Before your first meeting

Build your CMMC brief.

Choose broad categories for your organization, CUI workflows, and priorities. Get a brief you can edit and choose to share.

Begin the wizard
Keep this non-sensitive.Choose from the options below. There are no free-text fields or file uploads, and no answers are saved or sent as you work.
Step 1: Organization profile

Your organization

Choose an answer for each question. “Unsure” is fine. No company or person name is requested.

How large is your organization?

Which role fits best?

Step 2: CUI situation

Current state

Describe your CUI requirements.

Choose the closest current state. Uncertainty is useful planning information.

What is your CUI status?

Does your contract set requirements?

Examples include DFARS 252.204-7012 or a CMMC requirement. Do not enter clause text or contract details.

Which CMMC level is expected?

How many need CUI access?

Step 3: Workflow

Information paths

Map your CUI workflows.

Select every broad category that may receive, create, process, store, transmit, or protect CUI. Product names and technical details are not needed.

Which workflows may touch CUI?

Step 4: Operating footprint

Operating footprint

Map sites and support.

These categories help surface boundary and responsibility questions before a detailed architecture review.

How many locations are involved?

What connectivity do you need?

Where will the work happen?

Who supports IT and security?

Step 5: Stage, timing, and outcome

Priorities

Plan your first meeting.

Use the current stage, timing trigger, and desired outcomes to make the review useful.

Where are you today?

What drives your timeline?

What should the meeting cover?

Step 6: Review and meeting choice

Your planning brief

Review before you share.

Check your answers and edit any section. This planning aid does not assess readiness, interpret contracts, or determine which requirements apply.

Enable JavaScript to build a brief from your answers. You can still use the email link below to request a planning conversation.

Meeting is your choice

Share your planning brief.

Open an addressed draft in your email application, or copy the brief. Nothing is sent until you send the email. Review the draft and keep ordinary email non-sensitive.

Open email draft

CMMC basics and sources

How the requirements connect.

Each part has a different job. The order below is a planning model, not a determination of what applies to your organization.

  1. What CUI means

    The federal CUI program created a common approach for sensitive unclassified information that requires safeguarding or dissemination controls.

  2. NIST defines the safeguards

    SP 800-171 addresses protection of CUI in covered nonfederal systems. Revision 3 is NIST's current publication.

  3. Contracts define the requirements

    Applicable solicitation and contract language connects the organization to specific safeguarding, reporting, and verification obligations.

  4. CMMC defines verification

    Current CMMC Level 2 material maps to the 110 Revision 2 requirements. The required level and assessment type come from the acquisition context.

Reviewed September 2, 2026

Current program snapshot

Phase I began November 10, 2025. The CMMC program page states that Phase II was suspended July 13, 2026, while Phase I self-assessment requirements and existing contract safeguarding duties remain in place.

This planning aid will never infer a required CMMC level or produce a readiness score.