Engineering firms that design facilities, systems, or components for the Department of Defense often inherit security requirements they did not expect. CMMC and CUI sit at the center of those requirements. This guide explains what each term means, who it affects, and how a small or midsize firm can prepare without guessing.
What CMMC and CUI mean
CMMC stands for Cybersecurity Maturity Model Certification. It is a Department of Defense program that verifies whether contractors protect sensitive information on their systems. It applies to prime contractors and to subcontractors at every tier when they handle covered information.
That covered information falls into two groups. Federal Contract Information (FCI) is information that the government provides or that a contractor creates under a contract, and that is not intended for public release. Controlled Unclassified Information (CUI) is more sensitive, because the government requires specific safeguards for it even though it is not classified.
For an engineering firm, CUI can look ordinary. For example, it might include site drawings for a military installation, utility plans for a base, or technical specifications for a defense system.
How the requirements reach your firm
Most firms do not sign up for CMMC directly. Instead, the requirement arrives through contract clauses.
A prime contractor that holds a DoD contract must flow the relevant clauses down to subcontractors who will handle FCI or CUI. So a structural or MEP subconsultant on a defense project can carry the same obligations as the prime.
CMMC uses levels that scale with the sensitivity of the information. In general, the basic level covers FCI and relies on a set of foundational safeguards. Higher levels cover CUI and align with the security requirements in NIST SP 800-171.
Depending on the contract, a firm may self-assess or may need an assessment by an authorized third party. The rollout into contracts is phased, and details can change. Therefore, read each solicitation carefully and confirm your required level with the prime contractor or contracting officer.
Find where your CUI lives
You cannot protect information you cannot locate. First, list every project that involves defense work, current or recent. Then trace how files move through your firm from the moment they arrive.
Engineering data spreads quickly. A single set of base drawings might land in a project folder, get copied to a CAD workstation, sync to a laptop, and go out to a surveyor.
Each of those copies is in scope. As a result, many firms find their CUI footprint is much larger than they assumed.
Some firms reduce that footprint by creating a separate, tightly controlled environment for defense projects. People often call this approach an enclave.
It keeps CUI in a smaller set of systems, which makes assessment and daily compliance simpler. However, it only works if staff actually use it and do not copy files back out.
A practical readiness checklist
- Identify which current and expected contracts involve FCI or CUI.
- Map where that information is stored, processed, and shared, including backups and laptops.
- Decide whether to protect the whole network or build a smaller enclave.
- Write a system security plan that describes your environment and controls.
- Complete a self-assessment against NIST SP 800-171 and record gaps in a plan of action.
- Require multifactor authentication for every account that touches covered data.
- Confirm that your cloud services meet the requirements for the data you handle.
- Train staff to recognize CUI markings and handle marked files correctly.
Common gaps at engineering firms
Several gaps show up again and again in design firms. Shared logins on plotters, survey equipment, or license servers make it hard to prove who accessed what. Also, older CAD workstations sometimes run unsupported operating systems because a legacy application depends on them.
File sharing is another weak spot. Staff often send large drawing sets through consumer file transfer services when email rejects them. That habit can place CUI on a service your firm does not control.
In addition, some CUI, such as export-controlled technical data, may need a cloud environment built for government use. Confirm this with your prime and your IT partner before you choose a platform. Finally, remember that assessors look for written policies, logs, and evidence that controls work, so missing documentation can sink an otherwise secure firm.
Plan the work and the budget
Meeting NIST SP 800-171 is a project, not a checkbox. It usually touches identity, endpoints, email, file storage, logging, and physical security. Because of that, most firms phase the work over several months.
Start with the controls that reduce the most risk, such as multifactor authentication, endpoint protection, and encryption. Next, address logging and access reviews.
Then build the documentation as you go, rather than all at the end. That way, your plan of action shrinks steadily and your self-assessment reflects real progress.
If contract language is unclear at any point, involve counsel before you bid.
How WEBIT helps
WEBIT helps engineering firms understand their CMMC and CUI obligations, scope their environment, and close gaps in a realistic order. We baseline every client to the CIS Controls by default, which gives you a strong starting point that overlaps many NIST SP 800-171 requirements. In addition, every managed device gets Security Essentials, including Zero Trust EDR, application allowlisting, and vulnerability management.
For firms pursuing defense work, our managed compliance, managed SIEM, and vCISO advisory services support documentation, monitoring, and ongoing assessment. Learn more about our cybersecurity services or see how we support engineering firms.
Key takeaways
- CMMC applies to DoD contractors and subcontractors that handle FCI or CUI.
- Requirements usually reach engineering firms through flow-down contract clauses.
- Map where covered data lives before you choose tools or controls.
- An enclave can shrink your scope if staff use it consistently.
- Written plans and evidence matter as much as technical controls.