1FCI and CUI, More Closely
Everything in CMMC begins with a question of information: which of the two protected categories a contractor handles, and where that information actually lives. The level, the scope, and the assessment all follow from the answer, so the concepts in this part start there.
Federal contract information is the broader category: information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service, excluding both information the government has made public and simple transactional information such as what is needed to process a payment. Almost any contractor that produces deliverables for the government handles some FCI, which is why Level 1 reaches so much of the base.
Controlled unclassified information is the sensitive subset that raises the stakes: information the government creates or possesses, or that a contractor creates or possesses on the government's behalf, that a law, regulation, or governmentwide policy requires to be safeguarded or subjected to dissemination controls. CUI is defined and organized by the National Archives program at 32 CFR Part 2002 and catalogued in the CUI Registry, which lists the categories the government recognizes, from export-controlled material to controlled technical information. The registry also draws a distinction between CUI Basic, which follows the uniform baseline handling, and CUI Specified, which carries additional handling rules from the law or regulation that created it. For the purpose of CMMC, both are CUI, and either pulls the environment that touches it to Level 2.
The difficult part in practice is not the definition but the identification. The government is supposed to mark CUI and to tell a contractor, through the contract and the markings, exactly what it is receiving, and it frequently does neither cleanly, so contractors receive material that is CUI in substance but unmarked in fact. On a manufacturing floor the most common form is controlled technical information, the drawings, specifications, and process data that arrive under DFARS 252.204-7012, and the obligation to protect it does not disappear because a marking was omitted. The first real task of a readiness effort is usually the unglamorous one of finding where CUI actually is, because the location of that information determines the scope, which is the next concept.
2The Assessment Scope and Its Asset Categories
Before an environment can be assessed, its scope has to be drawn: which assets are in, and against what each will be judged. CMMC Level 2 does this by sorting every asset according to its relationship to CUI, and the categorization is the single most consequential early decision in a readiness effort, because it sets the size and the difficulty of everything that follows.
| Asset category | What it is | How it is treated |
|---|---|---|
| CUI Assets | Process, store, or transmit CUI | In scope, and assessed against all applicable Level 2 requirements |
| Security Protection Assets | Provide security functions to the environment, whether or not they themselves handle CUI | In scope, and assessed against the requirements relevant to the protection they provide |
| Contractor Risk Managed Assets | Could handle CUI but are not intended to, and are governed by security policy rather than full separation | In scope for documentation, and assessed through the system security plan unless a deficiency is evident |
| Specialized Assets | Government furnished equipment, operational technology, test equipment, restricted systems, and the like | Documented and managed through the system security plan, not assessed against the full set |
| Out-of-Scope Assets | Cannot process, store, or transmit CUI, and are separated from the assets that do | Not part of the assessment |
The category that governs the effort is the first one, because CUI Assets carry the full weight of the 110 requirements. The most effective way to control an assessment is therefore to control where CUI is permitted to go. An enclave, a small and deliberately separated environment built to hold CUI and nothing else, shrinks the population of CUI Assets and pulls the rest of the business into the lighter categories or out of scope altogether. Out-of-scope status is not a default that assets fall into, it is a status an asset earns by being both unable to reach CUI and separated from the assets that handle it, and an assessor will look for that separation rather than take it on faith.
Level 1 scoping is simpler by comparison. For FCI and Level 1 the scope is the set of assets that process, store, or transmit FCI, the asset-category taxonomy above does not apply in the same way, and the annual self-assessment covers those assets against the fifteen basic requirements. The detailed scoping guidance, including the mechanics of enclaves and the treatment of cloud and managed services, is substantial enough to warrant its own treatment, but the categories above are the concept a reader needs before the rest of the program makes sense.
3The SPRS Score
The result of a Level 2 self-assessment or certification assessment is expressed as a single number and posted to the Supplier Performance Risk System, the SPRS. Under the DoD scoring methodology reflected in 32 CFR 170.24, the score begins at 110, one point for each requirement, and every requirement scored NOT MET subtracts its weight from that starting total.
The weighting is where the number stops being a simple count. Each requirement is worth 1, 3, or 5 points, and the heavier weights sit on the requirements that do the most to protect CUI, among them boundary protection, multifactor authentication, and audit and accountability. A clean implementation scores the full 110. Because the deductions are weighted and cumulative, a weak environment can score well below zero, down to a floor of negative 203 under the methodology, which is why a low but positive score can still represent a serious gap. The number is best read not as a grade but as a claim: it is a representation to the government of how much of the standard is actually in place, and the affirmation attached to it is what turns an inflated score into False Claims Act exposure rather than a private optimism. Whether an imperfect score is nonetheless good enough to earn a conditional pass is decided by the plan of action rules.
4Conditional Status and the Plan of Action Rules
A Level 2 assessment ends in one of a few outcomes. Meeting all 110 requirements produces a Final CMMC Status, the clean certification. Passing with a small and specifically permitted set of gaps produces a Conditional CMMC Status, which is real enough to support a contract award but temporary and bound by a deadline. Falling below the threshold produces neither, and no award follows.
To earn Conditional status the score has to be at least 80 percent of the total, which for Level 2 is 88 of 110, and the gaps that remain have to be eligible for a plan of action and milestones, the POA&M. The eligibility rules in 32 CFR 170.21 are narrow by design. A plan of action can hold only requirements worth 1 point under the scoring methodology, which means every 3-point and 5-point requirement has to be fully met before the assessment. Six specifically named 1-point requirements are excluded even so: limiting connections to external systems (AC.L2-3.1.20), controlling information posted to publicly accessible systems (AC.L2-3.1.22), the system security plan itself (CA.L2-3.12.4), and the three physical controls covering visitor escort, physical access logs, and management of physical access devices (PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5). One narrow exception runs the other way, allowing a requirement above a single point onto a plan of action: SC.L2-3.13.11, FIPS-validated cryptography, may be deferred when encryption is in use but is not yet FIPS-validated, its 3-point partial-credit condition.
| Requirement | Eligible for a plan of action? | Why |
|---|---|---|
| 5-point requirements | No | Must be fully met before the assessment |
| 3-point requirements | No | Must be fully met before the assessment |
| 1-point requirements, in general | Yes | The only category a plan of action can carry |
| The six named 1-point requirements, including the system security plan | No | Excluded by name in 32 CFR 170.21 despite the single point |
| SC.L2-3.13.11, encryption present but not FIPS-validated | Yes, in that state only | The one requirement above 1 point a plan of action may carry |
The arithmetic leaves a narrow lane. Because the pass line is 88 and the ceiling is 110, only 22 points of gap can be carried at all, and every one of those points has to come from an eligible 1-point item, so a plan of action is a tool for finishing touches rather than a way to defer the requirements that carry real weight. Conditional status then runs 180 days from the Conditional CMMC Status Date, the date the results are posted to SPRS or eMASS, and within that window every open item has to be closed and confirmed by a closeout assessment, performed by the contractor for a self-assessment and by a C3PAO for a certification. Missing the window expires the Conditional status, which for a contract already in performance triggers the standard contractual remedies, and because assessor scheduling runs long the closeout is something to book at the start of the window rather than chase at the end.
5The System Security Plan
Every concept to this point converges in one document. The system security plan, the SSP, describes the assessment scope, names the assets in each category, and states requirement by requirement how each applicable control is met, by whom, and with what. It is the map an assessor works from and the record the score is drawn against, which makes it less a piece of paperwork than the written form of the environment itself.
The SSP is neither optional nor deferrable. The requirement to have it, CA.L2-3.12.4, is one of the six named requirements that cannot be placed on a plan of action, so an environment without a current SSP does not carry a small deduction, it lacks the floor beneath which an assessment does not meaningfully proceed. An SSP that has fallen behind the environment, describing controls as implemented that have since changed, becomes its own scoring risk, because the assessment tests the environment against the plan and scores the difference. The plan of action is the SSP's companion in this: the SSP records what is in place, the plan of action records what is not yet in place and when it will be, and read together they are the honest account of the environment that an affirmation attests to.
The evidence behind the SSP carries its own discipline. For a certification assessment the artifacts used as evidence are hashed with a NIST-approved algorithm and retained for six years from the CMMC Status Date, so that what was shown during the assessment can later be shown to be unchanged. Taken together, the scope, the score, the plan of action, and the plan itself stop being separate ideas in the SSP and become a single defensible description of the environment, and building that description to match reality, rather than to match the standard on paper, is most of the work and the whole of the point.
From the concepts to a documented environment
Drawing the scope, categorizing the assets, scoring honestly against the 110, and writing an SSP that matches the environment is onsite readiness work, done in the order an assessment will read it. That is the practice behind this guide.
Start CMMC Readiness or call 802-335-26626Sources
- 32 CFR Part 170, CMMC Program, including the scoring methodology at 32 CFR 170.24, the plan of action rules at 32 CFR 170.21, and the Level 2 status and artifact requirements at 32 CFR 170.16 and 170.17. ecfr.gov
- 32 CFR 170.21, Plan of Action and Milestones requirements, for the 80 percent threshold, the point-value limits, the named exclusions, and the 180-day closeout. ecfr.gov
- 32 CFR Part 2002 and the DoD CUI Registry, for the definition and categories of controlled unclassified information, including the distinction between CUI Basic and CUI Specified. ecfr.gov
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, the source of the controlled technical information obligation. acquisition.gov
- NIST SP 800-171 Rev 2 and NIST SP 800-171A, the 110 requirements and the assessment objectives to which CMMC Level 2 is pinned. csrc.nist.gov