Tuesday Journey | Beginner Path · Business Owner
Does CMMC Even Apply to Me? FCI, CUI, and the Level Question
Assume CMMC applies to you until you’ve confirmed otherwise. That part is rarely the hard part. The level is, because your level is where the time and the money actually live, and it’s the easiest thing to get wrong.
One of the first questions I ask a company is simple: what CMMC level are you pursuing?
The answer I hear surprisingly often is, “We think Level 1.”
Then I ask why. That’s usually where the room gets quiet.
It isn’t because they’re unprepared. Usually they’re good at what they do and they’ve already invested time and money. The quiet comes because nobody has actually answered the question. They assumed Level 1, built toward it, and never went back to check whether the assumption was true.
If you’re performing work under a Department of War contract or subcontract, you should assume CMMC applies to you until you’ve confirmed otherwise. That part is rarely the hard part. The level is, because your level is where the time and the money actually live, and it’s the easiest thing to get wrong.
The wrong problem, solved perfectly
A friend of mine once shared something that stuck with me. Their company had spent months solving the wrong problem. They stood up a Level 1 program, ran their self-assessment, and felt good about it. Then someone finally asked where the engineering team had been getting its drawings, and it turned out a prime had been sending controlled technical data for more than a year. Everything they’d built was competent. It was just aimed at the wrong target, and the head start they thought they had was gone.
The expensive mistake in CMMC is almost never a control someone failed to implement. It’s a question nobody thought to ask: where does our government information actually come from, and what’s in it?
This is also why your level isn’t something you set once and forget. You can genuinely be Level 1 in January and holding CUI by spring. A new task order adds a deliverable. A prime’s engineer emails a specification. Nobody sends a formal contract change and nobody announces it, so the paperwork still says Level 1 while the reality has moved on without you. Your compliance program has to evolve with your contracts.
Your level is discovered, not chosen
Here’s what I’ve learned. Your CMMC level isn’t something you pick. It’s something you discover. It’s decided by the information you handle, not the level you’d prefer to be.
So the real work at the start isn’t choosing a level. It’s telling the truth about your data, and letting the level fall out of that.
A new stop every Tuesday and Thursday.
Our twice-weekly series breaking CMMC down one step at a time. Opt in and we’ll send each one to your inbox.
FCI, CUI, and why the line is easy to miss
The reason this trips up smart people is that the two kinds of information look almost alike day to day. Federal Contract Information, or FCI, is the ordinary paperwork of doing business with the government. If you hold a federal contract you almost certainly have it, and on its own it puts you at Level 1: fifteen basic safeguards and a yearly self-assessment. Controlled Unclassified Information, or CUI, is the smaller, more sensitive slice, technical drawings, specs, export-controlled data, and the moment it lands in your environment you’re at Level 2: 110 requirements and, for most contracts, an outside assessor.
Here’s how the line gets crossed. Maybe today your team only receives schedules and invoices. Six months from now an engineer gets a technical drawing from a prime, and that one email changes your obligations. It rarely arrives with a label. So the real question is never “do we have FCI.” You do. It’s “do we have only FCI,” and that one word, only, is where the months are won or lost.
It doesn’t matter where you’re starting
One more thing, because it matters more than any regulation I could quote. When our CIO handed me the CMMC program and I owned it as the compliance lead, as our team reached Level 2 and began the early work for Level 3, what mattered wasn’t how far along we were when we started. It was that we answered the right question first. The companies that make real progress aren’t the ones with the biggest budgets or the most staff. They’re the ones that start with the truth about their data, wherever they happen to be standing today.
What I would do if I were in your seat
Ask the plain question before anything else
Where does our government information come from, and what’s actually in it? Walk it with your project managers and engineers, not just IT, because the answer usually lives with the people doing the work.
Pull your last few contracts and task orders
Including the delivery orders, and read them for technical data, drawings, and any controlled markings. The delivery orders are where the surprises hide, because that’s where scope tends to grow without anyone noticing.
When something is unmarked but describes a system, a technology, or a program
Treat it as sensitive until your contracting officer tells you otherwise, in writing. Over-including is easy to walk back. Under-including is what surfaces at the worst possible time.
If you can already see CUI-bearing work coming in the next year or two
Build for where you’re going, not only for where you are today. It’s far cheaper than doing the work twice.
Once you know what information you actually protect, every other CMMC decision starts to get easier. Scope, budget, technology, documentation, even your certification level, all of it gets clearer once this first question is answered. The companies that make steady progress don’t guess. They understand the truth about their data first, then build around it.
Don’t decide your level first. Discover it. Start with the data, because that’s where every other CMMC decision begins.
CMMC: Everything You Need to Know to Get Started (6th Edition)
Want the full compliance framework and the funding resources available to defense contractors? Our guide has it.
A few sources
- FAR 52.240-93 (formerly FAR 52.204-21): the basic safeguarding requirements behind Level 1
- NIST SP 800-171 and 32 CFR Part 170: the 110 requirements for CUI and the CMMC program levels
- The 48 CFR acquisition rule, effective November 10, 2025: what makes CMMC an enforceable contract requirement