Skip to content
CMMC Guidance
← Industries
Research, Science & Technology

The objective is not to restrict research. It is to build a controlled place where research can continue.

Research organizations run on collaboration: with government partners, with other institutions, with instruments and computing that were never designed for a corporate security model. Some of what they produce and receive is Controlled Unclassified Information (CUI). The program has to protect that without turning the laboratory into an office.

The objective isn't to restrict research. It's to design a controlled environment in which research can continue.

01 · What CUI Looks Like in Your Industry

What CUI may look like here.

Examples of information that may constitute CUI when appropriately designated or contractually identified include:

  • Research results
  • Experimental data
  • Prototype designs
  • Algorithms and models
  • Test results
  • Technical reports
  • Export-controlled research
  • Government-provided datasets
  • Emerging technology information
02 · Where Your CUI Typically Travels

The path a file takes.

  1. Government Sponsor
  2. Principal Investigator
  3. Lab Workstation
  4. Instrument
  5. Cloud Compute
  6. External Collaborator
  7. Report/Dataset
A sponsor provides a dataset or a set of requirements to a principal investigator. It reaches a laboratory workstation, is combined with data coming off an instrument, is processed on shared or cloud computing, is discussed with an external collaborator, and becomes a report or a dataset returned to the sponsor. Most of those stops are not laptops, and several are not owned by the organization at all.
03 · Where Organizations Like Yours Commonly Get Into Trouble

Where it goes wrong.

01

Information moves among systems that do not fit the laptop model

Researchers move information among laboratory systems, specialized workstations, instruments, cloud resources, external collaborators, government partners and research facilities. Many of these do not fit the corporate-laptop security model: an instrument controller on an old operating system, a shared analysis server, a compute cluster with its own accounts. Applying office controls to them fails; ignoring them leaves the most sensitive data outside the boundary.

02

Collaboration is the point, and it crosses every boundary

A project may involve another institution, a government laboratory and an industry partner, each with its own systems and each needing to see some of the data. Sharing happens through whatever tool the collaboration adopted. Without a defined method, the organization cannot say where a controlled dataset has gone or under what terms.

03

Research computing has its own identity and access world

Clusters, shared servers and cloud research accounts are frequently administered by the researchers who use them, with credentials created for a project and never removed. Access reviews, individual accountability and multifactor authentication (MFA) are harder to demonstrate there than anywhere else in the organization.

04

Export-controlled and sponsor-provided material mixed with open work

Open research and controlled research live side by side on the same systems and in the same groups. Once mixed, everything inherits the higher handling requirement, and the effort to separate it later is far larger than the effort to keep it apart from the start.

04 · "But We..."

"These controls are going to interfere with our research."

They will, if they are applied as if a laboratory were an office. The objective is not to restrict research. It is to design a controlled environment in which research can continue: a defined set of systems, accounts and sharing methods for the controlled work, sized to what the projects actually need, and left open everywhere the sponsor has not asked for control.

In practice that means naming the projects and datasets that carry an obligation, giving them a place to live that is built for research computing rather than borrowed from the finance department, and treating instruments and legacy analysis systems as specialized assets with compensating protection around them rather than as workstations that failed a scan. Collaboration continues through a channel that records what left and to whom. Researchers keep working; the organization gains the ability to show a sponsor, or an assessor, exactly where its data is.

05 · What a Practical CMMC Environment Looks Like

An environment that holds.

01
A research enclave sized to the controlled projectsA defined environment, on premises or in a cloud built for it, that holds the controlled datasets, models and results and nothing else. Open research stays outside it. The enclave boundary is what the System Security Plan (SSP) describes and what an assessor tests.
02
Instruments and specialized systems as documented, compensated assetsInstrument controllers, shared analysis servers and legacy workstations are inventoried by category and, where a standard control cannot apply, protected by isolation, restricted access and monitoring, with the decision written down. The assessor sees a managed exception, not an unmanaged system.
03
Research computing with managed identityIndividual accounts with MFA on the enclave’s compute and storage, provisioned per project and removed when the project or the person leaves, with an access review on the calendar. Shared project logins go away.
04
A defined collaboration channelOne sanctioned way to share controlled data with external partners, with named recipients, logged transfers and a record of the terms each partner accepted. It replaces the ad hoc file link and it survives the collaboration ending.
05
Evidence collected from the lab, on a scheduleEach control has an owner who can produce its artifact from the research environment, not only from corporate IT. Open items sit on a Plan of Action and Milestones (POA&M) with dates, so the state of the program is known before a Certified Third-Party Assessment Organization (C3PAO) asks.
06 · How CMMCg Approaches It

The order we do it in.

  1. 01

    Discover CUI

  2. 02

    Define Scope

  3. 03

    Identify Gaps

  4. 04

    Design Controls

  5. 05

    Implement

  6. 06

    Collect Evidence

  7. 07

    Prepare for Assessment

  8. 08

    Maintain Compliance

This is the CMMCg Method applied to your environment. Read the Method →

Does this look like your environment?

The readiness call starts from where your information actually goes, not from a template. An engineer runs it.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.