Summary
Cybersecurity Maturity Model Certification (CMMC) readiness should not start with a spreadsheet of controls. It should start with the data. For defense contractors handling controlled unclassified information (CUI), the most effective path to CMMC is to identify where CUI lives, how it moves, who touches it, and where it should never go. Once that is clear, organizations can define scope, apply markings, enforce controls, and generate audit-ready evidence. This data-first approach helps reduce unnecessary cost, avoid scope creep, and demonstrate that CUI is being protected in practice — not just documented in policy.
CMMC Is About Protecting Data, Not Checking Boxes
Many organizations begin their CMMC programs by opening a control spreadsheet and working line by line through NIST SP 800-171. That instinct is understandable. CMMC Level 2 is tied to the security requirements in NIST SP 800-171 Revision 2, and the CMMC program exists to verify that contractors and subcontractors are safeguarding federal contract information (FCI) and controlled unclassified information (CUI).
But starting with the controls can quickly create confusion. Teams begin asking, “Do we have this tool?” or “Who owns this requirement?” before answering the more foundational question: “where is the CUI?” This often means teams are working the problem backward.
At Fortra, we see CMMC readiness stall when organizations treat it as a control-mapping exercise instead of a data protection program. The controls are important. But they only make sense once you understand what they are protecting.
“The better approach is to start with the data, the CUI or FCI, and define and enforce your scope and controls and prove protection continuously. Regulations can shift. The fundamental principle is focused on protecting the data. And remember, CMMC is all about the data. Complying with CMMC is all about the scope.” —Skip Chapman, CISSP, C|CISO, Director of Government Programs, Fortra
CMMC is designed to provide the DoW with assurance that contractors have implemented required cybersecurity standards for systems that process, store, or transmit FCI or CUI. That means the practical starting point is not the checklist. It is the data flow.
For defense contractors handling CUI, the most effective path to CMMC is to identify where it lives, how it moves, who touches it, and where it should never go. Once that is clear, organizations can define scope, apply markings, enforce controls, and generate audit-ready evidence. This approach helps reduce unnecessary cost, avoid scope creep, and demonstrate that CUI is being protected in practice — not just documented in policy.
Why “Find the Data First” Changes Everything
A data-first CMMC program asks five questions before remediation begins:
What CUI do we receive, create, process, store, or transmit?
Where does this CUI live today?
How does it move between users, systems, applications, vendors, and external partners?
Who has access to it?
Where should it never appear?
Those questions determine the true boundary of the environment. They also determine which controls are relevant, which systems need to be assessed, which business units must participate, and which evidence will be needed later.
The CMMC Level 2 scoping guidance is built around understanding which assets are part of the assessment scope, and 32 CFR 170.19 requires the CMMC assessment scope to be specified before assessment. In practice, that means organizations need more than a network diagram. They need a defensible view of CUI movement.
Data-first compliance helps organizations avoid two common and expensive mistakes:
Over-scoping: applying CMMC controls to systems, users, and locations that never touch CUI
Under-scoping: excluding systems or workflows where CUI actually exists
Over-scoping wastes budget. Under-scoping creates assessment risk. Both usually happen when the organization starts with tools and controls before understanding the data.
Lansing Nye-Madden, Solutions Engineer at Fortra, experienced the compliance process firsthand with a manufacturer in the DoW supply chain. His experience reinforces the need to simplify CMMC by starting with CUI:
“It’s about simplifying your CMMC approach by looking at CUI first. It’s identifying where the CUI is, who handles the CUI, how it moves through the system, and where it should never be. Then building your controls around that.” —Lansing Nye-Madden, Solutions Engineer, Fortra
This is the foundation of a data-first approach. Instead of asking, “Which tool maps to which control?” teams should first ask, “Where is the sensitive data, and what needs to happen to keep it inside the approved boundary?”
What Counts as CUI?
Controlled unclassified information is sensitive information that is not classified but still requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy. The National Archives maintains the government-wide CUI Registry, which identifies CUI categories, markings, and controls.
For defense contractors, common CUI-related data may include controlled technical information, export-controlled information, procurement information, engineering drawings, specifications, program documentation, or other information received from or generated for a DoW contract.
The challenge is that CUI is rarely confined to one folder or one system. It may be found in:
Email attachments
File shares
Collaboration platforms
Cloud storage
Managed file transfer workflows
Engineering systems
ERP or quality systems
Endpoint downloads
Printouts
Removable media
Backups
Archived project folders
Shadow IT repositories
If the organization does not know where CUI is, it cannot confidently say which systems are in scope or prove that CUI is protected.
The Fortra Practitioner Model: Find, Mark, Contain, Enforce, Prove
A practical CMMC readiness program should follow a repeatable data protection lifecycle.
1. Find the CUI
Start with discovery. Identify CUI based on content, context, and user knowledge.
Content-based discovery looks for keywords, patterns, markings, document structures, and sensitive data indicators.
Context-based discovery considers where the data came from, who sent it, which contract or project it relates to, and which workflow it entered through.
User-assisted classification brings human judgment into the process, especially when users understand contract context that technology alone may not infer.
The strongest programs combine all three. Automated discovery helps scale the effort. Context helps reduce false positives. Users help confirm accuracy.
2. Mark the CUI
Once CUI is identified, it should be marked consistently. CUI markings alert users that special handling may be required, and DoW guidance states that CUI markings communicate safeguarding and handling requirements. Marking should include both human-readable and machine-readable elements where possible:
Visual labels or banners
Metadata tags
Classification labels
Watermarks
Email subject/body indicators
Persistent file attributes
Visual markings help users make better decisions, while metadata helps downstream security controls identify and protect the data.
3. Contain the CUI
After finding and marking CUI, define where it is allowed to live. This is where CMMC scoping becomes practical.
For some organizations, containment means creating a CUI enclave. For others, it means segmenting workflows, limiting repositories, restricting email routing, or separating CUI-approved environments from commercial productivity environments.
The goal is not to put every system in scope. The goal is to create a realistic boundary where CUI can be protected and monitored.
4. Enforce the Boundary
Controls should reinforce the boundary. This may include:
Encryption
Access control
Multi-factor authentication
Endpoint restrictions
Cloud application controls
Email routing rules
Removable media controls
Print restrictions
Logging and alerting
The right mix depends on risk. Some workflows need a soft control, such as a user prompt or justification. Others require hard enforcement, such as blocking, quarantine, or encryption.
5. Prove Protection Continuously
CMMC readiness is not complete when controls are configured. Organizations must be able to prove that controls are operating as intended.
NIST SP 800-171A provides assessment procedures for evaluating the security requirements associated with protecting CUI. DoW’s CMMC resources also include Level 2 assessment guidance for organizations preparing to demonstrate implementation. Strong evidence includes:
Classification events
Data movement logs
DLP enforcement records
Access logs
Encryption status
Policy application history
User justifications
Alert and incident records
System configuration evidence
SSP-aligned documentation
Weak evidence is usually assembled last-minute. Strong evidence is generated as part of daily operations.
“There’s a continuous, five-step data protection process that creates audit-ready evidence at every step, and it starts with finding the data. The five steps are find, mark, contain, protect, and prove. The most critical piece here is proving it. You’re looking back to see if you accomplished what you set out to accomplish within the scope you defined.” —Lansing Nye-Madden, Solutions Engineer, Fortra
Why This Approach Reduces CMMC Cost
CMMC cost is heavily influenced by scope. Every system in scope may require technical controls, documentation, monitoring, evidence, and assessment effort. That is why CUI discovery is not just a security step, but a cost-control step as well. A data-first approach helps organizations answer:
Which users actually need access to CUI?
Which repositories should be approved for CUI?
Which workflows can be redesigned to keep CUI contained?
Which systems can be isolated from CUI entirely?
Which legacy systems require compensating controls or segmentation?
Which third-party services are in scope?
When organizations skip this step, they often buy tools before understanding the problem. That can lead to overlapping technologies, unnecessary licenses, misconfigured controls, and continued uncertainty about whether the environment is truly ready.
CMMC Readiness Requires Business Context
CUI does not flow only through IT. It moves through sales, contracts, engineering, manufacturing, quality, procurement, finance, legal, and customer support. That is why the data-first approach requires business participation.
A security team may know where file shares are located. But only sales may know which RFPs require CUI handling. Contracts may know which DFARS clauses apply. Procurement may know which suppliers receive controlled information. CMMC readiness is more efficient when these teams participate early.
What Is the Best First Step for CMMC Readiness?
The best first step for CMMC readiness is to identify where FCI and CUI are processed, stored, and transmitted. Once the organization understands its sensitive data flows, it can define the CMMC assessment scope, apply proper markings, implement controls, and collect evidence aligned to the actual environment. Use this checklist before beginning control remediation:
CMMC Data-First Readiness Checklist:
Identify contracts that may involve FCI or CUI.
Inventory systems that receive, process, store, or transmit CUI.
Map CUI data flows across users, systems, vendors, and locations.
Identify unauthorized or unexpected CUI repositories.
Confirm CUI categories and marking requirements using official guidance.
Define the CUI boundary.
Document the boundary in the system security plan.
Apply persistent markings and metadata.
Implement risk-based controls.
Generate evidence continuously.
How Fortra Helps
Fortra helps organizations approach CMMC as a practical data protection program. Our perspective is grounded in the realities of finding sensitive data, classifying it, controlling its movement, and producing evidence that stands up to scrutiny. We help organizations focus on the data that drives true CMMC readiness.
Learn more about data-first CMMC compliance.
This article features commentary from a Fortra webinar featuring Skip Chapman, CISSP, C|CISO, Director of Government Programs at Fortra and Lansing Nye-Madden, CISSP and Solutions Engineer at Fortra. Watch the recording for a discussion on CMMC readiness, CUI discovery, scoping, audit evidence, and AI governance.