Almost every CMMC question resolves to one prior question: do you handle Federal Contract Information, Controlled Unclassified Information, or both? Get that wrong and everything downstream is wrong, including your budget.

This page walks through what CMMC actually requires. For what is currently paused and what is not, see is CMMC still required in 2026.

FCI or CUI: the distinction that decides everything

Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release. Almost any federal contract creates it. It puts you at Level 1: 17 practices, aligned to the basic safeguarding requirements of FAR 52.204-21.

Controlled Unclassified Information is a defined category requiring specific safeguarding — technical drawings, specifications, export-controlled data, and much of what flows down from a prime on a DoD programme. It puts you at Level 2: all 110 controls of NIST SP 800-171 Rev 2.

The gap between those two tiers is enormous in cost and effort, which is why scoping is where competent engagements start.

Good to know: the most common error we see is an organisation assuming it is FCI-only because nothing arrived marked CUI. Marking is inconsistent in practice. What decides it is the nature of the information and the contract language, not whether somebody remembered to stamp it.

The 14 control families

NIST SP 800-171 organises its 110 controls into fourteen families. Knowing the shape of them makes the requirement far less intimidating.

FamilyWhat it covers in practice
Access ControlWho can reach what, least privilege, remote access, session controls
Awareness and TrainingSecurity training, and role-specific training for privileged users
Audit and AccountabilityLogging, log review, protecting the logs, traceability to a user
Configuration ManagementBaselines, change control, inventory, restricting non-essential software
Identification and AuthenticationUnique identities, multi-factor authentication, password management
Incident ResponseA plan, detection, reporting, and testing the plan
MaintenanceControlled maintenance, tooling, remote maintenance sessions
Media ProtectionRemovable media, sanitisation, transport, backup protection
Personnel SecurityScreening, and access removal on departure
Physical ProtectionFacility access, escorting visitors, protecting equipment
Risk AssessmentPeriodic assessment, vulnerability scanning, remediation
Security AssessmentAssessing your own controls, the SSP, and the POA&M
System and Communications ProtectionBoundary protection, encryption in transit, segmentation
System and Information IntegrityFlaw remediation, malicious code protection, monitoring

Two families — Personnel Security and Physical Protection — are frequently overlooked because they are not IT problems. They are still assessed.

What “implemented” means

This is where organisations get caught. A control is not satisfied because a policy describes it. It is satisfied when it is operating and you can show that it is.

Take multi-factor authentication. The policy says MFA is required. The evidence is a configuration export showing enforcement, a report showing coverage across accounts, and a record of the exceptions and why they exist. An assessor will ask for the second thing.

All three, for all applicable controls. That is the requirement.

The three documents

  1. System Security Plan (SSP). Describes your environment, its boundary, and how each control is met. Not a template with your name inserted.
  2. Plan of Action and Milestones (POA&M). Every control not yet met, with an owner and a date. A POA&M with no dates is not a POA&M.
  3. SPRS score. Your self-assessed score, submitted and kept current. This is a representation to the government and it carries real exposure if it is inflated.
Key takeaways
  • FCI means Level 1 and 17 practices. CUI means Level 2 and all 110 controls.
  • Marking is unreliable. Contract language and information type decide your tier.
  • A control needs policy, procedure and dated evidence. Policy alone fails.
  • Personnel Security and Physical Protection are not IT problems and are still assessed.

Remote and distributed contractors

A recurring question, and the answer is unwelcome: a home office that processes CUI is in scope. The practical route most organisations take is to keep CUI out of home environments entirely — a controlled enclave, virtual desktops, and a clear rule that CUI does not leave it.

Trying to bring every home network into scope is technically possible and almost never affordable.

Where to go next

If you need to know which requirements currently apply, read is CMMC still required in 2026. If you are hiring help, our guide to choosing a CMMC consultant covers what to verify. Virginia contractors should also see the regional picture.

Frequently asked questions

What are the CMMC requirements?

CMMC requirements depend on whether you handle Federal Contract Information or Controlled Unclassified Information. FCI puts you at Level 1: 17 practices aligned to FAR 52.204-21. CUI puts you at Level 2: all 110 controls of NIST SP 800-171 Rev 2, organised into 14 control families.

What is the difference between FCI and CUI?

Federal Contract Information is information provided by or generated for the government under a contract and not intended for public release. Controlled Unclassified Information is a defined category requiring specific safeguarding, such as technical drawings, specifications and export-controlled data. Contract language and information type decide which you hold, not whether a document was marked.

What does it mean for a CMMC control to be implemented?

A control is met when it is operating and you can evidence it. That requires three things: a policy saying what you do, a procedure describing how and by whom, and dated artefacts showing it happened. A policy describing multi-factor authentication does not satisfy the control if enforcement cannot be demonstrated.

Do CMMC requirements apply to remote workers?

A home office that processes Controlled Unclassified Information is in scope. Most organisations keep CUI out of home environments entirely using a controlled enclave or virtual desktops, with a clear rule that CUI does not leave it. Bringing every home network into scope is rarely affordable.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation