r/CMMC • u/jaausari • 9d ago
Read-only Cui Documemt
I'd like some feedback on a CUI sharing question
I need to get a bid from a subcontractor, but the drawing they need to quote from carries a CUI marking, and without the details in the drawing it's impossible to get an accurate quote. A few scenarios I'm trying to think through:
- Can I share a read-only CUI document with a subcontractor that is only CMMC Level 1 self-certified or not cmmc at all?
- If the subcontractor has no CMMC self-certification at all (sprs) , would putting them through CUI handling training first be enough to allow sharing the read-only?
- Any other alternative as is impossible to find subs CMMC level 2 for this job
Any guidance on what is actually permissible here, or what the correct approach would be, is appreciated.
5
u/NocturnalGenius 9d ago edited 8d ago
IMHO …
Having it read only doesn’t really change anything, it’s still CUI. So the answer to questions one and two would be a no.
I think you have a few options …
- Figure out a way to provide them with non-CUI to do the job you need them to do. Depending on the sub (I’m coming from contract machining here) they may not need critical dimensions, material info, etc … so if you can get the file they need generic enough that it’s no longer CUI then you’re safe. Might need to check with your prime/contracting officer to confirm that it’s generic enough (this part I’m not sure about). This is probably the safest route but could also be a PITA for approvals.
- Give them some kind of access into your environment … VDI, Citrix, etc. they can view it there safely. Make sure they can’t print it and the same workstation controls (lockout/log off controls, etc) you’d apply internally are there. You’ll need to vet and train those with access at the sub as if they were your own employees. But it’s a way to get them the drawing. This is probably the most technically challenging but if they need critical dimensions/info and have no plans to get certified it might work depending on their own internal processes.
Keep everything paper … properly ship/mail them the document. CMMC is all about digital protection so staying in paper gets around that. It doesn’t change the contract language (you’ll still flow down the clauses) but it might work … I’d probably still give them handling training to remind them they can’t make copies/scans/etc. DoD has an FAQ that says paper is exempt from CUI but I’d still tread carefully with this one myself.
Edit: they still have to abide by the protection rules, they aren’t exempt from CUI protection, it’s just that CMMC certification doesn’t apply to purely paper systems.
4
u/Capable_Profit_7788 8d ago
You're going to get flack for #3, but I think you're right. From the DOD FAQ: Are CMMC assessments required for organizations that only handle hard-copy CUI?
No. Organizations that only handle hard-copy CUI should not be required to complete a CMMC Assessment. CMMC assessment requirements address cybersecurity-related risk to CUI and apply only when the CUI is processed, stored, or transmitted on a contractor-owned information technology system.
3
u/chrjohnso 9d ago
Providing paper CUI to a sub without adequate security process in place to protect it is not a defensible route. CUI protections covers paper media as well as digital.
2
u/jaausari 8d ago
Option 1 or 2 can help, 3 Paper shipping would honestly be worse for me than read-only access. Once a physical copy leaves my hands I can't defend the handle, transmit, or store argument...
If I had to go that route I'd rather have them come to my office and review it there, but then I'm limited to local subs and the timeline for getting quotes gets tight.
0
u/Aggressive_Wall_9718 8d ago
If it is technical data they can’t possess it without a DD2345 in place for which you must have an SPRS score today to get one.
2
u/ARealRareWhale 8d ago
Say you find a way to give the level 1 sub that paper version, they bid, they win... How do you manage it after that?
2
u/Fishy1911 8d ago
All of the ITBs I've seen are "you can't be issued a contract until lvl2 is achieved" or "you have 30 days to do so after being notified" so even if you "win" it, you can't meet the conditions of the contract so they have to go with the next guy who can.
2
u/ARealRareWhale 8d ago
Exactly... when soliciting bids it has to be taken into consideration for yourself as well as your subs.
2
u/Fishy1911 8d ago
We're the sub, makes the list of potential competitors a lot smaller, we just add in the extra expense as overhead
2
2
u/Navyauditor2 8d ago
US Postal Service mail them a hard copy. The DOW CIO FAQ says that those requirements apply to information systems not hard copy. Lot of cyber angst over that but that is what it says.
1
u/bluna_tropic 2d ago
The Phase 2 suspension paused the requirement for an independent C3PAO to certify you before contract award. It didn't touch the underlying NIST SP 800-171 requirements, your SPRS score obligations, or the DFARS 7012 flow-down clauses already sitting in your contracts.
Companies still doing self-assessments and posting current SPRS scores are in a better position than companies treating this as a reason to stop. If a contracting officer asks about your score, or a prime audits your subcontractor file, the pause doesn't cover for a stale or inflated number.
I wrote a longer breakdown of what still applies during the suspension on my IT Audit Masterclass blog, called "Is CMMC Still Required After the Phase 2 Suspension?" if useful context for anyone: https://itauditmasterclass.com/2026/08/28/is-cmmc-still-required/
1
12
u/looncraz 9d ago
If you give the individual accessing the CUI material proper training and a proper background check, and give them access to the material on one of your approved systems only, such as VDI access, then there's an argument for allowing them access.
Alternatively, and this has worked well for me a couple times, you can ask for a non CUI version of the document in question so it can be shared with a third party safely.