How the requirements connect.
Each part has a different job. The order below is a planning model, not a determination of what applies to your organization.
What CUI means
The federal CUI program created a common approach for sensitive unclassified information that requires safeguarding or dissemination controls.
NIST defines the safeguards
SP 800-171 addresses protection of CUI in covered nonfederal systems. Revision 3 is NIST's current publication.
Contracts define the requirements
Applicable solicitation and contract language connects the organization to specific safeguarding, reporting, and verification obligations.
CMMC defines verification
Current CMMC Level 2 material maps to the 110 Revision 2 requirements. The required level and assessment type come from the acquisition context.
Reviewed September 2, 2026
Current program snapshot
Phase I began November 10, 2025. The CMMC program page states that Phase II was suspended July 13, 2026, while Phase I self-assessment requirements and existing contract safeguarding duties remain in place.
This planning aid will never infer a required CMMC level or produce a readiness score.