CMMC is here, but CUI still moves through email

CMMC enforcement is here. Discover how protecting CUI in email and collaboration tools supports NIST 800-171 and DFARS compliance.

by Gene Reich

August 10, 2026

A machining subcontractor in the Midwest passes its self-assessment in early 2026. The enclave is segmented, the drives are encrypted, and the score is posted in SPRS, Supplier Performance Risk System. Three weeks later, an engineer at the prime emails over a revised drawing package marked CUI, Controlled Unclassified Information, and a project manager forwards it to a tooling vendor to confirm lead times. The contractor is compliant on paper. The drawing now lives in three systems, two outside the assessment boundary, none governed.

That scenario is the condition CMMC, Cybersecurity Maturity Model Certification, enforcement now tests against. The final CMMC acquisition rule took effect on November 10, 2025, adding DFARS clause 252.204-7021 to applicable contracts. The harder deadline is November 10, 2026, when Phase 2 begins and applicable contracts can require Level 2 certification by a third-party assessment organization as a condition of award. That is the shift from self-attestation to outside verification, and assessors will increasingly expect contractors to demonstrate not only where CUI resides, but how it is transmitted, shared, and controlled.

The blind spot in a clean assessment

Demonstrating that is where most contractors stumble, because they treat CMMC as a systems-and-storage exercise. The instinct is understandable, since the visible work of Level 2 is implementing the 110 security requirements of NIST SP 800-171 inside a defined boundary. But the requirements do not stop at storage. Control 3.1.3 requires controlling the flow of CUI in accordance with approved authorizations. Control 3.13.8 requires cryptographic protection of CUI in transmission, and 3.13.11 requires that the cryptography be FIPS-validated. An assessor working from those requirements will ask where CUI travels, who authorized each path, and what protects it.

Everyday work answers those questions poorly. A spec gets forwarded to settle a quick question. A file gets dropped into chat because it is faster than the portal. Each move creates a fresh copy in a system nobody mapped, with no expiration and no record of access.

Flow-down compounds the problem and lands hardest on subcontractors. CUI moves down the supply chain by design, and every recipient becomes another copy outside the boundary, often in a mailbox holding it indefinitely. A false or inaccurate affirmation about how that data is protected can create contractual, regulatory, and False Claims Act exposure. In December 2025, the Justice Department announced a $421,234 settlement with Swiss Automation, an Illinois precision machining supplier, over allegations it failed to protect technical drawings of parts supplied to DoD prime contractors. The gap between the documented boundary and the actual data flow is a legal risk as well as a security one, and closing it starts with the data movement itself.

What to actually do

That work is a progression. See it, contain it, shrink it.

 

1. See it

Map where CUI actually moves through email, ticketing, shared drives, and chat, then follow it out to partners and vendors. Control 3.1.3 cannot be satisfied on paths nobody has traced, and the map usually surprises people. A drawing that policy says lives in one enclave often exists in a dozen places, several outside the company. Once the paths are visible, close them.

 

2. Contain it

Pull CUI out of general inboxes and chat and route it through a dedicated, controlled channel. An inbox retains by default, so every attachment becomes a standing copy. A controlled channel turns each exchange into a governed event with a defined path, which is what an approved authorization looks like in practice. Containment fixes the path, but existing copies keep accumulating.

 

3. Shrink it

That is what expiration and retention rules do. Apply them so copies stop piling up. A copy that no longer exists cannot leak, and an expiring exchange caps what a compromised account can reach. An attacker in a mailbox holding years of attachments takes years of CUI. An attacker in a channel where exchanges expire takes very little.

Making it stick

The hardest parts are verifying that a recipient is who they claim to be and proving who accessed what and when. A C3PAO works from evidence, not assertion. This is where a tool like Traceless fits. It moves sensitive exchanges through identity-verified access with an audit log, converting how CUI moved into a report instead of a reconstruction. It is one option for that layer, not a substitute for the rest of the program.

The half that fails quietly

And the program has a long runway. Phase 3 extends Level 2 certification to option exercises on existing contracts in November 2027, and Phase 4 covers all applicable DoD contracts in November 2028. A contractor that scrapes through one cycle on a self-assessment still faces a certified assessment on renewal. Assessor coverage consistently puts the journey from gap assessment to audit-ready at a year or longer, so starting today is starting on schedule, not early. The slowest work is rarely the enclave hardening, the part everyone planned for. It is tracing and closing the data flows nobody documented.

CMMC assessments begin with the boundary. Real-world breaches begin when data leaves it. Securing where CUI sits is only half the job. Securing how it travels is the half that fails quietly.

Prevent social engineering attacks

Start with one integration, validate quickly, and expand across your environment.