to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Treat this as CUI.

This has the marks of covered defense information. Your obligation is to protect it under all 110 requirements of NIST SP 800-171 Rev. 2 and to report cyber incidents affecting it to DoD within 72 hours.

What to do

  1. Confirm DFARS 252.204-7012 is in your contract and note the clause reference.
  2. Write down where this information lives: every system, share, laptop, and cloud service. That list is your CUI boundary.
  3. Ask the contracting officer in writing to confirm the CUI category and required markings, and file the reply.
  4. Mark it, restrict access to it, and encrypt it at rest and in transit with FIPS-validated cryptography.
  5. Assess yourself against all 110 requirements and post the score to SPRS.

DFARS 252.204-7012 §(b)(2) and §(c); NIST SP 800-171 Rev. 2; 32 CFR 170 for the CMMC level.

Which category?

The contracting officer confirms the category; the registry is the vocabulary they will use. A defense contractor most often holds one of these:

Every category, with NARA's definition and authorities, is in the registry. How the banner is built is in 32 CFR 2002.20.

Foxx Cyber, who publish this guide, build Bedrock CMMC, which does the boundary, system security plan, scoring and POA&M work this outcome describes.

Requirements this outcome points you to

  1. 3.12.4 Keep a system security plan CA Level 2 Not scored
  2. 3.1.3 Control where CUI is allowed to travel AC Level 2 1 pt
  3. 3.13.11 Use FIPS-validated cryptography SC Level 2 3 or 5 pt
  4. 3.8.4 Mark media MP Level 2 1 pt
  5. 3.6.1 Have an incident response capability that works IR Level 2 5 pt

Not the outcome you expected?

Run the worksheet again for one specific set of information, or read the other outcomes.

Whether information is CUI is the government's decision. This page sorts your situation; it does not designate anything. See FCI, CUI and CDI.