Guide

DD Form 2345, the JCP, and CMMC: The Compliance Gap Defense Contractors Miss (2026)

Last updated: 2026-03-12

What DD Form 2345 Is — And What It Isn't Two Frameworks on Two Different Axes Why Your DD2345 Almost Certainly Triggers CMMC The Missed Opportunities What JCP-Certified Contractors Should Do Now

What DD Form 2345 Is — And What It Isn't

DD Form 2345 is the Militarily Critical Technical Data Agreement. It is the certification required for U.S. and Canadian contractors to receive export-controlled defense technical data — engineering drawings, specifications, test parameters, and design documentation that has military or space application and is restricted under ITAR or the Export Administration Regulations (EAR).

The form is processed through the Joint Certification Program (JCP), a bilateral arrangement jointly administered by the U.S. Defense Logistics Agency (DLA) and the Canadian government. When approved, your organization is added to the JCP Certified Contractor database — a signal to DoD program offices and primes that you are authorized to receive restricted technical data packages.

For many defense contractors, obtaining a DD2345 was their first formal compliance step. It established organizational legitimacy. It unlocked access to the technical data needed to quote and perform on contracts. And for a long time, it was enough. CMMC has changed that equation entirely.

The Critical Distinction
The JCP controls who can receive militarily critical technical data. CMMC controls how that data is protected once received. A contractor can be fully JCP-certified — appearing in DLA's database as an approved recipient — and simultaneously be in complete violation of their CMMC obligations. The JCP never asked how you store the data. CMMC exists precisely to answer that question.

Two Frameworks on Two Different Axes

Understanding where JCP ends and CMMC begins is essential — because assuming one satisfies the other is one of the most common and costly compliance mistakes in the defense supply chain today.

JCP / DD Form 2345Controls who receives the data. Verifies organizational identity and legitimacy, confirms U.S. or Canadian registration, and establishes need-to-know for technical data. Grants access to ITAR/EAR-controlled data packages. Renewed every two years. Administered by DLA. Does not evaluate cybersecurity posture in any way.
CMMC Level 2Controls how the data is protected. Requires all 110 NIST SP 800-171 security controls on every system storing or processing CUI. Mandates a System Security Plan (SSP) and a verified SPRS score. Enforced through C3PAO third-party assessment. Tied directly to contract award eligibility under DFARS 252.204-7021.
ITAR / EARControls who the data can be shared with. The International Traffic in Arms Regulations and Export Administration Regulations restrict disclosure of defense technical data to foreign persons and entities. Your DD2345 operates within this framework. CMMC operates in parallel — sharing ITAR data improperly is a federal crime independent of any CMMC violation.

These three frameworks are complementary, not interchangeable. You can be fully JCP-certified, ITAR-compliant, and completely CMMC non-compliant at the same time. Enforcement increasingly treats each independently.

Why Your DD2345 Almost Certainly Triggers CMMC

The technical data you access through your DD2345 certification — engineering drawings, specifications, design documentation, and manufacturing processes for defense systems — falls squarely within a CUI category called Controlled Technical Information (CTI). CTI is defined as technical information with military or space application that is subject to controls on access, use, reproduction, modification, or disclosure.

CTI is not just one CUI category among many. It is the single most prevalent CUI category in the entire defense supply chain. If your work involves technical data packages for defense components, systems, or programs — the kind of data your DD2345 was obtained to receive — you are almost certainly handling CUI. And if you are handling CUI under a DoD contract, CMMC Level 2 applies.

This is not theoretical. DFARS 252.204-7012 has been a contractual requirement in most DoD contracts involving CUI since December 2017. It explicitly requires all contractors handling CUI to implement NIST SP 800-171. If your contract contains that clause — and if you have been receiving technical data through your JCP certification — you have been obligated to comply with NIST SP 800-171 for years. CMMC adds mandatory third-party verification on top of that existing obligation.

The Missed Opportunities

The practical consequences of treating a DD2345 as a substitute for cybersecurity compliance play out in five predictable ways. These are the gaps that show up repeatedly among JCP-certified contractors who have never formally addressed CMMC.

Contract award eligibilityCMMC is now being phased into new DoD solicitations. A contractor with a DD2345 but no SPRS score will be ineligible for new awards requiring CMMC Level 2. The JCP database does not appear in the CMMC ecosystem. Contracting officers look for a valid SPRS score and a C3PAO assessment report — your DD2345 does not satisfy either requirement.
Years of DFARS 7012 exposureIf your DoD contracts have contained DFARS 252.204-7012 — and they almost certainly have if CUI was involved — you have been out of compliance for every day you have not implemented NIST SP 800-171. That gap represents active False Claims Act exposure. The DOJ's Civil Cyber-Fraud Initiative has generated more than $26 million in settlements against contractors in exactly this posture.
Missing or inaccurate SPRS scoreContractors who have never performed a NIST SP 800-171 self-assessment either have no SPRS score on file — itself a compliance gap — or an inflated score that does not reflect actual posture. SPRS is the primary mechanism through which contracting officers verify baseline cybersecurity posture before award. An absent or inaccurate score, at a moment when DoD is actively enforcing DFARS 7019 and 7020, is an immediate vulnerability.
No System Security PlanA DD2345 says nothing about the systems on which you store, process, or transmit the technical data you are authorized to receive. CMMC Level 2 requires a System Security Plan that specifically documents how your environment protects CUI — network boundaries, access controls, encryption, monitoring, and incident response. Building an SSP from scratch under deadline pressure is significantly harder and more expensive than building it proactively.
Supply chain risk to your primesPrime contractors are under increasing pressure to verify the CMMC posture of their supply chains. A JCP-certified subcontractor who cannot produce an SPRS score or demonstrate progress toward Level 2 compliance is a liability — one that sophisticated primes are beginning to screen out during source selection, not after contract award. Your DD2345 tells the prime you are authorized to receive technical data. Your CMMC posture tells them whether they can trust you with it.

What JCP-Certified Contractors Should Do Now

A DD2345 certification represents meaningful groundwork. Your organization has already established its identity as a legitimate defense supplier, confirmed its organizational structure and key management personnel, and demonstrated an understanding of export control obligations. These feed directly into the organizational hygiene that CMMC compliance requires. The path forward is sequential.

Step 1: Scope your CUI environmentIdentify every system, location, and process where technical data received through your JCP authorization is stored, processed, or transmitted. This is your CUI boundary — the scope of your CMMC assessment. Every system within this boundary must meet all 110 NIST SP 800-171 requirements.
Step 2: Conduct a NIST SP 800-171 self-assessmentEvaluate your organization against all 110 requirements using the DoD Assessment Methodology. Calculate your SPRS score honestly. A score below 110 means you have gaps — document them in a POA&M and begin remediation. Submit the result to SPRS at piee.eb.mil. An accurate low score with an active POA&M is legally far safer than an inflated score.
Step 3: Build your System Security PlanDocument how your organization implements each of the 110 requirements. The SSP must describe your actual environment, tools, configurations, and personnel — not a generic template. It is the primary artifact a C3PAO assessor will examine, and it is the foundation of any successful CMMC assessment.
Step 4: Work your POA&MFor every requirement not yet fully implemented, create a POA&M item with a named owner, specific gap description, interim mitigation, and a credible completion date within 180 days. Track evidence of implementation — configurations, training records, policy documents — that assessors will review.
Step 5: Engage a C3PAO earlyC3PAO assessment capacity is limited and demand is rising sharply as CMMC enforcement accelerates through Phase 2. Waiting until a contract requires a certified assessment puts your award timeline at risk. Begin the C3PAO engagement process while you still have time to remediate assessor findings before they become contract-blocking issues.
DD2345 Renewal as a Trigger
DD Form 2345 certifications must be renewed every two years. If you are approaching a renewal and have not yet addressed your CMMC posture, that renewal is the moment to start. The data you are authorized to receive deserves the protection CMMC requires — and so does your continued authorization to receive it. A prime or program office that discovers your CMMC gap during a renewal cycle will have leverage they may not have had before.

Where 1TEN Fits

1TEN is an air-gapped, on-premises CMMC Level 2 compliance platform built specifically for defense contractors handling CUI. If you are a JCP-certified contractor who has recognized the gap described here and is ready to close it, 1TEN gives you a structured path from self-assessment to C3PAO readiness — without routing your compliance data through a cloud platform that itself becomes a CUI handling concern.

The platform covers all 110 NIST SP 800-171 requirements, automates SPRS score calculation, generates your System Security Plan, and tracks your POA&M through to closure — all within a system that stays on your network, in your control, and off the internet. For organizations whose entire reason for existence in the defense supply chain depends on protecting ITAR-controlled technical data, there is no defensible reason to manage that compliance work in the cloud.

Frequently Asked Questions

What is DD Form 2345?

DD Form 2345 is the Militarily Critical Technical Data Agreement — a certification required to receive export-controlled defense technical data such as engineering drawings, specifications, and design documentation for defense systems. It is processed through the Joint Certification Program (JCP), administered jointly by the U.S. Defense Logistics Agency and the Canadian government. Approved contractors are listed in DLA's Certified Contractor database.

Does a DD2345 satisfy any CMMC requirements?

Not directly. The DD2345 is an access authorization, not a security assessment. The organizational information gathered during the JCP application — company structure, key management personnel, facilities data — can inform portions of your System Security Plan and your personnel security documentation under CMMC's PS domain. But the JCP evaluates who you are, not how secure your systems are. CMMC evaluates both.

If I receive technical data through the JCP, do I need CMMC Level 2?

Almost certainly yes. Technical data received through a DD2345 authorization typically constitutes Controlled Technical Information — one of the most prevalent CUI categories in the defense supply chain. CUI handling under a DoD contract triggers CMMC Level 2 requirements under DFARS 252.204-7012 and, for new solicitations containing DFARS 252.204-7021, a mandatory C3PAO assessment as a condition of award.

How often does DD Form 2345 need to be renewed?

DD Form 2345 certifications are valid for two years and must be renewed through the JCP to maintain authorization to receive militarily critical technical data. Each renewal cycle is a natural trigger to reassess your CMMC posture — and an opportunity for a prime contractor or program office to ask questions about your cybersecurity compliance that they may not have asked previously.

Does the JCP apply to Canadian defense contractors?

Yes. The Joint Certification Program is a bilateral U.S.–Canada arrangement, and Canadian contractors who receive U.S. militarily critical technical data under a DoD contract face the same CMMC obligations as U.S.-based companies. CMMC applies based on where CUI is handled, not where the contractor is incorporated. Canadian contractors handling CUI must also navigate ITAR and EAR export control implications, which add additional layers of restriction on top of CMMC requirements.

My company has had a DD2345 for years and nothing bad has happened. Why act now?

The enforcement posture has changed dramatically. Prior to CMMC's final rule taking effect in November 2025, NIST SP 800-171 compliance was required under DFARS 7012 but verification was largely self-attested. C3PAO assessments, SPRS score verification under DFARS 7020, and False Claims Act enforcement actions are no longer theoretical. The window for proactive remediation — before a contracting officer, prime, or whistleblower surfaces the gap — is narrowing.

What cloud services can I use for technical data received under my DD2345?

Cloud services that process, store, or transmit CUI must meet FedRAMP Moderate baseline requirements at minimum. Standard commercial Microsoft 365, Google Workspace, and similar offerings do not meet this bar. You must use government cloud variants such as Microsoft 365 GCC or equivalent FedRAMP Moderate-authorized services. Using non-compliant cloud services for ITAR-controlled CUI compounds both your CMMC exposure and your ITAR exposure simultaneously.

How do I find out which of my contracts require CMMC?

Search your contract documents for DFARS clause numbers 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021. The presence of 7012 means NIST SP 800-171 compliance has been required since the contract was signed. The presence of 7021 means a CMMC certification is now contractually required. If you are a subcontractor, ask your prime in writing whether their DoD contract contains these clause numbers.

Prepare for assessment.

1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.

Request a Demo