Regulations and Frameworks for Defense Organizations
Several overlapping frameworks may apply to your defense organization depending on contract role, data handled, customer requirements, and jurisdiction. Not all apply to every organization — use this guide to identify which are relevant to you.
- Level 1 (17 practices covering FCI) — annual self-assessment and affirmation, no third-party assessment required; applicable to all DoD contractors handling FCI
- Level 2 (110 practices covering CUI on NIST SP 800-171) — triennial third-party assessment by a C3PAO (CMMC Third-Party Assessment Organization) under 32 CFR Part 170, required for CUI exposure by October 2026
- Level 3 (highest-priority programs, 134 practices on NIST SP 800-172) — DoD-led DIBCAC assessment for the highest-priority assets
- MSP / MSSP validation only for Level 3 — the DoD does not independently certify a contractor's external service provider at Levels 1 / 2; the contractor must attest to flow-down
- Plan of Action and Milestones (POA&M) for any unmet practice — pre-existing governance expectation, not a deferral
- NIST SP 800-171 control family mapping: AC (access control), AU (audit and accountability), AT (awareness and training), CM (configuration management), IA (identification & authentication), IR (incident response), MA (maintenance), MP (media protection), PS (personnel security), PE (physical and environmental), SC (system and communications protection), SI (system and information integrity) — full 14-family coverage as the CMMC L2 sampling unit
- NIST SP 800-172 (enhanced security requirements for Level 3) — for highest-priority programs handling critical CUI; penetration-test-grade controls over L2 baseline
- CUI awareness training records — annual CUI handling + marking + destruction + spillage cadence training for every employee handling CUI
- Flow-down to subcontractors: any Tier 1–3 subcontractor handling CUI must itself operate at CMMC Level 2 — the prime cannot contractually waive it
- Pre-2026 contracting: bidders on DoD contracts that include CMMC requirements must self-attest to Level 1 or Level 2 in the DD Form 254 / DFARS offer flowdown
Penalty: Loss of DoD contract eligibility on C3PAO assessment failure under 32 CFR Part 170; flow-down exclusion from DoD prime contractor contracts; potential DFARS cyber-incident False Claims Act exposure for material misrepresentations in self-attestation; cyber-insurance exclusions for missing MFA on CUI-touching accounts + missing CUI-system network segmentation; downstream subcontractor survival threatened when a prime is removed.
- CUI marking on every document, email, and file containing CUI: CUI//SP-XXXX banner line + designated CUI category (e.g. CUI//SP-PRIVCY, CUI//SP-PROP) + dissemination controls (e.g. NOFORN, ORCON)
- CUI destruction methods per 32 CFR Part 2002 + the CUI category — burning, cross-cut shredding, degaussing, NIST SP 800-88 sanitization; no general recycling of CUI-bearing media
- CUI spillage immediate containment + NARA spillage notification + DFARS cyber-incident cadence trigger — the moment a non-authorized person accesses CUI, the 72-hour DFARS clock starts
- CUI access controls — limited to authorized persons with a lawful government purpose; documented need-to-know reasoning
- CUI covered defense information (CDI) — defense information specifically protected by DFARS and ITAR/EAR — a subset of CUI with additional handling requirements
- CUI destruction at end-of-life — every CUI-bearing laptop, smartphone, USB drive, server, and backup tape must be sanitized per CUI category before disposal or reuse
- Annual CUI awareness training — every employee handling CUI must complete annual awareness training with documented training records (NARA CUI Training requirements + agency-specific training)
- CUI transmission safeguards — TLS 1.2+ for CUI in transit; FIPS-validated cryptography when CUI traverses federal systems or FedRAMP-authorized cloud; email encryption for CUI-bearing messages
- CUI incident reporting — any actual or suspected unauthorized disclosure of CUI must be reported to the originating agency and tracked through NARA CUI spillage procedures
- Controlled environments — CUI must be processed, stored, and handled in environments that meet the safeguarding requirements of 32 CFR Part 2002 (physical and logical safeguards)
Penalty: Federal contract loss of eligibility for mishandling CUI; NARA CUI Registry follow-up + agency-specific CUI program review; DFARS cyber-incident cadence triggers False Claims Act exposure when material misrepresentation occurred in self-attestation; potential OCI (Organizational Conflict of Interest) restrictions on follow-on contracts; loss of CUI-handling authority under 32 CFR Part 2002.
- DFARS 252.204-7012(c)(1) — safeguarding covered defense information + cyber-incident reporting obligation
- DFARS 252.204-7012(c)(2) — 72-hour cyber-incident reporting cadence to the DoD via the DIBNet portal at https://dibnet.dod.mil following discovery (the stricter 72-hour cadence shortens typical state AG notification)
- DFARS 252.204-7012(d) — preservation of covered defense information for forensic purposes following discovery (90 days minimum)
- DFARS 252.204-7012(e) — written cyber-incident report with required fields: cyber-incident timeline, affected systems, type of CUI/CDI compromised, mitigation steps, root-cause analysis
- DFARS 252.204-7012(f) — cooperation with DoD-led damage assessment activities; provide access to contractor systems + personnel for DIB damage assessment
- NIST SP 800-171 implementation — DFARS 252.204-7012 incorporates NIST SP 800-171 as the safeguarding standard, which became the CMMC L2 sampling unit
- False Claims Act exposure — material misrepresentation in self-attestation to NIST SP 800-171 compliance before the 2026 CMMC deadline triggers FCA liability under 31 U.S.C. §§ 3729-3733
- Cloud computing requirements — if CUI is processed or stored in cloud, the cloud service provider must meet FedRAMP Moderate baseline or equivalent (DFARS 252.204-7012(b)(2)(ii)(D))
- Subcontractor flow-down — every subcontract involving CDI/CUI handling must include the same DFARS clause language verbatim
- Reporting timeline: "rapidly report" means within 72 hours of discovery; written cyber-incident report due within 30 days unless extended
Penalty: Loss of DoD contract eligibility on cyber-incident reporting failure; False Claims Act exposure on material misrepresentation in pre-2026 self-attestation to NIST SP 800-171 compliance; downstream contract exclusions; potential criminal exposure under 18 U.S.C. § 1001 for false statements in self-assessment to the federal government; cyber-insurance exclusion for missing 72-hour DFARS cadence runbook.
- AC (Access Control) — 22 controls on CUI access enforcement, account management, wireless access restrictions, mobile code + sandboxing
- AU (Audit and Accountability) — 9 controls on auditable events, content of audit records, audit review/analysis/reporting, audit reduction, time synchronization
- AT (Awareness and Training) — 3 controls on security awareness training, role-based security training, annual CUI literacy training
- CM (Configuration Management) — 9 controls on baseline configurations, configuration change control, monitoring configuration changes, least functionality
- IA (Identification & Authentication) — 11 controls on user identification, device identification, MFA enforcement on privileged accounts + network access to CUI systems
- IR (Incident Response) — 3 controls on incident response plan, incident reporting + 72-hour DFARS cadence, incident response testing
- MA (Maintenance) — 6 controls on controlled maintenance, maintenance tools, nonlocal maintenance + MFA, maintenance personnel
- MP (Media Protection) — 9 controls on media access restrictions, media marking, media storage, media transport, media sanitization per NIST SP 800-88
- PS (Personnel Security) — 8 controls on personnel screening, personnel termination, personnel transfer, access agreements
- PE (Physical and Environmental) — 6 controls on physical access authorizations, monitoring physical access, visitor control, physical access logs
- SC (System and Communications Protection) — 16 controls on boundary protection, security engineering, mobile code, CUI system segregation, transmission confidentiality/integrity
- SI (System and Information Integrity) — 7 controls on flaw remediation + 30-day critical / 60-day high cadence, malicious code protection, monitoring system input/output, security alerts
- RA + SA control family at r3 alignment — risk assessment + security assessment family overlap with NIST SP 800-171 r3 — 6 additional controls
- FIPS-validated cryptography — when CUI traverses FedRAMP-authorized cloud or federal systems; SC family SC-13 references FIPS 140-2/3 validated modules
- MFA on every CUI-touching account — IA-2(1) / IA-2(2) requires MFA on local + network access to CUI systems
- 90+ day log retention + monthly vulnerability scans with remediation within 30 days critical / 60 days high — the SI + AU family input
Penalty: C3PAO L2 assessment failure with loss of DoD contract eligibility; DFARS False Claims Act exposure on material misrepresentation in self-attestation; cyber-insurance loading for missing MFA + missing log retention + missing vulnerability remediation cadence; documented as a SIP (Special Item) at the assessment to flag critical practice gaps.
- Supplier flow-down: every Tier 1–3 subcontractor handling CUI must operate at CMMC Level 2 — the prime cannot contractually waive it, and the prime bears FCA + flow-down exclusion consequences
- Subcontractor tiering — Tier 1 (system-integrator / OEM support with persistent CUI access) + Tier 2 (occasional CUI handlers) + Tier 3 (intermittent CUI access) with addenda matching tier risk
- Jump-server CUI access: jump-server with hardware-token MFA + session recording + time-bound credentials + no persistent VPN for every Tier 1–3 vendor with CUI access
- 72-hour breach-notification SLA: subcontractor cyber-incident must trigger DFARS DIBNet cadence within 72 hours of discovery — and tie to the prime's DFARS cyber-incident reporting obligation
- Cyber-insurance MFA + segmentation + IRP gates: insurance carriers require MFA on every CUI-touching account, CUI-system network segmentation evidence, OT-aware IRP runbook (for DIB manufacturers), and immutable + offline-tested backups as condition precedent for binding or renewal
- CUI-system network segmentation evidence: documented CUI-system vs corporate-IT segmentation with named conduits, controlled east-west traffic, and zone/conduit diagrams
- 50-state breach notification: state AG cadence (typically 30–60 days for most states) in parallel with DFARS DIBNet 72-hour cadence where the breach involves state-resident personal information
- CUI spillage immediate containment runbook: NARA CUI spillage procedure + DFARS cyber-incident cadence trigger + recursive CUI destruction across affected systems + NARA follow-up notification
- Cyber-insurance exclusions for missing MFA + missing CUI-system segmentation + missing immutable backups + missing DFARS 72-hour runbook — the four most common coverage exclusions for DIB suppliers
- C3PAO L2 attestation evidence lowers cyber-insurance pricing; missing CMMC L2 attestation evidence raises carrier loading
Penalty: Coverage exclusion for unsegmentated CUI systems; cyber-insurance loading for missing MFA + missing jump-server vendor remote access + missing OT-aware IRP + missing immutable backups; loss of DoD contract eligibility under DFARS 252.204-7012 false attestation; False Claims Act exposure on material misrepresentation in self-attestation; downstream subcontractor survival threatened when a prime is removed.
Frequently Asked Questions
Q: What cybersecurity standards apply to a small or mid-size DoD contractor handling CUI?
Five overlapping obligations apply. (1) CMMC 2.0 (Level 1 — 17 practices for FCI + Level 2 — 110 practices on NIST SP 800-171 for CUI under 32 CFR Part 170 + Level 3 — 134 practices on NIST SP 800-172 for highest-priority) is the contractual cybersecurity framework the DoD applies across the DIB. (2) CUI under 32 CFR Part 2002 + the NARA CUI Registry applies to every CUI-handling contractor with marking, destruction, spillage, and awareness-training operating discipline. (3) DFARS 252.204-7012 applies to every CDI/CUI-handling contractor with a 72-hour cyber-incident reporting cadence to DoD via the DIBNet portal + CUI preservation + written cyber-incident report + DFARS FCA exposure on material misrepresentation. (4) NIST SP 800-171 (110 controls for CMMC L2 — full 14-family coverage) is the CUI control set the C3PAO L2 assessment samples against. (5) Supplier flow-down under DFARS 252.204-7012 + cyber-insurance readiness + state breach-notification laws round out the layered regime. The right architectural model is to treat CMMC L2 110 practices + NIST SP 800-171 control families + DFARS 72-hour cadence + CUI marking/destruction as the audit-ready wrappers around a CUI-aware operating program, with Tier 1–3 supplier flow-down evidence and cyber-insurance MFA/segmentation/IRP/immutable backups layering on top.
Q: What does CMMC Level 2 require and when does the C3PAO assessment hit (October 2026 deadline)?
CMMC Level 2 covers 110 practices on NIST SP 800-171 across 14 control families (AC, AU, AT, CM, IA, IR, MA, MP, PS, PE, SC, SI + RA/SA family overlap at r3 alignment). CMMC 2.0 has three levels: Level 1 (17 practices for FCI, annual self-assessment and affirmation); Level 2 (110 practices for CUI, triennial C3PAO third-party assessment under 32 CFR Part 170 — required for CUI exposure by October 2026); Level 3 (134 practices on NIST SP 800-172 for highest-priority programs, DoD-led DIBCAC assessment — note MSP/MSSP validation only applies at Level 3). The October 2026 deadline hits Level 2 — defense suppliers handling CUI must be C3PAO-assessed by that point or risk loss of contract eligibility. For a DIB contractor, the C3PAO will sample the same controls a NIST SP 800-171 auditor samples: CUI access (AC, IA), CUI-aware IRP + DFARS 72-hour cadence (IR), OT-aware change windows where the CUI system controls OT (CM), CUI-system segmentation (SC), and CUI marking + destruction per 32 CFR Part 2002 (MP). The pre-2026 contracting path requires self-attestation + DD Form 254 / DFARS offer flowdown.
Q: What is CUI and how do 32 CFR Part 2002 + the NARA CUI Registry control marking, destruction, and spillage?
CUI (Controlled Unclassified Information) is government-created or government-possessed information that requires safeguarding or dissemination controls under federal law, regulation, or government-wide policy. 32 CFR Part 2002 is the implementing regulation; the NARA CUI Registry at https://www.archives.gov/cui is the authoritative list of CUI categories and applicable controls. Operationally: (1) MARKING — every CUI document, email, and file bears a CUI//SP-XXXX banner with a designated CUI category (e.g. CUI//SP-PRIVCY for privacy, CUI//SP-PROP for proprietary) plus applicable dissemination controls (e.g. NOFORN, ORCON). (2) DESTRUCTION — CUI must be destroyed using methods appropriate to the CUI category — burning, cross-cut shredding, degaussing, or NIST SP 800-88 sanitization; no general recycling of CUI-bearing media. (3) SPILLAGE — the moment a non-authorized person accesses CUI, the contractor triggers: immediate containment, NARA CUI spillage notification, DFARS 252.204-7012 72-hour cyber-incident reporting cadence to DoD, recursive CUI destruction across affected systems, and NARA follow-up. (4) AWARENESS TRAINING — every employee handling CUI must complete annual awareness training with documented training records. Covered Defense Information (CDI) is the subset of CUI protected specifically under DFARS and ITAR/EAR with additional handling requirements.
Q: What does NIST SP 800-171 map to under CMMC — the 110-practice 14-family coverage?
NIST SP 800-171 provides the 110-practice CUI control family that CMMC L2 is sampled against during the C3PAO triennial assessment under 32 CFR Part 170. The 14 control families (plus the RA/SA family overlap at r3 alignment) cover: AC (Access Control — 22 controls), AU (Audit and Accountability — 9 controls + 90-day log retention minimum), AT (Awareness and Training — 3 controls including annual CUI awareness training), CM (Configuration Management — 9 controls), IA (Identification & Authentication — 11 controls including MFA enforcement per IA-2(1)/IA-2(2)), IR (Incident Response — 3 controls including the 72-hour DFARS cadence), MA (Maintenance — 6 controls), MP (Media Protection — 9 controls including NIST SP 800-88 sanitization per CUI category), PS (Personnel Security — 8 controls), PE (Physical and Environmental — 6 controls), SC (System and Communications Protection — 16 controls including boundary protection, CUI system segregation, FIPS-validated crypto), SI (System and Information Integrity — 7 controls including 30-day critical / 60-day high vulnerability remediation cadence). NIST SP 800-171 r3 added overlay families (RA + SA) for risk assessment + security assessment to mirror NIST SP 800-53. SOC 2 CC6 ↔ NIST SP 800-171 AC + IA; SOC 2 CC7.4 ↔ NIST SP 800-171 IR; SOC 2 CC9.2 ↔ NIST SP 800-171 AC/IA/IR vendor-risk input.
Q: How does the DFARS 252.204-7012 72-hour cyber-incident reporting cadence work for DoD primes and subcontractors?
DFARS 252.204-7012(c)(2) requires the contractor to "rapidly report" cyber-incidents to the DoD — operationally interpreted as within 72 hours of discovery — via the DIBNet portal at https://dibnet.dod.mil. The triggering event is any cyber-incident affecting a contractor information system that processes, stores, or transmits CDI/CUI. The reporting flow has four components: (1) DFARS 252.204-7012(c)(2) — initial 72-hour cyber-incident notification via DIBNet; (2) DFARS 252.204-7012(d) — preservation of CDI for forensic purposes for at least 90 days following discovery; (3) DFARS 252.204-7012(e) — written cyber-incident report with required fields (timeline, affected systems, type of CDI/CUI compromised, mitigation steps, root-cause analysis) due within 30 days unless extended; (4) DFARS 252.204-7012(f) — cooperation with DoD-led damage assessment activities. For Tier 1–3 subcontractors, the prime's DFARS clause includes flow-down language that delegates the 72-hour cadence to the subcontractor when its information systems are the affected systems, with the prime coordinating the upward reporting to DIBNet. False Claims Act exposure under 31 U.S.C. §§ 3729-3733 applies to material misrepresentation in self-attestation to NIST SP 800-171 compliance.
Q: How do I tier Tier 1–3 subcontractors under supplier flow-down for CMMC + DFARS?
Supplier flow-down operates under DFARS 252.204-7012 + 32 CFR Part 170 (CMMC 2.0) — every subcontract involving CDI/CUI handling must include the DFARS clause verbatim. Three-tier model maps to CUI access depth: TIER 1 (highest) — system integrators + OEM support with persistent CUI access or engineering workstation access — required CMMC Level 2 attestation evidence + DFARS 252.204-7012 clause flow-down + 72-hour breach-notification SLA tied to DFARS cadence + jump-server access with hardware-token MFA + session recording + time-bound credentials + no persistent VPN. TIER 2 — occasional CUI handlers during warranty / engineering windows — required CMMC Level 2 attestation evidence + jump-server with MFA + session recording + time-bound credentials. TIER 3 — intermittent CUI-handling subcontractors — required CMMC Level 2 attestation evidence + jump-server with non-persistent credentials. The flow-down package must include: (1) CMMC Level 2 attestation evidence; (2) DFARS 252.204-7012 clause language to cascade the 72-hour cadence; (3) 72-hour breach-notification SLA tied to DFARS DIBNet timing; (4) MFA enforcement, session recording, time-bound credentials, no persistent VPN; (5) downstream flow-down clauses for Tier 2/3 subcontractors; (6) C3PAO L2 readiness evidence + a recent (within 12 months) C3PAO assessment report or self-attestation if pre-assessment.
Q: What cyber-insurance controls are required for DIB suppliers and which gaps cause exclusions?
Cyber-insurance carriers writing DIB suppliers increasingly require four control categories as condition precedent for binding or renewal: (1) MFA on every CUI-touching account (FIPS-validated hardware-token MFA on admin + privileged accounts, TOTP on standard CUI-handling accounts — no SMS); (2) CUI-system network segmentation with documented CUI-system vs corporate-IT segmentation evidence + named conduits + controlled east-west traffic + zone/conduit diagrams; (3) immutable backups with monthly tested-offline backups of every CUI-handling system + quarterly restore test signed off by operations + NIST SP 800-88 sanitization of decommissioned CUI media; (4) CUI-aware IRP runbook with named owners + DFARS 252.204-7012 72-hour cyber-incident reporting cadence documented + DIBNet portal access + CUI spillage immediate containment + recursive CUI destruction across affected systems. Beyond these four, carriers also evaluate jump-server CUI access controls (hardware-token MFA + session recording + time-bound credentials + no persistent VPN) and OT-aware continuous monitoring (Dragos / Claroty / Nozomi class) for DIB manufacturers on the IT/OT boundary. The most common coverage exclusions for DIB suppliers are missing MFA on CUI-touching accounts, missing CUI-system segmentation, missing DFARS 72-hour cadence runbook, and missing immutable backups of CUI media. CMMC L2 attestation evidence lowers insurance rather than raising it; pre-2026 False Claims Act exposure is excluded by most carriers.
Q: What is the minimum-viable program for a small DIB subcontractor before a CMMC Level 2 self-attestation?
For a small DIB subcontractor before CMMC Level 2 self-attestation, the minimum-viable program is the seven-control baseline every C3PAO L2 assessor will sample on. (1) CUI marking + destruction per 32 CFR Part 2002 — every CUI document, email, file marked CUI//SP-XXXX + designated category + cross-cut shredding + degaussing + NIST SP 800-88 sanitization at end-of-life. (2) CUI access scoping + boundary evidence — documented need-to-know reasoning + CUI-system vs corporate-IT segmentation + named conduits + zone/conduit diagrams. (3) DFARS 252.204-7012 72-hour cyber-incident cadence runbook — DIBNet portal access + preservation of CUI + written cyber-incident report + cooperation with DoD-led damage assessment. (4) Multi-factor authentication on every CUI-touching account — FIPS-validated hardware-token MFA on admin + privileged accounts, TOTP on standard CUI-handling accounts — no SMS. (5) Supplier flow-down contractual evidence — Tier 1–3 CMMC L2 attestation evidence + DFARS 252.204-7012 flow-down + 72-hour breach-notification SLA + jump-server + session recording. (6) Separation of CUI systems from corporate IT — dedicated accounts + dedicated devices + no shared administrative credentials. (7) Annual CUI awareness training records — every employee handling CUI with documented training completion. With these seven controls in place, your C3PAO L2 assessor will have the NIST SP 800-171 sampling unit evidence drawn together — and the DFARS 72-hour cadence + cyber-insurance gates are documented into the same CUI-aware program.