Almost every CMMC question resolves to one prior question: do you handle Federal Contract Information, Controlled Unclassified Information, or both? Get that wrong and everything downstream is wrong, including your budget.
This page walks through what CMMC actually requires. For what is currently paused and what is not, see is CMMC still required in 2026.
FCI or CUI: the distinction that decides everything
Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release. Almost any federal contract creates it. It puts you at Level 1: 17 practices, aligned to the basic safeguarding requirements of FAR 52.204-21.
Controlled Unclassified Information is a defined category requiring specific safeguarding — technical drawings, specifications, export-controlled data, and much of what flows down from a prime on a DoD programme. It puts you at Level 2: all 110 controls of NIST SP 800-171 Rev 2.
The gap between those two tiers is enormous in cost and effort, which is why scoping is where competent engagements start.
The 14 control families
NIST SP 800-171 organises its 110 controls into fourteen families. Knowing the shape of them makes the requirement far less intimidating.
| Family | What it covers in practice |
|---|---|
| Access Control | Who can reach what, least privilege, remote access, session controls |
| Awareness and Training | Security training, and role-specific training for privileged users |
| Audit and Accountability | Logging, log review, protecting the logs, traceability to a user |
| Configuration Management | Baselines, change control, inventory, restricting non-essential software |
| Identification and Authentication | Unique identities, multi-factor authentication, password management |
| Incident Response | A plan, detection, reporting, and testing the plan |
| Maintenance | Controlled maintenance, tooling, remote maintenance sessions |
| Media Protection | Removable media, sanitisation, transport, backup protection |
| Personnel Security | Screening, and access removal on departure |
| Physical Protection | Facility access, escorting visitors, protecting equipment |
| Risk Assessment | Periodic assessment, vulnerability scanning, remediation |
| Security Assessment | Assessing your own controls, the SSP, and the POA&M |
| System and Communications Protection | Boundary protection, encryption in transit, segmentation |
| System and Information Integrity | Flaw remediation, malicious code protection, monitoring |
Two families — Personnel Security and Physical Protection — are frequently overlooked because they are not IT problems. They are still assessed.
What “implemented” means
This is where organisations get caught. A control is not satisfied because a policy describes it. It is satisfied when it is operating and you can show that it is.
Take multi-factor authentication. The policy says MFA is required. The evidence is a configuration export showing enforcement, a report showing coverage across accounts, and a record of the exceptions and why they exist. An assessor will ask for the second thing.
- Policy — what you say you do
- Procedure — how it is done, by whom
- Evidence — artefacts showing it happened, dated
All three, for all applicable controls. That is the requirement.
The three documents
- System Security Plan (SSP). Describes your environment, its boundary, and how each control is met. Not a template with your name inserted.
- Plan of Action and Milestones (POA&M). Every control not yet met, with an owner and a date. A POA&M with no dates is not a POA&M.
- SPRS score. Your self-assessed score, submitted and kept current. This is a representation to the government and it carries real exposure if it is inflated.
- FCI means Level 1 and 17 practices. CUI means Level 2 and all 110 controls.
- Marking is unreliable. Contract language and information type decide your tier.
- A control needs policy, procedure and dated evidence. Policy alone fails.
- Personnel Security and Physical Protection are not IT problems and are still assessed.
Remote and distributed contractors
A recurring question, and the answer is unwelcome: a home office that processes CUI is in scope. The practical route most organisations take is to keep CUI out of home environments entirely — a controlled enclave, virtual desktops, and a clear rule that CUI does not leave it.
Trying to bring every home network into scope is technically possible and almost never affordable.
Where to go next
If you need to know which requirements currently apply, read is CMMC still required in 2026. If you are hiring help, our guide to choosing a CMMC consultant covers what to verify. Virginia contractors should also see the regional picture.
Frequently asked questions
What are the CMMC requirements?
CMMC requirements depend on whether you handle Federal Contract Information or Controlled Unclassified Information. FCI puts you at Level 1: 17 practices aligned to FAR 52.204-21. CUI puts you at Level 2: all 110 controls of NIST SP 800-171 Rev 2, organised into 14 control families.
What is the difference between FCI and CUI?
Federal Contract Information is information provided by or generated for the government under a contract and not intended for public release. Controlled Unclassified Information is a defined category requiring specific safeguarding, such as technical drawings, specifications and export-controlled data. Contract language and information type decide which you hold, not whether a document was marked.
What does it mean for a CMMC control to be implemented?
A control is met when it is operating and you can evidence it. That requires three things: a policy saying what you do, a procedure describing how and by whom, and dated artefacts showing it happened. A policy describing multi-factor authentication does not satisfy the control if enforcement cannot be demonstrated.
Do CMMC requirements apply to remote workers?
A home office that processes Controlled Unclassified Information is in scope. Most organisations keep CUI out of home environments entirely using a controlled enclave or virtual desktops, with a clear rule that CUI does not leave it. Bringing every home network into scope is rarely affordable.
Keep exploring
- Is CMMC still required in 2026?
- How to choose a CMMC consultant
- NIST 800-171 compliance
- CMMC compliance services
Ready for a clear path forward?
Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.
Start with a Clarity Conversation