A compliant cloud platform does not automatically create a compliant organization.
Engineering and technical services firms often run on laptops and Microsoft 365, with no server room to speak of. That does not make the environment small for CMMC purposes. Controlled Unclassified Information (CUI) is in the mailboxes, the OneDrive folders, the Teams channels and the downloads folder of every engineer, and the program is about identity, endpoints and governance rather than infrastructure.
A compliant cloud platform does not automatically create a compliant organization.
What CUI may look like here.
Examples of information that may constitute CUI when appropriately designated or contractually identified include:
- Engineering drawings
- Calculations
- Models and simulations
- Technical reports
- Specifications
- Requirements
- Government-furnished information
- Field data
- Project documentation
The path a file takes.
- Government/Prime
- Engineer Laptop
- OneDrive/SharePoint
- Analysis Tool
- Technical Report
- Client
Where it goes wrong.
"Simple" is measured by servers, not by where CUI is
A company may believe it has a simple environment because it has no servers and operates primarily in Microsoft 365. But CUI may still exist across OneDrive, SharePoint, Teams, Outlook, laptops, downloads folders, temporary files, mobile devices and software-as-a-service (SaaS) applications. The environment is simple to run and wide to assess, and the two are easy to confuse.
Identity and endpoints carry the whole program
With no data centre to protect, the controls concentrate on who can log in, from which device, and whether that device is managed. A personal phone with the Outlook app on it, or a laptop that never enrolled in device management, is a hole in the boundary that no cloud setting closes.
Cloud services are configured, but not documented or governed
The tenant may be set up well. What is usually absent is the paperwork that turns settings into a program: which controls the platform inherits from the provider, which the firm still owns, what the policy says, who reviews the configuration and where the evidence goes. An assessor cannot accept "the platform handles it" as an answer to a control the firm is responsible for.
Information governance is nobody’s job
Where CUI may be stored, how it is labelled, how long it is kept and how it is deleted are decisions that need an owner. In firms this size that owner is often the founder, part-time, and the decisions live in habit rather than a written standard.
"We're already using Microsoft 365 GCC/GCC High, so aren't we compliant?"
A compliant cloud platform does not automatically create a compliant organization. Microsoft 365 GCC High is a sound place to put CUI, and it addresses a set of requirements at the platform level. It does not know which of your laptops are managed, whether multifactor authentication (MFA) is enforced for every account, who has been granted access to which site, whether your engineers save controlled files to a personal folder, or whether any of that is written down and reviewed.
The platform is one input to the System Security Plan (SSP), and the shared-responsibility line has to be drawn explicitly: which controls are inherited from the provider, which are the firm’s to implement, and how each is evidenced. The controls that stay with the firm are the ones about identity, endpoints, access, awareness and governance. That is exactly the set that a small engineering firm has usually never had to formalize, and it is the work.
An environment that holds.
- 01
- A tenant scoped and documented as a CUI enclave — Microsoft 365 GCC High or an equivalent, configured for the controls it inherits and documented for the ones it does not. The SSP records the shared-responsibility split, and the tenant configuration is exported as evidence on a schedule.
- 02
- Managed endpoints and enforced identity — Every device that can reach CUI is enrolled, encrypted, patched and monitored, and every account has MFA. Personal devices either enroll or lose access to the enclave. That one decision closes most of the gaps in this industry.
- 03
- A defined list of where CUI may live — Named SharePoint sites and Teams for controlled work, a rule that CUI does not go to personal OneDrive folders or unlisted SaaS tools, and a short, maintained inventory of the applications that are allowed to touch it. The list is what makes the boundary real.
- 04
- Governance sized to the firm — A small set of written policies, a named owner for each, an annual review and a place where the evidence goes. Enough structure to answer an assessor; not so much that a small firm cannot keep it up.
The order we do it in.
- 01
Discover CUI
- 02
Define Scope
- 03
Identify Gaps
- 04
Design Controls
- 05
Implement
- 06
Collect Evidence
- 07
Prepare for Assessment
- 08
Maintain Compliance
This is the CMMCg Method applied to your environment. Read the Method →
Open these first.
The working documents from the CMMCg Resource Library that fit this kind of organization, in the order to use them.
CUI Identification Worksheet
Worksheet to list the information your organization receives, creates, processes or transmits that may constitute CUI, with origin, access, storage and marking.
Open →CUI Flow Mapping Template
Template to trace each CUI type from receipt through processing, storage, transmission, sharing and disposition, and mark where it leaves your boundary.
Open →CMMC Scoping Worksheet
Worksheet to sort people, systems, endpoints, networks, cloud services, facilities and providers into CMMC asset categories, and defend every exclusion.
Open →CMMC Level 2 Readiness Checklist
High-level readiness review across all 14 NIST SP 800-171 Rev 2 requirement families that CMMC Level 2 assesses, 3 to 5 review prompts per family.
Open →
Further along than that? The path continues with the Evidence Collection Tracker, the Gap & POA&M Tracker (a POA&M is a Plan of Action and Milestones) and the Assessment Preparation Checklist.
Does this look like your environment?
The readiness call starts from where your information actually goes, not from a template. An engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.