Skip to content
CMMC Guidance
← Industries
Defense & Aerospace

Protecting CUI is the easy half. Knowing everywhere it goes is the hard one.

Defense and aerospace suppliers usually already own the security products an assessor expects to see. What they usually cannot yet do is name every system, mailbox, share and subcontractor that holds Controlled Unclassified Information (CUI), and show that each one is protected. That inventory is where the work starts.

The challenge isn't simply protecting CUI. It's knowing everywhere your CUI goes.

01 · What CUI Looks Like in Your Industry

What CUI may look like here.

Examples of information that may constitute CUI when appropriately designated or contractually identified include:

  • Technical drawings
  • Engineering specifications
  • Controlled Technical Information (CTI)
  • Test results
  • Engineering change information
  • Technical manuals
  • Program documentation
  • Export-controlled information
  • Supplier and subcontractor technical information
02 · Where Your CUI Typically Travels

The path a file takes.

  1. Prime Contractor
  2. Program Manager
  3. Email
  4. SharePoint/Teams
  5. Engineering Workstation
  6. Subcontractor
  7. Deliverable
A technical data package arrives from the prime, lands in a program manager’s mailbox, is filed to SharePoint or shared in Teams, is opened on engineering workstations, is passed in part to a subcontractor, and comes back as a deliverable. Every hop is a place CUI now lives, and every hop is one the organization has to be able to point to.
03 · Where Organizations Like Yours Commonly Get Into Trouble

Where it goes wrong.

01

CUI is distributed, and nobody holds the map

CUI tends to become distributed across engineering, program management, Microsoft 365, endpoints, email, SharePoint and Teams, and subcontractors. Each group knows its own corner. No one document says where all of it is, so the first honest answer to "where is your CUI" is usually a list that grows every time someone asks a different department.

02

Security products are mistaken for demonstrated compliance

The issue is often not whether security products exist. It is whether the organization knows everywhere CUI exists and can demonstrate that the applicable systems and processes are properly protected. A firewall, multifactor authentication and endpoint detection are inputs. The assessment asks for the evidence that each control is implemented on each in-scope system, and that evidence is rarely collected until someone asks for it.

03

The subcontractor boundary is assumed, not defined

Technical information flows down to suppliers because the program requires it. What is seldom written down is which suppliers receive CUI, through what channel, and under what flow-down obligation. The prime will ask. Without a defined list, the answer becomes an audit of email history under time pressure.

04

Program and engineering tools live outside the security team’s view

Product lifecycle tools, engineering file servers, simulation environments and program-management workspaces are usually chosen by the teams that use them. They hold some of the most sensitive technical data in the company and are often the last systems anyone thinks to put inside the assessed boundary.

04 · "But We..."

"We already have IT and cybersecurity."

Having firewalls, multifactor authentication (MFA), endpoint detection and response (EDR) and other security products does not by itself establish CMMC compliance. Those tools are necessary. They are not the thing being assessed. The organization must be able to demonstrate that its CUI environment satisfies the applicable requirements and produce evidence supporting that implementation, control by control, system by system.

In practice this is the difference between an IT department that can say "we have MFA" and a compliance program that can say "here is the list of every system in scope, here is the policy that requires MFA on each, here is the configuration export that proves it, and here is who reviewed it last quarter." The security team you already have is where the evidence will come from. What is usually missing is the scoping, the documentation and the collection discipline that turn its work into something an assessor can accept.

05 · What a Practical CMMC Environment Looks Like

An environment that holds.

01
A written CUI inventory and flow mapOne maintained record of where CUI enters, is stored, is processed and leaves, covering program management, engineering, Microsoft 365, endpoints and every subcontractor channel. It is the document the rest of the program is scoped against, and it is updated when a new program or supplier is added, not rediscovered before each assessment.
02
A defined boundary that includes the engineering toolsThe assessed boundary is drawn deliberately to include the file shares, lifecycle tools and workstations that actually hold technical data, and to keep out what does not need to be in. Systems inside are managed, monitored and covered by the System Security Plan (SSP); systems outside have a documented reason for being there.
03
Controlled channels to suppliersA defined list of subcontractors that receive CUI, a defined method for getting it to them, and a record of the flow-down obligation each one has accepted. Ad hoc email attachments to a supplier are replaced by a channel someone owns.
04
Evidence collected as a routine, not a projectEach control has a named owner, an expected artifact and a collection cadence, so that the evidence for the current period already exists when the Certified Third-Party Assessment Organization (C3PAO) asks for it. Open items are carried on a Plan of Action and Milestones (POA&M) with dates, not in someone’s memory.
06 · How CMMCg Approaches It

The order we do it in.

  1. 01

    Discover CUI

  2. 02

    Define Scope

  3. 03

    Identify Gaps

  4. 04

    Design Controls

  5. 05

    Implement

  6. 06

    Collect Evidence

  7. 07

    Prepare for Assessment

  8. 08

    Maintain Compliance

This is the CMMCg Method applied to your environment. Read the Method →

Does this look like your environment?

The readiness call starts from where your information actually goes, not from a template. An engineer runs it.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.