Selling to the US government: the two questions that price everything
Federal contracting security looks like a wall of acronyms, but the entire cost structure of your compliance program hangs on two questions. Answer them precisely and everything else becomes a plan. Answer them vaguely and you'll buy the most expensive version of everything.
Question 1: Do you handle FCI or CUI?
Federal Contract Information (FCI) — information provided by or generated for the government under contract, not intended for public release — puts you under FAR 52.204-21: fifteen basic safeguards, which map closely to the foundations you should have anyway. Under CMMC this is Level 1, self-assessed annually.
Controlled Unclassified Information (CUI) is a different world: NIST SP 800-171's 110 requirements, CMMC Level 2, and for most CUI contracts, a third-party (C3PAO) assessment. The cost difference between FCI-only and CUI handling is not incremental — it's an order of magnitude. Which makes "do we actually receive CUI, and on which contracts?" a question worth pressing your contracting officer and primes on until you get it in writing. Some companies are carrying CUI-level obligations they don't actually have; others are handling CUI without realizing it. Both are expensive, in different currencies.
Question 2: Where does CUI live?
Scope is the cost lever nobody pulls early enough. If CUI flows through every laptop, mailbox, and file share, your assessment boundary is the whole company. If it lives in a deliberately small enclave — a handful of machines, a segregated environment, a government-cloud tenant — you're certifying ten systems instead of two hundred.
Containment beats coverage. Designing the enclave first and the compliance program second is, in practice, the single biggest cost decision a small contractor makes. This includes the M365 question: for CUI, a commercial tenant may not meet the bar — GCC or GCC High is an architecture decision with a five-figure consequence, made better before migration than after.
The clock, as it stands
| Date | What changed / changes |
|---|---|
| Nov 10, 2025 | Phase 1 began: CMMC self-assessment requirements started appearing in solicitations as a condition of award. Your SPRS score needs to be current and honest. |
| Nov 10, 2026 | Phase 2 begins: third-party (C3PAO) certification becomes the default for Level 2 / CUI contracts. |
| Nov 2027–2028 | Phases 3–4: requirements extend across effectively all DoD solicitations. |
Certification realistically takes 6–18 months of preparation and assessment, and here's the queue math that matters: assessor capacity is finite while demand is rising into each phase date. When arrivals outpace capacity, wait times grow for everyone — regardless of how ready you are. You can't expedite a queue you joined late. If a 2027 contract depends on certification, the work isn't a next-year problem.
The honesty trap
Your SPRS self-assessment score is a representation to the federal government, and inflated scores have already produced False Claims Act settlements. The pattern to avoid is scoring aspirationally — "we're basically doing that" — instead of literally. Score what an assessor would score, document gaps in a POA&M with dates, and let the number be unflattering if it's true. An honest 70 with a credible plan beats a fictional 110 in every scenario that ends in front of an auditor or a judge.
The flow-down surprise
If you're a subcontractor, requirements reach you through your prime's contract clauses — often late, often as a questionnaire with a deadline. Don't wait for it: ask your primes now what they'll require for the next contract cycle. Also worth knowing: DFARS 252.204-7012 carries a 72-hour cyber incident reporting obligation to DoD — your incident response policy needs that contact and clock built in before the incident, not during.
How this connects: the gap workbook isn't an 800-171 assessment, but its foundations overlap heavily with Level 1 and the easier half of Level 2 — it's a sensible warm-up. Seed your register from the US government section of the risk library, and put the CMMC timeline risk in front of leadership using the briefing template — it's a decision request, not an FYI.
Dates and rules current as of mid-2026; this area moves. Verify against current DoD and acquisition.gov guidance before committing budgets.