Purpose of the Template
Your CMMC compliance boundary might not be as accurate as you think. Controlled Unclassified Information (CUI) often moves beyond the lines drawn on architecture diagrams. This template helps you map where CUI actually flows in your organization, through collaboration platforms, email threads, subcontractor communications, and business documents that never touch your secure enclave. Use it to identify compliance gaps before your C3PAO does, and to build the evidence trail your CEO needs to sign that attestation with confidence.
The template creates a living document that tracks CUI propagation patterns, not just storage locations. You'll use it to answer the critical question: "Where does controlled information go when people do their jobs?"
Prerequisites
Before you start mapping, ensure you have:
Access and authority:
- Permission to interview staff across engineering, program management, finance, and business development.
- Read access to collaboration platforms, file shares, and email systems your teams use daily.
- Authority to review subcontractor agreements and communication channels.
Technical baseline:
- Current system security plan (SSP) scope definition.
- List of systems designated for CUI processing in your NIST SP 800-171 assessment.
- Network diagrams showing your defined compliance boundary.
Business context:
- Active defense contracts with CUI requirements under DFARS 252.204-7012.
- List of subcontractors and suppliers you share technical information with.
- Understanding of which programs involve controlled technical information or export-controlled data.
You don't need specialized software. A spreadsheet works fine. What you need is honest visibility into how information moves when deadlines are tight and collaboration happens naturally.
The Template
Copy this structure into a spreadsheet or document management system. Each row represents one data flow pattern, a repeatable way CUI moves through your organization.
Column A: Flow ID
Unique identifier (F001, F002, etc.)
Column B: Source System
Where the CUI originates or enters your organization (prime contractor portal, secure email, contract documents).
Column C: Information Type
What kind of CUI moves through this flow (controlled technical information, export-controlled data, contractor performance information, security clearance details).
Column D: Business Activity
Why the information moves (proposal development, technical collaboration, subcontractor tasking, cost reporting, quality review).
Column E: Destination System(s)
Where the information lands (Teams channel, SharePoint folder, email thread, subcontractor system, presentation deck).
Column F: In Scope?
Is the destination system inside your current CMMC compliance boundary? (Yes/No)
Column G: Protection Status
If No in Column F: What controls protect the CUI in this location? (none, commercial encryption, access restrictions, subcontractor SSP).
Column H: Propagation Risk
Can CUI spread further from this destination? (High: easily copied or forwarded; Medium: restricted but possible; Low: endpoint with controls).
Column I: Detection Method
How would you know if CUI entered this flow? (manual review, content scanning, user reporting, none).
Column J: Remediation Owner
Who's responsible for bringing this flow into compliance? (name and role).
Column K: Status
Current state (Under Review, Remediation Planned, In Scope, Accepted Risk).
Customizing the Template
For small contractors (under 50 employees):
Focus on Columns B through F first. Document the flows before planning remediation. Your biggest risk is likely CUI in commercial collaboration tools and email to subcontractors. Start there.
For mid-tier suppliers with multiple programs:
Add a "Program" column after Flow ID to filter by contract. Different programs often have different CUI handling patterns. Your engineering teams may share controlled technical information one way while your proposals group handles it differently.
For organizations with classified work:
Add a "Classification Level" column and map those flows separately. The template still works, but you'll need to track National Industrial Security Program requirements alongside CMMC obligations.
For supply chain visibility:
Extend Column E to capture which tier the destination sits at (Tier 2, Tier 3). This matters because DFARS 252.204-7012 flow-down requirements mean your subcontractors' compliance gaps become your compliance gaps.
Customization you should NOT make:
Don't limit the template to "known CUI" or "labeled CUI." The goal is discovering where controlled information goes based on context, not labels. If you only map flows where someone explicitly marked something CUI, you'll miss the propagation patterns that create actual risk.
Validation Steps
Step 1: Interview-based validation (Week 1)
Schedule 30-minute sessions with 3-5 people in each functional area. Don't ask "Do you handle CUI?" Ask "Walk me through how you worked on [specific recent project]." Listen for phrases like "I pulled the specs into..." or "We shared that with..." Document every system and platform they mention.
Step 2: Spot-check evidence (Week 2)
Pick five flows from your template at random. Go look at the actual systems. Open the Teams channel. Check the SharePoint folder. Review the email thread. Verify the flow exists and operates the way your interviews described. If you find gaps between documented flows and reality, your template needs more work.
Step 3: Boundary comparison (Week 3)
Print your SSP scope definition. Highlight every destination system in Column E that appears in your SSP. Count how many flows land outside your defined boundary. If the number is zero, you're either a unicorn or you're not being honest about business operations.
Step 4: Assessment simulation (Week 4)
Hand the template to someone who wasn't involved in creating it, ideally your internal audit function or a trusted advisor. Ask them: "Based on this map, where would you look for compliance gaps?" Their answer shows you whether the template communicates risk clearly enough for assessment purposes.
Step 5: CEO review (Before attestation)
Your chief executive has to attest that your organization adequately protects CUI. This template is the evidence that supports that statement. If your CEO can't understand the flows and the remediation plan from this document, you're not ready for attestation.
Ongoing validation:
Update the template quarterly or when you start a new program. CUI flows change as your business changes. The template remains useful only if it reflects current operations, not last year's architecture.
When you finish, you'll have documentation that shows where CUI actually goes, not where your SSP says it should stay. That's the foundation for CMMC compliance that survives beyond the day your C3PAO completes the assessment.



