The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · R&D firms and CMMC scope

CMMC for R&D Firms: Which Level Applies, and When Research Data Becomes CUI

Last updated:

Last verified: against 32 CFR Part 170, DFARS, the CUI Registry, DoD research guidance, and related primary sources.

Status — verified August 18, 2026: On July 13, 2026, the Department suspended the transition to CMMC Phase II and all later implementation milestones. Phase I Level 1 and Level 2 self-assessment requirements remain in force, as do DFARS 252.204-7012 safeguarding obligations and the CMMC rule's incorporation of NIST SP 800-171 Revision 2. Do not treat the former November 10, 2026 third-party milestone as a live deadline. What changed →

By The Defense Compliance Report Editorial Team Published August 18, 2026 · Last reviewed: August 18, 2026 Editorial research. Confirm award-specific scope and applicability with a qualified CMMC practitioner or federal-contracts counsel before acting.


CMMC for R&D firms is not “usually Level 2,” and the word research does not decide it. Your required CMMC status comes from the solicitation, contract, subcontract, or agreement; your actual obligation comes from the Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) your systems handle in performance. During the current implementation suspension, government program managers and requiring activities may newly designate only Level 1 (Self) or Level 2 (Self). A fundamental-research or publication-rights analysis can narrow the answer, but it does not erase inbound FCI or CUI that the award requires you to handle.

Four facts resolve the expensive part: the RDT&E budget activity funding the work, the publication and release restrictions in the award, the CUI categories that apply, and the instrument and security terms you actually signed.

Here is the part almost nobody tells you: two of those four facts are not yours to determine. You have to ask for them, in writing, from someone specific. We will show you which two, who holds them, and the exact words to use.


The four questions that decide your CMMC obligation

Read this table before you read anything else. It is the whole page in one screen.

# — The question — Who actually decides it — Where the answer lives — What it changes
#The questionWho actually decides itWhere the answer livesWhat it changes
1Which RDT&E budget activity funds this work, and has the work been designated fundamental research?DoD program office and contracting or agreements officer — not youAward funding line; solicitation or topic description; written determinationBudget activity informs the designation. It does not override the award's FCI/CUI terms or the information actually handled.
2Does the award restrict publication or release?Contracting or agreements officer — but you can read the language todayDFARS 252.204-7000; publication-review, approval, distribution, export-control, or data-rights termsCan affect whether research results qualify for the EAR fundamental-research exclusion and how results may be released. It does not, by itself, create or eliminate CUI.
3Which CUI categories apply to information you receive or create?The government designating authority or information owner — not youCUI markings; contract or agreement data list; distribution statements; Security Classification Guide; written directionDefines the information to protect and, under the January 2025 level guide, informed the historical self-assessment-versus-certification path. During the suspension, new government designations are limited to Level 1 (Self) and Level 2 (Self).
4What instrument and security terms govern the work?Contracting, agreements, grants, or prime-contractor personnel — but you can read the instrument todaySolicitation, award, subcontract, grant, OT, CRADA, and incorporated termsDecides which FAR/DFARS clauses or negotiated security provisions apply and what CMMC status the award or flow-down requires.

Questions 2 and 4 you can answer this afternoon from paperwork already in your files. Questions 1 and 3 usually require a written government or prime-contractor answer. Most firms discover that eighteen months and one enclave purchase too late.

Rule-stated fact versus operating test

The rule-stated fact is what your solicitation, award, and incorporated clauses require. The operating test is whether your people and systems actually process, store, or transmit the FCI or CUI covered by those terms. You need both. A contract label without a data flow creates bad scoping. A data flow without the controlling award language creates bad representations.

Last verified August 18, 2026. Primary sources for every row appear below.


Who this page is for — and who should leave

This is for you if you hold or are pursuing DoD research funding: an SBIR or STTR award, a Broad Agency Announcement award, a grant, an Other Transaction, a university subaward, or an R&D subcontract to a prime. Ten people or four hundred, employee count does not decide applicability. What matters is the award, the information, and the systems used in performance.

This is not for you if:

  • You already know your data is Controlled Technical Information and you are choosing a vendor. Your question is a purchasing question, not a determination question. Go to CMMC provider categories instead.
  • You are a university research office rather than a company. Your instrument mix, your indirect-cost structure, and your institutional obligations differ enough that this page will mislead you at the margins. Start with CMMC for subcontractors and a qualified CMMC practitioner.
  • You receive finished technical data as a service provider rather than generating research. That is a different scoping problem with a different answer. See CMMC for engineering firms.

We would rather lose you in the first ninety seconds than waste an hour of your time.

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source support for regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.


Does CMMC for R&D firms apply to every research award?

No. CMMC applies when the governing solicitation, contract, subcontract, or agreement requires a CMMC status and contractor systems will process, store, or transmit FCI or CUI in performance. It is not triggered by having a defense customer, by the word “research,” by company size, or by how sensitive you personally believe the work is.

Let us define the moving parts once, then use them freely.

CMMC (Cybersecurity Maturity Model Certification) is the Department's program for verifying, by self-assessment, third-party assessment, or government assessment, that contractors implement the cybersecurity requirements associated with the information they handle. The program rule is at 32 CFR Part 170, effective December 16, 2024. The DFARS acquisition rule that brings the current CMMC provisions into solicitations and contracts became effective November 10, 2025.

FCI (Federal Contract Information) is nonpublic information provided by or generated for the government under a contract to develop or deliver a product or service, excluding information intended for public release and certain simple transactional information.

CUI (Controlled Unclassified Information) is unclassified information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that law, regulation, or government-wide policy requires or permits an agency to safeguard or control for dissemination. It is not a synonym for “sensitive,” “proprietary,” or “we would rather competitors not see it.”

The five-question applicability test

Run these in order.

  1. What instrument governs the work? A FAR-based prime contract, a subcontract, a grant, an Other Transaction, a CRADA, and a resulting award from a BAA or Commercial Solutions Opening do not carry identical terms.
  2. Which clauses or negotiated security articles are actually present? For FAR-based work, search for FAR 52.204-21, DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025. Do not assume FAR 52.204-21 was universally renumbered: the codified clause remains 52.204-21. FAR 52.240-93 appears under the FAR overhaul model deviation and controls only where the awarding agency adopted that deviation and put it in the instrument.
  3. Will contractor systems be used in performance? FAR 52.204-21 covers qualifying systems owned or operated by the contractor. DFARS 252.204-7012 reaches covered contractor information systems owned by the contractor, or operated by or for the contractor.
  4. Will those systems handle FCI, CUI, or only information intended for public release?
  5. What CMMC status does the solicitation, award, or flow-down require? DFARS 252.204-7025 states the solicitation-level requirement; DFARS 252.204-7021 carries the contract obligation and flow-down.

The Level 1 floor research firms miss

Many FAR-based research awards create FCI through nonpublic contract administration even when the science is intended for publication: deliverable schedules, draft reports, nonpublic correspondence, access instructions, or other information generated for the government under the contract.

Where Level 1 is required, the rule contains 15 basic safeguarding requirements, drawn from FAR 52.204-21. Level 1 requires an annual self-assessment and annual affirmation in the Supplier Performance Risk System (SPRS). No plan of action and milestones is permitted at Level 1. You meet all 15 requirements or you do not.

If you read one number on this page, read that one. Fifteen. Not a hundred and ten.

Two SPRS records that are not interchangeable

A NIST SP 800-171 DoD Assessment score under DFARS 252.204-7019 and 252.204-7020 is one record. For award purposes, that score generally must be current—no more than three years old unless the solicitation specifies a shorter period. A CMMC status and annual affirmation under DFARS 252.204-7021, 252.204-7025, and 32 CFR Part 170 is another; the affirmation cannot be older than one year. Both use SPRS. Posting one does not silently satisfy the other.

Where Level 2 applies, the current CMMC requirement set is NIST SP 800-171 Revision 2: 110 security requirements organized in 14 families. NIST Revision 3 is not the CMMC-controlling edition unless the rule is amended.

One thing that does not trigger CMMC

Reading a public solicitation is not contract performance. Publicly released solicitation material is not FCI merely because it relates to a government opportunity. Once you receive nonpublic government-furnished information, marked proposal material, controlled attachments, or award-specific direction, follow the markings and governing terms rather than carrying the public-document assumption forward.


Which RDT&E budget activity funds your work—and what does it change?

The budget activity does not decide CMMC by itself. It tells you how DoD's published fundamental-research guidance approaches the work, which can materially change the questions you should ask before the award is fixed. The award terms and the FCI/CUI actually handled still control the safeguarding analysis.

That structure comes from the May 24, 2010 memorandum from the Under Secretary of Defense for Acquisition, Technology, and Logistics — universally called the Carter Memo — as restated in the DoD Basic Research Office's published Fundamental Research Guidance. It implements National Security Decision Directive 189 (NSDD-189, September 21, 1985), which defines fundamental research as basic and applied research in science and engineering whose results are ordinarily published and shared broadly, and directs that its products remain unrestricted to the maximum extent possible.

Here is the map. We built it by joining that guidance to the RDT&E budget activity definitions in DoD Financial Management Regulation 7000.14-R, Volume 2B.

Budget activity — Name — DoD fundamental-research guidance — What it changes in your CMMC analysis
Budget activityNameDoD fundamental-research guidanceWhat it changes in your CMMC analysis
6.1Basic ResearchShould be designated fundamental research unless controls are required by statute, regulation, or executive orderStrong reason to request the written designation. Still verify whether the award separately requires you to handle FCI or CUI.
6.2Applied ResearchCarries the fundamental-research designation under this guidance when conducted on a university campus⚠️ A for-profit company lab does not inherit the campus default. Ask for the Component's decision.
6.3Advanced Technology DevelopmentMay be designated fundamental research at the Component's electionAsk. Never assume. The decision is normally made before award and should rarely be revisited without a reason.
6.4Advanced Component Development and PrototypesNo automatic designation in the guidancePrototype, interface, and test data often increase the chance of CTI, but the award and data designation still decide it.
6.5System Development and DemonstrationNo automatic designation in the guidanceSystem-level technical data often raises CUI risk. “Often” is not “automatically.”
6.6RDT&E Management SupportNo automatic designation in the guidanceDepends entirely on the information and systems the support effort touches.
6.7Operational System DevelopmentNo automatic designation in the guidanceOperational and sustainment data may be controlled; confirm the specific category and marking basis.
6.8Software and Digital Technology PilotsNo automatic designation in the guidanceSoftware artifacts may be CUI or may remain unrestricted. The category, award terms, and release path decide it.

Budget activities 6.1 through 6.3 together are what DoD calls the science and technology budget. That is the neighborhood where the fundamental-research conversation actually lives.

This table is our editorial synthesis of published DoD guidance and budget definitions, applied to a contractor's planning question. The designation belongs to the government and should appear in writing.

The honest problem with the exemption you are counting on

Now the part we would rather not write, because it will cost us a few readers who wanted better news.

The fundamental-research exemption that many R&D companies believe protects the entire company probably does not.

Much of the published fundamental-research guidance is written around universities. That is not an accident. The 6.2 default in DoD's guidance is expressly tied to performance on a university campus. If you are a for-profit R&D company running applied research in your own facility, you sit outside both of those defaults. The designation is not automatic. And it was never yours to declare in the first place.

Even a valid fundamental-research designation does not create a blanket company exemption. The CMMC final-rule preamble rejects that reading: contractor systems that process, store, or transmit CUI remain subject to NIST SP 800-171 when DFARS 252.204-7012 applies, whether or not the contractor also performs fundamental research.

We have watched firms build an entire compliance posture — or an entire refusal to build one — on a paragraph written for a university research office.

Now the part that makes it worth knowing.

Because the designation is normally made pre-award and should rarely be reassessed, it is a question you can raise while the award is still being shaped. That is leverage almost nobody uses, because almost nobody knows the question exists. DoD's published review materials give program and contracting personnel a structured way to decide whether the work qualifies.

DoD's own guidance also warns against the opposite error: over-controlling research that could otherwise be fundamental can forfeit the benefits. The Department is not trying to sweep every experiment into scope. Somebody has to ask.

And if you are a subawardee, your prime can ask on your behalf. The guidance encourages prime awardees to contact the program manager, contracting officer, or grants officer about a subawardee's portion of the work and to avoid flowing restrictions to performers doing fundamental research when those restrictions are unnecessary. Most subs have no idea that door exists. It does. The letters below give you the words.

✅ Before you price anything, find out which determination you are waiting on

You now know the four questions and which two are outstanding. That is the moment to figure out what kind of help — if any — you actually need.

Map my R&D situation to a provider category →

Free · two minutes · educational triage only · do not submit CUI, drawings, source code, or contract details.


Who should an R&D firm hire first for CMMC?

Hire against the unresolved decision, not the acronym on the vendor's homepage. If applicability, CUI categories, or the boundary is unresolved, start with qualified scoping and federal-contracts help. If the boundary is known but the controls are weak, you need implementation. If the controls exist but the evidence is scattered, you need evidence management. A C3PAO belongs at the end, when a valid certification requirement exists and you are assessment-ready.

Your unresolved problem — Provider category to investigate first
Your unresolved problemProvider category to investigate first
Award interpretation, CUI designation, scope, fundamental-research questionQualified CMMC practitioner and, where contract interpretation matters, federal-contracts counsel
Identity, logging, endpoint, network, cloud, incident-response implementationMSP or MSSP with documented CUI/CMMC experience
Bounded project environment for a small set of people and workflowsCUI enclave or compliant cloud architecture provider
SSP, POA&M, control ownership, evidence collectionGRC platform and/or readiness advisor
Formal Level 2 certification assessment required and readiness completeAuthorized CMMC Third-Party Assessment Organization (C3PAO)

The solicitation, contract, agreement, or flow-down states the required status; the requiring activity selects the government requirement; a prime or higher-tier contractor selects what it requires in a subcontract based on the information it will flow. A checklist does not set your level.

Use CMMC Levels to confirm the status names, Who to Hire First to separate advice from implementation, and RPO vs. C3PAO before you request quotes.

One current-state qualifier: during the present implementation suspension, verify whether a previously stated Level 2 (C3PAO) or Level 3 government requirement has been amended. A private subcontract is not rewritten merely because the government issued a memorandum; read the current flow-down.


Can publication restrictions turn research results into export-controlled CUI?

They can affect the answer, but the publication clause is not a universal CUI switch. Under 15 CFR 734.8, certain EAR “technology” or “software” arising during or resulting from fundamental research and intended to be published is not subject to the EAR. That exclusion is limited to the EAR analysis. It does not decide ITAR status, erase FCI, erase inbound CUI, or override a different safeguarding authority.

Follow the chain carefully.

  1. 15 CFR 734.8(a): qualifying technology or software arising from fundamental research and intended to be published is not subject to the EAR.
  2. 15 CFR 734.8(b): publication restrictions can prevent the research from satisfying that condition. Patent review and temporary delay do not automatically destroy it.
  3. The National Archives CUI Registry includes Export Controlled Research, category marking EXPTR, in the Export Control grouping.
  4. The government still has to identify the information and the applicable authority. A publication restriction can be evidence in that analysis; it does not label every result CUI by itself.

That distinction is the useful one. The same scientific work can move from an unrestricted publication path to an export-controlled path because the award changes what may be released. But “not freely publishable” is not a complete CUI determination.

The clause almost no CMMC article cites

DFARS 252.204-7000, Disclosure of Information. It is a release clause, not a cyber clause, which is exactly why it gets missed.

Its fundamental-research exception is narrow. The project must involve no covered defense information, must be scoped and negotiated by the contracting activity with the contractor and research performer, and must be determined in writing by the contracting officer to be fundamental research.

Do not turn that scoped exception into a universal rule that fundamental research can never involve covered defense information. That overreaches. The final CMMC rule's preamble answers the broader question directly: when a contractor processes, stores, or transmits CUI under a contract containing DFARS 252.204-7012, the safeguarding requirement applies whether or not the contractor is engaged in fundamental research. DoD also stated that some research it determines to be CUI remains subject to CMMC.

The payoff is still real:

  • A written DFARS 252.204-7000 exception can establish that the scoped project described in that determination involves no covered defense information.
  • It does not establish that every system, every award, every government input, or every future phase is outside CMMC.
  • The determination belongs in your file because it shows the basis for your scope. It is not a substitute for implementing requirements that do apply.

Prepublication review that does not break EAR fundamental-research status

This trips up good people. Not every review is a restriction.

Under 15 CFR 734.8, review solely to protect patent rights, with no more than a temporary delay, can remain consistent with publication. Review to prevent disclosure of a sponsor's proprietary inputs can also be treated differently from a sponsor right to suppress the research results. The operative question is what the reviewer can withhold and why.

If your award has a review clause, read the actual authority it grants. If the language is ambiguous, resolve it before using it as the basis for an export-control or CMMC representation.

Status can change mid-performance

Research can begin unrestricted and later involve controlled information. The trigger may be a modification, a new government-furnished input, a new deliverable, a distribution statement, a phase transition, or an agency designation applied to data you generate.

Practical consequence: your determination has a shelf life. Recheck it at option exercise, modification, new work package, new data exchange, and phase transition. A determination made for one effort does not automatically carry into another.


Which CUI category applies—and what assessment type follows?

First identify the category and the current contract requirement. Do not use the January 15, 2025 Level Determination Guide as though it still authorizes new certification designations during the suspension. The guide remains useful evidence of DoD's pre-suspension selection logic; the July 13, 2026 implementing direction currently limits new government designations to Level 1 (Self) and Level 2 (Self).

Before the suspension, the guide said Level 2 self-assessment was sufficient only for CUI outside the National Archives CUI Registry's Defense Organizational Index Grouping, and Level 2 certification was the minimum for CUI inside that grouping, subject to elevation and highest-applicable-level rules.

The current Defense grouping contains five categories, not four:

  1. Controlled Technical Information
  2. DoD Critical Infrastructure Security Information
  3. Naval Nuclear Propulsion Information
  4. Privileged Safety Information
  5. Unclassified Controlled Nuclear Information — Defense

Now here is what nobody has assembled in one decision table. The R&D categories below sit in different groupings, use different markings, and no longer map one-for-one to a currently permissible new government certification designation.

CUI category — Category marking and banner — Basic or Specified — Organizational grouping — Registry authority snapshot — January 15, 2025 guide path before the suspension — Current government designation during the suspension
CUI categoryCategory marking and bannerBasic or SpecifiedOrganizational groupingRegistry authority snapshotJanuary 15, 2025 guide path before the suspensionCurrent government designation during the suspension
Controlled Technical InformationCTI; CUI//SP-CTISpecifiedDefenseDFARS 252.204-7012 and listed DoD authoritiesLevel 2 Certification minimumNew designation limited to Level 2 (Self); confirm award amendment and any prime flow-down
Export Controlled ResearchEXPTR; CUI or CUI//EXPTRBasicExport Control15 CFR 734.8(b)Level 2 Self-AssessmentLevel 2 (Self), if CUI is actually handled and the award requires it
Export ControlledEXPT; CUI for Basic authorities or CUI//SP-EXPT for Specified authoritiesBasic or SpecifiedExport ControlApplicable EAR, ITAR, and other Registry-listed authoritiesLevel 2 Self-AssessmentLevel 2 (Self), if CUI is actually handled and the award requires it
Small Business Research and TechnologySBIZ; CUI or CUI//SBIZBasicProcurement and AcquisitionDescription: 15 U.S.C. 638(k)(2); safeguarding authority: 15 U.S.C. 638(k)(4)Level 2 Self-AssessmentLevel 2 (Self), if the narrow category applies and the award requires it

Registry grouping and marking snapshot verified August 18, 2026. The last column reflects the July 13, 2026 suspension direction, not a prediction about the reform outcome.

Four caveats, and they are not decoration:

  1. The table is not exhaustive. Privacy, source-selection, critical-infrastructure, patent, intelligence, and other categories may appear in R&D work.
  2. The January 2025 guide allowed program managers to elevate the level for high confidentiality, integrity, or availability risk and directed selection of the highest applicable level when multiple criteria applied.
  3. The current solicitation, award, modification, or subcontract governs over this table. A contracting officer may need to amend a stale requirement; a prime may need to clarify a private flow-down.
  4. The SBIZ category is narrow. It covers specified SBIR/STTR program information maintained under the cited statutory scheme; it does not turn every SBIR proposal, deliverable, or company document into CUI.

How to find out which categories apply

Ask the contracting officer to identify the categories or coordinate that identification with the program office, information owner, or agency CUI program. Ask for the category names, marking instructions, distribution statements, and any Security Classification Guide.

And understand this distinction, because it costs firms real money: “we have not received any marked documents” is not the same as “we have no CUI.” DFARS 252.204-7012's covered-defense-information definition reaches qualifying information collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of contract performance. Test data, failure analyses, interface specifications, and as-built configurations can become covered information when the government designates them under an applicable authority. Contractors should not invent the designation, but they also should not assume unmarked generated data is automatically public.


Which R&D systems and lab assets are in CMMC scope?

If your research data is CUI, your assessment scope reaches further than the server where the files sit. At Level 2, 32 CFR § 170.19 sorts every asset into five categories — CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets — and the correct treatment depends on whether an asset handles CUI, protects the environment, could reach CUI despite policy, or falls into a defined specialized class.

This is where R&D environments differ most sharply from an office. You have instruments. Vendor-controlled computers bolted to hardware. Compute clusters. Repositories. Researchers with local admin because that is how the work gets done.

Here is how those map. This table is ours; the categories are the rule's.

R&D asset or workflow — Likely category to investigate — Why — Evidence you will need — The common mistake
R&D asset or workflowLikely category to investigateWhyEvidence you will needThe common mistake
Repository holding CUI source codeCUI AssetIt processes, stores, or transmits CUIRepository inventory, access list, data-flow map, SSP treatmentCalling all source code "proprietary" instead of determining whether it is CUI
CAD models, drawings, simulation outputs, or test results designated CUICUI AssetThe content drives it, not the software brandMarking basis, storage path, sharing and export controlsAssuming every design file is CUI — or that none are
Researcher workstation that opens or analyzes CUICUI AssetDirect processing puts the endpoint in scopeAsset inventory, configuration baseline, users, per-requirement evidenceTreating "view only" as "no processing" without checking the architecture
Identity management, MFA, EDR, SIEM, firewall, backup, loggingSecurity Protection AssetIt provides a security function to the CMMC scopeService description, network diagram, configuration evidence, responsibility matrixLooking only for systems that visibly store CUI
General corporate or lab system capable of reaching CUI but deliberately preventedContractor Risk Managed Asset candidateThe rule recognizes assets capable of handling CUI but not intended to, because of policy, procedure, and practiceInventory, SSP treatment, network diagram, enforced technical and administrative restrictionsDeclaring a capable asset "out of scope" with policy alone and no enforceable boundary
Networked instrument or test rig that touches CUI and cannot be fully securedSpecialized Asset candidateTest Equipment is one of the five specialized asset types at 32 CFR § 170.4Inventory, SSP treatment, network diagram, risk-based controls, interface mapAssuming old firmware or vendor limits make it disappear from scope
Vendor-supplied instrument computerCUI Asset or Specialized Asset, depending on use and securabilityWho owns it and how annoying it is do not decide scopeData-flow test, documented technical limits, vendor support terms, segmentation designTrusting a vendor appliance without documenting how you treat it
HPC or simulation clusterDepends on whether it processes CUI and what protects it"HPC" is not its own exemption or asset categoryJob data flows, storage, identity, scheduler, logs, administrator accessScoping only the login node
Researcher laptop running VDI with no CUI beyond keyboard, video, and mousePotential Out-of-Scope AssetThe scoping treatment recognizes a tightly configured endpoint that cannot store, process, or transmit CUIVDI configuration evidence: clipboard, download, print, drive-mapping restrictions, validatedCalling any remote-desktop endpoint out of scope without proving the configuration
Commercial cloud storing or processing CUICloud service provider pathUnder DFARS 252.204-7012(b)(2)(ii)(D), a CSP handling covered defense information must meet the FedRAMP Moderate baseline or equivalentAuthorization or equivalency evidence, customer responsibility matrix, SSP, connected on-premises scopeBuying a commercial tenant because the vendor advertises general security certifications
University partner or subcontractor receiving project CUISeparate organizational scope plus applicable flow-downEach participant's systems and obligations stand on their ownSubcontract, flow-down matrix, data map, transfer methodAssuming the prime's status covers collaborators
Personal or BYOD endpointCUI Asset, risk-managed asset, or prohibited pathThe device's actual capability and use decide treatmentPolicy plus technical enforcement, VDI restrictions, data-loss controlsDeclaring BYOD out of scope by policy alone

The Specialized Asset asymmetry that catches labs

This is the single most expensive scoping surprise for an R&D firm, and it is a two-line rule.

At Level 1, under 32 CFR § 170.19(b)(2)(ii), Specialized Assets are out of scope and not assessed.

At Level 2, under § 170.19(c)(1), Specialized Assets are part of the assessment scope. They must be documented in the asset inventory, in the System Security Plan, and on the network diagram, and managed using the contractor's risk-based security policies, procedures, and practices — though they are not assessed against the other Level 2 requirements.

So a lab that has always treated its test benches as invisible is correct at Level 1 and wrong at Level 2. The same equipment. The same firmware. A different level.

The five specialized asset types at § 170.4 are Government Furnished Equipment, Internet of Things and Industrial IoT devices, Operational Technology, Restricted Information Systems, and Test Equipment. If you run a lab, at least one of those describes something on your floor right now.

✅ Turn this into your own inventory

Reading a table is not scoping. Building the list is.

Download the CMMC Readiness Checklist →

A practical checklist mapped to the 14 NIST SP 800-171 Revision 2 requirement families — scoping and CUI inventory, SSP and POA&M baseline, SPRS posting, and the assessment-type decision tree. Use it to build your asset list before anyone quotes you a price for protecting it.


Do grants, Other Transactions, and CRADAs require CMMC?

They can carry CMMC or equivalent safeguarding terms, but DFARS clauses do not attach automatically to every non-FAR instrument. Read the agreement. The January 15, 2025 DoD memorandum said program managers and requiring activities were expected to use its level-selection guide for non-FAR grants and other legal agreements. The current July 2026 suspension limits new government designations while the review proceeds. The instrument's own terms remain the controlling text.

This matters more to R&D firms than to any other segment of the industrial base, because R&D firms live on these instruments.

Instrument or acquisition method — Do DFARS clauses attach automatically? — What currently controls — What to read first
Instrument or acquisition methodDo DFARS clauses attach automatically?What currently controlsWhat to read first
FAR-based procurement contractYes, when prescribed and includedSolicitation, contract, modification, and applicable DFARSSearch for 7012, 7019, 7020, 7021, and 7025
Subcontract under a FAR primeBy required flow-down and the subcontract's termsCurrent subcontract and any amendmentFlow-down schedule, data-transfer terms, and prime clarification
Grant or cooperative agreementNoAward conditions and incorporated security termsData, cybersecurity, CUI, publication, and reporting articles
Other TransactionNo; clauses apply only if incorporated or negotiatedThe agreement's negotiated security and data termsAgreement articles, attachments, and statement of work
CRADANoThe CRADA's own data, publication, export-control, and safeguarding provisionsThe signed agreement and agency direction
BAA or Commercial Solutions OpeningThese are solicitation methods, not the final instrumentThe resulting contract, grant, OT, or other awardThe resulting award, not the solicitation label alone

The takeaway is uncomfortable and useful: the absence of a familiar clause number does not mean the absence of a requirement. It means you have to read the agreement instead of searching the PDF for “7012.”

Why an Other Transaction may give you negotiating room

Other Transactions are negotiated agreements rather than clause-driven FAR contracts. That often creates more room to define the security boundary, government-furnished information, generated information, markings, release process, and cost allocation before signature.

Raise scope during negotiation, not after award. Ask what information the government expects to furnish, what it expects you to generate, whether either is expected to be controlled, and who will make that designation. Put the answers in the agreement.

The historical waiver ladder—and the current answer

The January 2025 memorandum contained a demanding waiver process. Level 1 and Level 2 self-assessment waivers were described as circumstances unlikely to warrant approval; higher-level waivers required senior approval and alternate protection plans.

That is historical context, not the current operating route. The July 13, 2026 implementing direction says no CMMC waivers will be granted during the review. Do not build a proposal strategy around a waiver that the Department has said it will not issue.

The old guide also required alternate protection plans when certain higher-level waivers were pursued. The damaging admission survives the policy change: the waiver did not remove the security work; it moved the work into the proposal, where the government could evaluate it. That matters only if a future reform restores a waiver route.


What do SBIR and STTR firms need to know about CMMC?

Read the current topic and resulting award. There is no safe program-wide assumption. Current Department of the Navy FY26 topic materials provide concrete examples of CMMC status being identified at the topic level, but components and solicitation cycles vary. The topic tells you what the government expects; the signed award and the information actually handled tell you what you must do.

Read the topic, not just the program name

The Small Business Innovation Research and Small Business Technology Transfer programs are governed by 15 U.S.C. 638 and the SBA policy directive, then implemented through component solicitations and topics.

Practical instruction: before you invest proposal hours, open the live topic and search for CMMC, CUI, FCI, cybersecurity, export control, data rights, and distribution statements. Confirm the result against the award if you win. Requirements move between cycles.

SBIR “Phase” and CMMC “Phase” are unrelated terms

They collide constantly in conversation and cause real errors.

  • SBIR Phase I / II / III describe the maturity stage of the award.
  • CMMC implementation phases describe the Department's rollout schedule.
  • CMMC Levels 1 / 2 / 3 describe different cybersecurity requirement and assessment structures.

A Phase II SBIR does not mean CMMC Level 2. A CMMC Phase II milestone has nothing to do with the maturity of your SBIR award. Anyone who blurs them is not reading your contract carefully enough to advise you.

Where the information often changes

Phase I often emphasizes feasibility. Phase II often introduces prototypes, integration data, interface specifications, government-furnished technical material, and test results moving in both directions. That operating pattern increases the chance that CTI or another CUI category appears. It is not a rule that Phase II data is CUI.

If you are planning a Phase II proposal, treat the CUI question as a proposal input, not a post-award discovery.

The SBIZ category is narrower than “SBIR data”

The CUI Registry's Small Business Research and Technology category sits in the Procurement and Acquisition grouping. Its authority covers specified SBIR/STTR information maintained under the statutory government database provisions. The existence of the category does not mean every proposal, deliverable, company record, or research result carries CUI//SBIZ.

Data rights and CMMC solve different problems

DFARS 252.227-7018 protects rights in qualifying SBIR/STTR data. CMMC governs the contractor systems that process, store, or transmit covered information. A data-rights legend does not reduce CMMC scope, and a CMMC status does not preserve your data rights.

Two separate jobs. Two separate specialists. Do not let a vendor conflate them into one invoice.

The SPRS obligation that predates CMMC

A NIST SP 800-171 DoD Assessment score under DFARS 252.204-7019 and 252.204-7020 and a CMMC status under DFARS 252.204-7021 and 252.204-7025 are separate records. Both appear in SPRS. Check which record you have, its date, the systems it covers, and whether the award needs the other one. See SPRS score: what contractors need to know for the mechanics.


When can an R&D firm reach CMMC Level 3?

R&D firms fit some of the historical Level 3 risk criteria unusually well, but new Level 3 designations are currently suspended. The January 15, 2025 level guide tied Level 3 selection to factors such as CUI associated with breakthrough, unique, or advanced technology; significant aggregation of CUI; and system ubiquity that could create widespread Department vulnerability.

That first criterion sounds uncomfortably familiar because it describes what some research companies are paid to produce.

We are not telling you to expect Level 3. The final rule projected Level 3 for only a small portion of the affected population, and the January guide told program managers to avoid overuse. We are telling you to recognize the logic if the issue returns after reform.

Under the current 32 CFR § 170.14, Level 3 adds 24 selected requirements from the original February 2021 NIST SP 800-172 on top of Level 2. It also requires a Final Level 2 (C3PAO) status for the Level 3 scope before the government Level 3 assessment.

The version trap

NIST withdrew the original SP 800-172 on May 13, 2026 and superseded it with SP 800-172 Revision 3. That publication change did not silently rewrite 32 CFR Part 170. The current CMMC rule still incorporates the original February 2021 SP 800-172 by reference. Revision 3 becomes the CMMC basis only if the controlling rule is amended.

The same rule applies to NIST SP 800-171: NIST withdrew Revision 2 in May 2024 and published Revision 3, but current 32 CFR Part 170 still incorporates Revision 2 for CMMC Level 2.

If a prime says Level 3 flows down to you, ask for this by name

The January 2025 guide called for a Security Classification Guide when Level 3 was warranted so information could be segregated and lower-risk material could remain at lower levels. It warned that failing to do so could unnecessarily push Level 3 through the supply chain at significant program cost.

DoD wrote down the failure mode. Then it wrote down the fix. Ask for the Security Classification Guide, the exact CUI involved, the current flow-down, and the post-suspension contractual basis.


What did the July 13, 2026 CMMC suspension change?

It stopped the transition to Phase II and all later implementation milestones; it did not repeal the underlying safeguarding clauses. The acquisition rule originally established Phase 1 from November 10, 2025 through November 9, 2026, with Phase 2 planned for November 10, 2026. The Department suspended that transition on July 13, 2026.

During the review:

  • program managers and requiring activities may newly designate only Level 1 (Self) or Level 2 (Self);
  • new Level 2 (C3PAO) and Level 3 designations are not permitted;
  • no CMMC waivers are being granted;
  • DFARS 252.204-7012 remains in effect;
  • active solicitations containing the paused higher requirements are to be amended; and
  • existing contracts and agreements are to remove those requirements by modification before the next option exercise or next scheduled administrative modification, as directed by the implementing memorandum.

We keep the full status picture on our suspension page. Three points matter specifically to R&D firms.

One: it changed verification timing, not the identity of the information. Whether your systems handle FCI or CUI still comes from the award and data flow.

Two: it removed a milestone your vendor quote may still be priced against. If someone quoted a program built around November 10, 2026 certification, ask for a revised scope and price tied to your current award.

Three: the government memorandum does not, by itself, rewrite every private subcontract. Read the current flow-down. Ask the prime whether it has amended the requirement and what information it still expects to transmit.

No replacement Phase II date had been announced as of August 18, 2026.


What does CMMC cost an R&D firm?

There is no defensible universal price. DoD's own economic analysis in the CMMC Final Rule published per-entity assessment estimates — and for Levels 1 and 2 those figures expressly exclude implementation, ongoing maintenance, and remediation, because the rule assumes the underlying safeguards were already contractually required. The gap between "assessment cost" and "what you will actually spend" is where R&D firms get surprised.

We publish dollar figures and the DoD baseline on our CMMC Level 2 cost guide and CMMC cost for small business pages. Rather than repeat them, here is what is different about your cost structure.

Cost drivers most CMMC cost articles never mention, because they were written for offices:

  • Vendor-controlled instrument computers. Often unpatchable, unsupported, contractually locked, or physically attached to a machine you cannot replace. Segmentation and documentation may matter more than conventional remediation.
  • HPC and simulation environments. Scratch storage, job scheduling, shared tenancy with other research groups, and administrator access paths that nobody has diagrammed.
  • Source code and build systems. Repositories, CI pipelines, artifact stores, and dependency mirrors, all of which may hold or move controlled data.
  • Researcher privilege. Local administrator rights are not categorically prohibited by CMMC, but the access, accountability, configuration, and evidence requirements around them are real. Designing a workflow that satisfies them without stopping the science is genuine engineering work.
  • Publication and release workflow. You need an approved path for moving information from controlled to public. Many firms discover they never had one.
  • Collaborator interfaces. University partners, visiting researchers, foreign nationals, consortium members.
  • Rate of change. Research environments can change monthly while compliance evidence assumes stability. That tension is a cost.

The single biggest lever is not any of those. It is scope. Which is why we put the determination questions at the top of this page and the vendor conversation near the bottom.


How can R&D firms reduce CMMC scope without slowing the science?

Our operating rule: the cheapest defensible CMMC outcome for an R&D firm is usually a smaller, accurately bounded scope—not a more expensive product. Separating by project often works better than separating by department, because controlled and uncontrolled work in a lab can run through the same people and instruments.

Four architecture patterns, honestly compared

Pattern — Best fit — Real strength — The R&D drawback
PatternBest fitReal strengthThe R&D drawback
Whole-company environmentSmall firm where nearly every person and workflow touches CUIFewest boundary transitions; simplest story to an assessorImposes controlled-environment friction on commercial and internal work that never needed it
Project-based enclaveLimited programs and named people handle CUISmallest defensible boundary; clean cost allocation to the programContext switching; transfer controls; discipline required from researchers
VDI or cloud enclaveDistributed researchers, software-heavy workCentralized data and application control; endpoint may fall out of scope if properly configuredInstrument integration, latency, local tooling, clipboard and download restrictions
Physically localized lab environmentCUI concentrated around specific instruments or test rigsBoundary matches the physical workflowVendor computers, patching, remote support, and how data gets out for analysis

Why department-based separation fails in labs

An accounting department has a stable membership and a stable toolset. A research team does not. The same principal investigator runs a 6.1 project and a 6.4 project. The same environmental chamber serves both. The same postdoc moves between them on a Tuesday.

Draw the boundary around the department and you will spend the next year explaining exceptions. Draw it around the project — the data, the named people, the specific systems, and the defined transfer paths — and you have something an assessor can follow and a researcher can live with.

"Air-gapped" is not a complete answer

We hear it constantly and it is almost never the whole story. An isolated environment still involves removable media, maintenance laptops, remote vendor support, manual exports, identity administration, backups, logging, physical access, software installation, and — the one everybody forgets — how results get out for reporting and publication.

Isolation is a control. It is not a scope determination.

The one thing that undoes all of it

One researcher emailing a controlled dataset from the commercial tenant because the enclave was slow that morning.

Whoever designs your boundary, budget for training and for technical controls that make the wrong path genuinely hard. A boundary that depends on discipline is a boundary that fails during a deadline week.

✅ Which category of help do you actually need?

You now know your likely level, your likely scope, and your architecture options. That is the moment the vendor conversation gets cheap instead of expensive.

Provider category — Use it when — Do not treat it as — Verify before you hire
Provider categoryUse it whenDo not treat it asVerify before you hire
RPO / RP (Registered Practitioner Organization / Registered Practitioner)You need scoping, determination support, SSP and POA&M work, or rule interpretationA certifying assessorCurrent Cyber AB status, R&D and research-instrument experience, exact deliverables, conflict-of-interest boundaries
MSP / MSSP (Managed Security Service Provider)You need implementation and ongoing operation — identity, logging, endpoint, monitoring, incident responseA substitute for your own accountabilityCMMC experience, CUI handling, responsibility matrix, what evidence they actually produce for you
CUI enclaveCUI can be bounded to specific projects, people, and systemsA shortcut that erases scopeSupported applications, instrument integration, FedRAMP position, entry and exit paths, exit and data-export terms
GRC platformYou need a system of record for controls, evidence, SSP and POA&M workflowProof that controls are implementedExportable assessor-ready evidence and accurate Revision 2 mapping
C3PAO (CMMC Third-Party Assessment Organization)A valid Level 2 certification assessment is required and you are assessment-readyA readiness implementer for the same engagementCurrent authorized status in the official Cyber AB Marketplace, scope, availability, and conflict-of-interest handling

On independence, precisely: the current Cyber AB operational documents reviewed for this article are the CMMC Assessment Process (CAP) v2.0 and Code of Professional Conduct (CoPC) v2.0. Under 32 CFR Part 170, C3PAOs must follow the Cyber AB's conflict-of-interest and Code of Professional Conduct policies. The Cyber AB Code of Professional Conduct applies a three-year independence lookback to covered CMMC ecosystem members and assessment-team conflicts: a C3PAO must not assess an organization it helped prepare for that CMMC assessment during the prohibited period. Keep readiness and formal assessment in separate procurement lanes, check organizational and personnel affiliations, and get the conflict analysis in writing before you sign.

Compare CMMC provider categories → · Who should you hire first? →

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. Do not submit CUI, drawings, source code, export-controlled content, or sensitive contract details.

A note on why you will not find vendor names on this page: this is a determination page. You are trying to find out whether you have a problem. Recommending a specific company before that question is answered would be selling you a solution to a problem we have not established you have — and it would undercut the only thing that makes this page worth reading.


Why does the written determination matter before you attest?

Because a written determination supports the reasonableness of your scope; it does not immunize a false statement or replace a control you were required to implement. Cybersecurity enforcement increasingly targets the gap between what contractors represented and what their systems could prove.

In June 2026, DOJ announced that LOGZONE, Inc. agreed to pay $507,144 to resolve False Claims Act allegations involving Navy contracts. DOJ alleged the company reported a NIST SP 800-171 score of 110 while a later DCMA assessment produced a score of negative 170. The settlement resolved allegations; there was no determination of liability.

Research organizations are not outside this pattern. In September 2025, the Georgia Tech Research Corporation agreed to pay $875,000 to resolve civil cyber-fraud allegations tied to Air Force and DARPA contracts. Again, the settlement resolved allegations without a determination of liability.

Neither case says a contracting officer letter makes an inaccurate assessment safe. It does not. The useful lesson is narrower:

  • keep the written government basis for a fundamental-research designation;
  • keep the written CUI categories and marking instructions;
  • keep the award and modification that state the current CMMC status;
  • keep the system boundary and evidence that support what you post or affirm; and
  • do not convert an unanswered question into a perfect score.

The practical instruction: whatever you conclude about scope, write down how you concluded it, cite the authority, date it, and keep the correspondence. If your answer depends on a government determination, the file should contain the government's words, not an assumption your vendor supplied.


Which letters should you send this week?

These are not gated. Copy the applicable letters, change the brackets, and send them. If a determination takes four weeks to come back, the clock starts when you send, not when you finish reading.

1. To your contracting officer—requesting the fundamental-research determination

Subject: Request for written fundamental-research determination — [Contract/Award No.]

[Name],

We are documenting our information-safeguarding obligations under [Contract/Award No.]. To scope those obligations accurately, we request written confirmation of:

  1. Whether the Government has determined this effort, in whole or in part, to be fundamental research under NSDD-189 and the applicable award terms, including DFARS 252.204-7000 where present.
  2. The RDT&E budget activity funding the effort.
  3. Whether the scoped effort is expected to involve Federal Contract Information, covered defense information, or other Controlled Unclassified Information.
  4. The portion of the statement of work covered by the determination and any publication, release, export-control, or distribution restrictions that limit it.

We are asking so that we neither under-protect Government information nor apply unnecessary controls to research intended for public release.

[Name, title, company, CAGE code]

If the answer is “no determination has been made,” that is useful. It tells you the question is still open, which is when it is cheapest to raise.

2. To your contracting officer—requesting CUI categories and marking guidance

Subject: Request for CUI categories and marking guidance — [Contract/Award No.]

[Name],

To scope our information systems correctly, please identify, or coordinate identification with the program office, information owner, or agency CUI program of:

  1. The CUI categories, if any, expected to be provided to us or generated by us under this effort, using the National Archives CUI Registry category names and markings.
  2. The information, deliverables, or data elements to which those categories apply.
  3. Any distribution statements, limited-dissemination controls, marking guidance, or Security Classification Guide.
  4. The CMMC level and assessment type currently required, and whether a prior Level 2 (C3PAO) or Level 3 designation has been amended following the July 13, 2026 implementation suspension.

[Name, title, company, CAGE code]

3. To your prime—asking what the current flow-down requires

Subject: CMMC flow-down clarification — [Subcontract No.]

[Name],

Following the July 13, 2026 suspension of the CMMC Phase II transition, we are confirming our obligations under [Subcontract No.]. Please confirm in writing:

  1. The CMMC status and assessment type you require of us today.
  2. The contractual provision that creates that requirement and whether it has changed since July 13, 2026.
  3. Which categories of FCI or CUI you expect to transmit to us or require us to generate, and by what method.
  4. Whether any portion of our scope of work has been designated fundamental research by the Government.
  5. Any Security Classification Guide, distribution statement, or marking instruction that applies.

[Name, title, company, CAGE code]

4. To your agreements or grants officer—for non-FAR instruments

Subject: Information-safeguarding terms — [Agreement No.]

[Name],

To scope our obligations under [Agreement No.] accurately, please confirm in writing:

  1. Which cybersecurity, CUI, export-control, publication, or information-safeguarding terms apply under this agreement.
  2. Whether a CMMC status or other assessment requirement has been established for this effort.
  3. Whether the Government expects to furnish, or expects us to generate, information requiring safeguarding.
  4. Who will identify the applicable CUI categories and provide marking or distribution guidance.

[Name, title, company]

Send the letters that match your instrument and position. A prime contractor does not need the prime-flow-down letter; a subawardee without direct government access may start with its prime. They go to different people and come back on different clocks.


What should an R&D firm do in the next 30 days?

Open one active award today. Answer Questions 2 and 4 from the document; send the applicable requests for Questions 1 and 3.

The correct first move for an R&D firm is a contract and data review, not a technology purchase. In thirty days a small team can inventory its awards, extract the governing clauses, map where controlled information enters and leaves, request the two determinations it cannot make itself, draft a candidate boundary, and identify which provider category — if any — it needs.

Days — Action — Output
DaysActionOutput
1–3Inventory active and pending DoD awards, including subawardsAward register
1–5Extract every FAR/DFARS clause and security term from each awardClause matrix
3–6Send the applicable lettersCorrespondence log with dates
5–10Identify what information you receive, what you generate, and what is markedData register
8–14Map people, systems, instruments, cloud services, partners, and transfer pathsData-flow map
12–18Sort candidate assets into the five § 170.19 categoriesDraft assessment scope
15–20Log responses to your letters; escalate non-responsesDetermination file
18–24Compare boundary options against how your researchers actually workArchitecture decision memo
22–28Run a baseline gap review against the applicable requirement setFindings list
25–30Select the provider category that closes the verified gapsScoped statement-of-work request

Do not buy a CUI enclave because your company does DoD research. First establish which project information is actually controlled, who needs it, which instruments must touch it, and whether the proposed environment can support those workflows. An enclave that cannot run your simulation stack is not a compliance solution. It is an expensive inconvenience.


Which primary sources support this guide?

We do not ask you to take our word for any regulatory claim. Here is the source set reviewed on August 18, 2026 and the decision each source supports.

Primary source — What it supports
Primary sourceWhat it supports
32 CFR Part 170 and the October 15, 2024 Federal Register final ruleCMMC levels, assessments, affirmations, asset scoping, POA&M rules, incorporated NIST editions, effective date, and DoD's response rejecting a blanket fundamental-research exemption for systems that handle FCI or CUI
DFARS CMMC final acquisition ruleNovember 10, 2025 effective date, four-phase implementation structure, and the original Phase 1/Phase 2 dates
CMMC program status page and July 13, 2026 suspension releasePhase II and later milestones suspended; Phase I self-assessment requirements remain
Implementing Suspension of CMMC Phase II memorandumOnly Level 1 (Self) and Level 2 (Self) new designations during review; solicitation and contract modification instructions; no waivers; DFARS 252.204-7012 remains
DoD Basic Research Office, Fundamental Research Guidance6.1, 6.2 campus, and 6.3+ designation framework; pre-award decision; subawardee route; warning against unnecessary controls
DFARS Part 252252.204-7000, -7012, -7019, -7020, -7021, and -7025 clause and provision text
FAR 52.204-21 and FAR overhaul Part 40 deviation guideCodified basic-safeguarding clause and the limited agency-deviation context for FAR 52.240-93
15 CFR 734.8EAR fundamental-research and publication analysis
National Archives CUI Registry and marking listCurrent category groupings, category markings, banners, and Basic/Specified status
NIST SP 800-171 Revision 2, Revision 3, SP 800-172, and SP 800-172 Revision 3Publication and withdrawal dates; separation between NIST's current publications and the editions still incorporated by 32 CFR Part 170
Cyber AB ecosystem roles, official downloads, and MarketplaceCurrent RPO/RP/C3PAO role definitions, CAP v2.0, CoPC v2.0, and the official status-verification route
DOJ LOGZONE settlement release and Georgia Tech Research Corporation settlement releaseExact settlement amounts, allegations, and no-liability posture

Current version snapshot

Publication — NIST publication status — CMMC-controlling edition under current 32 CFR Part 170
PublicationNIST publication statusCMMC-controlling edition under current 32 CFR Part 170
NIST SP 800-171Revision 2 withdrawn May 14, 2024; Revision 3 is NIST's current publicationRevision 2
NIST SP 800-172Original withdrawn May 13, 2026; Revision 3 is NIST's current publicationOriginal February 2021 edition

That mismatch is deliberate legal reality until the CMMC rule is amended. Do not substitute Revision 3 into a CMMC assessment merely because it is NIST's current publication.

Regulation-stated versus operationally verified

  • Regulation-stated: what 32 CFR, FAR, DFARS, the Federal Register, and incorporated publications require.
  • Operationally verified: the July 2026 suspension status, current CUI Registry grouping, current NIST publication status, current Cyber AB role/status route, and current solicitation/topic language reviewed for this article.
  • Award-specific: your clauses, modifications, flow-down, markings, category list, program guidance, and actual data flows. No public article can verify those for you.

Verification limits

We did not and cannot establish from public sources:

  • the terms of your award or whether it has been modified after July 13, 2026;
  • the CUI categories applicable to your specific data;
  • whether your prime has amended a private flow-down;
  • current provider pricing, availability, or conflicts for a specific engagement; or
  • whether an unmarked item should be designated CUI without agency-owner direction.

Those are not holes to paper over. They are the questions the letters are designed to resolve.


Frequently asked questions

Does all defense-funded research require CMMC?

No. The governing award or flow-down, the information involved, and the contractor systems used in performance decide the path. Research does not receive a company-wide exemption merely because its results may be published.

Is fundamental research exempt from CMMC?

Not as a blanket rule. A written DFARS 252.204-7000 determination can establish that the scoped project covered by that exception involves no covered defense information. The CMMC final-rule preamble separately states that systems handling CUI remain subject to NIST SP 800-171 when DFARS 252.204-7012 applies, whether or not the contractor also performs fundamental research.

Who decides whether my work is fundamental research?

The government. Under DFARS 252.204-7000, where that clause applies, the exception depends on a written contracting officer determination after the project has been scoped and negotiated with the contracting activity and research performer. Do not self-declare it.

My work is budget activity 6.2 but we perform it in our own lab. Are we automatically fundamental research?

No. DoD's published guidance gives the 6.2 default to work conducted on a university campus. Company-facility work requires the Component's decision. Ask for it.

What is budget activity 6.1?

It is Basic Research in the DoD RDT&E budget structure. DoD guidance says 6.1 work should be designated fundamental research unless controls are mandated by statute, regulation, or executive order. That is a reason to request the written designation, not permission to ignore award terms.

Does a publication restriction automatically make the data CUI?

No. It can affect the EAR fundamental-research analysis and the release path. CUI still requires an applicable law, regulation, or government-wide policy plus agency designation or direction.

Is SBIR data automatically CUI?

No. SBIZ is a narrow CUI category in the Procurement and Acquisition grouping. It does not cover every SBIR/STTR document or research result.

Does every SBIR award require Level 1?

Do not assume so. Read the current topic and resulting award. Current Navy FY26 examples identify CMMC status at the topic level, but components and cycles vary.

Does SBIR Phase II mean CMMC Level 2?

No. SBIR phases, CMMC implementation phases, and CMMC levels are three different numbering systems.

Can the CMMC obligation change between SBIR Phase I and Phase II?

Yes, because the work, data exchanges, award terms, or CUI categories can change. Prototype and integration work often increases the chance of CTI; it does not automatically create it.

Does CMMC apply to grants and Other Transactions?

A grant or OT does not automatically receive DFARS clauses. It can contain negotiated CMMC or other safeguarding terms. Read the agreement and request the current government determination.

Is research data we generate ourselves in scope?

It can be. DFARS 252.204-7012 reaches qualifying covered defense information collected or developed by the contractor in support of contract performance, not only files the government sends. The government still owns the designation and marking direction.

Can source code be CUI?

Yes, where it meets an applicable CUI authority and is treated as covered information under the award. Not all source code is CUI, and “proprietary” is not the same determination.

Is laboratory test equipment in CMMC scope?

It can be. Test Equipment is one of the five Specialized Asset types in 32 CFR Part 170. At Level 1, Specialized Assets are out of scope and not assessed. At Level 2, they are in the assessment scope with the specialized treatment described in § 170.19.

Are Specialized Assets exempt at Level 2?

No. They receive different assessment treatment, not invisibility. Inventory, SSP, network-diagram, and risk-based treatment requirements still apply.

Can a researcher's laptop stay out of scope through VDI?

Potentially, when the architecture prevents the endpoint from storing, processing, or transmitting CUI beyond keyboard, video, and mouse interaction. Clipboard, download, print, drive mapping, synchronization, local caching, and administrative paths have to support that conclusion.

Can we use commercial cloud for CUI?

Only when the service and its use satisfy the applicable award requirements. Under DFARS 252.204-7012, a cloud service provider handling covered defense information must meet the FedRAMP Moderate baseline or equivalent, and the contractor remains responsible for its side of the shared-responsibility model.

Does a university partner inherit our CMMC status?

No. Each organization has its own systems, status, and contractual obligations. Map the information transfer and flow-down.

Do I need a C3PAO right now?

Not for a newly designated government requirement during the current suspension, because new Level 2 (C3PAO) and Level 3 designations are paused. A legacy award, an unamended subcontract, a private prime requirement, or readiness for a future requirement may still create a C3PAO-related decision. Verify the current contract before hiring one.

Is CMMC Level 2 based on NIST SP 800-171 Revision 2 or Revision 3?

Revision 2 under the current rule. NIST withdrew Revision 2 and published Revision 3, but 32 CFR Part 170 still incorporates Revision 2. See NIST SP 800-171 Revision 2 vs. Revision 3 for the authority map.

Is CMMC Level 3 based on NIST SP 800-172 Revision 3?

No, not under the current rule. NIST published SP 800-172 Revision 3 in May 2026, but 32 CFR Part 170 still incorporates the original February 2021 edition and selects 24 requirements from it.

Is Phase II still starting November 10, 2026?

No. The Department suspended that milestone on July 13, 2026, and no replacement date had been announced as of August 18, 2026.

Did the suspension eliminate DFARS 252.204-7012?

No. The implementing direction expressly kept it in force.

Does the January 2025 Level Determination Guide still let a program office designate Level 2 certification today?

Not during the suspension. It remains useful historical evidence of the selection logic, but the July 2026 direction limits new government designations to Level 1 (Self) and Level 2 (Self).

Is FAR 52.204-21 now FAR 52.240-93 everywhere?

No. FAR 52.204-21 remains the codified clause. FAR 52.240-93 appears in the FAR overhaul model deviation and controls only where an agency adopted the deviation and included the clause.

How long does Level 2 readiness take for a small research company?

There is no reliable public figure specific to R&D firms. Build the estimate after the award analysis, CUI determination, boundary, and baseline gap review — in that order.


What is the bottom line for CMMC for R&D firms?

CMMC for R&D firms comes down to four questions, and two of them usually are not yours to answer.

You can answer today: what instrument and security terms you signed, and what publication or release restrictions it contains.

You usually have to request: the written fundamental-research/budget determination and the CUI categories, markings, and distribution instructions that apply to the work.

Those answers tell you whether the stated requirement fits the work, what boundary to build, what evidence to maintain, and what kind of provider — if any — belongs in the next step. Nobody can sell you a shortcut past them, and anyone who tries is quoting a scope that has not been established.

Send the applicable letters. Then decide.

Need help deciding what type of CMMC provider you need?

Tell us your current required status, scope, and timeline, and we will route you to source-checked provider categories.

Find My CMMC Path → · Download the CMMC Readiness Checklist →

Free · no obligation · educational triage only. Do not submit CUI, drawings, source code, export-controlled content, or sensitive contract details. This intake is for provider-category routing only. Provider matching may generate referral or lead-routing compensation, disclosed at the point of recommendation.


About this report

The Defense Compliance Report Editorial Team is an independent editorial team covering CMMC and Defense Industrial Base compliance. We do not accept editorial-approval rights from sponsors. Our methodology, editorial standards, and corrections policy are published in full.

The Defense Compliance Report is not affiliated with the Cyber AB, the Department, DCMA DIBCAC, NIST, the National Archives, or any U.S. government agency.

This article is educational research and is not legal, contractual, export-control, or compliance advice. Requirements vary by award, system boundary, information handled, and modification status. The governing award and actual FCI/CUI handling set the obligation — not a checklist. Confirm scope and applicability with a qualified CMMC practitioner or federal-contracts counsel before making consequential compliance representations or purchases.

We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or provider-status verification.

Last reviewed: August 18, 2026. Next scheduled review: September 2026, or immediately upon a new CMMC rule, memorandum, class deviation, implementation date, or material Cyber AB process change.