By The Defense Compliance Report Editorial Team · Last verified: August 19, 2026 · Independent research. Primary sources: 32 CFR Part 170, Acquisition.gov, the National Archives CUI Registry, the Federal Register, NIST CSRC, The Cyber AB, and ABA materials.
CMMC for law firms serving defense contractors usually does not apply to the firm. The CMMC Program Rule reaches contractors and subcontractors that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on their own systems in the performance of a DoD contract or subcontract. That phrase comes directly from 32 CFR § 170.23(a). Legal fees may be treated as overhead, but accounting treatment is evidence, not the CMMC test. The contract, the work being performed, the information, and the systems decide the answer. And a law firm is not an External Service Provider under § 170.4 merely because it practices law; that definition requires IT or cybersecurity services as well as CUI or Security Protection Data on the provider's assets.
Program status, August 19, 2026: The Department suspended the transition to CMMC Phase II on July 13, 2026. During the suspension, new procurement requirements may designate only Level 1 (Self) or Level 2 (Self), while Level 2 (C3PAO) and Level 3 (DIBCAC) designations are not permitted. Active solicitations containing those higher assessment requirements are to be amended as soon as practicable; existing awards are to be modified before the next option exercise or during the next scheduled administrative modification. Phase I remains active. DFARS 252.204-7012 and NIST SP 800-171 Revision 2 remain in force where the governing instrument requires them; where a live CMMC requirement applies, the applicable SPRS entries and annual affirmations also remain in force. No replacement Phase II date has been announced. (July 13 implementation procedures)
Four things change that answer. Your firm holds its own DoD contract, or another instrument expressly requires a CMMC status. Your engagement is performed under the client's DoD contract. You also provide IT or cybersecurity services to the client. Or a qualifying contractual instrument requires the firm to handle FCI or CUI in performance.
Here is where firms actually land.
| Your situation | Does CMMC reach the firm? | Likely path | What you owe regardless |
|---|---|---|---|
| Door 1 — the firm holds its own DoD contract, or another instrument expressly requires a CMMC status | Yes, directly under that instrument | Status set by the solicitation, clause, or flowdown | Everything in the instrument |
| Door 2 — the engagement is performed under the client's DoD contract and FCI or CUI lands on firm systems | Yes, if the qualifying instrument and information path are present | FCI only → Level 1. CUI → Level 2 (Self) minimum under § 170.23 | Contract terms + professional duties |
| Door 3 — you also provide IT, hosting, or cybersecurity services and CUI or Security Protection Data is on those service assets | Possibly, as an ESP and possibly as a subcontractor | Service and subcontract analysis; relevant services may enter the assessed scope | Service description + Customer Responsibility Matrix + contract terms |
| Door 4 — none of the above | No, not from the client relationship alone | No CMMC status from that relationship alone | Engagement terms + professional rules + the client's approved handling requirements |
Now the part that costs money.
For most law firms that serve defense contractors, CMMC does not apply from that client relationship alone. Which means this page cannot sell you a compliance program, and we're not going to try.
The dangerous part runs in the opposite direction. One uncontrolled workflow — a partner forwarding a marked attachment into ordinary email, an associate saving it to the document management system, a paralegal uploading it to an eDiscovery platform, a records clerk sending it to an expert — can turn a matter you thought was contained into a firm-and-vendor scoping problem. And a "yes" you signed on a client questionnaire six months ago becomes a representation you now have to defend.
So the real question isn't do we need CMMC. It's where is this data actually going, what instrument controls it, and what did we already tell the client.
All three are answerable today. Let's do it.
The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance. We use primary sources for regulatory claims and map a contractor's level, CUI scope, assessment type, and timeline to the right provider category before the contractor buys.
CMMC for law firms: Does it apply when you serve defense contractors?
Usually not. The CMMC Program Rule at 32 CFR Part 170 applies to systems that process, store, or transmit FCI or CUI in the performance of a DoD contract or subcontract. A law firm advising a defense contractor on corporate, employment, litigation, or transactional matters is often outside that performance chain. A client's accounting treatment of legal fees can support the analysis, but it is not a regulatory safe harbor. Client identity does not decide the question. The instrument, the work, the information, and the systems do.
We want to be precise about this, because a lot of what's published on the internet says the opposite.
The three gates
Run every engagement through these in order. A clean "no" can end the CMMC question for that path; it does not erase separate DFARS, contract, privacy, or professional duties.
Gate 1 — the instrument. Is there a solicitation, contract, subcontract, purchase order, task order, engagement addendum, or other contractual instrument that requires the firm to hold a CMMC status or to perform with FCI or CUI? A questionnaire or procurement email can reveal the client's expectation, but it does not substitute for the instrument that creates the duty.
Gate 2 — the information. Will the firm receive FCI, CUI, covered defense information, or ordinary confidential client material? These are not synonyms, and the difference can change the entire scope and spend.
Gate 3 — the systems. Which firm, client, cloud, and vendor assets will actually process, store, transmit, print, secure, or back up that information?
You need the gates to line up. A defense client with no qualifying instrument and no FCI or CUI required for performance does not create a CMMC status for the firm from the relationship alone. The firm's contractual, ethical, privacy, and security duties still remain.
What does not decide the answer
None of these seven settles the question.
- The client is a defense contractor.
- The matter concerns a government contract.
- The document is confidential.
- The document is privileged.
- The firm has a strong general cybersecurity program.
- A client questionnaire mentions CMMC.
- Somebody told the firm that all vendors to defense contractors need Level 2.
What DoD said when someone asked this exact question
In our review of law-firm-facing guidance, we did not locate this comment-and-response chain. It is the reason we're confident about the answer above.
When DoD finalized the DFARS clause implementing CMMC — DFARS Case 2019-D041, published in the Federal Register at 90 FR 43560 on September 10, 2025, effective November 10, 2025 — it reported responses from 97 respondents and answered the comments on the record. We read the full preamble. Four separate exchanges point in the same direction, and one of them is close to your question.
At 90 FR 43564–65, commenters objected that the proposed clause "appears to require the safeguarding of contractor information systems that are not used in performance under a contract but nonetheless might process or transmit FCI or CUI." They asked DoD to delete it as too broad.
DoD's response: "if there is a requirement for CMMC, then it applies to all information systems that process, store, or transmit FCI or CUI in performance of the contract."
That is the issue a law firm's document management system presents. It may hold a defense client's information without being used in performance of the DoD contract. But that conclusion has to come from the actual engagement and instrument; the fact that the system belongs to a law firm does not decide it.
Three more from the same preamble:
| Where | What DoD said |
|---|---|
| 90 FR 43563 | “A subcontractor that does not process, store, or transmit FCI or CUI on its subcontractor information systems during performance of the subcontract would not have a requirement for a CMMC assessment.” |
| 90 FR 43566 | Flowdown “is only required when there is a requirement under the subcontract or other contractual instrument for a CMMC level,” because the instrument will require FCI or CUI processing, storage, or transmission in performance. |
| 90 FR 43568 | “DoD does not require the flowdown of CMMC requirements to subcontractors that do not receive FCI or CUI from the prime contractor.” |
And one more that matters for a firm already living under a client's security addendum. At 90 FR 43569, DoD stated plainly that "the requirements of CMMC, which is an assessment framework, are separate from the cyber incident reporting requirements in the clause at DFARS 252.204-7012."
Read that twice. A firm can have duties under DFARS 252.204-7012 or a client security addendum without the same instrument creating a CMMC status. The clauses and frameworks are separate. Whether that is your position depends on the exact flowdown and the work being performed.
The 60-second document check
Before you spend a dollar, open the engagement letter, the client's outside counsel guidelines, and any security addendum, and search for these strings:
252.204-7012 · 252.204-7019 · 252.204-7020 · 252.240-7997 · 252.204-7021 · 252.204-7025 · 52.204-21 · 52.240-93 · CMMC Level 1 · CMMC Level 2 · FCI · CUI · covered defense information · flow-down · other contractual instrument · SPRS · CMMC UID · 72 hours
If none of those appear anywhere, that supports a Door 4 conclusion, but still confirm what information the client expects to send and whether another incorporated document controls the matter. Document the conclusion in the matter file today, while the facts are fresh.
Check one engagement before you change the whole firm
Use the three gates above, then run the matter through the CMMC readiness checklist. Record the controlling instrument, the information category, the system path, the date, and who approved the conclusion.
→ Open the CMMC readiness checklist
Do not enter client names, matter details, contract text, or CUI into public forms.
Is a law firm an External Service Provider under the CMMC rule?
No — not by practicing law. 32 CFR § 170.4 defines an External Service Provider (ESP) as external people, technology, or facilities used for the provision and management of IT and/or cybersecurity services on behalf of an organization, and CUI or Security Protection Data must be processed, stored, or transmitted on the ESP's assets. Both conditions must be met. A law firm practicing law fails the service prong even when client CUI lands on its file server. That does not resolve whether the firm is a contractor or subcontractor under a separate qualifying instrument.
This matters more than it sounds, because it explains why the questionnaire you received doesn't fit.
Two conditions, not one
Most of the third-party-vendor CMMC guidance on the internet was written for managed service providers. It reduces the ESP test to a single question — does the vendor touch CUI? — and stops there.
The rule doesn't stop there. It has a service prong and a data prong, and they're conjunctive. A managed service provider that runs your network and has CUI on its service assets can meet both. A law firm that reads a drawing to advise on an export question meets only the data condition, not the IT-or-cybersecurity service condition.
That distinction is one of the sharpest lines between this page and generic "CMMC for your vendors" guidance.
When a firm actually does become an ESP
Say it out loud on your own page, because the edge case is real:
- The firm operates and manages a client-facing data room or portal as an IT service, and CUI or Security Protection Data is on those service assets.
- The firm bundles managed IT or cybersecurity services with an outsourced legal operations arrangement.
- The firm's affiliate or captive service company provides IT or security functions to the client and handles CUI or Security Protection Data on its assets.
- The firm provides incident-response technology or security-management services and handles the client's log data, configuration data, vulnerability findings, credentials, or security-tool output as part of that service.
That last one catches people. A firm running a privileged incident-response engagement can end up holding exactly the kind of Security Protection Data the rule contemplates. Holding it does not automatically make the firm an ESP; the firm must also be providing and managing IT or cybersecurity services. It deserves a conversation before the engagement letter is signed rather than after.
A correction: a CMMC "Letter of Attestation" is not a recognized program status
If someone tells your firm to obtain a "Letter of Attestation" from a C3PAO — a CMMC Third-Party Assessment Organization — as third-party validation of the firm's security program, ask what program status the letter is supposed to establish.
We checked. A "Letter of Attestation" is not a CMMC status or certificate recognized by 32 CFR Part 170. The recognized result is a CMMC status in SPRS; for a successful Level 2 certification assessment, the CMMC Assessment Process calls for a Certificate of CMMC Status. A private firm can issue any letter its contract allows, but that letter does not become a CMMC status merely because a C3PAO signed it.
If a vendor is offering one as a substitute for a required CMMC status, ask for the CMMC UID, the status in SPRS, and the section of the governing instrument that accepts the letter.
Which of your practice areas actually carry CUI risk?
Most don't — and practice-area labels never create CUI by themselves. The National Archives CUI Registry sorts categories into Organizational Index Groupings for browsing by subject. NARA says those groupings are not used to control CUI. The legal category, authority, agency instruction, contract, and actual information decide whether something is CUI and how it must be handled.
The 2025 DFARS final-rule preamble added a separate DoD procurement signal: all CUI would require at least a self-assessment, and, in general, Defense-grouping CUI would have pointed to a Level 2 C3PAO assessment. That was not an automatic rule created by the Registry, and the July 13, 2026 suspension now prevents program offices from making new Level 2 C3PAO or Level 3 designations during the suspension. For current new requirements, CUI points to Level 2 (Self); the live instrument still controls the status.
We built this table by reading the complete NARA CUI marking list on August 19, 2026 and mapping categories to legal work that can encounter them. The map tells you where to investigate. It does not designate the information, replace the contract, or assign a CMMC status.
The Practice-Area CUI Map
| Your practice area | Possible CUI category | Registry marking | NARA grouping | What it means now |
|---|---|---|---|---|
| Mishap, aviation safety, or product liability on a fielded military system | Privileged Safety Information | CUI//PSI when the category and authority apply | Defense | Strong investigation signal; during the suspension, a new qualifying CUI requirement may designate Level 2 (Self), not a new C3PAO status |
| Work involving government-controlled drawings, specifications, or technical data | Controlled Technical Information | CUI//SP-CTI | Defense | Confirm CTI authority and contract; Level 2 (Self) is the current minimum for qualifying CUI performance |
| Export-control counsel (ITAR / EAR) | Export Controlled | CUI//SP-EXPT or CUI, depending on authority | Export Control | Confirm the exact authority, markings, and dissemination limits; do not infer status from the practice name |
| Patent prosecution and IP for defense technology | Patent Applications / Inventions / Secrecy Orders | CUI with category markings APP, INVENT, or PSEC | Patent | Patent-grouping data was generally a self-assessment signal in the 2025 preamble; the live instrument controls |
| Bid protests and source-selection challenges | Source Selection | CUI//SP-SSEL or CUI, depending on authority | Procurement and Acquisition | Confirm whether government material retains CUI status and which authority applies |
| Government-contract cost and pricing disputes | General Procurement and Acquisition | CUI//SP-PROCURE or CUI, depending on authority | Procurement and Acquisition | Confirm category and authority; ordinary company pricing data is not automatically CUI |
| Litigation involving government-created privileged material | Legal Privilege | CUI; category marking PRIVILEGE; alternative CUI//PRIVILEGE | Legal | Government-designated or government-created privileged material can be CUI; the firm's own privileged files are not CUI merely because they are privileged |
| Discovery under a protective order | Protective Order | CUI//SP-LPROT or CUI, depending on authority | Legal | A court order alone does not answer the federal CUI question; check the underlying authority and agency direction |
| M&A of a defense contractor | Mergers / General Proprietary Business Information | CUI with MERG, or CUI//SP-PROPIN where specified authority applies | Financial / Proprietary Business Information | Deal confidentiality alone is not CUI; trace the information to a government authority and instruction |
| Labor, employment, and general corporate work | Usually no CUI category merely from the practice area | — | — | Usually no CMMC status from the client relationship alone unless the instrument and information path say otherwise |
Sources: NARA CUI Registry and marking list, verified August 19, 2026; 90 FR 43569; 32 CFR §§ 170.14 and 170.23; July 13, 2026 implementation procedures. The NARA grouping is a research field, not a control. The instrument sets the required CMMC status.
The mishap practice most law-firm guidance misses
Here's the finding that surprised us.
The current Defense Organizational Index Grouping contains five categories: Controlled Technical Information, DoD Critical Infrastructure Security Information, Naval Nuclear Propulsion Information, Unclassified Controlled Nuclear Information–Defense, and Privileged Safety Information.
The NARA CUI marking list and the Privileged Safety Information entry describe information reflecting the deliberative process of a safety investigation or information given under a promise of confidentiality for mishap prevention. Its category marking is PSI; the alternative banner for its Basic authorities is CUI//PSI.
Translate that into practice terms. If your firm defends a manufacturer after a military aircraft or vehicle mishap, and an agency provides material that it identifies under the Privileged Safety Information category, you may be holding Defense-grouping CUI — the same Registry grouping that contains Controlled Technical Information. Before the 2026 suspension, that grouping was the strongest general signal in DoD's published level-determination policy for a C3PAO requirement. It is not an automatic certification rule, and it is not a current authorization for a new C3PAO designation.
In our review, we did not locate a law-firm-facing map that puts that category beside the actual mishap workflow. If your firm has an aviation or products practice serving defense manufacturers, this is the paragraph to send to your practice group leader.
Patent and IP work sits in the Patent grouping — not Defense
Intellectual property firms serving defense clients are among the most anxious readers on this topic, and the anxiety is mostly misdirected.
Patent Applications (APP), Inventions (INVENT), and Secrecy Orders (PSEC) appear in the Patent Organizational Index Grouping and are shown as CUI Basic on the current marking list. In the 2025 DFARS preamble's general policy description, non-Defense-grouping CUI pointed toward self-assessment rather than C3PAO assessment. The July 2026 suspension now makes Level 2 (Self) the only CMMC Level 2 designation available for new requirements during the suspension.
The exception is the obvious one: if the invention disclosure is accompanied by Controlled Technical Information — government-controlled drawings, specifications, or technical data that meet the CTI authority — analyze the CTI separately. The legal task does not erase the information's category.
How to check any marking yourself
We'd rather you verify us than trust us.
- Find the category or marking in the NARA CUI marking list, then open the category detail page and read the safeguarding authority.
- Confirm that the agency, prime, or governing instrument actually identifies the information under that authority. A practice area, confidentiality legend, protective order, or client's preference is not enough by itself.
- Check the live solicitation, clause, CMMC status designation, and the July 2026 suspension procedures. The Registry grouping does not choose the status.
That is still faster than buying a solution for the wrong problem.
Map one matter before you map the firm
Put one live matter through the contract, information, and system gates. Then use the CMMC readiness checklist to record the boundary and the evidence you still need.
→ Open the readiness checklist
Do not submit client names, matter details, contract text, or CUI.
Can your attorneys access CUI without it entering firm systems?
Potentially, yes — and the rule says so explicitly. 32 CFR § 170.19 describes an Out-of-Scope Asset as one that cannot process, store, or transmit CUI and does not provide security protection for CUI Assets, and it gives a specific example: an endpoint hosting a virtual desktop infrastructure (VDI) client configured to prevent any CUI processing, storage, or transmission beyond keyboard, video, and mouse traffic. That is a narrow, configuration-dependent carve-out — not a blanket exemption for "we use a portal."
This is the most important section on this page for most firms, so we're going to be careful with it.
What the rule actually blesses
The KVM-only VDI treatment is unusual. Regulations rarely hand you an architecture. This one does, and it happens to fit legal work better than almost any other kind of work.
Why? Because legal work on technical data is mostly reading work. A manufacturer has to open the drawing in CAD, modify it, and produce against it. A lawyer has to read it, understand it, and write about it. That asymmetry is a genuine advantage, and it's available to your firm in a way it isn't available to your client.
The catch is that the exception is written tightly. "No CUI processing, storage, or transmission beyond keyboard, video, and mouse traffic" is a technical statement about what the endpoint can do, not an aspiration in a policy document.
The thirteen-point configuration test
Before anyone at your firm represents to a client that attorneys will access CUI only in the client's environment, someone technical has to answer all thirteen of these — in writing, with test evidence:
- Are downloads disabled?
- Is clipboard copy and paste disabled in both directions?
- Is printing disabled, or routed only to a controlled device inside the client's environment?
- Is local drive mapping and redirection disabled?
- Is file synchronization to the endpoint disabled?
- Is browser and application caching addressed, including thumbnails and preview generation?
- Are screenshots and local screen recording addressed?
- Can CUI appear in local crash dumps, diagnostic bundles, or support logs?
- Can CUI reach local email, chat, or notes applications?
- Is the endpoint excluded from firm backup ingestion for anything derived from the session?
- Is the identity and authentication path approved by the client?
- Where do attorney notes, drafts, and work product live — and is that location inside or outside the boundary?
- Are the support and incident paths for the session defined and approved?
If the answer to any of those is "we think so," you don't have a defensible out-of-scope position yet. You have a plan.
"We use a portal" is not the same thing
There is real daylight between these, and the words people use in meetings blur all of it:
| What people say | What it actually is | Out-of-scope potential |
|---|---|---|
| “We use the client's portal” | A browser application that may cache, allow download, permit clipboard use, and generate local temporary files | Low without configuration evidence |
| “We use their VDI” | Could be KVM-only, or could allow download, clipboard, printing, and drive mapping | Depends entirely on configuration |
| “They gave us a laptop” | A client-managed endpoint that may sit inside the client's boundary | Strong only when ownership, management, boundary, support, and permitted use are documented |
| “We built a secure folder” | A location on firm infrastructure | Not out of scope — this is a boundary, not an exclusion |
| “We have an enclave” | A firm-operated environment separated from the rest of the firm | In scope by design; the point is to keep the rest of the firm out |
The word "portal" carries no regulatory meaning. Test the configuration.
The operational problem containment plans miss
Here's where most containment strategies break, and it isn't technical.
Attorneys have to take notes. Draft advice. Circulate revisions. Prepare filings. Brief the client. Work with experts. Preserve the matter record. Respond to a document request three years later.
A no-download session that forces an associate to retype the substance into an ordinary Word document on a firm laptop has not contained anything. It has just moved the CUI into a less controlled place and removed the marking on the way. That is worse than the original problem, and it happens constantly.
Decide where each of those activities occurs before the first session, not after. That single decision is what separates a real client-controlled-access architecture from a policy statement.
Which firm systems enter scope when CUI crosses the boundary?
More than the folder the document is in. Under 32 CFR § 170.19, CUI Assets are assets that process, store, or transmit CUI, and Security Protection Assets are assets that provide security functions for those assets even when they never hold the matter documents themselves. A law firm therefore needs a data-flow and a security-flow inventory, not a list of repositories.
This is the matrix we'd want on the wall of the conference room where this gets decided.
The Law-Firm CUI Exposure Matrix
| System or workflow | The question to answer | Likely treatment if CUI is present | Evidence to keep |
|---|---|---|---|
| Attorney mailbox and email gateway | Can a message body or attachment contain CUI? | CUI Asset — or excluded by an enforced no-CUI architecture | Mail-flow rules, approved-use policy, test results |
| Shared mailboxes, archives, and journaling | Do secondary copies land in archives or journals? | CUI Asset when those systems store the CUI | Journaling configuration, archive scope |
| Document management system | Does CUI or derived work product enter the repository? | CUI Asset | Workspace configuration, permissions, retention rules |
| Local document folders and temporary files | Do Word, PDF, OCR, preview, or indexing tools write local copies? | CUI Asset when the endpoint processes or stores the CUI | Endpoint configuration, temporary-file handling |
| eDiscovery or review platform | Is CUI uploaded, indexed, exported, or produced? | The platform is in the data path; analyze the assets plus CSP/ESP and contract requirements | Exact offering, contract, data locations, subprocessors |
| Legal research and AI drafting tools | Is CUI pasted into a prompt or uploaded for analysis? | The tool and service enter the data path; an unapproved upload may also create a disclosure problem | Tool inventory, approved-use rules, retention and training terms, logs |
| Attorney laptops and home workstations | Can CUI be opened, cached, copied, or saved locally? | CUI Asset — or Out-of-Scope only under the § 170.19 VDI conditions | Configuration baseline and test evidence |
| Mobile devices | Can CUI be opened, cached, photographed, or forwarded? | CUI Asset, or a prohibited endpoint | MDM policy, access rules, test evidence |
| Printers and multifunction devices | Can CUI be printed, scanned, cached on disk, or emailed from the panel? | Device and physical handling path may enter scope | Device configuration, spool handling, physical controls |
| Backup and disaster recovery | Can it store or restore a CUI-bearing system or file? | CUI Asset if it stores CUI; otherwise it may be a Security Protection Asset | Backup scope, encryption, restore test |
| Identity provider | Does it control access to CUI Assets? | Security Protection Asset | Configuration, conditional-access policy |
| EDR, SIEM, and SOC tooling | Does it collect CUI, or only Security Protection Data? | CUI Asset or Security Protection Asset; the provider may also be an ESP | Data fields collected, logging configuration, service description |
| Help desk, ticketing, and remote management | Can a ticket attachment, support log, or remote session expose CUI? | CUI Asset or Security Protection Asset; provider role requires separate analysis | Ticket policy, session-recording policy, access model |
| Paper files and conference-room displays | Is CUI printed, filed, photographed, or displayed physically? | Physical CUI handling path; associated devices and facilities require analysis | Marking, access, storage, transport, destruction records |
The secondary-copy problem
Many rows above generate copies you didn't intend. Search indexes. Document previews. Version histories. Mailbox archives. Mobile sync. Replication to a second data center. The backup that runs at 2 a.m. whether or not you've decided what to do yet.
This is the practical reason to stop uncontrolled intake before designing a solution. Every day a marked document sits in ordinary email is another day of copies you'll have to find, account for, and possibly explain to a client.
If you take one operational instruction from this page, take this one: the first move is always to stop the spread, not to build the enclave.
How do eDiscovery, cloud, MSP, and expert vendors change the answer?
All four can change the answer, but through different doors. A cloud service that stores covered defense information may trigger the cloud-security and incident obligations in DFARS 252.204-7012. An IT or cybersecurity provider that has CUI or Security Protection Data on its service assets can meet the ESP definition in 32 CFR § 170.4 and enter the assessed scope. Expert witnesses, court reporters, translators, investigators, and local counsel are not ESPs merely by providing professional services — but they can still become subcontractors or recipients under another contractual instrument when their performance requires FCI or CUI.
The vendor conversation is where law firms lose control of scope fastest, because legal work runs on other people's platforms.
Cloud Service Provider versus External Service Provider
These get used interchangeably and they aren't the same:
- A Cloud Service Provider (CSP) delivers a cloud service. When covered defense information is stored, processed, or transmitted in the cloud under DFARS 252.204-7012, the clause requires the provider to meet security requirements equivalent to the FedRAMP Moderate baseline, plus the clause's cyber-incident, malicious-software, evidence-preservation, forensic-access, and damage-assessment obligations. The clause does not itself require a FedRAMP authorization.
- An External Service Provider (ESP) provides and manages IT or cybersecurity people, technology, or facilities and has CUI or Security Protection Data on its assets. A non-CSP ESP's relevant services can be assessed inside the assessed organization's scope under Part 170.
- A professional-services recipient can be outside the ESP definition and still be a subcontractor or party to another contractual instrument that must carry CMMC or DFARS terms when performance requires FCI or CUI.
- A provider that handles neither CUI nor Security Protection Data does not meet the CMMC ESP definition. It may still matter contractually for other reasons.
The ten questions for an eDiscovery or review platform
Ask these before the first upload, not after the production:
- Which exact product and environment will hold the data — not which parent company?
- Can that specific offering support the required CUI and DFARS handling?
- Where do data, backups, logs, and support personnel sit geographically?
- Who handles an incident, on what clock, and who preserves forensic evidence?
- Which subprocessors touch the environment?
- Can data be exported into ordinary firm systems, and by whom?
- What happens to review workstations and local exports?
- What happens at matter closeout?
- Can the provider produce a Customer Responsibility Matrix showing which requirements it supports and which stay with the firm?
- Has the client approved this platform in writing?
That last one can prevent a scope dispute. Written client approval does not transfer the firm's obligations or erase an unapproved period; it can establish the approved path before the data moves and going forward.
Vendor verification, by category
| Vendor type | What to verify | Common mistake |
|---|---|---|
| Cloud / eDiscovery platform | Exact offering, FedRAMP or equivalency evidence where required, incident terms, data flow, support path, subprocessors | Assuming a company-wide marketing claim covers the specific product you bought |
| MSP, MSSP, or SOC | Whether it handles CUI or Security Protection Data, its service description, Customer Responsibility Matrix, and remote-access model | Believing the provider's own CMMC status transfers to the firm — it does not |
| CUI enclave provider | Whether the full attorney workflow fits inside it: drafting, exports, print, notes, collaboration, preservation, closeout | Buying storage before mapping how lawyers produce work product |
| GRC platform | Evidence workflow, classification handling, access, export, ownership | Treating documentation software as if it were the security environment |
| Expert, court reporter, translator, investigator, or local counsel | Whether the recipient is performing under a qualifying instrument; required status or flowdown; approved access; minimum necessary data; return and destruction | Calling the recipient an ESP, or assuming that “not an ESP” means “not a CMMC or DFARS issue” |
Your expert witness is not an External Service Provider
We're going to be blunt about this because getting it backwards creates a real scoping problem.
An expert witness who receives CUI is not an ESP under § 170.4 merely because the expert receives it. Neither is a court reporter, a translator, an investigator, a jury consultant, or local counsel merely because of that professional role. None is providing IT or cybersecurity services on those facts. Forcing the ESP label onto them produces a security questionnaire that does not fit the role and a delay the rule does not justify.
But not an ESP does not mean not a subcontractor. If the recipient will process, store, or transmit FCI or CUI in performance of a subcontract or other qualifying instrument, 32 CFR § 170.23 and DFARS 252.204-7021(f) may require the correct flowdown and current status before award. If those triggers do not exist, the recipient still needs a written handling path: what is received, how it is received, what may be done with it, incident escalation, and return or destruction. Solve both questions in the retention agreement.
What to send back when a client asks for your CMMC level
Don't answer the question as if “CMMC level,” “CMMC status,” and every SPRS assessment record were the same artifact. They are not. Legacy instruments may still use DFARS 252.204-7019 and -7020 for the NIST SP 800-171 DoD Assessment path. Under DoD Class Deviation 2026-O0025, Revision 2, the current Part 240 path uses DFARS 252.240-7997 for government Medium or High assessments and does not carry forward the standalone 7019 Basic-score gate for covered new solicitations. Separately, DFARS 252.204-7021 and -7025 address CMMC status, CMMC UID, self-assessment results, and annual affirmations in SPRS. A law firm may have none, one, or multiple records depending on the live instruments and systems. Answer what exists, what does not, and the question underneath it: can you send us this information through the proposed path without violating the governing contract or your own System Security Plan?
The question that does most of the work
Of all the language in this article, this is the sentence we'd put first in the reply.
DFARS 252.204-7012(m)(1) requires the contractor to include the clause in subcontracts "or similar contractual instruments" where performance will involve covered defense information — and then adds: "The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer."
So write back:
"Have you determined, under DFARS 252.204-7012(m)(1), that the information you intend to send us retains its identity as covered defense information? If so, please provide the CUI category and marking."
That single question puts the first contractual determination where DFARS 252.204-7012(m)(1) puts it — on the contractor deciding what a subcontractor needs for performance. It does not relieve the firm from reading its own instrument or handling what it receives correctly.
The six questions to send back
- Which contract, subcontract, purchase order, or client requirement creates this obligation, and which DFARS or FAR provisions apply?
- Have you made the 252.204-7012(m)(1) determination, and what CUI category and marking apply?
- Is our engagement being performed under the DoD contract, and what facts support that conclusion?
- What CMMC status, if any, does the instrument require of us?
- Will the information sit on our systems, or may we work inside your environment?
- Who has authority to approve an alternative handling arrangement?
Four replies, keyed to your door
If you're in Door 4 (no qualifying instrument, no FCI or CUI):
"We've reviewed the instruments and information path for this matter. Based on the current scope, our work is not being performed under your DoD contract, and no FCI or CUI has been identified as required for transfer to our systems. On that basis, 32 CFR § 170.23(a) does not create a CMMC status requirement for our systems from this engagement alone. We remain bound by our professional duties and the security terms in our engagement letter. If another incorporated instrument, your contracting officer, or your System Security Plan requires a different arrangement, please identify it before any controlled information is transferred."
If you may be in Door 2 (performance is possible):
"Some of the work you've described may constitute performance under your DoD contract. Before we proceed, we need to confirm which instrument applies, what CMMC status it requires, and what CUI categories are involved, so that we can scope our environment appropriately rather than making a representation we can't support."
If you'd prefer to keep the data in their environment:
"Rather than transferring the material to our systems, we'd propose that our attorneys access it inside your controlled environment. We'll need to confirm the configuration — downloads, clipboard, printing, local storage, and where our notes and drafts will live — and to agree in writing on how we produce and preserve work product for this matter."
If unmarked or ambiguous material has already arrived:
"We've received material that may be controlled. We have restricted access to it pending your confirmation of its CUI category, the governing authority, the applicable contract clause, and your approved transfer method. We have not distributed it further. Please advise on the approved handling path."
Representations never to sign
We've read enough of these to know which ones come back to hurt.
- "The firm is CMMC certified" — when you aren't.
- "All firm systems comply with NIST SP 800-171."
- "Our vendor's certification covers us."
- "We use [named cloud product], so we're compliant."
- "The client portal means we're out of scope" — without configuration evidence.
- "Privilege overrides incident reporting."
- "There is no CUI unless it's marked."
Every one of those is a statement someone will read back to you later. ABA Model Rule 4.1 addresses false statements of material fact to third persons; the rule adopted in your jurisdiction controls. Separate from ethics rules, a false or misleading questionnaire answer can create contractual and litigation risk. If you wouldn't sign it in a certification to the government, don't sign it in a vendor portal.
Save the response before the next questionnaire arrives
Copy the six questions and the reply that matches your door into the firm's approved template library. Add matter-specific language only after contracts, security, and the responsible lawyer agree on the facts.
→ Use the CMMC readiness checklist to document the answer
Educational language only. Have the firm's own counsel review before sending.
What if CUI already reached your email, DMS, or an expert?
Treat it as a scoping and incident-triage event, not automatically as a reportable breach. Stop further movement, preserve the facts before you clean anything up, identify every destination and copy, determine the controlling contract and CUI category, and then decide whether the material can be removed from unauthorized systems or whether your boundary has to change. Deleting the visible file does not remove backups, archives, search indexes, caches, or synchronized copies.
This is the section most firms need, and few guides make it operational.
If it reached ordinary email. Stop forwarding immediately. Identify every recipient, device, mailbox copy, archive, journal entry, mobile sync, and backup. Preserve before you purge — reflexive cleanup destroys the evidence you'll need to describe what happened. Then establish an approved replacement channel before the next document arrives.
If it reached the document management system. Map the workspace, the search index, the preview cache, prior versions, replicas, and the retention schedule. Restrict access. Then answer the harder question: does the derived work product — the memo an associate wrote from the drawing — itself contain or reveal the controlled information? Often it does.
If it reached eDiscovery. Pause additional uploads. Identify the exact environment and its subprocessors. Confirm the handling and incident terms actually in your contract. Map exports, review workstations, productions, and anything already sent downstream to experts.
If it reached an expert or vendor. Determine precisely what was transferred and when. Confirm the retention agreement terms and whether the client authorized the disclosure. Restrict further distribution, define an approved access path going forward, and set return-or-destruction terms.
Four things not to do. Don't erase evidence reflexively. Don't tell the client "nothing happened" before you've mapped the facts and checked the governing clauses. Don't move the material to another unapproved platform for safekeeping. And don't send it through any web form — including ours. If DFARS 252.204-7012 may apply, engage the people who can preserve the 72-hour reporting option before the clock is spent.
Does attorney-client privilege replace CUI handling rules?
No — and the relationship is more interesting than most guidance suggests. Privilege, work-product protection, professional confidentiality, CUI designation, and contractual cybersecurity duties are separate layers that can overlap. The CUI Registry contains a Legal Privilege category built out of the Federal Rules themselves. But your own privileged files do not become CUI merely by being privileged. CUI status must trace to a CUI category and authority and to the government's or authorized holder's designation and instructions; contractors may create or mark CUI on behalf of the Government when authorized or required to do so.
We fetched the Legal Privilege category page at archives.gov on August 19, 2026. It was last reviewed July 29, 2025. Here's what's on it.
CUI//PRIVILEGE is a real category, and its authorities are the Federal Rules
| Field | Value |
|---|---|
| Banner marking for the listed Basic authorities | CUI |
| Category marking | PRIVILEGE |
| Alternative banner shown by NARA | CUI//PRIVILEGE |
| Basic or Specified | All twelve listed authorities are Basic |
| NARA grouping | Legal |
The category description draws on 15 U.S.C. § 78x(f)(4) and Federal Rule of Evidence 502(g): work-product privilege, attorney-client privilege, governmental privilege, or other privilege recognized under federal, state, or foreign law.
The twelve listed safeguarding authorities include Federal Rule of Civil Procedure 26(b)(3) and 26(b)(5), Federal Rules of Evidence 501 and 502(g), Federal Rule of Criminal Procedure 16(a)(2), 26 U.S.C. § 7525, 10 CFR 2.347(b), 16 CFR 1025.31(c)(3), 28 CFR 16.23, 76 FR 34986, and three additional 18 CFR authorities. The sanctions column points to FRCP 37. (NARA Legal Privilege category)
Read that list again. The federal government took the privilege doctrine, wrote it into an information-handling category, and cited the Federal Rules as the safeguarding authority. If you've spent a career litigating Rule 26(b)(3), it's a strange thing to find in a records registry.
The two dissemination controls, and why they matter
The Registry note on that page is short and load-bearing:
"There are two limited dissemination control markings that can be used with this category; Attorney Work Product (AWP), Attorney Client Privilege (AC). These limited dissemination control markings may be used to help identify the type of privilege in the document and limit the dissemination of that information so as to preserve that privilege. These limited dissemination control markings (AWP, AC) may only be used on information protected under the CUI 'Legal Privilege' category."
AC and AWP exist for one purpose: to stop the information from traveling far enough to break the privilege.
The collision — and this is our analysis, not a rule
Here is the tension, stated plainly and labeled as editorial judgment.
A CMMC assessment works by giving assessors access to evidence. The AC and AWP controls exist to restrict dissemination. No DoD, NARA, or Cyber AB guidance we could find addresses how those two things interact. We looked. It isn't there.
Until it is, our default architecture — editorial judgment derived from the verified facts above, not a published rule — is to separate the client's CUI from the firm's own privileged work product wherever the legal workflow permits it. A segregated enclave can hold the client's controlled source material while privileged notes and advice stay in a separately governed path, but the design must still account for any work product that reproduces or reveals the underlying CUI. Do not put privileged material into an assessment boundary casually. Once the boundaries overlap, assessor access and privilege protection become an unresolved design problem with the client's interests at stake.
Two things that are both true
Privileged does not mean CUI. A private client's privileged email is not CUI merely because it is privileged. A government-created record, or a record created for or on behalf of the Government, may fall in the Legal Privilege category when the authority and designation apply. Derived legal work can preserve or reveal underlying CUI even when it's separately privileged. Don't guess CUI status from privilege.
CUI does not eliminate privilege. Keep access need-to-know. Limit distribution. Involve privilege counsel in incident response. Read reporting obligations alongside privilege and confidentiality rather than treating one as overriding the other. And coordinate with the client before an incident, not during one.
Anyone who tells you privilege "wins" over CMMC, or that a required incident report automatically waives privilege, is overstating in both directions.
What the ABA rules require whether or not CMMC applies
Your obligation to protect client information doesn't depend on a DFARS clause. ABA Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation. Comment 8 to Rule 1.1 ties competence to understanding the benefits and risks of technology. Rules 5.1 and 5.3 extend supervision to other lawyers, nonlawyer staff, and third-party electronic-information vendors. The Model Rules are models — your jurisdiction's adopted rules govern.
Two ABA formal opinions turn those into practical duties. Formal Opinion 477R (2017) addresses securing electronic communication of protected client information and uses a fact-specific, risk-based analysis rather than one universal method. Formal Opinion 483 (2018) addresses obligations after a data breach, including stopping the intrusion, restoring systems, determining what occurred, and notifying affected current clients when the rules require it.
Put the two rulebooks side by side and the practical problem becomes obvious.
| Question | CMMC / DFARS | ABA Model Rules and opinions |
|---|---|---|
| What triggers it | A solicitation, contract, subcontract, or other instrument and an FCI/CUI performance path | Taking on a client matter and the jurisdiction's adopted duties |
| Who administers or enforces | Contracting authorities administer the clauses; DoD can use contract remedies; DOJ may use the False Claims Act for knowing, material cyber misrepresentations | State disciplinary authorities; civil litigants may raise malpractice or contract claims |
| The standard | Level 2 uses NIST SP 800-171 Rev. 2 — 110 requirements across 14 families | “Reasonable efforts” under Rule 1.6(c), informed by the jurisdiction's adopted comments and law |
| Vendor duty | Flow the applicable clause/status when the instrument and information trigger it; scope CSPs, ESPs, and subcontractors correctly | Rules 5.1 and 5.3 address supervision of lawyers, staff, and nonlawyer assistance |
| Competence and attestation | An Affirming Official makes the required annual CMMC affirmation in SPRS | Rule 1.1 comment 8 addresses keeping abreast of technology's benefits and risks |
| Electronic transmission | Implement the applicable NIST and contract requirements, including the controls governing transmission and cryptographic protection | Formal Opinion 477R uses a matter-specific analysis; no one product or method is automatically sufficient |
| After a covered cyber incident | Report to DoD within 72 hours of discovery when DFARS 252.204-7012 applies; coordinate with the prime or client as the instrument requires | Notify affected current clients when required under the adopted rules and Formal Opinion 483's analysis |
| Evidence preservation | Preserve relevant images and monitoring/packet-capture data for at least 90 days from submission of the cyber-incident report under DFARS 252.204-7012 | Preserve what the ethical investigation, insurer, litigation hold, and applicable law require |
One incident. Two clocks. Two audiences. If DFARS 252.204-7012 applies directly to the firm, the firm has the DoD reporting duty; if the firm is working under a client's incident terms, coordination with that client or prime may also be required. Separately, the firm may owe affected clients notice under the governing professional rules. If you haven't decided in advance who calls whom, in what order, with what content, you'll be deciding it at 2 a.m. with a forensics firm on hold.
That's a tabletop exercise, and it takes an afternoon. Do it before you need it.
Which CMMC level would a law firm need in 2026?
The instrument sets the required status — a checklist doesn't. Under 32 CFR § 170.23, a subcontractor handling only FCI in performance requires Level 1 (Self). A subcontractor handling CUI in performance requires Level 2 (Self) at minimum. A higher status follows only when the associated prime contract and flowed-down instrument require it.
The codified phased schedule originally made Phase 1 run from November 10, 2025 through November 9, 2026. The July 13, 2026 implementation procedures suspended the transition to Phase II and currently allow only Level 1 (Self) and Level 2 (Self) designations in new requirement documents.
| Your path | Baseline | Assessment or status now |
|---|---|---|
| FCI with a Level 1 requirement | 15 safeguarding requirements from FAR 52.204-21 | Annual Level 1 self-assessment and annual affirmation |
| CUI with a Level 2 (Self) requirement | 110 requirements from NIST SP 800-171 Rev. 2 across 14 families | Level 2 self-assessment every three years, annual affirmation, results and status data in SPRS |
| Existing award still containing Level 2 (C3PAO) or Level 3 language | Contract-specific until modified | July 13 procedures direct removal before the next option or at the next scheduled administrative modification; confirm the actual modification |
| Active solicitation containing Level 2 (C3PAO) or Level 3 | The higher designation is inconsistent with the suspension procedures | Contracting activity is directed to amend the solicitation as soon as practicable; obtain the amendment |
| No qualifying instrument and no FCI or CUI performance path | No CMMC status from the client relationship alone | Document the analysis; maintain professional and contractual duties |
Which DFARS and FAR clause numbers should you search in 2026?
Search both generations. The codified clauses still appear on Acquisition.gov and in legacy instruments, while DoD Class Deviation 2026-O0025, Revision 2, supplies the current Part 240 path for covered new DoD solicitations. The live instrument controls.
| Purpose | Legacy or codified reference you may still see | Current DoD deviation path for covered new solicitations |
|---|---|---|
| FCI basic safeguarding | FAR 52.204-21 | FAR 52.240-93 under the RFO deviation; the 15-safeguard baseline remains |
| Standalone NIST SP 800-171 DoD Assessment notice / Basic score gate | DFARS 252.204-7019 | Not prescribed in the Part 240 deviation path; a CMMC Level 2 (Self) result and affirmation still arise through Part 170 and DFARS 252.204-7021 when required |
| Government Medium or High NIST SP 800-171 assessment | DFARS 252.204-7020 | DFARS 252.240-7997 |
| Covered defense information safeguarding and 72-hour reporting | DFARS 252.204-7012 | Unchanged |
| CMMC status, CMMC UID, affirmation, and flowdown | DFARS 252.204-7021 and solicitation provision 252.204-7025 | Unchanged by the Part 240 deviation |
The practical rule is simple: do not tell a client that 7019 or 7020 can never matter, and do not treat them as the current prescription for every new DoD solicitation. Match the clause number to the actual solicitation, award, modification, or flowdown. (DoD RFO class-deviation index; FAR Part 40 deviation guide; FAR Part 52 deviation guide)
NIST SP 800-171 Revision 3 does not control CMMC Level 2 today
NIST published SP 800-171 Revision 3, but 32 CFR Part 170 still incorporates and defines CMMC Level 2 through NIST SP 800-171 Revision 2, including the January 28, 2021 updates. Do not substitute Rev. 3 into a CMMC assessment or claim it is the CMMC-controlling set unless DoD amends the rule or the governing instrument lawfully changes the requirement.
The same version discipline applies at Level 3. Part 170 selects 24 requirements from the February 2021 edition of NIST SP 800-172. NIST has since published SP 800-172 Revision 3, but that newer publication is not the CMMC-controlling Level 3 set unless the rule changes.
NIST has withdrawn the Rev. 2 catalog entry in favor of Rev. 3 and withdrew the February 2021 SP 800-172 in favor of SP 800-172 Revision 3 in May 2026. Those NIST catalog actions do not rewrite the editions incorporated by 32 CFR Part 170.
For the full status hierarchy, see CMMC Level 1 vs. Level 2 vs. Level 3. For a side-by-side version analysis, see NIST SP 800-171 Rev. 2 vs. Rev. 3 and NIST SP 800-171 vs. SP 800-172.
Why “CUI means C3PAO” is wrong right now
It is a recurring statement in law-firm-facing CMMC content, and it is wrong on two levels.
First, even in the codified program, CUI points to Level 2 and Level 2 has both self-assessment and C3PAO statuses. Section 170.23 makes Level 2 (Self) the minimum for a subcontractor processing CUI in performance; the prime contract and flowed-down instrument determine whether a higher Level 2 status is required.
Second, Phase II is suspended. During the suspension, program managers and requiring activities may not make new Level 2 (C3PAO) or Level 3 designations. Active solicitations with those designations are to be amended, and existing awards are to be modified on the schedule stated in the July 13 procedures.
If a client's supply-chain team is demanding third-party certification from your firm, ask which live instrument creates the requirement, whether it has been modified, and whether the demand is a contractual flowdown or the client's own commercial policy. A customer can set commercial conditions, but it should not describe an internal preference as a current DoD procurement designation.
One naming note. July 2026 memoranda and releases use Department of War, while the current codified text at 32 CFR Part 170 and the DFARS still uses Department of Defense. This page uses the name shown by the source being discussed. The terminology does not change the underlying clause text.
What must you do after a suspected incident involving defense CUI?
Run the tracks in parallel, not in sequence. Where DFARS 252.204-7012 applies, a covered cyber incident requires reporting to DoD within 72 hours of discovery and preservation of relevant system images and monitoring or packet-capture data for at least 90 days from submission of the report. A law firm may also have client-notification duties under the rules adopted in its jurisdiction and the facts, with ABA Formal Opinion 483 providing a model analysis, plus privilege, insurance-notice, and potentially state breach-notification issues — and none of those tracks should wait for the others.
First four hours — our operational sequence, not a separate regulatory deadline. Activate incident response. Get designated legal and forensic leadership involved. Contain without destroying evidence. Identify which defense matters are potentially affected. Locate the governing contract and the client's reporting terms. Write down the discovery time — the 72-hour clock runs from discovery, not from investigation.
First 24 hours — our operational sequence. Determine affected systems. Identify whether FCI, CUI, or covered defense information is involved. Identify the client, prime, or next-higher-tier contacts. Preserve logs, images, and relevant communications. Build the known-facts chronology. Decide how privilege and confidentiality are being handled in every workstream.
Before 72 hours, where the clause applies. Submit the required facts available by the deadline through the DoD reporting process, coordinate the incident report number with the prime or next-higher-tier as the instrument requires, and document what remains unknown for follow-up. Do not spend the reporting window trying to reach certainty the clause does not give you time to reach. Keep unnecessary privileged narrative out of the report while still providing the required information.
For at least 90 days from report submission. Preserve affected system images and relevant monitoring or packet-capture data. Maintain chain of custody. Track government and client requests. Document remediation and any resulting scope change.
A common failure described in this space isn't technical. It's an organization that spent the first 36 hours deciding who was allowed to make decisions. Make sure the reporting account and required medium-assurance credential exist before the incident, not during it.
Is CMMC Phase II suspended in 2026?
Yes. Phase II is suspended, and the underlying obligations are not. On July 13, 2026, the Department issued a public suspension announcement and implementation procedures stopping the transition to CMMC Phase II, which had been scheduled for November 10, 2026. Phase I self-assessment requirements remain. The CIO also created a reform task force and directed delivery of a report to the CIO within 60 days; the source does not promise a public report or a replacement Phase II date.
What changed:
- New procurement request and requirement documents may designate only Level 1 (Self) or Level 2 (Self).
- Program managers and requiring activities may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) during the suspension.
- Active solicitations containing those higher designations are to be amended as soon as practicable.
- Existing contracts or agreements already containing those higher requirements are to be modified before the next option exercise or during the next scheduled administrative modification.
- Further guidance was promised after the CIO's 60-day review, but no replacement Phase II date had been announced as of August 19, 2026.
What did not change:
- DFARS 252.204-7012 safeguarding, cloud, 72-hour reporting, and evidence-preservation duties where that clause applies
- Legacy DFARS 252.204-7019 and -7020 duties where those clauses remain in a live instrument, and the current DFARS Part 240 deviation / 252.240-7997 government-assessment path where the deviation applies
- NIST SP 800-171 Revision 2 as the CMMC Level 2 requirement set in 32 CFR Part 170
- Level 1 and Level 2 self-assessment pathways, applicable SPRS entries, and annual CMMC affirmations
- Security terms already in an engagement letter, outside-counsel guidelines, subcontract, or other live instrument until they are changed
The government-wide FAR CUI rule remains proposed. FAR Case 2026-001, published June 23, 2026 after the January 2025 proposal, reworked the CUI clauses and proposed a Part 40 / Standard Form XXX mechanism with a 72-hour incident-reporting clock. Comments closed July 23, 2026. It is not a final generally applicable FAR clause as of August 19, 2026. If your firm holds civilian-agency legal-services contracts, watch that rulemaking — but do not treat the proposed clause as current law.
And one thing that emphatically did not pause: the Department of Justice Civil Cyber-Fraud Initiative, which uses the False Claims Act in matters involving knowing cybersecurity noncompliance or misrepresentation. Nothing about the Phase II suspension makes an inaccurate security representation safer to sign.
Until your client's contract or other instrument is actually modified, the text on it still matters. Confirm the status of specific matters in writing rather than assuming a headline rewrote an agreement.
What law firm leadership should do in the next 30 days
Start with discovery and architecture, not procurement. You cannot get an accurate quote from any provider until you know which matters involve FCI or CUI, where that information would travel, and which access model you intend to use. Buying first risks buying the wrong scope.
Week 1 — find the matters. Pull your active defense-contractor clients and the firm's own federal awards, if any. Flag government contracts, investigations, disputes, IP, export control, procurement, mishap, and cybersecurity matters. Search engagement terms for the clause strings listed earlier. Identify any known marked CUI already in your possession.
Week 2 — map the workflows. For each flagged matter: intake, attorney access, drafting, email, DMS, research, eDiscovery, experts, printing, backup, incident response, closeout. Where does the information go, and who else can reach it?
Week 3 — choose an architecture per matter. Four options:
- No-CUI firm environment. Nothing controlled enters firm systems. Document the exclusion in intake.
- Client-controlled access. Attorneys work inside the client's environment under the § 170.19 conditions, with the thirteen-point test answered in writing and the work-product path resolved.
- Matter-specific CUI enclave. A limited team handles CUI in a separated firm environment with the complete workflow inside it.
- Defined in-scope firm environment. Named systems are treated as in scope and assessed accordingly.
Week 4 — document and test. Client confirmation in writing. Engagement terms updated. Access configuration tested, not assumed. Vendor evidence collected. Training for the actual matter team. Escalation path published. DoD reporting access and credentials checked where DFARS 252.204-7012 may apply. Incident tabletop run. Offboarding path tested. Record the result in the CMMC readiness checklist.
If you're a boutique: prioritize options 1 and 2. Do not transform every firm system because one matter might involve CUI.
If you're a multi-office firm: the hard problems are global identity, the shared DMS, endpoint standards, backup, follow-the-sun support, and cross-office matter staffing. Those are the things that quietly put every office in scope.
If you're eDiscovery-heavy: the review platform, exports, productions, and downstream experts are your architecture, not a footnote to it.
Which CMMC provider category should a law firm hire first?
It depends on what's still unresolved — and for many firms the answer is "none yet." Contract applicability questions belong with qualified federal-contracts counsel. Scoping and readiness can belong with an experienced CMMC readiness advisor, including a Registered Provider Organization (RPO) or Registered Practitioner (RP). Those are voluntary Cyber AB ecosystem designations, not government licenses and not guarantees of quality. Operational security belongs with an MSP or MSSP that can prove its role in the boundary. A C3PAO is an assessor, not a first stop for architecture or remediation.
We are not naming providers on this page, and we want to explain why rather than just doing it.
A named-provider recommendation is only useful once you know you have a problem. Most readers arriving at this page do not yet know that. Recommending a vendor before establishing whether you need one would undercut the only thing that makes this article worth reading. The CMMC Path Framework routes to a category, not a named provider, and it is not a score, ranking, certification promise, or substitute for legal or compliance advice.
For the broader routing sequence, see Who to Hire First: Consultant, MSP, MSSP, RPO, or C3PAO.
| What's unresolved | First category to engage | Deliverable to require | Red flag |
|---|---|---|---|
| Does this agreement actually flow CMMC or DFARS duties to us? | Qualified federal-contracts attorney | Written contract, performance, and flowdown analysis | Gives a product answer without reading the instrument |
| Which people, systems, facilities, and vendors are in scope? | Experienced readiness consultant; RPO or RP may be one option | Written scope memo, data-flow diagram, asset categorization, assumptions | Opens with the 110 requirements before mapping where data goes |
| How should the environment be built and run? | CMMC-focused MSP or MSSP | Architecture, service description, Customer Responsibility Matrix, operations plan | Claims its own CMMC status transfers to the firm |
| Can this matter be isolated? | CUI enclave or secure-collaboration category, plus independent readiness review | End-to-end attorney workflow including drafting, export, print, notes, preservation, and closeout | Demonstrates storage but not how lawyers actually produce work |
| How do we organize evidence? | GRC platform, as a supporting layer | Evidence map, System Security Plan and POA&M workflow, ownership | Treats software as proof that requirements are implemented |
| Do we need a formal Level 2 certification assessment? | C3PAO only when a live requirement makes that status relevant | Independence and member-level conflict confirmation, defined scope, assessment contract, no outcome guarantee | Promises a certificate, bundles the result into compensation, or cannot document conflict screening |
That last red flag is not a matter of taste. 32 CFR § 170.8(b)(17) requires the Cyber AB's code to prohibit CMMC Ecosystem members from participating in a Level 2 certification assessment when they previously served as a consultant preparing that organization for any CMMC assessment within three years. The prohibition is member-specific; do not turn it into a broader claim the rule does not make about every service line in a corporate family. Require the C3PAO to disclose and manage organizational and individual conflicts. The CMMC Assessment Process v2.0 also prohibits a C3PAO from offering guarantees or promises about the assessment result or using compensation contingent on issuance of a Certificate of CMMC Status.
Get matched with the provider category that fits the matter
Tell us the required level, whether FCI or CUI is involved, your proposed access model, and your timeline. We'll map it to source-checked provider categories — the category first, so you can compare scoped quotes against a defined boundary instead of a guess.
→ Compare CMMC provider categories
Do not submit CUI, drawings, contract documents, client names, or matter details.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
Can a law firm sell CMMC services, or become a C3PAO?
A law firm can provide legal and readiness services. Becoming a C3PAO is a different proposition entirely. The Cyber AB ecosystem includes voluntary RPO and RP designations for readiness work, while a C3PAO conducts formal Level 2 certification assessments under the CMMC Program. Marketplace status is time-sensitive; verify any claimed designation directly in the Cyber AB Marketplace on the date it matters rather than relying on an old press release.
The C3PAO path is where the operating model changes, and it's worth understanding even if you never pursue it — because it explains why advisory work and assessment participation require a deliberate conflict structure.
Two provisions do the damage. First, under 32 CFR § 170.9, all C3PAO company personnel participating in the Level 2 certification assessment process must complete a Tier 3 background investigation, initiated using SF-86, or meet the DoD-determined equivalent when ineligible. The rule says this does not produce a security clearance and is not for government employment. Second, § 170.8(b)(17) bars a CMMC Ecosystem member from participating in a Level 2 certification assessment when that member prepared the organization for any CMMC assessment within the prior three years.
For a firm whose value is its advisory relationships, that member-level three-year bar is a hard constraint. A law firm considering both readiness and assessment work would need a structure that satisfies the actual personnel, impartiality, accreditation, background-investigation, quality, and conflict requirements — not a marketing wall between two service pages.
There is a third path that fits law firms better: legal advice supporting readiness under a properly structured attorney-client relationship. That can add privilege protection to qualifying communications and work product, but hiring a law firm or stamping “privileged” on a gap report does not automatically create privilege. Purpose, legal-advice content, recipients, jurisdiction, waiver, and handling all matter. Do not sell “privileged assessment” as a guaranteed shield.
What we actually verified
We think you should be able to check us. Here's exactly what we read and what the source establishes as of August 19, 2026.
| Element verified | Primary authority | What the source establishes |
|---|---|---|
| CMMC applicability through the supply chain | 32 CFR § 170.23 | CMMC applies when contractors or subcontractors process, store, or transmit FCI or CUI on contractor systems in performance; FCI requires Level 1, CUI Level 2 (Self) minimum |
| ESP definition | 32 CFR § 170.4 | IT/cybersecurity service prong plus CUI or Security Protection Data on ESP assets |
| Asset categories and KVM-only VDI example | 32 CFR § 170.19 | A properly restricted VDI endpoint can be Out-of-Scope; CUI Assets and Security Protection Assets remain in scope |
| Level 2 control set | 32 CFR § 170.14 and NIST SP 800-171 Rev. 2 | CMMC Level 2 remains identical to Rev. 2: 110 requirements across 14 families |
| Rev. 3 status | NIST SP 800-171 Rev. 3 compared with Part 170 | NIST has published Rev. 3, but Part 170 has not substituted it for the incorporated CMMC Level 2 set |
| Level 3 control set | 32 CFR § 170.14(c)(4) and NIST SP 800-172 | CMMC Level 3 uses 24 selected requirements from the February 2021 publication; SP 800-172 Rev. 3 is not yet the Part 170 set |
| In-performance limits and flowdown comments | 90 FR 43563–69 | DoD's responses repeatedly tie CMMC to FCI/CUI in performance and separate CMMC from 252.204-7012 incident duties |
| Covered-defense-information determination and reporting | DFARS 252.204-7012 | Contractor makes the (m)(1) determination; covered cyber incidents are reported within 72 hours; relevant images/data preserved 90 days from report submission |
| Legacy NIST SP 800-171 DoD Assessment path | DFARS 252.204-7019 and 252.204-7020 | These codified clauses can remain in legacy instruments; do not describe them as the universal current prescription for new DoD solicitations |
| Current DoD Part 240 assessment path | DoD Class Deviation 2026-O0025, Revision 2 and FAR Part 40 deviation guide | 252.240-7997 carries the government Medium/High assessment path; 7019 is not prescribed in that new-solicitation path; 7012, 7021, and 7025 remain separate |
| CMMC solicitation and contract artifacts | DFARS 252.204-7025 and 252.204-7021 | Required status, CMMC UID, annual affirmation, reporting, and flowdown mechanics |
| NARA grouping limitation | NARA Registry Change Log | Organizational Index Groupings display categories by subject and are not used to control CUI |
| Practice-area category and marking data | NARA CUI marking list | Current categories, Basic/Specified banners, category markings, and groupings used in the map |
| Legal Privilege and AC/AWP | NARA Legal Privilege category | PRIVILEGE category, listed Basic authorities, and AC/AWP limitation to this category |
| Phase II suspension and current designation rules | July 13 announcement and implementation procedures | Phase II transition suspended; new L2 C3PAO/L3 designations stopped; solicitation and existing-award modification instructions; Phase I and 7012 remain |
| C3PAO conflicts and no guarantees | 32 CFR § 170.8(b)(17) and CAP v2.0 | Member-level three-year consulting conflict; C3PAO must manage impartiality and cannot promise an assessment result |
| Professional duties | ABA Model Rule 1.6, Formal Opinion 477R, and Formal Opinion 483 | Model confidentiality, technology, communication-security, and breach-response analysis; jurisdiction-adopted law controls |
| Government-wide FAR CUI rule status | January 2025 proposed rule and June 2026 FAR overhaul proposal | The government-wide CUI clause remains proposed, not a final generally applicable FAR clause |
What we could not establish
Four honest gaps, and we'd rather you hear them from us.
One. In the 2025 DFARS rulemaking, commenters asked whether CMMC applies to collaboration under a memorandum of understanding or other non-contract data-sharing arrangement and whether cyber-consulting services for contractors and subcontractors would be required to comply. The published combined responses did not squarely answer those two fact patterns. The silence does not create an exemption or requirement.
Two. No DoD, NARA, or Cyber AB guidance we located addresses how a C3PAO's evidence access interacts with attorney-client privilege or the AC and AWP dissemination controls. Our boundary recommendation is editorial analysis derived from the verified sources and is labeled that way.
Three. We found no defensible law-firm-specific CMMC cost dataset. A cost range without a disclosed law-firm sample does not establish a law-firm-specific benchmark. We won't publish one. For general cost drivers, use our CMMC Level 2 cost guide.
Four. We did not take a dated Cyber AB Marketplace snapshot or verify a named law firm's current RPO, RP, or C3PAO status for this article. Marketplace status changes. This page therefore names no provider and makes no current status claim about a law firm.
We also did not evaluate, score, or rank any named provider for this page.
Frequently asked questions
Does CMMC apply to law firms that represent defense contractors? Usually not from the client relationship alone. Under 32 CFR § 170.23(a), CMMC reaches contractor and subcontractor systems that process, store, or transmit FCI or CUI in performance of a DoD contract or subcontract. Representation of a defense contractor is not, by itself, performance of that contract.
What if we're not a direct DoD contractor or subcontractor? Check whether the client has placed a qualifying requirement into an engagement letter, purchase order, subcontract, or other contractual instrument and whether FCI or CUI is required for performance. DFARS 252.204-7021 can flow through “other contractual instruments,” so the document label is not decisive.
Is a law firm an External Service Provider under CMMC? Not by practicing law. Section 170.4 requires both the provision and management of IT or cybersecurity services and CUI or Security Protection Data on the provider's assets. A firm that also provides hosting, managed IT, or security services can meet the definition. The firm may separately be a contractor or subcontractor even when it is not an ESP.
If we never receive CUI, do we need Level 2? Not from that client relationship alone. Confirm whether FCI is involved, whether any instrument independently requires a status, and whether the no-CUI architecture is enforced rather than aspirational.
Can attorneys access CUI from ordinary firm laptops? It depends on configuration. Section 170.19 describes an endpoint running a VDI client restricted to keyboard, video, and mouse traffic as Out-of-Scope. An ordinary laptop that can download, cache, print, sync, copy, or create derived work product outside the controlled environment is not that example.
Does client-hosted VDI keep the whole firm out of scope? No. The rule's example addresses the endpoint. Identity, support paths, notes, drafts, exports, printing, incident response, and every other system touching the matter still require analysis.
Is privileged information automatically CUI? No. Legal Privilege is a CUI category, but a private privileged document does not become CUI merely because it is privileged. CUI status must trace to an approved category and authority plus the government's or authorized holder's designation and instructions.
Does receiving CUI waive privilege, or does privilege override CMMC? Neither statement is accurate. They are separate protections and duties that can coexist. Coordinate contract, CUI, ethics, privilege, and incident analysis based on the actual facts and governing law.
Does the Phase II suspension eliminate CMMC? No. It suspended the transition to new Level 2 C3PAO and Level 3 designations. Phase I self-assessments, 32 CFR Part 170, applicable CMMC statuses and affirmations, DFARS 252.204-7012, legacy 7019/7020 duties where they remain in live instruments, and the current 252.240-7997 government-assessment path where the Part 240 deviation applies all remain relevant.
Can a client require our firm to get a C3PAO certification right now? A new DoD procurement designation may not require Level 2 C3PAO during the suspension. Active solicitations are to be amended, and existing awards are to be modified on the July 13 schedule. A client may still impose its own commercial policy or point to an unmodified instrument. Ask which document creates the requirement and whether it has been amended.
Does NIST SP 800-171 Revision 3 control CMMC Level 2? No. NIST published Rev. 3, but 32 CFR Part 170 still incorporates and defines Level 2 through Revision 2. Rev. 3 becomes the CMMC-controlling set only if the rule or governing requirement changes lawfully.
What does NIST SP 800-172 do in CMMC? Level 3 uses 24 selected requirements from the February 2021 edition of SP 800-172, in addition to the Level 2 baseline. NIST's later SP 800-172 Revision 3 is not the Part 170 Level 3 set today.
Is an SPRS assessment record the same as a CMMC status? No. Legacy 7019/7020 records, current government Medium/High assessments under 252.240-7997, and CMMC status, UID, self-assessment, and affirmation records under 7021/7025 are distinct artifacts. Read the live instrument before answering a questionnaire.
Why do some 2026 contracts say 252.240-7997 or 52.240-93? DoD and other agencies are using Revolutionary FAR Overhaul deviations while the codified FAR/DFARS still displays legacy clause numbers. For covered new DoD solicitations, 252.240-7997 replaces the 252.204-7020 government-assessment path, and 52.240-93 carries the FCI safeguarding clause. Existing instruments may still cite 7019, 7020, or 52.204-21.
Do we need Microsoft GCC High? No CMMC rule names a product. Your firm needs an environment and service arrangements that satisfy the actual requirements applicable to it. Product-first answers usually mean the scoping was skipped.
Does our eDiscovery vendor need CMMC? Evaluate the exact offering, the information, the contract, whether covered defense information is present, and the vendor's role. A company-wide marketing claim is not evidence about the specific environment. A cloud provider may have 7012 obligations; an IT/cyber provider may be an ESP; another recipient may be a subcontractor.
Is our MSP or SOC in scope? It may be an ESP if its IT or cybersecurity services have CUI or Security Protection Data on service assets. Get the service description, data flow, remote-access model, and Customer Responsibility Matrix.
Does an expert witness or court reporter need CMMC? Not as an ESP merely because the person receives information. But the recipient can still be a subcontractor or party to another qualifying instrument if performance requires FCI or CUI. Analyze flowdown and status separately from the ESP definition.
Can a C3PAO prepare us and then assess the same scope? A CMMC Ecosystem member may not participate in a Level 2 certification assessment if that member served as a consultant preparing the organization for any CMMC assessment within the prior three years. Require member-level conflict disclosure and the C3PAO's organizational conflict process. Do not overstate that rule into a prohibition it does not contain.
Can a C3PAO guarantee that we will pass? No. CAP v2.0 prohibits guarantees or promises about the Level 2 certification result and compensation contingent on issuance of a Certificate of CMMC Status.
What should the engagement letter say about CUI? Define the controlled information and authority, approved transfer and access paths, systems that may receive it, vendor and subcontractor approval, incident escalation and reporting coordination, retention and destruction, change control, and the exact representations the firm is making.
What do we do when marked or suspected CUI arrives unexpectedly? Restrict access, stop further distribution, preserve context, locate the governing instrument, ask for the category, authority, and approved transfer method, and preserve the ability to meet any 72-hour obligation. Do not ingest it into more ordinary systems while you wait.
Can CUI be filed with a court? That depends on the category authority, agency instructions, protective order, court rules, client direction, and applicable law. Escalate it before filing. Do not treat a public or sealed filing as ordinary distribution.
Who at the firm should own this? In practice, a small standing group: government-contracts counsel, the CIO or CISO, the firm's general counsel, records, and the responsible matter partner. One person cannot answer the instrument gate, information gate, system gate, and professional-duty questions alone.
The bottom line
For most law firms serving defense contractors, CMMC does not reach the firm from the client relationship alone, and you can document that conclusion this week with the three gates and the 60-second document check.
The risk that actually costs firms money is narrower and more mundane: a representation nobody could support, or a controlled document that quietly reproduced itself across email, the DMS, a review platform, and an expert's laptop before anyone asked where it should live.
Check the practice-area map, run one matter through the three gates, and send the client the six questions before you sign anything.
Need help deciding what type of CMMC provider you need? Map your level, scope, assessment status, architecture, and timeline before you request quotes.
→ Request scoped CMMC provider options
Do not submit CUI, drawings, contract documents, client names, matter details, or incident information.
About this article
The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance. We are not affiliated with The Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, NARA, the ABA, or any U.S. government agency.
This article is educational research, not legal, contractual, assessment, cybersecurity, or compliance advice. The governing instrument, the information's actual status, and the approved system boundary set the requirements — not a web checklist. Use qualified federal-contracts counsel for legal applicability and an appropriately experienced readiness or security professional for technical scoping. The ABA Model Rules are models; the rules and law adopted in your jurisdiction govern.
We may receive compensation for disclosed sponsorships, qualified introductions, or partner referrals. Compensation does not control our regulatory analysis, provider-category framework, or verification standards. Read our Methodology, Editorial Standards, and Corrections Policy.
Byline: The Defense Compliance Report Editorial Team · Last verified: August 19, 2026