providers.
What’s an SPRS score?
The result of your self-assessment against NIST SP 800-171 using DoD’s assessment methodology, posted in the Supplier Performance Risk System. It starts at 110 and goes down for each requirement not met, so it can be negative.
Start with scope
Tell us in general terms what CUI you handle and where it lives today. Please don’t send any CUI through the form.