The Decision You're Facing
You're looking at a contract modification, a subcontractor questionnaire, or an email thread with your contracting officer. You need to decide if Controlled Unclassified Information (CUI) will be involved. Your decision impacts assessment scope, cybersecurity investment, subcontractor selection, and whether you'll spend months explaining CMMC Level 2 requirements to a machine shop that cuts commercially available parts.
The issue isn't understanding CUI. It's that the DoD doesn't consistently mark it, prime contractors assume worst-case scenarios, and you're left building compliance frameworks around vague information categories. The Office of Advocacy identified CUI uncertainty as a major concern for small businesses under the Cybersecurity Maturity Model Certification (CMMC), and the Pentagon paused third-party assessments partly due to this ambiguity, which drives unnecessary costs across the Defense Industrial Base.
You need a decision framework that acknowledges the reality: you're working in a system where contracting officers mark publicly available information as CUI, email footers carry blanket designations regardless of content, and your prime contractor lacks confidence in scoping determinations.
Key Factors That Affect Your Choice
Factor 1: Contract language specificity
Does your contract statement of work specify anticipated CUI categories, data flows, systems, or deliverables? Or does it include boilerplate DFARS 252.204-7012 language without defining what information requires protection?
Factor 2: Your role in the supply chain
Are you the prime contractor responsible for scoping subcontractor requirements, or are you a subcontractor receiving flow-down language? Prime contractors face audit liability for under-scoping; subcontractors face compliance costs for over-scoping.
Factor 3: Information you'll create versus receive
Will you receive marked CUI from DoD, or will you generate technical reports, engineering data, or drawings that might qualify as CUI during contract performance? The latter requires judgment calls about your own work product.
Factor 4: Access model
Will your team store and process CUI in your own systems, or will you access it view-only within a prime-controlled environment? This distinction matters for CMMC scoping but rarely appears in flow-down language.
Path A: Conservative Scoping (When to Protect Everything)
Choose this path if:
- Your contract doesn't clearly identify CUI categories or boundaries.
- You're a prime contractor without confidence in your scoping analysis.
- Your contracting officer can't or won't clarify what constitutes CUI for this effort.
- You'll generate technical data or engineering deliverables for sensitive DoD technology.
- The cost of under-scoping (audit findings, contract breach) exceeds the cost of over-scoping.
What this path requires:
You'll treat all information related to the contract as CUI. Your CMMC assessment boundary expands to include every system, user, and facility that touches contract work. You'll implement NIST SP 800-171 Rev 2 controls across that expanded boundary and pursue third-party assessment for Level 2 certification if required.
The practical reality:
This is what most contractors do today. The Professional Services Council noted "significant variation" in how contracting officers apply CMMC requirements, creating uncertainty that you mitigate through over-protection. You're building expensive cybersecurity architecture around undefined information categories because you can't risk getting it wrong.
The cost:
Your assessment scope includes systems that may never touch genuinely sensitive data. Small businesses absorb compliance costs for protection that doesn't produce corresponding cybersecurity benefit. You pass those costs to DoD through contract pricing.
Path B: Targeted Scoping (When to Push for Clarity)
Choose this path if:
- You can identify specific CUI categories in your contract or deliverables.
- Your contracting officer is responsive to scoping questions.
- You're willing to document your scoping rationale and accept audit scrutiny.
- The information you'll handle has clear regulatory or policy protection requirements (e.g., export-controlled technical data under ITAR, specific CUI categories from NARA's registry).
- You have legal or compliance resources to support your analysis.
What this path requires:
Before you scope your assessment, engage your contracting officer with specific questions: What CUI categories do you anticipate? What deliverables will contain CUI? What systems will receive marked data? Document their responses. Scope your CMMC assessment boundary to systems and users that will actually store, process, or transmit the identified CUI.
The practical reality:
Defense acquisition rules direct prime contractors to consult their contracting officer when they're unsure about CUI scope. You're following that guidance. You're also creating an audit trail that shows you performed scoping diligence rather than defaulting to blanket protection.
The risk:
If you under-scope and an assessment or audit identifies CUI outside your boundary, you face findings, potential contract breach, and the cost of expanding your boundary retroactively. This is why most contractors choose Path A.
Path C: Enclave Access Model (When Your Team Doesn't Store CUI)
Choose this path if:
- You need to view CUI but won't store, process, or transmit it in your own systems.
- Your prime contractor or DoD customer can provide access through a certified environment.
- Your contract work involves bid evaluation, limited review, or consultation rather than data manipulation.
- You're a specialized subcontractor (construction, manufacturing, logistics) with no business need to maintain CUI in your infrastructure.
What this path requires:
Negotiate contract terms that specify view-only access within a prime-controlled or government-furnished enclave. Your CMMC obligations shift from system certification to identity verification, access controls, and training requirements. You don't build your own 800-171-compliant environment.
The practical reality:
This is the model Associated Builders and Contractors recommended to the CMMC Reform Task Force: tiered requirements that distinguish between bid-only access to non-CUI, view-only access to CUI within certified enclaves, and subcontractor storage of CUI in their own systems. It's not yet formalized in DoD policy, but you can negotiate it contractually.
The limitation:
This only works if your prime contractor or customer will provide the enclave and if your work truly doesn't require you to store or manipulate CUI. Many primes impose blanket Level 2 flow-downs on every subcontractor because they lack confidence in making these distinctions.
Summary Matrix
| Decision Factor | Path A: Conservative | Path B: Targeted | Path C: Enclave Access |
|---|---|---|---|
| Contract clarity | Undefined or ambiguous | Specific categories identified | Limited access clearly scoped |
| Your role | Prime or uncertain sub | Prime with CO engagement | Subcontractor with no storage need |
| Information source | Created or received | Clearly defined receipt | View-only access |
| Risk tolerance | Low (avoid audit exposure) | Moderate (document rationale) | Requires prime cooperation |
| CMMC scope | All contract-related systems | Systems handling identified CUI | Identity/access controls only |
| Cost profile | Highest compliance cost | Balanced if scoping succeeds | Lowest if enclave provided |
The hard truth: Until DoD establishes clear, contract-level processes for identifying CUI categories, markings, data flows, and deliverables before imposing CMMC requirements, you'll keep making these decisions in an ambiguous environment. The governmentwide CUI acquisition rule proposed in 2024 may eventually provide the clarity you need. A potential executive order consolidating the current 100-plus CUI categories could simplify application.
For now, document your scoping decisions, engage your contracting officer early, and recognize that you're not building cybersecurity architecture around well-defined threats. You're building it around regulatory uncertainty.



