Industry Guide

Defense Cybersecurity: CMMC 2.0 L1/L2/L3 + CUI + DFARS 252.204-7012 Guide for DoD Contractors

Five overlapping obligations apply to defense contractors pursuing SOC 2 + federal procurement eligibility: CMMC 2.0 (Level 1 17 practices for FCI + Level 2 110 practices on NIST SP 800-171 for CUI under 32 CFR Part 170 + Level 3 134 practices on NIST SP 800-172 for highest-priority programs), CUI under 32 CFR Part 2002 + the NARA CUI Registry (marking, destruction, spillage, awareness training), DFARS 252.204-7012 72-hour cyber-incident reporting cadence back to the DoD via the DIBNet portal with preservation of CUI for forensic purposes and False Claims Act exposure for material misrepresentation, NIST SP 800-171 as the 110-control CUI family that CMMC L2 is sampled against with full 14-family coverage + FIPS-validated crypto + monthly vulnerability scans, and supplier flow-down requiring every Tier 1–3 subcontractor handling CUI to operate at CMMC Level 2 with a 72-hour breach-notification SLA tied to DFARS cadence. Defense industrial base (DIB) suppliers hold uniquely targeted data — Controlled Unclassified Information + Covered Defense Information + ITAR/EAR export-controlled technical data — making them prime targets for nation-state APT, CUI exfiltration, and ransomware on CUI systems. The IT/OT overlay on defense manufacturers means a single shared credential between corporate IT and OT systems handling CUI can halt production on the OT side while exporting CUI on the IT side — a $1.7M/day average shutdown cost (Ponemon 2025) plus False Claims Act exposure for material misrepresentation in self-attestation. This guide covers which CMMC 2.0 + CUI + DFARS + NIST 800-171 obligations apply to your operation, what controls satisfy the C3PAO assessment sampling unit, and how to close the CUI-aware + supplier-flow-down gaps before a C3PAO assessment finding, a NARA CUI spillage investigation, or a DoD contract loss of eligibility surfaces them.

📅 Updated June 2026 ⏱ 8 min read 🏢 Defense Sector
110
practices on NIST SP 800-171 required for CMMC Level 2 — required for DoD CUI suppliers by October 2026
32 CFR Part 170
Get Your Free Assessment
See exactly how your defense organization scores on cybersecurity readiness
Get Your Defense Security Score →

CMMC readiness checklist

Use these five checkpoints to organize the controls and evidence a CMMC assessment will sample.

Asset inventory

  • Document every system, device, application, cloud service, and media location that stores, processes, or transmits CUI.
  • Define the CUI system boundary and keep an approved inventory tied to owners, locations, and data flows.
  • Record CUI-bearing media and sanitize or destroy it using the approved method at end of life.

MFA

  • Require phishing-resistant or FIPS-validated MFA for every account with access to a CUI system.
  • Use unique identities for people, devices, and services; remove shared credentials and review privileged access.
  • Protect remote maintenance and supplier access with MFA, time-bound permissions, and recorded sessions.

Incident response

  • Maintain a CUI-aware incident response plan with named owners, escalation contacts, and decision points.
  • Document the DFARS 252.204-7012 DIBNet reporting path and the 72-hour cyber-incident reporting cadence.
  • Test containment, CUI preservation, spillage handling, and forensic evidence collection in a tabletop exercise.

Access control

  • Limit CUI access to authorized people with a documented need to know and least-privilege role assignments.
  • Separate CUI systems from corporate IT and OT, with documented boundaries, conduits, and controlled east-west traffic.
  • Review access quarterly and revoke CUI access promptly after termination, transfer, or role change.

Evidence collection

  • Organize the system security plan, CUI boundary diagram, policies, inventories, and POA&M in one assessment-ready location.
  • Retain access reviews, MFA reports, audit logs, vulnerability scans, training records, and incident-response test results.
  • Map each CMMC practice to an owner, implementation status, and dated artifact a C3PAO can sample.

Top Cyber Risks for Defense Businesses

CMMC Level 2 C3PAO assessment failure
Loss of DoD contract eligibility under 32 CFR Part 170; 110 practices on NIST SP 800-171 required for CUI by October 2026
CUI spillage + uncontrolled disclosure
NARA CUI Registry spillage notification + DFARS 252.204-7012 72-hour cadence + recursive CUI destruction across affected systems
DFARS 252.204-7012 cyber-incident reporting failure + FCA exposure
72-hour breach-notification to DoD via DIBNet missed; False Claims Act exposure for material misrepresentation in self-attestation
Supplier flow-down exclusion cascading to Tier 1–3
A single Tier 1 subcontractor CMMC L2 failure excludes every downstream Tier 2/3 contractor from the same prime contract
IT/OT CUI-system OT-network admin separation failure on defense manufacturers
Shared service account pivots from corporate IT to OT handling CUI — production shutdown + CUI export in one path

Regulations and Frameworks for Defense Organizations

Several overlapping frameworks may apply to your defense organization depending on contract role, data handled, customer requirements, and jurisdiction. Not all apply to every organization — use this guide to identify which are relevant to you.

CMMC 2.0 — DoD defense industrial base contractors under 32 CFR Part 170

Applies to: Every DoD prime + subcontractor at every tier handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under DFARS 252.204-7012 / NIST SP 800-171. CMMC 2.0 is the contractual cybersecurity framework the DoD applies across the defense industrial base.

  • Level 1 (17 practices covering FCI) — annual self-assessment and affirmation, no third-party assessment required; applicable to all DoD contractors handling FCI
  • Level 2 (110 practices covering CUI on NIST SP 800-171) — triennial third-party assessment by a C3PAO (CMMC Third-Party Assessment Organization) under 32 CFR Part 170, required for CUI exposure by October 2026
  • Level 3 (highest-priority programs, 134 practices on NIST SP 800-172) — DoD-led DIBCAC assessment for the highest-priority assets
  • MSP / MSSP validation only for Level 3 — the DoD does not independently certify a contractor's external service provider at Levels 1 / 2; the contractor must attest to flow-down
  • Plan of Action and Milestones (POA&M) for any unmet practice — pre-existing governance expectation, not a deferral
  • NIST SP 800-171 control family mapping: AC (access control), AU (audit and accountability), AT (awareness and training), CM (configuration management), IA (identification & authentication), IR (incident response), MA (maintenance), MP (media protection), PS (personnel security), PE (physical and environmental), SC (system and communications protection), SI (system and information integrity) — full 14-family coverage as the CMMC L2 sampling unit
  • NIST SP 800-172 (enhanced security requirements for Level 3) — for highest-priority programs handling critical CUI; penetration-test-grade controls over L2 baseline
  • CUI awareness training records — annual CUI handling + marking + destruction + spillage cadence training for every employee handling CUI
  • Flow-down to subcontractors: any Tier 1–3 subcontractor handling CUI must itself operate at CMMC Level 2 — the prime cannot contractually waive it
  • Pre-2026 contracting: bidders on DoD contracts that include CMMC requirements must self-attest to Level 1 or Level 2 in the DD Form 254 / DFARS offer flowdown
Penalty: Loss of DoD contract eligibility on C3PAO assessment failure under 32 CFR Part 170; flow-down exclusion from DoD prime contractor contracts; potential DFARS cyber-incident False Claims Act exposure for material misrepresentations in self-attestation; cyber-insurance exclusions for missing MFA on CUI-touching accounts + missing CUI-system network segmentation; downstream subcontractor survival threatened when a prime is removed.

CUI under 32 CFR Part 2002 + the NARA CUI Registry

Applies to: Every DoD contractor handling Controlled Unclassified Information (CUI) — government-created or possessed information that requires safeguarding or dissemination controls under federal law, regulation, or government-wide policy. 32 CFR Part 2002 is the implementing regulation; the NARA CUI Registry (https://www.archives.gov/cui) is the authoritative list of CUI categories and applicable controls.

  • CUI marking on every document, email, and file containing CUI: CUI//SP-XXXX banner line + designated CUI category (e.g. CUI//SP-PRIVCY, CUI//SP-PROP) + dissemination controls (e.g. NOFORN, ORCON)
  • CUI destruction methods per 32 CFR Part 2002 + the CUI category — burning, cross-cut shredding, degaussing, NIST SP 800-88 sanitization; no general recycling of CUI-bearing media
  • CUI spillage immediate containment + NARA spillage notification + DFARS cyber-incident cadence trigger — the moment a non-authorized person accesses CUI, the 72-hour DFARS clock starts
  • CUI access controls — limited to authorized persons with a lawful government purpose; documented need-to-know reasoning
  • CUI covered defense information (CDI) — defense information specifically protected by DFARS and ITAR/EAR — a subset of CUI with additional handling requirements
  • CUI destruction at end-of-life — every CUI-bearing laptop, smartphone, USB drive, server, and backup tape must be sanitized per CUI category before disposal or reuse
  • Annual CUI awareness training — every employee handling CUI must complete annual awareness training with documented training records (NARA CUI Training requirements + agency-specific training)
  • CUI transmission safeguards — TLS 1.2+ for CUI in transit; FIPS-validated cryptography when CUI traverses federal systems or FedRAMP-authorized cloud; email encryption for CUI-bearing messages
  • CUI incident reporting — any actual or suspected unauthorized disclosure of CUI must be reported to the originating agency and tracked through NARA CUI spillage procedures
  • Controlled environments — CUI must be processed, stored, and handled in environments that meet the safeguarding requirements of 32 CFR Part 2002 (physical and logical safeguards)
Penalty: Federal contract loss of eligibility for mishandling CUI; NARA CUI Registry follow-up + agency-specific CUI program review; DFARS cyber-incident cadence triggers False Claims Act exposure when material misrepresentation occurred in self-attestation; potential OCI (Organizational Conflict of Interest) restrictions on follow-on contracts; loss of CUI-handling authority under 32 CFR Part 2002.

DFARS 252.204-7012 + 72-hour cyber-incident reporting cadence

Applies to: Every DoD contractor handling Covered Defense Information (CDI) or Controlled Unclassified Information (CUI) on contractor information systems — the clause is incorporated by reference into every DoD contract that involves CDI/CUI handling.

  • DFARS 252.204-7012(c)(1) — safeguarding covered defense information + cyber-incident reporting obligation
  • DFARS 252.204-7012(c)(2) — 72-hour cyber-incident reporting cadence to the DoD via the DIBNet portal at https://dibnet.dod.mil following discovery (the stricter 72-hour cadence shortens typical state AG notification)
  • DFARS 252.204-7012(d) — preservation of covered defense information for forensic purposes following discovery (90 days minimum)
  • DFARS 252.204-7012(e) — written cyber-incident report with required fields: cyber-incident timeline, affected systems, type of CUI/CDI compromised, mitigation steps, root-cause analysis
  • DFARS 252.204-7012(f) — cooperation with DoD-led damage assessment activities; provide access to contractor systems + personnel for DIB damage assessment
  • NIST SP 800-171 implementation — DFARS 252.204-7012 incorporates NIST SP 800-171 as the safeguarding standard, which became the CMMC L2 sampling unit
  • False Claims Act exposure — material misrepresentation in self-attestation to NIST SP 800-171 compliance before the 2026 CMMC deadline triggers FCA liability under 31 U.S.C. §§ 3729-3733
  • Cloud computing requirements — if CUI is processed or stored in cloud, the cloud service provider must meet FedRAMP Moderate baseline or equivalent (DFARS 252.204-7012(b)(2)(ii)(D))
  • Subcontractor flow-down — every subcontract involving CDI/CUI handling must include the same DFARS clause language verbatim
  • Reporting timeline: "rapidly report" means within 72 hours of discovery; written cyber-incident report due within 30 days unless extended
Penalty: Loss of DoD contract eligibility on cyber-incident reporting failure; False Claims Act exposure on material misrepresentation in pre-2026 self-attestation to NIST SP 800-171 compliance; downstream contract exclusions; potential criminal exposure under 18 U.S.C. § 1001 for false statements in self-assessment to the federal government; cyber-insurance exclusion for missing 72-hour DFARS cadence runbook.

NIST SP 800-171 — 110 CUI controls sampled against for CMMC Level 2

Applies to: Every DoD prime + subcontractor handling CUI under DFARS 252.204-7012 / CMMC 2.0 Level 2 / 32 CFR Part 170. NIST SP 800-171 is the foundational CUI control family — CMMC L2 samples every practice during the C3PAO assessment.

  • AC (Access Control) — 22 controls on CUI access enforcement, account management, wireless access restrictions, mobile code + sandboxing
  • AU (Audit and Accountability) — 9 controls on auditable events, content of audit records, audit review/analysis/reporting, audit reduction, time synchronization
  • AT (Awareness and Training) — 3 controls on security awareness training, role-based security training, annual CUI literacy training
  • CM (Configuration Management) — 9 controls on baseline configurations, configuration change control, monitoring configuration changes, least functionality
  • IA (Identification & Authentication) — 11 controls on user identification, device identification, MFA enforcement on privileged accounts + network access to CUI systems
  • IR (Incident Response) — 3 controls on incident response plan, incident reporting + 72-hour DFARS cadence, incident response testing
  • MA (Maintenance) — 6 controls on controlled maintenance, maintenance tools, nonlocal maintenance + MFA, maintenance personnel
  • MP (Media Protection) — 9 controls on media access restrictions, media marking, media storage, media transport, media sanitization per NIST SP 800-88
  • PS (Personnel Security) — 8 controls on personnel screening, personnel termination, personnel transfer, access agreements
  • PE (Physical and Environmental) — 6 controls on physical access authorizations, monitoring physical access, visitor control, physical access logs
  • SC (System and Communications Protection) — 16 controls on boundary protection, security engineering, mobile code, CUI system segregation, transmission confidentiality/integrity
  • SI (System and Information Integrity) — 7 controls on flaw remediation + 30-day critical / 60-day high cadence, malicious code protection, monitoring system input/output, security alerts
  • RA + SA control family at r3 alignment — risk assessment + security assessment family overlap with NIST SP 800-171 r3 — 6 additional controls
  • FIPS-validated cryptography — when CUI traverses FedRAMP-authorized cloud or federal systems; SC family SC-13 references FIPS 140-2/3 validated modules
  • MFA on every CUI-touching account — IA-2(1) / IA-2(2) requires MFA on local + network access to CUI systems
  • 90+ day log retention + monthly vulnerability scans with remediation within 30 days critical / 60 days high — the SI + AU family input
Penalty: C3PAO L2 assessment failure with loss of DoD contract eligibility; DFARS False Claims Act exposure on material misrepresentation in self-attestation; cyber-insurance loading for missing MFA + missing log retention + missing vulnerability remediation cadence; documented as a SIP (Special Item) at the assessment to flag critical practice gaps.

Supplier flow-down + DFARS cyber-incident + cyber-insurance readiness

Applies to: Every DoD prime + Tier 1–3 subcontractor handling CUI/CDI, every defense contractor operating in a state with breach-notification + reasonable-security laws (all 50 states), and every DIB supplier with cyber-insurance coverage requiring MFA + segmentation + IRP + immutable backups as condition precedent.

  • Supplier flow-down: every Tier 1–3 subcontractor handling CUI must operate at CMMC Level 2 — the prime cannot contractually waive it, and the prime bears FCA + flow-down exclusion consequences
  • Subcontractor tiering — Tier 1 (system-integrator / OEM support with persistent CUI access) + Tier 2 (occasional CUI handlers) + Tier 3 (intermittent CUI access) with addenda matching tier risk
  • Jump-server CUI access: jump-server with hardware-token MFA + session recording + time-bound credentials + no persistent VPN for every Tier 1–3 vendor with CUI access
  • 72-hour breach-notification SLA: subcontractor cyber-incident must trigger DFARS DIBNet cadence within 72 hours of discovery — and tie to the prime's DFARS cyber-incident reporting obligation
  • Cyber-insurance MFA + segmentation + IRP gates: insurance carriers require MFA on every CUI-touching account, CUI-system network segmentation evidence, OT-aware IRP runbook (for DIB manufacturers), and immutable + offline-tested backups as condition precedent for binding or renewal
  • CUI-system network segmentation evidence: documented CUI-system vs corporate-IT segmentation with named conduits, controlled east-west traffic, and zone/conduit diagrams
  • 50-state breach notification: state AG cadence (typically 30–60 days for most states) in parallel with DFARS DIBNet 72-hour cadence where the breach involves state-resident personal information
  • CUI spillage immediate containment runbook: NARA CUI spillage procedure + DFARS cyber-incident cadence trigger + recursive CUI destruction across affected systems + NARA follow-up notification
  • Cyber-insurance exclusions for missing MFA + missing CUI-system segmentation + missing immutable backups + missing DFARS 72-hour runbook — the four most common coverage exclusions for DIB suppliers
  • C3PAO L2 attestation evidence lowers cyber-insurance pricing; missing CMMC L2 attestation evidence raises carrier loading
Penalty: Coverage exclusion for unsegmentated CUI systems; cyber-insurance loading for missing MFA + missing jump-server vendor remote access + missing OT-aware IRP + missing immutable backups; loss of DoD contract eligibility under DFARS 252.204-7012 false attestation; False Claims Act exposure on material misrepresentation in self-attestation; downstream subcontractor survival threatened when a prime is removed.

Required Controls at a Glance

These controls provide a practical baseline for sector-specific compliance and cybersecurity gap assessments.

Required controls at a glance
Control AreaRequired Control
CUI marking + destruction per 32 CFR Part 2002 Every CUI document, email, and file marked CUI//SP-XXXX with designated category + dissemination controls; destruction via cross-cut shredding, degaussing, or NIST SP 800-88 sanitization per CUI category — the 32 CFR Part 2002 + NARA CUI Registry operating discipline
CUI access scoping + boundary evidence Documented need-to-know reasoning for every CUI-authorized account; CUI-system vs corporate-IT segmentation with named conduits + controlled east-west traffic + zone/conduit diagrams — the SC family sampling unit
CMMC Level 2 evidence package on NIST SP 800-171 Documented mapping of every CMMC Level 2 practice (110 controls on NIST SP 800-171) to the contractor's controls — including CUI access governance + DFARS cyber-incident cadence + CUI-system segmentation — ready for C3PAO L2 assessment under 32 CFR Part 170
DFARS 252.204-7012 72-hour cyber-incident cadence runbook Documented 72-hour cyber-incident reporting cadence to the DoD via the DIBNet portal at https://dibnet.dod.mil; preservation of CUI for forensic purposes; written cyber-incident report with required fields; cooperation with DoD-led damage assessment — the IR family + DFARS clause language input
Multi-factor authentication on every CUI-touching account FIPS-validated MFA on every CUI-touching account (admin + engineer + CUI-handling user); hardware-token MFA on privileged accounts, TOTP on standard CUI-handling accounts, no SMS — the IA-2(1)/IA-2(2) + SC family sampling unit
Supplier flow-down contractual evidence (Tier 1–3 CMMC L2 attestation) Documented CMMC L2 attestation evidence for every Tier 1–3 subcontractor handling CUI; jump-server + MFA + session-recording + time-bound credentials + 72-hour breach-notification SLA tied to DFARS cadence — the supplier flow-down requirement that the prime cannot contractually waive
Separation of CUI systems from corporate IT CUI systems operated on a logically + physically segregated network from corporate IT — dedicated accounts, dedicated devices, no shared administrative credentials, controlled east-west traffic — the SC family + CUI access scoping input
CUI awareness training (annual) Annual CUI handling + marking + destruction + spillage awareness training for every employee handling CUI; documented training records with completion dates; refresher training on CUI category updates — the AT family + 32 CFR Part 2002 awareness requirement

CMMC + NIST SP 800-171 + DFARS + CUI Crosswalk for DoD Contractors

For a defense contractor pursuing CMMC 2.0 alongside DFARS 252.204-7012 + 32 CFR Part 2002 CUI operating discipline + cyber-insurance readiness, the right architectural model is to treat CMMC L2 110 practices on NIST SP 800-171 + DFARS 252.204-7012 72-hour cadence + CUI marking/destruction per 32 CFR Part 2002 as the audit-ready evidence wrappers, and supplier flow-down + cyber-insurance MFA/segmentation/IRP/immutable backups as the contractual / readiness wrappers layered on top of the same CUI-aware controls. Operationally: CMMC AC (Access Control) ↔ NIST SP 800-171 AC family tests the same CUI-system vs corporate-IT segmentation + need-to-know reasoning a defense contractor implements for every CUI-touching account; CMMC IA ↔ NIST SP 800-171 IA family tests the FIPS-validated MFA on every CUI-touching account; CMMC IR ↔ NIST SP 800-171 IR family tests the DFARS 252.204-7012 72-hour cyber-incident cadence runbook with DIBNet portal access + CUI preservation + written cyber-incident report + damage-assessment cooperation; CMMC MP ↔ NIST SP 800-171 MP family tests the CUI destruction per 32 CFR Part 2002 + NIST SP 800-88 sanitization; CMMC SC ↔ NIST SP 800-171 SC family tests CUI system segregation + FIPS-validated crypto + boundary protection; CMMC SI ↔ NIST SP 800-171 SI family tests 30-day critical / 60-day high vulnerability remediation cadence; supplier flow-down tests every Tier 1–3 subcontractor CMMC L2 attestation evidence + DFARS clause language the prime cannot contractually waive. The seven highest-leverage crosswalk pairs are: CMMC L2 AC/IA ↔ CUI access governance + FIPS-validated MFA on every CUI-touching account, CMMC L2 IR ↔ DFARS 252.204-7012 72-hour cyber-incident cadence + DIBNet portal runbook, CMMC L2 SC ↔ CUI-system segmentation + FIPS-validated crypto + boundary protection, CMMC L2 MP ↔ CUI destruction per 32 CFR Part 2002 + NIST SP 800-88 sanitization, 32 CFR Part 2002 CUI spillage ↔ DFARS 72-hour cadence trigger + NARA CUI Registry notification, supplier flow-down ↔ Tier 1–3 CMMC L2 attestation + DFARS clause flow-down + 72-hour SLA, cyber-insurance gates ↔ MFA on CUI-touching accounts + CUI-system segmentation + DFARS cadence runbook + immutable backups.

CMMC + NIST SP 800-171 + DFARS + CUI Crosswalk for DoD Contractors
CMMC practiceNIST SP 800-171 controlImplementation / evidence
AC.L2-3.1.1–3.1.223.1 Access ControlCUI system boundary, least-privilege roles, approved access list, and quarterly access reviews.
AT.L2-3.2.1–3.2.33.2 Awareness and TrainingAnnual CUI/security awareness records plus role-based training completion for privileged users.
AU.L2-3.3.1–3.3.93.3 Audit and AccountabilityCentralized audit logs, synchronized time, defined review cadence, and retained review tickets.
CM.L2-3.4.1–3.4.93.4 Configuration ManagementApproved secure baselines, asset inventory, change tickets, and configuration monitoring results.
IA.L2-3.5.1–3.5.113.5 Identification and AuthenticationUnique IDs, phishing-resistant or FIPS-validated MFA, service-account ownership, and access logs.
IR.L2-3.6.1–3.6.33.6 Incident ResponseCUI-aware IRP, tabletop results, DIBNet contact/runbook, and documented 72-hour escalation procedure.
MA.L2-3.7.1–3.7.63.7 MaintenanceApproved maintenance requests, technician authorization, MFA-protected remote sessions, and session records.
MP.L2-3.8.1–3.8.93.8 Media ProtectionCUI media register, marking and chain-of-custody records, transport approvals, and sanitization certificates.
PS.L2-3.9.1–3.9.23.9 Personnel SecurityScreening records, signed access agreements, and termination/transfer checklists revoking CUI access.
PE.L2-3.10.1–3.10.63.10 Physical ProtectionBadge authorization list, visitor logs, facility monitoring, and physical access review records.
RA.L2-3.11.1–3.11.33.11 Risk AssessmentCUI risk assessment, vulnerability scan reports, threat tracking, and documented remediation priorities.
CA.L2-3.12.1–3.12.43.12 Security AssessmentSystem security plan, POA&M, assessment results, and management review of corrective actions.
SC.L2-3.13.1–3.13.163.13 System and Communications ProtectionCUI/IT segmentation diagram, boundary rules, encrypted transmissions, and firewall review evidence.
SI.L2-3.14.1–3.14.73.14 System and Information IntegrityVulnerability remediation tickets, malware protection alerts, integrity monitoring, and scan cadence reports.
  • CMMC L2 AC + IA families ↔ CUI access governance + need-to-know reasoning + FIPS-validated MFA on every CUI-touching account — the AC/lA family sampling unit a C3PAO L2 assessor will sample
  • CMMC L2 IR family ↔ DFARS 252.204-7012 72-hour cyber-incident cadence + DIBNet portal runbook + CUI preservation + written cyber-incident report + damage-assessment cooperation
  • CMMC L2 SC family ↔ CUI-system segmentation + FIPS-validated crypto when CUI traverses FedRAMP-authorized cloud + boundary protection + controlled east-west traffic
  • CMMC L2 MP family ↔ CUI destruction per 32 CFR Part 2002 + NIST SP 800-88 sanitization + CUI media marking + CUI media transport safeguards
  • 32 CFR Part 2002 CUI spillage ↔ DFARS 72-hour cadence trigger + NARA CUI Registry notification + recursive CUI destruction across affected systems
  • Supplier flow-down ↔ Tier 1–3 CMMC L2 attestation + DFARS 252.204-7012 clause flow-down + 72-hour breach-notification SLA + jump-server MFA + session recording + time-bound credentials
  • Cyber-insurance gates ↔ MFA on CUI-touching accounts + CUI-system segmentation + DFARS 72-hour cadence runbook + immutable CUI media backups with NIST SP 800-88 sanitization at end-of-life

Defense-vs-Manufacturing Side-by-Side Compliance Posture Row

Defense contracting and manufacturing both handle CUI when overlapping on the defense industrial base, both increasingly field SOC 2 enterprise procurement demands where commercial buyers reach back into the supply chain, and both operate inside a layered compliance regime with a customer-driven input — but the regulatory regime, primary-data class, threat profile, and enforcement patterns diverge in ways that shape a very different control program. Both are operationally CUI-aware vs. OT-aware equivalents: where the manufacturer controls analytically protect OT systems + CUI + IP and respond to ransomware crossing IT/OT + supply-chain OT compromise, the defense contractor controls analytically protect CUI systems + CDI + national-security export-controlled technical data and respond to nation-state APT targeting CUI + CUI exfiltration to foreign intelligence services + ransomware on CUI systems. Use the comparison below to understand where the manufacturer's instinct for OT-aware controls breaks down for a defense contractor — and where the controls, despite different vocabulary, are operationally just as audit-ready as the OT-aware playbook's.

  • Primary regime — Defense: CMMC 2.0 L1/L2/L3 + 32 CFR Part 2002 CUI + DFARS 252.204-7012 72-hour cyber-incident cadence + NIST SP 800-171 110 CUI controls + supplier flow-down + cyber-insurance + state breach notification ↔ Manufacturing: NIST CSF 2.0 OT-aware + SOC 2 CC6/CC7/CC9.2 + CMMC 2.0 (for DoD-touching manufacturers) + IEC 62443 customer-driven OT + cyber-insurance + 50-state breach
  • Breach-notification cadence — Defense: DFARS 252.204-7012 72-hour cyber-incident cadence to DoD via DIBNet portal + state AG for PII breach + 32 CFR Part 2002 NARA CUI spillage notification ↔ Manufacturing: state AG (typically 30–60 days) + DFARS cyber-incident 72-hour for DoD-touching manufacturers
  • Primary-data class — Defense: CUI + CDI + ITAR/EAR export-controlled technical data + National Security Information (NSI) + Critical Infrastructure Information ↔ Manufacturing: trade-secret process IP + CUI + CAD/ladder logic + OT process IP
  • Carve-out — Defense: CUI marking per 32 CFR Part 2002 + NARA CUI Registry drives every disclosure decision + ITAR/EAR license controls on export-controlled technical data ↔ Manufacturing: trade-secret + patent-pending protection (with CMMC CUI as the regulated subset)
  • SOC 2 driver — Defense: DoD prime contract eligibility under 32 CFR Part 170 + C3PAO L2 assessment cadence + FedRAMP-authorized cloud for federal system CUI ↔ Manufacturing: enterprise OEM / automotive / energy buyers + defense industrial base prime contract eligibility
  • Threat profile — Defense: nation-state APT targeting CUI + CUI exfiltration to foreign intelligence services + ransomware on CUI systems + insider threat from CUI-handling staff + IT/OT CUI-system compromise on DIB manufacturers ↔ Manufacturing: ransomware crossing IT/OT boundary + supply-chain OT compromise + nation-state IP theft + OT-aware supply chain attack
  • Regulator enforcement — Defense: C3PAO L2 assessment failure + DoD contract loss of eligibility + DFARS False Claims Act exposure on material misrepresentation + NARA CUI Registry follow-up + ITAR/EAR violations on export-controlled disclosure ↔ Manufacturing: C3PAO L2 failure + DoD contract loss of eligibility + IEC 62443 contractual breach + cyber-insurance exclusion
  • Cyber-insurance expectation overlap — Defense: MFA on every CUI-touching account + CUI-system segmentation + DFARS 72-hour cadence runbook + immutable CUI media backups ↔ Manufacturing: OT-vendor addenda inventory + jump-server MFA + IT/OT segmentation evidence + immutable SCADA backups — both verticals centered on the same contractual mechanics (addenda + breach-notification SLA + MFA + immutable backups) despite different operational vocabulary

Frequently Asked Questions

Q: What cybersecurity standards apply to a small or mid-size DoD contractor handling CUI?
Five overlapping obligations apply. (1) CMMC 2.0 (Level 1 — 17 practices for FCI + Level 2 — 110 practices on NIST SP 800-171 for CUI under 32 CFR Part 170 + Level 3 — 134 practices on NIST SP 800-172 for highest-priority) is the contractual cybersecurity framework the DoD applies across the DIB. (2) CUI under 32 CFR Part 2002 + the NARA CUI Registry applies to every CUI-handling contractor with marking, destruction, spillage, and awareness-training operating discipline. (3) DFARS 252.204-7012 applies to every CDI/CUI-handling contractor with a 72-hour cyber-incident reporting cadence to DoD via the DIBNet portal + CUI preservation + written cyber-incident report + DFARS FCA exposure on material misrepresentation. (4) NIST SP 800-171 (110 controls for CMMC L2 — full 14-family coverage) is the CUI control set the C3PAO L2 assessment samples against. (5) Supplier flow-down under DFARS 252.204-7012 + cyber-insurance readiness + state breach-notification laws round out the layered regime. The right architectural model is to treat CMMC L2 110 practices + NIST SP 800-171 control families + DFARS 72-hour cadence + CUI marking/destruction as the audit-ready wrappers around a CUI-aware operating program, with Tier 1–3 supplier flow-down evidence and cyber-insurance MFA/segmentation/IRP/immutable backups layering on top.
Q: What does CMMC Level 2 require and when does the C3PAO assessment hit (October 2026 deadline)?
CMMC Level 2 covers 110 practices on NIST SP 800-171 across 14 control families (AC, AU, AT, CM, IA, IR, MA, MP, PS, PE, SC, SI + RA/SA family overlap at r3 alignment). CMMC 2.0 has three levels: Level 1 (17 practices for FCI, annual self-assessment and affirmation); Level 2 (110 practices for CUI, triennial C3PAO third-party assessment under 32 CFR Part 170 — required for CUI exposure by October 2026); Level 3 (134 practices on NIST SP 800-172 for highest-priority programs, DoD-led DIBCAC assessment — note MSP/MSSP validation only applies at Level 3). The October 2026 deadline hits Level 2 — defense suppliers handling CUI must be C3PAO-assessed by that point or risk loss of contract eligibility. For a DIB contractor, the C3PAO will sample the same controls a NIST SP 800-171 auditor samples: CUI access (AC, IA), CUI-aware IRP + DFARS 72-hour cadence (IR), OT-aware change windows where the CUI system controls OT (CM), CUI-system segmentation (SC), and CUI marking + destruction per 32 CFR Part 2002 (MP). The pre-2026 contracting path requires self-attestation + DD Form 254 / DFARS offer flowdown.
Q: What is CUI and how do 32 CFR Part 2002 + the NARA CUI Registry control marking, destruction, and spillage?
CUI (Controlled Unclassified Information) is government-created or government-possessed information that requires safeguarding or dissemination controls under federal law, regulation, or government-wide policy. 32 CFR Part 2002 is the implementing regulation; the NARA CUI Registry at https://www.archives.gov/cui is the authoritative list of CUI categories and applicable controls. Operationally: (1) MARKING — every CUI document, email, and file bears a CUI//SP-XXXX banner with a designated CUI category (e.g. CUI//SP-PRIVCY for privacy, CUI//SP-PROP for proprietary) plus applicable dissemination controls (e.g. NOFORN, ORCON). (2) DESTRUCTION — CUI must be destroyed using methods appropriate to the CUI category — burning, cross-cut shredding, degaussing, or NIST SP 800-88 sanitization; no general recycling of CUI-bearing media. (3) SPILLAGE — the moment a non-authorized person accesses CUI, the contractor triggers: immediate containment, NARA CUI spillage notification, DFARS 252.204-7012 72-hour cyber-incident reporting cadence to DoD, recursive CUI destruction across affected systems, and NARA follow-up. (4) AWARENESS TRAINING — every employee handling CUI must complete annual awareness training with documented training records. Covered Defense Information (CDI) is the subset of CUI protected specifically under DFARS and ITAR/EAR with additional handling requirements.
Q: What does NIST SP 800-171 map to under CMMC — the 110-practice 14-family coverage?
NIST SP 800-171 provides the 110-practice CUI control family that CMMC L2 is sampled against during the C3PAO triennial assessment under 32 CFR Part 170. The 14 control families (plus the RA/SA family overlap at r3 alignment) cover: AC (Access Control — 22 controls), AU (Audit and Accountability — 9 controls + 90-day log retention minimum), AT (Awareness and Training — 3 controls including annual CUI awareness training), CM (Configuration Management — 9 controls), IA (Identification & Authentication — 11 controls including MFA enforcement per IA-2(1)/IA-2(2)), IR (Incident Response — 3 controls including the 72-hour DFARS cadence), MA (Maintenance — 6 controls), MP (Media Protection — 9 controls including NIST SP 800-88 sanitization per CUI category), PS (Personnel Security — 8 controls), PE (Physical and Environmental — 6 controls), SC (System and Communications Protection — 16 controls including boundary protection, CUI system segregation, FIPS-validated crypto), SI (System and Information Integrity — 7 controls including 30-day critical / 60-day high vulnerability remediation cadence). NIST SP 800-171 r3 added overlay families (RA + SA) for risk assessment + security assessment to mirror NIST SP 800-53. SOC 2 CC6 ↔ NIST SP 800-171 AC + IA; SOC 2 CC7.4 ↔ NIST SP 800-171 IR; SOC 2 CC9.2 ↔ NIST SP 800-171 AC/IA/IR vendor-risk input.
Q: How does the DFARS 252.204-7012 72-hour cyber-incident reporting cadence work for DoD primes and subcontractors?
DFARS 252.204-7012(c)(2) requires the contractor to "rapidly report" cyber-incidents to the DoD — operationally interpreted as within 72 hours of discovery — via the DIBNet portal at https://dibnet.dod.mil. The triggering event is any cyber-incident affecting a contractor information system that processes, stores, or transmits CDI/CUI. The reporting flow has four components: (1) DFARS 252.204-7012(c)(2) — initial 72-hour cyber-incident notification via DIBNet; (2) DFARS 252.204-7012(d) — preservation of CDI for forensic purposes for at least 90 days following discovery; (3) DFARS 252.204-7012(e) — written cyber-incident report with required fields (timeline, affected systems, type of CDI/CUI compromised, mitigation steps, root-cause analysis) due within 30 days unless extended; (4) DFARS 252.204-7012(f) — cooperation with DoD-led damage assessment activities. For Tier 1–3 subcontractors, the prime's DFARS clause includes flow-down language that delegates the 72-hour cadence to the subcontractor when its information systems are the affected systems, with the prime coordinating the upward reporting to DIBNet. False Claims Act exposure under 31 U.S.C. §§ 3729-3733 applies to material misrepresentation in self-attestation to NIST SP 800-171 compliance.
Q: How do I tier Tier 1–3 subcontractors under supplier flow-down for CMMC + DFARS?
Supplier flow-down operates under DFARS 252.204-7012 + 32 CFR Part 170 (CMMC 2.0) — every subcontract involving CDI/CUI handling must include the DFARS clause verbatim. Three-tier model maps to CUI access depth: TIER 1 (highest) — system integrators + OEM support with persistent CUI access or engineering workstation access — required CMMC Level 2 attestation evidence + DFARS 252.204-7012 clause flow-down + 72-hour breach-notification SLA tied to DFARS cadence + jump-server access with hardware-token MFA + session recording + time-bound credentials + no persistent VPN. TIER 2 — occasional CUI handlers during warranty / engineering windows — required CMMC Level 2 attestation evidence + jump-server with MFA + session recording + time-bound credentials. TIER 3 — intermittent CUI-handling subcontractors — required CMMC Level 2 attestation evidence + jump-server with non-persistent credentials. The flow-down package must include: (1) CMMC Level 2 attestation evidence; (2) DFARS 252.204-7012 clause language to cascade the 72-hour cadence; (3) 72-hour breach-notification SLA tied to DFARS DIBNet timing; (4) MFA enforcement, session recording, time-bound credentials, no persistent VPN; (5) downstream flow-down clauses for Tier 2/3 subcontractors; (6) C3PAO L2 readiness evidence + a recent (within 12 months) C3PAO assessment report or self-attestation if pre-assessment.
Q: What cyber-insurance controls are required for DIB suppliers and which gaps cause exclusions?
Cyber-insurance carriers writing DIB suppliers increasingly require four control categories as condition precedent for binding or renewal: (1) MFA on every CUI-touching account (FIPS-validated hardware-token MFA on admin + privileged accounts, TOTP on standard CUI-handling accounts — no SMS); (2) CUI-system network segmentation with documented CUI-system vs corporate-IT segmentation evidence + named conduits + controlled east-west traffic + zone/conduit diagrams; (3) immutable backups with monthly tested-offline backups of every CUI-handling system + quarterly restore test signed off by operations + NIST SP 800-88 sanitization of decommissioned CUI media; (4) CUI-aware IRP runbook with named owners + DFARS 252.204-7012 72-hour cyber-incident reporting cadence documented + DIBNet portal access + CUI spillage immediate containment + recursive CUI destruction across affected systems. Beyond these four, carriers also evaluate jump-server CUI access controls (hardware-token MFA + session recording + time-bound credentials + no persistent VPN) and OT-aware continuous monitoring (Dragos / Claroty / Nozomi class) for DIB manufacturers on the IT/OT boundary. The most common coverage exclusions for DIB suppliers are missing MFA on CUI-touching accounts, missing CUI-system segmentation, missing DFARS 72-hour cadence runbook, and missing immutable backups of CUI media. CMMC L2 attestation evidence lowers insurance rather than raising it; pre-2026 False Claims Act exposure is excluded by most carriers.
Q: What is the minimum-viable program for a small DIB subcontractor before a CMMC Level 2 self-attestation?
For a small DIB subcontractor before CMMC Level 2 self-attestation, the minimum-viable program is the seven-control baseline every C3PAO L2 assessor will sample on. (1) CUI marking + destruction per 32 CFR Part 2002 — every CUI document, email, file marked CUI//SP-XXXX + designated category + cross-cut shredding + degaussing + NIST SP 800-88 sanitization at end-of-life. (2) CUI access scoping + boundary evidence — documented need-to-know reasoning + CUI-system vs corporate-IT segmentation + named conduits + zone/conduit diagrams. (3) DFARS 252.204-7012 72-hour cyber-incident cadence runbook — DIBNet portal access + preservation of CUI + written cyber-incident report + cooperation with DoD-led damage assessment. (4) Multi-factor authentication on every CUI-touching account — FIPS-validated hardware-token MFA on admin + privileged accounts, TOTP on standard CUI-handling accounts — no SMS. (5) Supplier flow-down contractual evidence — Tier 1–3 CMMC L2 attestation evidence + DFARS 252.204-7012 flow-down + 72-hour breach-notification SLA + jump-server + session recording. (6) Separation of CUI systems from corporate IT — dedicated accounts + dedicated devices + no shared administrative credentials. (7) Annual CUI awareness training records — every employee handling CUI with documented training completion. With these seven controls in place, your C3PAO L2 assessor will have the NIST SP 800-171 sampling unit evidence drawn together — and the DFARS 72-hour cadence + cyber-insurance gates are documented into the same CUI-aware program.

Take Action

Your next steps — all free, no account required to start.

Start Your CMMC + CUI + DFARS Gap Analysis →

Map your current controls against CMMC 2.0 L1/L2/L3 + NIST SP 800-171 110-control CUI family + 32 CFR Part 2002 CUI marking + DFARS 252.204-7012 72-hour cyber-incident cadence + Tier 1–3 supplier flow-down + cyber-insurance alignment — get a prioritized gap report in minutes.

Take Your Free 47-Control Security Assessment →

Full-stack security scoring across authentication, patching, network, and access controls — including the CUI-system segmentation baseline. Free, no account required. Direct path to a documented CUI-aware posture.

Score Your Tier 1–3 Subcontractor CMMC C3PAO L2 + DFARS Risk →

CMMC AC/IA/IR practice families + DFARS 252.204-7012 flow-down obligate supplier due diligence. Tier every system integrator, OEM support, and CUI-handling subcontractor, and document jump-server MFA + session-recording + time-bound credentials + CMMC L2 attestation evidence

Generate Your DFARS-CUI-Aware Incident Response Plan →

Generate an IRP aligned to DFARS 252.204-7012 72-hour cyber-incident reporting cadence via the DIBNet portal + CUI spillage immediate containment + recursive CUI destruction across affected systems + NARA CUI Registry notification

Generate CUI-Aware Security Policies →

Document your information-security program + CUI marking policy + CUI destruction policy + DFARS 72-hour cyber-incidence cadence + supplier flow-down contractual evidence — aligned to CMMC 2.0 L1/L2 + 32 CFR Part 2002 + DFARS 252.204-7012

Download Your Defense Contractor Security Posture Report →

Detailed actionable report on CMMC + CUI + DFARS findings, CUI-system segmentation evidence, and C3PAO L2 audit-readiness priorities — built for SMB defense contractors and DIB suppliers

Read the CMMC Compliance Guide →

CMMC 2.0 L1/L2/L3 requirements for defense contractors — understand the practice levels, CUI scope, assessment path, and evidence expectations before you start closing gaps.

Read the CMMC Readiness Guide →

CMMC 2.0 L1/L2/L3 readiness for SMB defense contractors — 110 practices on NIST SP 800-171 for CUI Level 2 + C3PAO assessment cadence + DFARS cyber-incident 72-hour reporting runbook + supplier flow-down for Tier 1–3

CyberStackHub Tools for Defense

These tools are most relevant for defense businesses based on your sector's specific risk profile and compliance requirements.

Identifies CUI-aware access control gaps, CUI-system segmentation drift, CUI marking + destruction omissions, and DFARS 252.204-7012 72-hour cadence gaps that nation-state APT + ransomware crews exploit to reach CUI systems — the CMMC L2 sampling unit
Assesses CMMC 2.0 L1/L2/L3 readiness against NIST SP 800-171 (110 CUI practices) + 32 CFR Part 2002 CUI program operating discipline + DFARS 252.204-7012 72-hour DIBNet cadence + Tier 1–3 supplier flow-down + cyber-insurance readiness
CMMC AC/IA/IR practice families + DFARS 252.204-7012 flow-down obligate Tier 1–3 supplier due diligence — score every system integrator + CUI-handling subcontractor with CMMC L2 attestation evidence + jump-server MFA + session-recording + time-bound-credentials evidence
IRP aligned to CMMC IR practice family (IR-4 / IR-5 / IR-6 / IR-8) + DFARS 252.204-7012 72-hour DIBNet cyber-incident cadence + CUI spillage immediate containment procedure per 32 CFR Part 2002 + recursive CUI destruction across affected systems

Defense Cybersecurity Statistics

Data from public sources including Verizon DBIR, IBM Cost of Data Breach, FBI IC3, and industry-specific research.

110
NIST SP 800-171 practices for CMMC Level 2 CUI handling — required by Oct 2026
NIST SP 800-171 r2 / 32 CFR Part 170
72-hour
DFARS 252.204-7012 cyber-incident reporting cadence for DoD CUI/CDI suppliers
DFARS 252.204-7012(c)(2)
34
CUI categories on the NARA CUI Registry driving marking + destruction + spillage cadence
NARA CUI Registry
8x
Increase in nation-state APT targeting of CUI-handling contractors since 2022
CISA / NSA Joint Advisory 2025