What DD Form 2345 Is — And What It Isn't
DD Form 2345 is the Militarily Critical Technical Data Agreement. It is the certification required for U.S. and Canadian contractors to receive export-controlled defense technical data — engineering drawings, specifications, test parameters, and design documentation that has military or space application and is restricted under ITAR or the Export Administration Regulations (EAR).
The form is processed through the Joint Certification Program (JCP), a bilateral arrangement jointly administered by the U.S. Defense Logistics Agency (DLA) and the Canadian government. When approved, your organization is added to the JCP Certified Contractor database — a signal to DoD program offices and primes that you are authorized to receive restricted technical data packages.
For many defense contractors, obtaining a DD2345 was their first formal compliance step. It established organizational legitimacy. It unlocked access to the technical data needed to quote and perform on contracts. And for a long time, it was enough. CMMC has changed that equation entirely.
Two Frameworks on Two Different Axes
Understanding where JCP ends and CMMC begins is essential — because assuming one satisfies the other is one of the most common and costly compliance mistakes in the defense supply chain today.
| JCP / DD Form 2345 | Controls who receives the data. Verifies organizational identity and legitimacy, confirms U.S. or Canadian registration, and establishes need-to-know for technical data. Grants access to ITAR/EAR-controlled data packages. Renewed every two years. Administered by DLA. Does not evaluate cybersecurity posture in any way. |
|---|---|
| CMMC Level 2 | Controls how the data is protected. Requires all 110 NIST SP 800-171 security controls on every system storing or processing CUI. Mandates a System Security Plan (SSP) and a verified SPRS score. Enforced through C3PAO third-party assessment. Tied directly to contract award eligibility under DFARS 252.204-7021. |
| ITAR / EAR | Controls who the data can be shared with. The International Traffic in Arms Regulations and Export Administration Regulations restrict disclosure of defense technical data to foreign persons and entities. Your DD2345 operates within this framework. CMMC operates in parallel — sharing ITAR data improperly is a federal crime independent of any CMMC violation. |
These three frameworks are complementary, not interchangeable. You can be fully JCP-certified, ITAR-compliant, and completely CMMC non-compliant at the same time. Enforcement increasingly treats each independently.
Why Your DD2345 Almost Certainly Triggers CMMC
The technical data you access through your DD2345 certification — engineering drawings, specifications, design documentation, and manufacturing processes for defense systems — falls squarely within a CUI category called Controlled Technical Information (CTI). CTI is defined as technical information with military or space application that is subject to controls on access, use, reproduction, modification, or disclosure.
CTI is not just one CUI category among many. It is the single most prevalent CUI category in the entire defense supply chain. If your work involves technical data packages for defense components, systems, or programs — the kind of data your DD2345 was obtained to receive — you are almost certainly handling CUI. And if you are handling CUI under a DoD contract, CMMC Level 2 applies.
This is not theoretical. DFARS 252.204-7012 has been a contractual requirement in most DoD contracts involving CUI since December 2017. It explicitly requires all contractors handling CUI to implement NIST SP 800-171. If your contract contains that clause — and if you have been receiving technical data through your JCP certification — you have been obligated to comply with NIST SP 800-171 for years. CMMC adds mandatory third-party verification on top of that existing obligation.
The Missed Opportunities
The practical consequences of treating a DD2345 as a substitute for cybersecurity compliance play out in five predictable ways. These are the gaps that show up repeatedly among JCP-certified contractors who have never formally addressed CMMC.
| Contract award eligibility | CMMC is now being phased into new DoD solicitations. A contractor with a DD2345 but no SPRS score will be ineligible for new awards requiring CMMC Level 2. The JCP database does not appear in the CMMC ecosystem. Contracting officers look for a valid SPRS score and a C3PAO assessment report — your DD2345 does not satisfy either requirement. |
| Years of DFARS 7012 exposure | If your DoD contracts have contained DFARS 252.204-7012 — and they almost certainly have if CUI was involved — you have been out of compliance for every day you have not implemented NIST SP 800-171. That gap represents active False Claims Act exposure. The DOJ's Civil Cyber-Fraud Initiative has generated more than $26 million in settlements against contractors in exactly this posture. |
| Missing or inaccurate SPRS score | Contractors who have never performed a NIST SP 800-171 self-assessment either have no SPRS score on file — itself a compliance gap — or an inflated score that does not reflect actual posture. SPRS is the primary mechanism through which contracting officers verify baseline cybersecurity posture before award. An absent or inaccurate score, at a moment when DoD is actively enforcing DFARS 7019 and 7020, is an immediate vulnerability. |
| No System Security Plan | A DD2345 says nothing about the systems on which you store, process, or transmit the technical data you are authorized to receive. CMMC Level 2 requires a System Security Plan that specifically documents how your environment protects CUI — network boundaries, access controls, encryption, monitoring, and incident response. Building an SSP from scratch under deadline pressure is significantly harder and more expensive than building it proactively. |
| Supply chain risk to your primes | Prime contractors are under increasing pressure to verify the CMMC posture of their supply chains. A JCP-certified subcontractor who cannot produce an SPRS score or demonstrate progress toward Level 2 compliance is a liability — one that sophisticated primes are beginning to screen out during source selection, not after contract award. Your DD2345 tells the prime you are authorized to receive technical data. Your CMMC posture tells them whether they can trust you with it. |
What JCP-Certified Contractors Should Do Now
A DD2345 certification represents meaningful groundwork. Your organization has already established its identity as a legitimate defense supplier, confirmed its organizational structure and key management personnel, and demonstrated an understanding of export control obligations. These feed directly into the organizational hygiene that CMMC compliance requires. The path forward is sequential.
| Step 1: Scope your CUI environment | Identify every system, location, and process where technical data received through your JCP authorization is stored, processed, or transmitted. This is your CUI boundary — the scope of your CMMC assessment. Every system within this boundary must meet all 110 NIST SP 800-171 requirements. |
| Step 2: Conduct a NIST SP 800-171 self-assessment | Evaluate your organization against all 110 requirements using the DoD Assessment Methodology. Calculate your SPRS score honestly. A score below 110 means you have gaps — document them in a POA&M and begin remediation. Submit the result to SPRS at piee.eb.mil. An accurate low score with an active POA&M is legally far safer than an inflated score. |
| Step 3: Build your System Security Plan | Document how your organization implements each of the 110 requirements. The SSP must describe your actual environment, tools, configurations, and personnel — not a generic template. It is the primary artifact a C3PAO assessor will examine, and it is the foundation of any successful CMMC assessment. |
| Step 4: Work your POA&M | For every requirement not yet fully implemented, create a POA&M item with a named owner, specific gap description, interim mitigation, and a credible completion date within 180 days. Track evidence of implementation — configurations, training records, policy documents — that assessors will review. |
| Step 5: Engage a C3PAO early | C3PAO assessment capacity is limited and demand is rising sharply as CMMC enforcement accelerates through Phase 2. Waiting until a contract requires a certified assessment puts your award timeline at risk. Begin the C3PAO engagement process while you still have time to remediate assessor findings before they become contract-blocking issues. |
Where 1TEN Fits
1TEN is an air-gapped, on-premises CMMC Level 2 compliance platform built specifically for defense contractors handling CUI. If you are a JCP-certified contractor who has recognized the gap described here and is ready to close it, 1TEN gives you a structured path from self-assessment to C3PAO readiness — without routing your compliance data through a cloud platform that itself becomes a CUI handling concern.
The platform covers all 110 NIST SP 800-171 requirements, automates SPRS score calculation, generates your System Security Plan, and tracks your POA&M through to closure — all within a system that stays on your network, in your control, and off the internet. For organizations whose entire reason for existence in the defense supply chain depends on protecting ITAR-controlled technical data, there is no defensible reason to manage that compliance work in the cloud.