Solutions Who We Serve Insights & Events About Contact
Published on August 24, 2026 7 min read

CUI Boundary Scoping After the CMMC Pause: What Defense Contractors Still Owe Under NIST 800-171

Technology data protection cyber security on digital data background. HUD circular with padlock privacy secure concept illustration.

Summary: CMMC Phase 2 is on hold, but DFARS 252.204-7012, NIST SP 800-171, and your SPRS score are not. Scoping the CUI boundary correctly remains the decisive step.

On July 13, 2026, the Department of Defense paused CMMC Phase 2, the milestone that would have made third-party assessment a condition of award for most contracts involving Controlled Unclassified Information (CUI). For defense contractors who had spent months preparing for a November certification deadline, the announcement arrived like a reprieve, and my inbox filled with a single recurring question: does the pause permit us to slow the effort?

The answer is no, and the reason has little to do with CMMC itself. The obligation to protect CUI did not originate with CMMC. It resides in DFARS 252.204-7012, in the 110 controls of NIST SP 800-171, and in the flow down language already embedded in your contracts. Phase 2 changed how that compliance would be verified, but it did not change the underlying obligation. Your self-assessment requirements, the SPRS score you submitted, and every prime-to-subcontractor flow down remain binding. If anything, the pause removes the external deadline that had been setting your priorities and returns that judgment to your leadership.

That judgment begins with the step that matters most and receives the least attention: scoping the CUI boundary.

The enclave is not the CUI boundary

In a previous article, I described the GCC High CUI enclave as an “easy button,” a clean and defensible environment you can attest to when you need to show a C3PAO where your CUI resides. That remains true, and enclaves are genuinely useful. Yet many organizations treat the enclave as though it were the boundary itself, and it is not.

An enclave provides an email address and a collaboration space. It does not follow CUI into the operational reality of how a business runs: the engineer who opens a CUI attachment in a commercial environment, the contracts manager who receives a specification from a prime, or the subcontractor three tiers removed.

An enclave can also introduce friction that encourages people to work around it, and when the secure path is slower than the insecure one, users will naturally choose the insecure path. The enclave does not replace the boundary already governing your current contracts; it is one room in the house, not the fence around the property.

Security and compliance are not the same discipline

Consider this example that has stayed with me: a prime emails CUI to a subcontractor at a .com address. Is that message travelling to a commercial computing environment? Almost certainly. A .us address offers no guarantee of a government cloud either. This is the point at which two commonly conflated ideas, security and compliance, diverge.

Security is the sender’s system performing its function: data loss prevention inspecting the message and encryption protecting the payload so that it cannot be read if it reaches the wrong inbox. Those controls guard against the accident. Once the message clears the sender’s defenses, however, protection becomes the recipient’s responsibility. The subcontractor must then handle that CUI within its own compliant boundary, which is a contractual compliance obligation that the prime’s encryption cannot satisfy on the subcontractor’s behalf.

The difficulty is ultimately a matter of trust. Even though flow down assigns the subcontractor responsibility for protecting CUI, a loss at the subcontractor still triggers an incident response process in which the prime remains a stakeholder. Trust travels downhill; liability travels upward. Technology cannot repair a trust problem. What a rigorous CMMC Level 2 self-assessment can do is reveal where that trust is unearned and educate everyone in the supply chain about the reasons those controls exist.

Physical CUI is still CUI

Digital risk attracts attention, yet paper is where I most often see defense contractors struggle. The instinct is to reach for a technical control, but the sounder instinct would be to begin with the business process.

Let’s use a payroll analogy. A CFO or bookkeeper already understands how to protect payroll on paper through locked doors, shredding bins, secure offices, cameras, and a documented chain of custody. CUI deserves the same class of controls. On the factory floor, that discipline can be difficult when a paper trail resists confinement to a locked room. Even so, securing the printer, marking the documents, and logging the physical movement of CUI does not eliminate the risk so much as render it visible and governable. You cannot protect what you cannot see.

A disciplined approach to CUI boundary scoping

If defense contractors were to do one thing during this pause, I would ask them to scope the boundary properly. The sequence is straightforward, but it demands discipline:

  • Begin with the contract and confirm precisely which CUI obligations you have accepted;
  • Identify the business processes, systems, and people that require access to CUI to perform the work and exclude everything else;
  • Design a CUI dataflow that gives you complete visibility into how CUI is stored, processed, and transmitted, and into where the gaps remain; and
  • Finally, apply the principle of “deny all, permit some,” designing the dataflow with security first, even when doing so introduces friction. A measured amount of friction confirms that a user is working inside a secure environment rather than circumventing one.

Leave no room for shortcuts. The Department of War has been unambiguous that cybersecurity is nonnegotiable. When a user calls a control a blocker, resist the urge to grant an exception, because the true obstacle is more often a training gap or a broken process and not the technology. When a user frames a control as an obstacle, treat the objection as a diagnostic rather than a veto.

That observation points to the quietest failure of all, which is education. We assume that everyone handling CUI understands their obligations. NIST 800-171 has been in force for years, yet no prescriptive, standardized training exists for identifying CUI, handling it, and observing the rules of engagement that apply inside a boundary. Reinforcement is not condescension; it is how a control becomes a habit. A related difficulty is the document that arrives without CUI markings yet plainly contains CUI. No clean answer exists, and some senders adopt a blanket approach, asking recipients to treat every document as CUI. This practice quietly strains a compliance program by extending the boundary to material that lies outside its proper limits.

Final thoughts: why the CUI boundary is a personal risk

I will close with a case that my colleague raises in nearly every meeting, because it reframes everything we’ve discussed above. In 2025, MORSE Corp agreed to pay $4.6 million to settle False Claims Act allegations after reporting an SPRS score of 104 when a third-party review placed its actual score at negative 142, roughly a fifth of the required controls in place. The whistleblower, the company’s own head of security and facility security, received $851,000.

Will a multimillion-dollar penalty change behavior? The dollar figure is not the point. The point is that an officer of the company attested to that score, and attestation creates personal accountability. Your true cybersecurity posture may never be exposed by an actual security incident, yet it can readily be exposed by a subpoena, an audit, or a departing employee who knows that the reported posture conceals real risk: noncompliance, unreported security events, or CUI residing outside the attested boundary.

That SPRS score is a claim about all 110 NIST 800-171 controls across every asset, system, and process that stores, transmits, or handles CUI, which means the score is only as reliable as your boundary is accurate. Scope too narrowly and you underreport your risk; scope carelessly and you attest to protection you cannot demonstrate. Getting the boundary right is the first step toward ensuring that what you report as compliant is precisely what you protect, exactly as DFARS 252.204-7012 requires.

The CMMC deadline may have moved. Your obligation to know where your CUI resides, and to protect it there, has not.

How we can help

Scope the boundary with advisors who have seen it before. Aprio helps defense contractors scope the CUI boundary, tighten the self-assessment behind their SPRS score, and prepare for certification without guessing at what an assessor will ask. Talk to us about CMMC assessment services today. Connect with us

Technology data protection cyber security on digital data background. HUD circular with padlock privacy secure concept illustration.