What CMMC Protects: FCI and CUI
The DLA webinar opened by framing cybersecurity not as an IT issue but as a fundamental readiness issue. CMMC is built around protecting two categories of sensitive information that flow through the defense supply chain.
Federal Contract Information (FCI) is information generated for the government under a contract that is not intended for public release. Pricing data submitted during a procurement is one example. Critically, DLA has not made a blanket determination that all DLA contracts contain FCI, unlike some other DoD components. The rule permits each requiring activity to make that determination independently.
Controlled Unclassified Information (CUI) is a broader category governed by law, regulation, or government-wide policy. Technical drawings are CUI under the National Archives CUI registry. So is any data that contains program-specific details that adversaries could exploit, including something as seemingly minor as the specific adhesive compound used in a defense component. ITAR and export-controlled data is also considered CUI and will carry a Level 2 C3PAO requirement.
The Three CMMC Levels
CMMC is structured into three tiers. Understanding which level applies to your contracts is the first practical step every DLA supplier must take.
| Level | What It Covers | Requirements | Assessment Type |
|---|---|---|---|
| Level 1 — Foundational | Protects FCI | 15 basic practices | Annual self-assessment + affirmation. Pass/fail only. |
| Level 2 — Advanced | Protects CUI | 110 practices aligned to NIST SP 800-171 Rev 2 | Annual self-assessment OR triennial C3PAO third-party assessment, depending on contract sensitivity |
| Level 3 — Expert | Protects CUI on critical programs against APTs | 110 Level 2 practices + 24 additional from NIST SP 800-172 | Government-led DCSA (DCPAS) assessment every 3 years. Level 2 C3PAO is a prerequisite. |
For most DLA small business suppliers, the operative question is whether Level 2 self-assessment (RD004) or Level 2 C3PAO (RD005) applies. The DLA panelists confirmed that the majority of automated DLA procurements will route to Level 2 self-assessment. C3PAO assessments are triggered primarily by ITAR and export-controlled items, where the services have marked the technical data as requiring a higher level of protection.
Phase-In Timeline
The DoD is rolling out CMMC across four phases. DLA has aligned to the department schedule while making a clear enterprise decision on when mandatory compliance takes effect for its own suppliers.
| Phase | Date | What Changes |
|---|---|---|
| Phase 1 | November 10, 2025 | Contracting officers may begin including Level 1 and Level 2 self-assessment requirements in solicitations. CMMC is voluntary at this stage but can appear in new awards. |
| Phase 2 | November 10, 2026 | Level 2 C3PAO and self-assessment requirements may be included in solicitations involving CUI. DLA can begin requiring Level 2 from this date. |
| Phase 3 | November 10, 2027 | Level 3 requirements may be introduced. Level 2 C3PAO becomes more broadly available across solicitations. |
| Phase 4 | November 10, 2028 | DLA mandatory deadline. All DLA automated procurements will require CMMC as a condition of award. Suppliers without certification will be unable to access DLA systems, which contain CUI by default. |
Just because the department is permitted to require a given level from a certain date does not mean DLA will require it that day. DLA made the deliberate decision to use November 10, 2028 as its uniform mandatory date for automated procurements rather than phasing in earlier, giving its supplier base more runway to prepare.
DLA-Specific Contract Language to Watch For
DLA uses two mechanisms to communicate CMMC requirements in solicitations and contracts: DFARS clauses and DLA Standard Text Objects (STOs, sometimes called STOEs).
DFARS clauses are the DoD-wide contractual vehicles for CMMC. The key provision is DFARS 252.204-7025, which will specify the required CMMC level and assessment type. When this provision appears in a solicitation, CMMC is an immediate requirement for that contract.
DLA Standard Text Objects are DLA-specific inserts placed into solicitations. The CMMC-specific STOs to look for are:
| STO | What It Means |
|---|---|
| RD004 | Level 2 self-assessment will be required. The STO will specify a date, typically November 10, 2028, by which compliance must be demonstrated. This is the standard STO for most automated DLA procurements. |
| RD005 | Level 2 C3PAO third-party assessment will be required. Triggered by ITAR/export-controlled items or other high-sensitivity markings from the military services. Seeing both RD004 and RD005 in the same solicitation was an early system error; DLA has resolved that issue. |
| L39–L42 | DLA procurement notes in solicitations that indicate either a current CMMC assessment requirement or a future requirement by full implementation date. |
| NIST STOs | Older STOs referencing NIST SP 800-171 compliance under DFARS 252.204-7012 may still appear alongside or separately from the new CMMC STOs during the transition period. Both requirements can coexist. |
If none of these clauses or STOs appear in a solicitation or existing contract, and CUI has never been identified in that procurement, it is safe to assume CMMC is not currently required for that award. That assumption should be revisited when the contract is modified or recompeted.
Identifying CUI in Your Contracts
The most common question in the webinar was some variation of: how do I know if my contract has CUI? The honest answer from DLA's CMMC policy lead is that the system is still maturing. Here is how to work through it today.
Check the technical data package. Technical drawings are CUI under the National Archives CUI registry, full stop. If you receive engineering drawings or specifications from DLA or the military services as part of your contract, you are handling CUI.
Look at existing NIST 800-171 language in your contracts. If your current contract already includes a DFARS 252.204-7012 clause requiring NIST SP 800-171 compliance, the item was already classified as CUI-bearing. That contract will almost certainly carry a CMMC requirement when it is recompeted.
Contact your contracting officer if there is a dispute. If you believe an item is commercially available off-the-shelf (COTS) and should not carry CUI designation, the contracting officer is the current escalation path. DLA is working to develop an enterprise-level challenge process but it is not yet in place. The KO can work through engineering support activities to dispute the marking.
ITAR and export-controlled items require Level 2 C3PAO. If your item involves International Traffic in Arms Regulations (ITAR) controls, it will be treated as CUI and will carry the higher C3PAO assessment requirement, not just self-assessment.
Self-Assessment vs. C3PAO: What the Difference Actually Means
This distinction generated significant confusion in the webinar Q&A and is worth spelling out clearly.
A Level 2 self-assessment is an internal evaluation conducted by your own organization against all 110 NIST SP 800-171 requirements. You score yourself, document your findings in a System Security Plan (SSP), submit your score to SPRS, and provide an annual affirmation of continued compliance. The score you submit is your representation to the government that you have assessed your posture accurately.
A Level 2 C3PAO assessment starts with you completing the self-assessment first. The C3PAO will ask for your SPRS score and supporting documentation before they begin. They then conduct an independent review of the same 110 controls, examining people, process, technology, and documented procedures. At the end, they issue a separate certification that carries more weight than a self-assessment because it is not self-attested.
Think of it the way the DLA panelists framed it: the self-assessment is you telling the DMV you know how to drive. The C3PAO certification is the DMV giving you the license after verifying it themselves.
Costs mentioned during the webinar ranged from $30,000 for well-prepared organizations with documentation already in place to $100,000 for larger or less-prepared companies. The Cyber-AB marketplace is the authoritative source for finding accredited C3PAO assessors.
SPRS Submission and POA&M Rules
After completing an assessment, every contractor must enter their results into the Supplier Performance Risk System (SPRS). SPRS has two relevant modules: the existing NIST 800-171 module (where contractors have been submitting self-assessment scores since 2017) and the newer CMMC module, which is the formal certification record.
The two modules coexist during the transition period. Submitting a score to the NIST module is your self-certification that you have assessed against the 110 requirements. The CMMC module is the formal, verified record, equivalent to the driver's license in the analogy above. Both will be visible to DLA contracting officers when evaluating award eligibility.
Contractors must also submit an annual affirmation in SPRS to maintain their compliance status after each assessment cycle.
For Level 2 self-assessments, a Plan of Action and Milestones (POA&M) may be permitted for a limited period to address unmet requirements. The DLA presenter noted that POA&M items must be closed within 180 days. This tracks with the regulatory rule: open POA&M items cannot remain unresolved indefinitely. Not all requirements are eligible for POA&M status under the final rules.
How to Get Started
The DLA webinar outlined a straightforward sequence for suppliers beginning their compliance journey.
Step 1: Inventory your assets and map CUI flow. Before you can implement security controls, you need to know where sensitive data enters, moves through, and exits your environment. This scoping exercise defines your system boundary and is the foundation of your SSP.
Step 2: Implement the required security controls. Work through each of the 110 NIST SP 800-171 requirements and close gaps. For Level 1, the 15 basic practices are the target. For Level 2, all 110 apply.
Step 3: Document everything in a System Security Plan. The SSP is the primary artifact your assessor will review. Generic template language is not sufficient. Each control must be described in terms of how your specific environment implements it, who is responsible, and what evidence demonstrates compliance.
Step 4: Gather evidence. Policies, screenshots, configuration exports, training records, and access logs are all examples of evidence that supports your SSP assertions. Evidence is what differentiates a strong assessment from a finding-heavy one.
Step 5: Submit your score to SPRS. Once your assessment is complete, enter your results in SPRS. If your contract requires C3PAO certification, engage an accredited assessor through the Cyber-AB marketplace.
Frequently Asked Questions from the Webinar
If CUI is not mentioned in a solicitation, does CMMC still apply?
If neither the CMMC clause, DFARS provision, nor a relevant STO appears in a solicitation, and CUI has not been identified in the procurement, it is safe to assume CMMC is not required for that award. However, treat this as a procurement-by-procurement determination, not a company-wide exemption. As existing contracts are recompeted and modified through 2028, CUI and CMMC requirements will be added to items that previously did not have them.
Are all technical drawings considered CUI?
Yes. According to the National Archives CUI registry, technical drawings are CUI. If you receive, store, process, or transmit engineering drawings as part of a DLA contract, you are handling CUI and will be subject to CMMC requirements when the relevant solicitation is recompeted.
Does ITAR automatically require a C3PAO assessment?
In practice, yes. Export-controlled items marked as ITAR will be considered CUI and will carry a Level 2 C3PAO requirement under DLA's current approach. This is driven by the technical markings the military services assign to the data, which DLA incorporates into the procurement requirements.
If I am a distributor who never touches CUI, do I need Level 2?
If CUI flows from the prime down to the subcontractor or distributor, the prime is required to flow the CMMC requirement down to match the information being shared. If the distributor genuinely never accesses CUI (for example, they only handle physical product with no access to technical drawings or program data), the prime would have no basis to flow a Level 2 requirement. At minimum, Level 1 may apply if FCI is present. This is a conversation to have with your prime contractor and review the terms of your subcontract.
What happens if a solicitation includes both RD004 and RD005?
Having both STOs in the same solicitation was an early system error that DLA has since corrected. If you encounter a solicitation with both, look for ITAR or export control language to determine which applies. In most automated DLA procurements, RD004 (Level 2 self-assessment) is the correct STO. If in doubt, contact the contracting officer directly for clarification.
Is Project Spectrum free to use?
Yes. Project Spectrum is a free government resource that provides cybersecurity training, checklists, and tools for small defense contractors. DLA referenced it throughout the webinar as a starting point for suppliers beginning Level 1 and Level 2 self-assessments. It does not replace a compliance platform or professional assessment support, but it provides useful foundational materials at no cost.
How long does it take to get a C3PAO assessment?
The DLA panelists noted that C3PAO costs range from $30,000 to $100,000 depending on organization size and documentation readiness. As of this April 2026 webinar, broader industry reporting put booking windows at accredited C3PAOs as high as 8 to 14 months for some organizations. Contractors who need a C3PAO assessment before November 2028 should begin engaging assessors well in advance, particularly if their JETS IDIQ or other DLA vehicle has an earlier compliance date.