AnalysisAnalysis

Controlled Unclassified Information for Contractors

Identify CUI, connect it to the right contract obligations, and keep system and assessment records current through the CMMC Phase II suspension.

ByMilitary Contractor Editorial
PublishedSeptember 7, 2026
Last checkedSeptember 7, 2026
Reading time11 minutes
Purple Standard Form 901 CUI coversheet with blank instruction fields and a notice to protect attached information
Blank Standard Form 901 (11-2018), shown as a public handling-form example. No controlled contract information is displayed.

As of September 7, 2026, Phase II of the Cybersecurity Maturity Model Certification (CMMC) rollout is suspended, but Phase I self-assessments and underlying information-protection requirements remain. The current defense CIO guidance confirms that distinction. Contractors should continue protecting CUI and maintaining accurate assessment records while checking amendments and modifications for their particular work.

On This Page

Identify the information and its authority

Start with the solicitation or subcontract, its security instructions, and the information needed to perform the work. Ask the contracting contact to identify the relevant CUI category, authority, marking instructions, and sharing restrictions. Record the answer against the actual deliverable or data set so engineering, contracts, and security personnel are working from the same determination.

CUI Basic uses the program's common controls where its underlying authority does not prescribe specific ones. CUI Specified has particular controls in its underlying authority; Basic controls fill the gaps. These are handling distinctions, not CMMC assessment levels. A company's private information does not become CUI merely because the company sells to the government. The government relationship and legal basis matter, as the National Archives glossary explains.

One relevant defense category is controlled technical information. It covers military or space technical information subject to distribution controls and can include engineering drawings, process sheets, technical reports, or software. The category excludes information lawfully available to the public without restrictions. A public product brochure and a restricted engineering package therefore need separate treatment, even if both describe the same equipment.

Federal contract information (FCI) is another term to keep distinct. Under FAR 52.204-21, it concerns nonpublic information supplied by or generated for the government under a product or service contract, with exclusions for public information and simple payment-related transactions. That clause establishes basic system safeguards. Meeting those safeguards alone does not discharge additional CUI obligations.

Missing markings need clarification. The National Archives contractor FAQs direct questions about marked or unmarked information to the originator or government contracting activity. They also explain that protection follows the applicable contract, including for information created for the government. Do not assume a blank banner authorizes public sharing, or indiscriminately stamp an entire company file collection CUI.

For a subcontractor, route the question through the prime's authorized contracting contact where appropriate. A useful request identifies the file or deliverable, conflicting instruction, intended recipient, and decision that cannot proceed without clarification. Keep the response with the contract records.

Separate the contract obligations

The Defense Federal Acquisition Regulation Supplement (DFARS) assigns different jobs to safeguarding, assessment, and CMMC provisions. A reference to one should prompt a check for the others, not an assumption that they are interchangeable.

Contract referenceFunctionWhat to reconcile before committing
DFARS 252.204-7012Safeguarding, incident reporting, and flowdownsInformation involved, covered systems, service providers, and subcontract handling
DFARS 252.204-7019Pre-award NIST assessment requirement when applicableCurrent assessment and posted scores for systems relevant to the offer
DFARS 252.204-7020Assessment procedures and government accessSystem security plans, assessment records, and applicable supplier assessments
DFARS 252.204-7021Required CMMC status and continuing complianceOperative level, system identifiers, affirmations, and contract changes

Source basis: the linked DFARS provisions below, checked September 7, 2026. The final column is a suggested contractor review method, not prescribed form language.

DFARS 252.204-7012 covers qualifying government-provided and contractor-developed information. System requirements differ for contractor business systems and systems operated on the government's behalf. The clause flows down for subcontract work involving covered defense information or operationally critical support.

Read the actual clause and applicable deviations. The National Institute of Standards and Technology (NIST) has superseded Revision 2 of SP 800-171 with Revision 3 as a publication, while current defense CIO guidance still identifies Revision 2's 110 requirements for CMMC Level 2. A newer NIST document does not, by itself, rewrite an existing contract.

What the July 2026 suspension changes

The implementation memorandum for the CMMC Phase II suspension limits procurement requirement designations during the pause to Level 1 (Self) or Level 2 (Self). It directs amendments removing Level 2 third-party assessment and Level 3 assessment requirements from active solicitations. For existing contracts or agreements, it directs removal by modification before the next option exercise or during the next scheduled administrative modification.

That distinction makes the amendment file important. If a package still specifies a third-party assessment, request the corresponding formal change rather than silently treating the text as deleted. The memorandum expressly preserves DFARS 252.204-7012 cybersecurity requirements. Do not use an older November 2026 rollout graphic as the current rule.

The CIO's current overview describes Level 2 self-assessment every three years, annual affirmation, and narrowly permitted plans of action and milestones (POA&Ms) requiring closeout within 180 days. A POA&M is not blanket permission to postpone any requirement. Check the permitted conditions before claiming a conditional status.

Define where CUI can travel

Follow the information through the work, including copies. As an illustrative example, a supplier might receive a controlled drawing, produce manufacturing instructions, send a necessary extract to a subcontractor, and retain an inspection report. This is a planning example, not a determination that every drawing or inspection report is CUI.

For each step, identify the people, endpoint, application, transfer method, and retained copy. Check email attachments, downloaded files, backups, printers, support tools, and supplier portals. An approved location for the original does not establish that every subsequent location is suitable.

NIST SP 800-171 Revision 2 covers components that handle CUI and those protecting them. Its requirements include access restrictions, training, audit records, configuration management, incident handling, media protection, physical security, and vulnerability management. Multifactor authentication applies to local and network access to privileged accounts and network access to nonprivileged accounts. FIPS-validated cryptography is required when cryptography protects CUI confidentiality. These examples do not replace the complete requirement set.

A separated CUI environment can reduce unnecessary information movement, but only if the working arrangements support that boundary. Before relying on one, ask an engineer to walk through a normal task: retrieving a drawing, making notes, requesting help, and delivering the result. Identify where convenience would encourage copying information elsewhere. Resolve those steps in the approved process.

Under DFARS 252.204-7012, an external cloud provider handling covered defense information must meet security equivalent to the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline and specified incident obligations. Ask for evidence covering the actual service and responsibilities.

Paper also needs protection. The National Archives FAQs describe a controlled environment with a locking barrier and note that specified categories can have additional requirements. The official CUI resources page identifies SF 901 as the approved coversheet when an agency chooses to require one. The blank form shown with this article is a public example, not a controlled contract document or a substitute for physical safeguards.

Maintain records that match the system

The system security plan (SSP) should explain the actual boundary, operating environment, implementation of requirements, and connections to other systems. NIST Revision 2 requires periodic updates to that plan, plans to correct deficiencies, and ongoing monitoring. A purchased template cannot establish that a control operates in your environment.

Organize the working records so a responsible manager can trace a stated capability to current evidence:

  • Contract and information determinations: governing clauses, modifications, category and marking guidance, and resolved questions about particular files or deliverables.
  • System and control evidence: the SSP, system inventory, implementation records, and evidence supporting each assessment finding.
  • Open work: a deficiency's owner, planned correction, due date, and evidence of closure, with any conditional-status restrictions checked separately.
  • Assessment submissions: the assessed scope and date, submitted result, relevant system identifiers, and applicable affirmations.
  • Supplier responsibilities: information to be shared, contractual flowdowns, applicable assessment evidence, and service responsibilities.

This is a suggested filing structure. Each record's required content and submission route come from the applicable requirement; the list does not create a new mandatory government deliverable.

DFARS 252.204-7019 requires a current assessment for relevant covered systems when the offeror must implement NIST SP 800-171, generally no more than three years old unless the solicitation specifies less. It also requires verification that summary scores are posted in the Supplier Performance Risk System (SPRS). A score covering another environment is not an answer for the systems proposed here.

DFARS 252.204-7020 ties Basic Assessment records to SSPs and identifies information such as Commercial and Government Entity (CAGE) codes, assessment date, score, and planned completion date. It also provides for government access for Medium or High assessments and requires applicable subcontract assessments before award. Self-assessment should therefore remain supported by records that explain the score.

Where DFARS 252.204-7021 applies, maintain the required CMMC status and annual affirmation for the relevant systems. The clause requires CMMC unique identifiers to be furnished to the contracting officer and covers applicable supplier status and affirmation obligations. Keep these records distinguishable from a Basic NIST assessment score.

Prepare for an incident before one happens

DFARS 252.204-7012 requires reporting qualifying cyber incidents within 72 hours of discovery, including incidents affecting contract-identified operationally critical support. Preserve affected system images and relevant monitoring or packet-capture data for at least 90 days after report submission. Subcontractors promptly provide the incident report number to the prime or next tier.

Before accepting information, name the incident decision owner and backup, establish access to the prescribed reporting mechanism, and agree who can preserve evidence. Include outside providers in that conversation. A reporting deadline is difficult to meet if the person noticing an incident cannot reach the person authorized to act.

Distinguish incident preservation from ordinary document retention. The National Archives FAQs state that CUI status itself does not set a special records-retention period. Apply the relevant contract, records, and incident requirements; do not turn the 90-day incident rule into a universal deletion schedule.

Resolve the handoffs before accepting CUI

The failure points to check are mismatches: an unresolved information designation, a system boundary that omits a working copy, a control claim without evidence, or a supplier receiving information before responsibilities are settled. These are practical review scenarios, not a measured ranking of contractor failures.

Bring contracts, security, engineering, and supply-chain staff together around one representative deliverable. Have them identify its authority, follow its copies, show the relevant protection and assessment records, and explain the incident handoff. Assign an owner to each unresolved issue and resolve it before the affected transfer or commitment. That review gives management a concrete basis for deciding whether the company can handle the information the work requires.

Source notes

  • National Archives CUI glossary. Executive-agent definitions of CUI, Basic and Specified controls, and the government-information relationship.
  • Defense CIO: About CMMC. Current program guidance on the suspension, self-assessment levels, Revision 2, and affirmation cycles.
  • CUI Registry: Controlled Technical Information. Official category description, examples, authority, and public-information exclusion.
  • FAR 52.204-21. Federal contract clause defining FCI and its basic system safeguards.
  • National Archives CUI FAQs. Official guidance on contractor questions, markings, physical protection, and retention.
  • DFARS 252.204-7012. Defense clause covering information, systems, cloud services, incidents, and flowdowns.
  • Implementing Suspension of CMMC Phase II. Official implementation memorandum directing assessment designations and formal solicitation and contract changes.
  • NIST SP 800-171 Revision 2. Technical standard for the cited controls and SSP requirements. Archived by NIST after Revision 3 superseded it; current defense guidance still invokes Revision 2.
  • National Archives CUI resources. Official explanation of SF 901 coversheet use.
  • DFARS 252.204-7019. Solicitation provision for current assessments and posted summary scores.
  • DFARS 252.204-7020. Contract clause establishing assessment procedures, records, government access, and applicable subcontract requirements.
  • DFARS 252.204-7021. Contract clause addressing CMMC status, identifiers, affirmations, and subcontract obligations; read with current suspension instructions and formal changes.

DFARS pages displayed Change 5/7/2026; the FAR page displayed FAC 2026-01. CMMC implementation is subject to further guidance following the announced review.

Last checked: September 7, 2026.

Sources

These are the recoverable records used for this analysis. Dates describe the source record; access dates describe our verification pass.

  1. National Archives CUI glossaryNational Archives · Publication date not recorded · checked September 7, 2026
  2. Defense CIO: About CMMCDefense Chief Information Officer · Publication date not recorded · checked September 7, 2026
  3. CUI Registry: Controlled Technical InformationNational Archives · Publication date not recorded · checked September 7, 2026
  4. FAR 52.204-21Acquisition.gov · Publication date not recorded · checked September 7, 2026
  5. National Archives CUI FAQsNational Archives · Publication date not recorded · checked September 7, 2026
  6. DFARS 252.204-7012Acquisition.gov · Publication date not recorded · checked September 7, 2026
  7. Implementing Suspension of CMMC Phase IIDefense Chief Information Officer · Publication date not recorded · checked September 7, 2026
  8. NIST SP 800-171 Revision 2National Institute of Standards and Technology · Publication date not recorded · checked September 7, 2026
  9. National Archives CUI resourcesNational Archives · Publication date not recorded · checked September 7, 2026
  10. DFARS 252.204-7019Acquisition.gov · Publication date not recorded · checked September 7, 2026
  11. DFARS 252.204-7020Acquisition.gov · Publication date not recorded · checked September 7, 2026
  12. DFARS 252.204-7021Acquisition.gov · Publication date not recorded · checked September 7, 2026