1. Do you handle FCI or CUI?
FCI generally points toward Level 1. CUI generally points toward Level 2. The contract and information flow determine the applicable requirement, not company size.
Small defense contractors can control CMMC complexity by confirming the contract requirement, identifying where FCI or CUI is received, stored and transmitted, defining the appropriate boundary, and building evidence as the required safeguards operate. The objective is to implement the required security without placing unrelated systems into the CMMC environment unnecessarily.
The Department's current CMMC implementation is paused in Phase 1. Level 1 Self and Level 2 Self may be required. Mandatory Phase II C3PAO requirements are suspended while the program is under review. Contract review, scope, NIST SP 800-171 implementation, SPRS readiness and annual affirmation therefore remain central to current readiness work.
FCI generally points toward Level 1. CUI generally points toward Level 2. The contract and information flow determine the applicable requirement, not company size.
Review the solicitation, contract, order and prime flow-down. Do not assume a C3PAO assessment solely because the organization handles CUI; current Phase 1 includes Level 2 Self.
Email, endpoints, shared drives, cloud applications and third-party services can all affect scope. Trace the information flow before selecting the architecture.
Inventory existing MFA, endpoint security, logging, vulnerability management, training, incident response and administrative processes before replacing or adding technology.
A broad CUI footprint can require a small business to secure, document and operate more systems than the contract requires. A purpose-built secure enclave can be appropriate when only a subset of users needs to exchange CUI.
PreVeil is one example. It provides end-to-end encrypted email and file sharing designed to work alongside Microsoft 365 or Google Workspace. PreVeil publishes FedRAMP Moderate Equivalency and FIPS 140-3-validated cryptography information. A properly scoped enclave can help keep CUI in a smaller set of users and workflows and can therefore reduce unnecessary CMMC implementation and operating cost.
An enclave does not automatically make all other assets out of scope. Level 2 scoping still includes defined asset categories such as Security Protection Assets and has rules for external service providers. Cyberneza evaluates the boundary and supporting assets before recommending an enclave architecture.
Use specialist support to trace CUI flows, categorize assets, evaluate enclave options and minimize unnecessary scope.
Use specialists for identity, logging, endpoint security, configuration, incident response and other technical gaps when internal capacity is limited.
Build the SSP, procedures and evidence map from the operating environment rather than relying on generic templates.
Your organization owns the self-assessment, SPRS submission and affirmation. A consultant can prepare and support those activities but cannot make the government-facing representation on your behalf.
Cyberneza works with small defense contractors on contract review, FCI/CUI scoping, Level 1 and Level 2 implementation, documentation, evidence preparation and assessment readiness. Start with the contract, the information flow and the systems you already operate.