Event
June 25, 2025
Understanding CUI: The Key to CMMC Compliance
Overview
Watch CUI expert James Goepel, Fathom Cyber CEO, and Bill Wootton, C3 Chief Revenue Officer, in this on-demand webinar on understanding and securing Controlled Unclassified Information (CUI) for CMMC compliance. Learn to identify, categorize, and protect CUI, whether you’re starting your compliance journey or preparing for an assessment.
Here’s what you will learn:
- What qualifies as CUI
- How CUI fits into the CMMC framework
- Best practices for identifying and handling CUI in your environment
- Common pitfalls and how to avoid them
- Real-world examples and lessons learned from CMMC preparation
Video Transcript
Lorita Ba
Hi, everyone. Thanks so much for joining us today. My name is Lorita Ba. I’m with C3 Integrated Solutions and welcome to our webinar. We’re focused on Understanding CUI: The key to CMMC Compliance. Today we’re joined by Bill Wootton, our Chief Revenue Officer here at C3. Hey, Bill.
Bill Wootton
Hey.
Lorita Ba
And we have the great pleasure to have our special guest, Jim Goepel CEO of Fathom Cyber, here as well. Hey, Jim.
Jim Goepel
Morning. Afternoon.
Lorita Ba
But before you know it. Right? So, before we get started here, obviously, as I mentioned, we’re going to be talking about a topic that we get lots and lots of questions about. I think all of us, have a lot of have heard a lot of questions about around controlled unclassified information and there’s no one better to help us answer those than Jim.
But before we get started with today’s webinar, I just want to review a few logistics. Our webinar will last, you know, just under an hour. We plan to be available for Q&A, so there should be, time for you to go ahead and put your questions in the questions panel in the Go To Webinar control panel.
You’ll likely find that on the right side of your screen; there should be a little dropdown for that. Attendees will be muted during the call. But you can submit those questions at any time. We’ll start with a little bit of a presentation and then Bill and Jim will go through some of the common questions that we certainly hear a lot.
And some of the core points to hear. And then we’ll go through questions from, from the audience. We will be recorded, and we will have the slides available after the call, that will send to you via email. And with that, I’m going to go ahead and turn it over to Bill. To get started. Bill.
Bill Wootton
Right. Thanks, Lorita. As Lorita mentioned, one of the questions that we get all the time when we talk to, clients and prospective clients is just anything and everything around the concept of controlled unclassified information CUI. And really trying to just get a better understanding for it. Today I’m super excited to have Jim here presenting with us.
You know, if you think about the entire CMMC ecosystem and the folks that are actively involved in it, I can count certainly less than one hand. The folks that I feel are it truly understand it. And, you know, I go to for advice on my stuff when we get questions around these pieces here. And Jim is that person there.
So we’re delighted to have Jim as part of it. Jim’s had a, has an illustrious career is starting with being the CEO and General Counsel of Fathom Cyber, as well as President and General Counsel of Peak InfoSec. Long history of working in the CMMC ecosystem, even though it’s only been around here for a couple of years.
Being one of the founding directors of the accreditation board at one point and also being a provisional CMMC instructor, a Certified CMMC Assessor and Certified CMMC Professional, CISM, CCP, there’s a lot going on there. Sorry about the alliteration. Probably more importantly for me, Jim has his JD out of George Mason University and is a fellow Drexel Dragon, like myself, with his original bachelor’s.
So, Jim, welcome to the program. So glad to have you here. And, I’ll turn it over to you and let you run with it.
Jim Goepel
Thanks, Bill. It’s an honor to be here. I really appreciate it. This is a great opportunity. As you and I talked about, I love talking about CUI. So, hopefully we’ll keep things interesting and keep things moving.
Before we get started, I do have to give the stereotypical legal disclaimer of this is not legal advice, but there’s lots of intricacies along with this stuff. So, be sure you get engage somebody who really knows what they’re doing. There are times where, it is really advantageous to have a good lawyer. And if you need one, I can point you to some, I am not in private practice.
I don’t give legal advice to people, as a rule, like I am my company’s lawyer, but that’s about it. So, this is also not representative of anything the Cyber AB or DoD necessarily says or does. So just, take this with a grain of salt, but hopefully it’ll be useful for you. Let’s, what we wanted to do was to spend a little bit of time just going over some core, basic information that people need.
When you’re dealing with CUI to really help you understand this CUI program. And then, as Lorita said, we’ll get to some of the questions for the end. To do that, fundamentally, the biggest thing you need to understand is that for a government contractor CUI doesn’t really have to be that complicated. You’ll hear people trying to make it really complex and make it so that, they’re considered the subject matter expert.
I’ll do the opposite and tell you that it’s actually not that hard most of the time. Basically, all it is controlling unclassified information is unclassified information. First off, it has to be created or received for or on behalf of the government. And there has to be a law, regulation or government-wide policy that says that either it needs to be subject to safeguarding controls.
That is, you have to protect it some way or limited dissemination controls, meaning you can’t just give it to anybody. You can only give it to certain groups of people. And the other important part of this is that nonfederal systems, that is your information system, if you’re a government contractor, has to be protected, in accordance with 800-171 NIST SpeCUIl Publication effort.
If you are handling CUI. That’s it. It’s not that crazy. It’s not that hard. Or at least if you’re handling what’s called CUI Basic, it’s 800-171. There’s a little more intricacy. But basically, those are the things that if you can keep that stuff in the back of your mind, the rest of the CUI program is a piece of cake.
It is important to understand the history of the CUI program because it actually results from the 9/11 attacks, and it results from, Congress actually appointing the 9/11 Commission who came in and did an analysis to try to understand what it was that actually led to, the 9/11 attacks and how the attackers were successful.
What they found was that the agencies actually had the information they needed to be able to catch the bad guys, but the agencies were reluctant to share for a bunch of different reasons. And they the 9/11 Commission really just went after a lot of the federal agencies talking about how there was internal distrust among the agencies. There was stovepipes there’s all these other things.
And they said, look, the government needs a whole new approach to the way that we handle sensitive information. That approach has to be consistent across the entire federal government. So we can’t have different agencies doing things their own way. We need to recognize that unclassified information is unclassified and get away from that need to know mindset. And we need to actually move to, an approach that actually encourages information sharing across the entire government and especially to persons who are authorized to handle that information.
So, in 2006, 2008, the Bush administration came in. There was this early executive order in 2003 that overhauled how the classified information program worked. Congress in 2004 passed this Intelligence Reform and Terrorism Prevention Act, which basically said to the executive branch, hey, you need to clean up your act. You need to actually do a better job of handling all this stuff.
There was an executive memo that actually created the beginnings of the CUI program. There was, when the, Obama administration came in in 2010, they looked at everything that had happened. And actually, you would think that given the way some of the presidential transitions have happened lately, you might expect that Obama would have just completely trashed everything that the Bush administration did.
But in fact, while they did refine things, they actually embraced a good chunk of the changes that the Bush administration had done. So, again, we were fundamentally rethinking the way that information was handled both on the classified and unclassified levels. There were these two executive orders that were passed just a couple of months apart. At this point, most people are familiar with executive orders.
Those are instructions from the president that tell the agencies how they’re supposed to do things. And so we have these two executive orders that really just define the way both, I’m sorry, the way classified information is handled, as well as the way that unclassified but sensitive information is handled. And that’s our CUI program. One of the big things about the CUI program is that they looked at the different legacy information programs that were out there.
You had the LES the Law Enforcement Sensitive the FOUO, SBU, all these other programs, you had a lot of inconsistency between them. One agency would call something FOUO or the other agency would call that same kind of information SBU, for example. Or, one agency would say that, FOUO was not, couldn’t be sent outside the agency.
Another agency would say it would fine to do that as long as there were all these different, different issues that that would creep up. And so they wanted to fundamentally gut everything. So they actually got rid of it. They brought it all together, and they created that one ring to rule them all. And they call that thing the Controlled Unclassified Information program.
So on the unclassified side, this is the way that you handle sensitive information in the government. And they put the National Archives and Records Administration in charge of it because their job is to preserve information. So that the rest of the world can actually look at it, and U.S. citizens have access to it and all these other wonderful things.
But they put NARA in charge of it because, they were about the most neutral agency that existed. What NARA was very quick to point out was that the, old legacy information was not necessarily Controlled Unclassified Information. It doesn’t automatically become CUI just because it was sensitive at one time. One of the big things that they saw with the 9/11 Commission saw was that people would slap FOUO, SBU, other labels that these legacy information, markings on information in an attempt to hide it from Congress, hide it from the public in some way that somebody at the agency would do something stupid.
And we’re all human. We all make mistakes. But somebody would do something stupid. And then rather than owning up to it, they would slap a label on it to try to limit the dissemination of it so that, again, Congress wouldn’t get it or wouldn’t wind up in the Washington Post, etc. So, the National Archives said in the CUI program, just because it has these old legacy markings, that’s not good enough.
The agency has to go through every piece of old information, and if they want to consider it as Controlled Unclassified Information, they have to make sure that it actually meets one of the requirements to for it to be CUI. And so what, what NARA did was to bring together the National Archives said was to bring together a bunch of the laws, regulations and government wide policies that that exist.
And they create a list of those, and they make the agency go through that list and figure out does the information that they’re holding actually meet the requirements in a while? Regulation or government policy? If not, then it is not Controlled Unclassified Information. Before agencies can disseminate information to you. If it has that those legacy markings on it, the agencies are supposed to again review that decide whether it is CUI or not.
If it’s not CUI then those legacy markings go away and there’s no other markings. It is what’s called federal contact information or just unclassified nonpublic information. And the agencies are supposed to take the appropriate steps to protect it. If those legacy markings remain on information, they’re actually void in most cases. Now, there’s some wiggle room that the agencies have because they have to adopt the CUI program.
And a lot of there’s, over 50% of the federal agencies haven’t begun to even adopt the CUI program. And we’re, almost next year’s the 25th anniversary of the 9/11 attacks. It’s really sad that we’re that far along. And over half of the federal agencies still don’t even haven’t even tried to, make our life better. But that’s a whole separate conversation.
So the whole idea, again, was standardization across the government. There is this one definition. That is what sensitive information is and basically what it says. The, you’ll see the long definition of it up top at the bottom is this oversimplification. The oversimplification is that CUI is unclassified information created or received for or on behalf of the government that a law, regulation, or government policy says can or must be safeguarded or subject to limited dissemination controls.
That’s it. It’s actually not that bad. There’s a lot there. There’s a that’s a mouthful, but it’s basically the government’s information or the, the information that the government has received that the government needs to protect. And then, there’s a law, regulation or government wide policy that says that it has to be protected. That’s all. It’s not anything crazy.
There’s no really weird definitions here or anything. It’s actually pretty straightforward. The one wrinkle is that there is a recognition that some of the laws that are out there actually have specific requirements in them for how information is to be protected, or additional steps that somebody that is handling that information have to put in place. And so for those there’s a recognition that those things specify, additional safeguarding controls.
That makes it the that information CUI Specified. So if the law, regulation or government policy that applies to them says you have to protect it in a certain way, that makes that information CUI Specified. Otherwise, if it’s generic and a good chunk more than a half, probably closer to two thirds of the laws, regulations or government policies that have been reviewed and accepted by NARA are just generic.
They don’t say anything. They just say that this information is sensitive. Then that information is what’s called CUI Basic. It does establish as well, again, that the way to protect that CUI Basic is through the protections that are in 800-171. If you have CUI Specified, then you have to not only implement the things that are in 800-171, you also have to implement the additional, safeguarding controls that are in the corresponding law, regulation or government policy.
A question that comes up often for me is there’s a fundamental misunderstanding of designation and marking. There those are actually two different concepts in the CUI program. Most people jump right to, “do I need to mark this information as CUI?” The first question is, is it CUI to begin with. And so that the idea of marking is as it says on the screen applying appropriate notices on, to the information that you’re handling.
And there are there’s a whole set of training DoD. You’ll hear me kind of talk trash about some of their training. DoD’s marking training is excellent. The National Archives marking, information is excellent. They do a really good job of that. What they don’t talk about so much is that designation piece. Designation is determining whether a law, regulation or government policy applies to the information, and only laws, regulations, or government policies that NARA has approved are the basis for that CUI designation.
So there’s this list that the National Archives has published. This thing called the CUI Registry. That CUI Registry, again has a list of about 400, 450 laws, regulations, government policies that all can be the basis for designating information as CUI. That’s when you mark something as CUI there is a recognition that that impedes the free flow of that information.
The free flow of information is core to our democracy, is core to our government. We want to make sure that all the different agencies have access to the information that they need. We actually want to make sure that Congress gets it. The public gets it. All that good stuff. We need to make sure that we have that free flow of information.
So the idea that you mark something as CUI. Now you’re starting to put in place restrictions on who can get access to that information. That is an inherently governmental act. That is not something to be taken lightly. And so, only the people that have actually been delegated the authority to do that are actually authorized to do that, make those designation determinations.
It turns out that actually improperly designating information CUI can open you up to sanctions. And ultimately, it’s an agency level decision as to whether information is CUI or not. When you read through the vast majority of 32 CFR Part 2002, which is the CUI program, it talks about how the agency does things and it talks over and over again about the designating agency.
Designating agency. There is one part in there that has a little more wiggle room, where it makes it sound as though there’s the individuals have the ability to designate information as CUI that actually happens. In one of the definitions, it really doesn’t apply. The rest of it, when you talk to the folks at NARA and you talk to the people that help write the regulations, which I did, you’ll find that they intended that.
So, fundamentally, again, this is a really it’s a governmental decision and government only decision. And so somebody inside of the agency needs to be the one who makes that determination, not you as a contractor.
Who in DoD has the designation authority? We get that question a lot. The DoD defines its CUI Program in what’s called DoD Instruction or DoD 5200.48. And in there, they delegate the authority to make that designation decision to what are called Original Classification Authorities or OCAs. And they are the only ones that really have the authority to do this.
There are two implied delegations of authority in different documents. One of them is this other one that deals with controlled technical information, where program managers are at least maybe arguably delegated the authority to designate information. And then there’s one that deals specifically with nuclear information, where one person, the Undersecretary of Defense for Nuclear, Chemical and Biological Defense programs, gets to determine whether other information falls under that category.
Aside from that, it’s really just those original classification authorities. Those are the people who get to make the determination as to whether the information is CUI or not. Everybody always asks, how do I know if the information I receive is CUI? Fundamentally, the CUI program requires that before information is shared with anybody, it has to be overtly marked as CUI or the container that it’s in, like a file cabinet or the USB drive that it’s on, has to be marked as CUI. Or there might be in your contract.
It can tell you that the information is CUI. It’s not supposed to be done that way—most of it because not all information is CUI, right? It has to be information that is sensitive enough that there’s, again, a law, regulation, or government policy that says that it has to be protected. Not everything that’s communicated with you is going to meet those requirements.
So marking at the contract level doesn’t really happen that often. It’s mostly either, again, overtly marked on that piece of paper or other document, or the container that it’s in has some kind of marking. Agencies can get away with marking at the room level if it’s really bad—if it’s really burdensome to mark everything that’s in that room, they can actually put a sign on the door that says, “Hey, this is what you’re supposed to do.”
It’s interesting because the marking materials don’t talk about how nonfederal organizations are supposed to handle that scenario, in part because whenever the agency gives you information, they are supposed to mark it as CUI. So as soon as it crosses the threshold—it leaves the government—they’re supposed to mark it as CUI. Now, a lot of times contractors ask, what about the information that I create?
The agency that owns that information—only they have the authority to actually designate it as CUI. If the agency hires you to create information, they should communicate any CUI designations as part of your contract. The way they usually do that—what DoD has said to do—is through what’s called a Security Classification Guide, or SCG. There is this new FAR CUI rule that’s coming out sometime.
We’ve been waiting for it since 2016, so I’m not sure it’s going to happen tomorrow. But at some point in the not-too-distant future, there should be a FAR CUI Rule that says what information is sensitive. There’s actually a form that’s supposed to be given to you that sort of takes the place of that Security Classification Guide. Regardless of whether it’s the form or the Security Classification Guide, it’s supposed to help you understand the attributes of the information that make it CUI.
There’s actually a sample one there on the left-hand side of the screen. And in contracts to create information, you need to refer back to the security classification guide. If the information that you create meets those or has those attributes, then you need to mark it as CUI. If it doesn’t, it doesn’t. If you receive information that’s marked as CUI
or are told information has been designated as CUI and you don’t think it should be, you want to ask for that Security Classification Guide. What I have found as a general best practice, and in all the clients that we’ve advised, is if you ask for the security classification guide and you ask for the corresponding law, regulation, or government-wide policy that is the basis for it,
nine times out of ten—or actually more than that—the agency will decide that the information isn’t Controlled Unclassified Information to begin with, and so they will withdraw all the CUI markings from it, and they will just give it to you. What you’ve basically done is to catch them in one of those scenarios where, again, they may have been slapping what they thought was the equivalent of FOUO or SBU on information without really jumping through the hoops that they’re supposed to jump through as part of this new program.
Once that information has been designated as CUI, it must be properly marked before it’s disseminated to anyone. So if you are creating—if you’re writing code, if you are creating some document, you’re doing an analysis, whatever it is—your output, once the agency has told you, “Hey, if it has these attributes, it’s CUI,”
and you create something that has that information, you must mark it as CUI before you give it to anyone. It doesn’t matter whether that’s the person sitting in the cubicle next to you that’s working with you or somebody else downstream, or going back up to the government. Doesn’t matter. You have to mark it as CUI before you disseminate it to anyone.
And then if you give your information to the government, always be sure to mark your information as proprietary before giving it to the government. There are laws, regulations, and government policies that say they have to protect your information when it comes across. Depending on exactly the scenario when you received, there are important ones that can help protect your information, but you want to make sure that you’re marking it as proprietary.
You also want to include a cover letter wherever you can that just says, hey, we think this information should be treated as CUI, should be designated a CUI by the agency. And here’s why. If you know the law, regulation, etc., that should be the basis for it. Communicate that to them. It doesn’t hurt.
It kind of puts them on the defensive. Now they’re having to push back. But don’t mark it as CUI. You are not an agency. If you’re a contractor, you’re not an agency. You don’t have the authority to make that determination. At the end of the day, that is up to the agency itself. And then be careful about using the term confidential.
Confidential is one of the categories of the Classified Information System. So marking something as confidential when it gets into DoD just creates headaches. In the interest of time, I’m not going to go through marking training because there is some really good marking training, like I said, from DoD. Strongly encourage you make sure you take that training.
One of the other questions that people ask me, though, is what do I do about copies and derivative works? So CUI is fundamentally about the protection of information. If you copy information, it’s still a copy of the information. It still retains that information for the same attributes. So it’s still CUI. Derivative works—that is information like a subset of the original information.
So one drawing out of a set of 50 or something along those lines. How do I know whether that’s still CUI or not? Well, if you look back in the security classification guide, it tells you this: this is what makes it sensitive. So therefore, this is what makes it sensitive. If that subset of information, that derivative work, still has those attributes,
it’s still CUI. So again, if you’re not sure once you’re working with information that is CUI, it is better to assume that the information in your derivative work is CUI. And you’ll use the same markings as the information that you got, as the information that is the basis for the derivative work. When you’re giving out that information, if you have to share it with other people, you are authorized to do that as what’s called an authorized holder.
But you have to make sure that the recipient is an authorized holder—that is, that they have what’s called a lawful government purpose for handling that information and that they are reasonably—you have to have a reasonable belief that they will properly handle the CUI. How do you provide a reasonable belief about that? Well, you can ask a lot of questions.
You see a lot of the prime contractors today doing that. They have questionnaires that they’re disseminating to people. You’re supposed to help understand how mature your organization is. They are of limited value. At the end of the day, you’ll see some primes are now asking for the SPRS score and some questions to help validate it.
That’s a little bit better than just a generic questionnaire. Or basically, you learn from DoD. And that’s where the CMMC program comes from. CMMC is really, at the end of the day—while I recognize that DoD early on talked about how we need to safeguard our warfighters and all of DoD’s personnel, and I agree with that completely—
really, what this is about is DoD needs to live up to its obligations under the CUI program. If it’s going to give you sensitive information, they need to make sure that you can actually handle it appropriately. And we’ve seen time and time and time again that contractors just don’t do a good job of trying to secure that information.
So that’s where we get into the CMMC program, where we’re now getting third party validation that you’re actually doing all this stuff. All right, Bill, that was a fire hose. Did I put everybody to sleep? I hope not. Hopefully I kept things moving well enough.
Bill Wootton
I think the microphone woke everyone up about halfway through, so I think we’re good there. You know, fantastic. You’re right—that’s a fire hose. There’s so much information in there. You’ve spent a career working on this, and understanding it is so hard to digest and bring it down into, you know, 25 years of what’s a process and regulation and government angst. But we’re finally here.
We’re finally at this point where we’re on the threshold of a verifiable third-party program to protect CUI and make sure it’s being protected. The thing that jumped out to me in particular was that tip on challenging the SCG, around CUI and the markings and the pushback on it. It’s a great way to kind of hold the government accountable, make sure they’re doing their job, and presenting you information that is relative to CUI.
I had a couple of questions that I wanted to kind of talk through and kind of maybe work through, and then we’ll get into questions from the audience themselves. You know, one of the questions that we get a lot—and that our clients really wrestle with—is who can they disseminate or share CUI with?
Jim Goepel
So basically, they’re an author as long as they’re an authorized holder, which means that they again, have a lawful government purpose. A lawful government purpose means there is a definition for it that the oversimplification is that, as long as the person that is going to receive that information, is helping to further the purpose of your government contract, then awesome.
They likely have a lawful government purpose. So my favorite example for that is your cleaning crew, right? Your cleaning crew probably does not have a lawful government purpose to have access to your CUI. So that’s why some organizations have clean desk policies. They put away copies of their stuff at the end of the day, right.
They put them in a locked—and doesn’t have the key—program, doesn’t require, you know, massive vaults and all this kind of stuff. It goes in a locked drawer and in your desk, and that’s fine, but you have to actually lock it, and/or you lock the room that it’s in, and then the cleaning crew doesn’t go into that room once it’s locked.
When I was in private practice, that’s what we did. Our cleaning crews would go around, they’d clean every night. But if we had something open, if I didn’t—if I couldn’t clean my desk that night, I would just walk out of my office, lock the door, and the cleaning crew wouldn’t go in that room.
We had monitors there to make sure that that happened and all that stuff. There are ways of dealing with it. But again, that cleaning crew fundamentally doesn’t have a lawful government purpose, so they shouldn’t have access to the CUI. It’s a great point. Like, you think of all the natural ways that it makes sense—subcontractors, your supply chain, all of those different pieces there.
But the unintended spillage is literally, I think, the term that’s used there of things like a cleaning crew, you know, other folks that should not necessarily have access to that information. Digging in on that a little more—how about just like your system administrators or maybe your third-party service providers? How does this play in like in that context? It gets interesting there.
So there are arguments on both sides. I’m a lawyer. I tend to be risk averse, right? So, I am also a former systems administrator. There were times where I locked myself out—intentionally locked myself out—of certain information. There was stuff that was sensitive enough that I would work with the head of the office that I worked for.
I was a systems administrator for Congress, among other places. I would work with the head of the office and say, okay, where I’m going to lock myself out. You have full access. You can add and remove people as you need to. I can always come in and take control. I can always get myself back in there.
But there are log files that will show that I did that. There are ways of catching me. If I start to do bad things, you’ll be able to catch me. And that’s the mindset that you really want to have in place for all of this: if your systems administrator doesn’t have a lawful government purpose, if their access to that information doesn’t help forward the purpose of your contract, they really shouldn’t be in there.
And in fact, one of the other scenarios that comes up a lot is, Bill, if you and I were both employees of the same company, you might be working on one contract. I’m working on another. That doesn’t mean that you automatically get access to mine, or vice versa, right? We actually need to compartmentalize that information. Same thing goes with your systems administrators, and it’s not crazy. Again, there are relatively straightforward things that you can do to keep people out.
Bill Wootton
You’re 100% right there. I know as a service provider, when we set up systems with our clients, we take actions and have protocols in place to do everything within reason to prevent ever even being able to access that data for exactly those reasons. And then if there is anything from a support standpoint, you know, there’s ways to trace that and track that and be aware of it.
So in kind of a similar vein, you know, you talk a little bit about need-to-know and, you know, if you’re working on different programs, those types of things. Does CUI have any limitations around only being handled by U.S. citizens, at all?
Jim Goepel
Yes-ish, but only for certain categories of CUI.
So there’s what are called export-controlled information, and those things that are subject to export controls—whether that’s ITAR, EAR, or if DoD or another agency slaps another limited dissemination control on it—then you can only make that information available to people that are authorized to handle that information.
So, if it says “NOFORN,” meaning no foreign nationals, you can’t have anyone who is not a U.S. person actually handling that information.
Same thing goes with the ITAR or EAR controlled information—any export-controlled information. There are even forms of dissemination controls that say that it’s only releasable to specific individuals. So, despite that whole idea of free flow of information, you can actually—you can wind up locking down that CUI pretty tight. And again, you’ve got to make sure that when—if you get it—that you are taking steps to not release it to anybody that is not on that authorized list.
Now, those don’t happen that often. It’s not something crazy that most contractors are going to have to deal with, but it’s something to be aware of.
Bill Wootton
Totally makes sense. Totally makes sense. When you were talking about the definition around CUI, you mentioned that, you know, CUI obviously has to be created for or on behalf of the government.
How does that apply? Like when, you know, a contractor’s own information… is that considered CUI? Is it more proprietary information? How does that work?
Jim Goepel
So this is one of those areas where DoD steps on its toes. That if you ask DoD, for example, is my system security plan—the CMMC program is all about creating a documented security program that can then be reviewed by third parties.
That thing that you create, the documentation, is what’s called a system security plan. If you ask DoD, “Hey, is a contractor SSP controlled unclassified information?” DoD will tell you, yes, it is. And they are absolutely right. Because what if they get a copy of it? It is controlled unclassified information for a number of reasons. There are a bunch of laws, regulations, government policies that apply that would make it that way.
But in the contractor’s own hands, that information is not CUI. So it was not created for or on behalf of the government. It wasn’t created under a government contract. It was just created because that’s how you run your company. Same thing goes with Social Security numbers, for example. You have them because you have employees. You have to pay taxes to make sure that they’re paying their taxes.
When you get that information, that information is not created for or on behalf of the government. Yes, you’re a government contractor, but you need to do that because you’re a business, period. It’s not a requirement in a particular contract. It’s not. It is ancillary to the performance of that contract. So those are foundational things that again—by contrast—if I was doing a data analysis for the government and the government gives me a whole stack of Social Security numbers and other information about people and says, “Here,” that information—then when I receive it, because I’m receiving it from the government under contract—then that personally identifiable information is CUI.
Bill Wootton
Great. Like, I’ve run into several clients who just obsess over that thing and get all wrapped around the axle. So it’s really helpful to get that clarification. So you taking it from a little bit of a different perspective, you know, if that data comes in all of those numbers on a performance of the contract, but government doesn’t mark it what should a company do there? Like, if you’re looking at something, it looks like it’s CUI, acts like its CUI, sounds like it’s CUI. What do you do there?
Jim Goepel
So I’ve heard people tell you that you must mark that information as CUI. That is absolutely wrong. You do not have the authority to mark that information as CUI, to make that designation determination on your own. However, you need to treat it like it is CUI. We actually recommend putting a cover letter, cover sheet on it if you have to give it to somebody else. Sometimes, you know, life gets in the way, and so you have to give it to a subcontractor right away.
In those scenarios, put a cover sheet on it and say, “Hey, we suspect that this might be CUI. Please be thoughtful when you’re handling it,” blah, blah, blah. And then on the flip side, you want to go back to whoever gave it to you and ask, “Hey, is this CUI?” Now, ironically, just yesterday I put together a whole bunch of these things—sample language, template language—that you can use to share that.
And I’ll send a copy to you guys. You’re welcome to share it if you want. But the idea is you want to make sure you go back and ask. And especially if you’re a prime contractor, you want to go back and ask the government, “Hey,” you know, “because we’re all human and we all make mistakes. We’re all in a hurry to try to get stuff done,” and somebody might forget to put a label on something.
If you go back and ask them in a nice way, “Hey, every other time I’ve seen this kind of information, it was designated a CUI. Are you sure this isn’t?” Right? And now you’re being that thoughtful, responsible citizen. If you go back to them and go, “Hey, moron, you forgot to put CUI,” that’s going to set a different tone in the relationship.
Not really what I recommend, but that softer tone of “I want to be the right—I want to do the right thing,” is the right thing to do. What we generally recommend is, don’t disseminate. I talked a second ago about putting a cover sheet on and giving it to somebody else. Recommend don’t do that, but instead go back to the person who gave it to you and say, “Hey, I’m going to give you three days—or five days, whatever.”
If you got a little bit of wiggle room, “I’m going to give you five days. Please tell me if this information is CUI. It looks and smells like CUI, but you didn’t mark it. Could you just please confirm?” And then what that does is it gives them enough time to start asking the right questions. But it also gives you time that if they don’t respond in five days, you’re going to presume that it is not.
Because again, if you’re creating information, you are supposed to mark it as CUI before you give it to anybody. Again, we all make mistakes, but fundamentally, it needs to be marked. So as long as it gives the person that’s giving it to you—the disseminator—the ability to go, “Oops, thanks,” and fix the problem.
Bill Wootton
Sounds great. And I would imagine if you’re two or three levels down the supply chain, the appropriate answer is to go back up that ladder to eventually the prime. And then they would press it on to the government, you know, the government agency that would be responsible for making that decision.
Jim Goepel
Generally, yeah. But yes, you walk it up the ladder. You let the prime do the interacting with the government. There are ways of scooting around that line. I don’t generally recommend it because now you’re poking the prime in the eye, and that’s not generally a good idea.
Bill Wootton
Yeah.
Jim Goepel
The other approach that people want is to label that information—mark it as CUI. And the problem with taking that initiative is now if there’s somebody in between you and the government, they may have already done the diligence.
They’ve already asked, “Hey, is this CUI?” And been told, “No, it is not.” And now you’ve created a scenario where there might be a spill. And what do we do? Because a spill—we don’t really know how the government wants you to handle spills. That’s not well-defined yet. There’s a rudimentary outline of one, but there’s no good incident response program for that. That is going to create all sorts of havoc.
And so if that’s where—ask. Just ask.
Bill Wootton
That just totally makes sense. I got a couple more questions. I want to take a step back a little bit on this. And like when we think about these issues and when our clients come to us and talk about these things, you know, we think about it in terms of what’s that compliance scope going to look like for the client.
How are they going to build a virtual line around their assets and say, “These are things that are in or out of scope?” Do you have any advice on—like, when a contractor looks at all of this information that they’re pulling in and data and all of that—how should they put that in perspective of, “I’m going to evaluate where my compliance scope is going to look like?”
Jim Goepel
That is fundamentally what determines the scope. So if anything that stores, processes, or transmits CUI is in scope for that CMMC assessment—and in fact, anything that’s not physically or logically separated from that information is going to be in scope. So I’m actually helping a client right now who, they’re trying to do the right thing, trying to get better.
But their front door is open for members of the community to be able to come in and use some of the resources that they have, which is awesome. I love great conceptual—not a bad idea—but there are desks over in the corner where they handle the CUI. And those people that come in from the community theoretically can just walk right up to one of those desks and see all that information.
We’ve got to put up a boundary wall now that separates that CUI environment from the public areas, or we’ve got to lock people out of that facility—not really what the owner wants to do. So we’re trying to find a compromise that works. Same idea goes with other forms of information, right? That logical separation means that you’re putting things on Virtual Private Networks or on a VLAN or something along those lines where now you’re segmenting off that information or you’re literally putting it on an entirely separate network.
All of that stuff works just fine. But you have to compartmentalize the public-facing, or the less secure area, from the secure area.
Bill Wootton
You know, it’s interesting you went to a physical example as opposed to a virtual example. One of the challenges we have—clients are always asking us about printing—and we have to kind of talk through the point of like, you know, if you allow printing, you’ve now created a physical artifact of that data.
Now you have physical security in scope, and you’ve just sort of opened up a little bit of a Pandora’s box around it. So that’s interesting. I’m glad you used that as an example in there. One of the things we see clients also struggle with is this wrestling between, you know, do I handle CUI in almost like a surgical sense—a document-by-document basis—or do they take more of a broader approach in terms of, you know, I know some subset of this data is CUI, but I’ve got a lot of data associated with this contract.
Is there any recommendation around how you balance that?
Jim Goepel
At the end of the day, it’s about efficiency, right? The general number that I use is about 65%. So if about 65% or more of the information is CUI, just dump it all together because it’s going to be easier. You’ll only have one set of training, then you only have one set of requirements that everybody has to comply with.
It’s just easier as an organization, even though it will be more expensive because you’re bringing everybody into that CUI environment, but you’re training up, you’re doing everything right. And quite frankly, your business probably handles a bunch of information that is similar to CUI, but it’s only not CUI because it’s not the government’s. Where we talked before about Social Security numbers. You have bank account information for all your employees for direct deposit purposes. You have healthcare information. You have probably your business partners’ information—all this other stuff that needs to be protected too. Why not just put it in the secure environment at that point? But that’s a business decision. Again, 65% is my general line.
Bill Wootton
So, you’re thinking about that in context of going for an enclave versus all-in approach with the organization.
Jim Goepel
Correct.
Bill Wootton
Interesting. We’ve done some math on that. We found a much lower number starts to do all the different—so this is an interesting piece—is our inflection point is based on cost. At some point, when you’re paying for two identities, two licenses, two support systems, somewhere around 25% to 30% is that inflection point where, you know, there’s other factors in here we could always talk about.
But that’s where you start to think about, “Am I paying more money for an enclave than I am to go all-in?” So, it actually got a bit more on our end in some.
Jim Goepel
And I don’t disagree with that analysis. I’ve had some clients who have said, “We’re in the construction industry, we’re in the whatever.” Like, not weird niche, but weird niche that has these other issues.
And there’s just no way that my guys—love them—they are not going to change. Right. So okay. And so, we have to have a less secure environment that most of our people can stay in. Okay, fine.
Bill Wootton
And those are those other considerations. From a straight dollars perspective, you start thinking about it. We also recommend clients do what they can to minimize their footprint.
Can you take assets out of the system? CRM is a great example of that. Am I loading contracts in a CRM when I really don’t need to? Take it out of the system. Take it out of your environment boundary. I think we’re going to see a point not all that far in the future where folks build enclaves, start bringing people in, and by the time they’re done, they have a reverse enclave where 10-20% of their business still sits in that commercial environment—partially whether it’s an app that can’t be used, it’s a division in a group that doesn’t make sense, or you just have a group that’s kind of dug in and you’re not really confident in.
I think that’s the way the trend is going to go over the next couple of years. So, that kind of covers a lot of things that I wanted to talk about. Lorita, I want to bring you back in.
Lorita Ba
We have so many questions, Bill!
Bill Wootton
Are we going long today? What are we doing?
Lorita Ba
So, I’m going to go ahead and just start firing them off. All right? So, with security controls in place, we treat all contract information as CUI. So, PII etc. Is that a bad approach or good security posture from your perspective?
Jim Goepel
I would say it’s definitely not a bad thing. Right? There’s no harm—to Bill’s point from a moment ago.
It is more expensive, but there’s no harm in overprotecting information. It’s just there is a point where you don’t need to treat it like it’s classified information. You don’t need to go build a SCIF. You don’t need to go do all of the crazy things that you do on the classified side. I’m crazy about appropriate things that you do on the classified side, but, you know—so there is a point where you get to diminishing returns.
But practically speaking, I don’t think there’s a problem with bringing that in there. Bill, do you disagree?
Bill Wootton
No, I don’t. I have a little bit of a different justification for it, though. You know, CMMC is based on NIST 800-171. NIST 800-171 is a very solid, sound baseline for cybersecurity. The difference between, say, NIST 800-171 and CMMC is probably the maturity of your documentation and the artifacts you are collecting.
But in terms of—from a cybersecurity standpoint—that should be a baseline. Not a ceiling, but a floor. And there are actually things we recommend from time to time that are above and beyond 171 to have a good, sound cybersecurity-based baseline. So if you’re protecting all of your data and you’re doing it within the same scope—from a compliance standpoint and support standpoint—then you’re just putting yourself in a really good cybersecurity foundation, and you should be happy about the investments you’ve made on that.
Jim Goepel
And from a legal perspective—I mean, when you have a breach (and breach is inevitable, no matter how good a security program you have, you’re going to have a breach eventually)—so the whole goal is to have a good compliance program. The compliance program proves that you had a good security program. It wasn’t just “Yeah, we thought we were doing this,” but “Oops, we didn’t.”
We actually have the proof to be able to show that we were doing everything. And, if you have a good compliance program, the courts won’t really beat you up. You may get hit, you may get slapped on the wrist still, but you won’t get hit with massive fines and penalties. And the way that you help distinguish your compliance program and ultimately your security program…and make sure that you have a good argument as to why you were doing the right thing is to base it off of something like 800-171. What better thing from a legal perspective than to stand in front of a judge and say, “No, Your Honor, I didn’t just make up my security program. I used the same thing that the government wants me to do.”
If I was a government contractor handling that sensitive information, I’m doing the exact same thing that they wanted me to do. That is really hard for opposing counsel to fight at that point.
Bill Wootton
Yeah. And just to layer on top of that, you know, if you’re putting those controls in place and you’re making the investments in the cybersecurity services and the things you should be doing, you will more than likely identify that breach, quarantine it, and mitigate it much, much sooner than if you’re not doing some of the things that are included in 171.
Lorita Ba
Great. Thanks, guys. Here’s another question. So, this person says, we sell COTS products and don’t believe we handle CUI through our products. But because they have a MAS IDIQ contract, they definitely have FCI. But at the bottom of the contract negotiating letter from their CO there’s a footnote that the letter is CUI. Is it just because they say it is, or can they argue that it’s just FCI?
Do they have to go through the whole CMMC process just because of the single footnote on their negotiation letter?
Jim Goepel
So FCI and CUI are not the same thing. FCI is Federal Contract Information. That’s nonpublic unclassified information. It’s nonpublic, uncontrolled unclassified information. So there is no law, regulation, or government policy that says it has to be protected.
It’s not classified information, but it’s not intended for public use or public access. So in that scenario, you really only have to meet the requirements in FAR 52.204-21. There are 15 requirements and they are pretty straightforward.
Lorita Ba
So Jim, I think the question is slightly different. It’s that they understand the difference between FCI and CUI, but the footnote in the letter that they received from their CO in the contract negotiating letter says the letter itself is CUI.
Jim Goepel
Okay. So I would push back and ask for the law, regulation, or government policy that is the basis for designating information as CUI. If they tell you that it’s proprietary information and that it’s your proprietary information, you can tell them that that is not their role to determine whether your information—information of yours—is proprietary or not.
Bill Wootton
Yeah. I think it goes back to your point of pushing back, asking for the SCG, was it? And making them justify the reasoning for that. Makes total sense.
Lorita Ba
Okay. Next question. So this audience member is a DIB manufacturing company that produces components in support of some government contracts. The government has yet to identify what is CUI pending the release of the standard form.
We understand the definition and the eight-hour timeline of reporting violations of what and how to handle CUI. Our difficulty is how/when to mark certain information as CUI if/when the component produced is a common component in the commercial sector, but in this case is for a government contract. So, their perspective is that unless identified by the government contractor, we should identify the CUI as when the government order product is paired with the component that is being produced.
Jim Goepel
Not necessarily. So if you have a commercial item—if I have a washer, just to make it really simple—if I have a washer that is a commercial washer that anybody can basically go to Home Depot and buy my washer, then great. That’s a commercial item. And it is not CUI. Never is CUI.
When it goes into some landing gear for a next-gen fighter or whatever, my washer is still a commercial washer. Now, if the government, when they buy washers from me, says, “Not only do we want that commercial washer, but we want you to test every one or a subset of them according to MIL standard or whatever,” now that changes things. Because now I am taking some additional steps. I’m ensuring that washer meets those additional requirements. That is potentially no longer a commercially available item.
Now, if I was doing that for every one of my commercial items anyway, that would be different. But now, if I’m going above and beyond, I’m taking some kind of steps to validate or to enhance the washer, now that changes things. And now it’s no longer a commercial item.
Bill Wootton
That’s interesting. It’s not just the change in the design or how it’s constructed or those pieces, but even how you test and validate the capability of it.
Jim Goepel
Yeah, or at least there are arguments. And I would not want to—I try to keep my clients out of court where I can. So, you know, I would err on the side of caution on that one, right?
Lorita Ba
There’s that attorney coming out in you again, Jim.
All right. How about this? What about security documentation like the SSP? The FedRAMP PMO says that the SSP is CUI.
Jim Goepel
Yeah, we talked about that a little bit. That SSP is not CUI in your environment. Your own information is not CUI in your environment. But if you give that SSP to the government—including an SSP that the FedRAMP PMO gets—that information is CUI. And so, the FedRAMP PMO is going to have to treat that SSP as though it is CUI.
Lorita Ba
Great. Next question is: which marking guide should we use? NARA and the DoD each have their own.
Jim Goepel
So DoD is supposed to be a subset of the NARA. NARA is supposed to be the bigger, like, “This is government-wide.” But then you’ll see that if you read both, the NARA one has some flexibility, and it says agencies can do certain things.
And DoD establishes DoD official policy. So if you are a DoD contractor working on a DoD contract, you should be following DoD. NASA published a marking guide as well. If you’re working on a NASA contract, you want to follow the NASA marking guides.
The frustrating thing is that this is supposed to be consistent from agency to agency. There’s still a lot of wiggle room in some of this stuff, but fundamentally, that NARA one is the superset. You want to make sure that you are meeting whatever the individual agency you’re working with says needs to be done.
Lorita Ba
Thanks, Jim. Okay, this question you sort of touched on a little bit, but I think let’s just be explicit for this questioner:
If data’s extracted from a CUI-identified document, does the receiving document of the extracted information become CUI? For example, CUI-designated drawing has some final dimensional measurements transferred to our internal use drawing. Does our drawing become CUI?
Jim Goepel
Sometimes yes, sometimes no. So I’ll give you my favorite legal answer: it depends. If those dimensions are part of what made that thing CUI, then—again, that goes back to getting the Security Classification Guide—but if those dimensions are what made it CUI, then yes, your document is still CUI.
Go back. Think about that washer example. If, in the opposite direction, you’ve got a drawing that is the landing gear for some major new next-gen fighter, as we start extracting out the capabilities of that landing gear, the design of that landing gear, all of that kind of stuff together is CUI.
And there may be certain features and functions of it that are CUI. When it comes to that washer, the specifications for that washer probably don’t have the attributes that made the landing gear CUI. So when I’m buying it, when I’m communicating with a subcontractor about making that washer, I may not—I won’t say I won’t—but I may not be exchanging CUI with them at that level.
Bill Wootton
And I think, kind of building off of that, if you’re sending the specs for the washer itself, everything’s great. If you’re sending the spec for the washer and the larger component that is the piece that does also have controlled information on it, now you’ve inadvertently sent CUI data to that supplier when you’re just trying to order a washer.
So being really careful of what you’re sending to each supply chain member becomes really important.
Jim Goepel
And in my legal—when I was in private practice—I ran into this scenario back in the day, and everybody thought that the prime contractors were just trying to be controlling, and they only wanted to give you the little slice so that you couldn’t compete with them.
You couldn’t get. And honestly, while that may be part of it, that’s not their only reason for doing what they’re doing. They’re actually doing the right thing under these programs and only giving you the information that you need.
Now, if it turns out that you need something else, ask, and hopefully they’ll be able to give it to you. Because at that point, if you really need it, you have a lawful government purpose for having it. So, get it. But generally speaking, that’s what the prime is trying to do—or the mid-tier is trying to do—is to limit your exposure so that you don’t have all of these safeguarding and other requirements that kick in.
Lorita Ba
I’m going to try to sneak in one last question. I know we’re going to be overtime, but the last question was: how do we secure CUI and how do we confirm that the person that we provided the CUI to has it under control? It’s a big question.
Jim Goepel
You have to secure it under 800-171, right? You need to make sure that you’re meeting all of the requirements in 800-171. As far as how do you make sure that the person that you give it to can handle it? That, again, goes back to CMMC. It’s all about making sure that that person can actually handle it. Otherwise, you’re either going to have to do an audit of every one of your suppliers that you’re giving CUI to—which gets really expensive and really onerous really quickly—or you’ve got to do some other questionnaire or something else. But then if you just send them a questionnaire, you have to actually analyze the answers that you get.
And are you really qualified to do that? Do you have a team that—oh, there’s all these other issues. CMMC just kind of helps solve that problem, because then you had a third party come in, validate the fact that all the security controls are in place and that they should be able to do a reasonably good job of handling that information.
Bill Wootton
Yeah. And I’ll put a plug in for an eBook that I know is on our website and we do on a regular basis around Five Keys to CMMC Success. We’ll walk you through that whole thought process. So, you know, what do you need to do to build a strategy to put the right technology in place from an operational standpoint and a documentation standpoint?
Jim, building off of kind of what you said from a—you know, looking down through your supply chain—there is a requirement through DFARS 7020 for you to validate the cybersecurity of your supply chain. And those are a lot of the techniques that we’ve seen. We’ll have clients come to us and say, “I just got this questionnaire,” and they range all over the board, but certainly want to have some understanding on where that contract subcontractor is in their journey around CMMC—what are the things that they’re putting in place?
Can you get a screenshot of their SPRS score? I’ve seen things and, you know, “Have you scheduled your CMMC assessment or what’s your timeline on there?” And then we’ve even seen a few folks go into detail around things like, “Tell me what you do for certain things like monitoring or access control.” That, to your point, starts to put you in the place of making a validation of what they’re doing, as opposed to saying, “What is an independent, objective reference that I can use?”
Certainly assessments, SPRS scores—those things are really good validations that allow you to be able to say, “Look, I have some confidence that this group is doing what they should be doing.”
Jim Goepel
I’ve had people ask for some of my clients’ SSPs. And my advice is generally: don’t send it.
And so what I’ve had my clients do is ask the prime that’s asking for the SSP for a copy of their SSP first, so that they can ensure—before they send them anything that’s sensitive—that they can actually handle the sensitive information appropriately.
Bill Wootton
It’s a similar request that we’ve gone through some interesting evolutions to be able to satisfy that requirement without necessarily handing over our security policies.
Jim Goepel
Yep.
Bill Wootton
That’s a great point. Absolutely great point.
Lorita Ba
Well, folks, we have obviously gone over time. Really appreciate the extra time, both from the two of you, Jim and Bill, and also from our audience, because I know so many of you have stuck around to the bitter end here.
We apologize that we were not able to answer all of the questions. We are keeping track of them, so we’ll try to get back to you after the fact with anything that didn’t get answered during the presentation. And as I mentioned earlier, we will be sending out the recording and a copy of Jim’s slides to the emails that you registered.
Jim, thank you so much again for sharing your knowledge and your expertise with us and with our audience, and Bill, for doing a great job of moderating a lot of those questions that we know—we know we flag for our clients. And to our audience, we do have a number of webinars coming up that Bill mentioned.
So, we’ll be sharing those in our follow-up message as well. As we continue to hear more and more about CMMC and we wait eagerly for Title 42 to come out, we’ll send to you guys the information that will help you protect yourselves.
And with that, thanks, everyone. Have a great afternoon, and we’ll talk soon. Thanks, everyone.