What CUI Actually Is (and Isn't)
Controlled Unclassified Information is government-created or government-owned information that requires safeguarding under law, regulation, or agency policy, but isn't classified. If your contract has a DFARS 252.204-7012 clause, or the Statement of Work references CUI markings, you're handling it. Common examples in small-business contracts: technical drawings, unclassified export-controlled data, procurement-sensitive info, and certain program schedules or test data.
The mistake we see most often: contractors assume CUI is only what's stamped 'CUI' on a document. In practice, CUI status travels with the information, not just the marking. If a contracting officer sends you unmarked technical data derived from a marked CUI source, it's often still CUI. When in doubt, ask your contracting officer or COR for a CUI determination in writing. That single email can save you months of scope confusion later.
Also worth knowing: not everything in your business needs NIST 800-171 protection. Your accounting system, HR records, and general marketing files are almost certainly out of scope. The single best cost-saving move for a small contractor is scoping tightly, isolating CUI into a defined boundary (a specific network segment, a GCC High tenant, or a dedicated enclave) instead of trying to lock down your entire IT environment.
The Controls That Actually Move the Needle
NIST 800-171 Rev 2 has 110 controls across 14 families. Not all are equal in effort or risk reduction. If you're starting from near zero, prioritize these clusters before anything else:
- Access Control (AC): multi-factor authentication for all CUI system access, least-privilege accounts, and no shared logins. This alone addresses a large share of real-world incidents.
- Identification and Authentication (IA): unique user IDs, password complexity, and MFA enforcement — pairs directly with AC.
- Configuration Management (CM): a documented baseline for your CUI systems and a change process, even a simple one, so you can prove what's running and why.
- Incident Response (IR): a written plan and a tested contact chain. DFARS 7012 requires reporting cyber incidents to DoD within 72 hours — you need this ready before you need it.
- System and Communications Protection (SC): boundary protection (firewalls, network segmentation) around wherever CUI actually lives.
- Audit and Accountability (AU): logging on CUI systems, retained long enough to investigate an incident.
How SPRS Scoring Actually Works
The Supplier Performance Risk System (SPRS) score is a self-assessment number from -203 to 110. You start at 110 (full credit for all NIST 800-171 controls) and subtract points for each control you haven't implemented. Some controls cost more points than others; MFA and system boundary controls tend to carry heavier deductions than documentation-only controls, because NIST weighted them by risk impact.
A negative score is common for small contractors early in the process and it's not disqualifying by itself — but it is visible to contracting officers evaluating your bid, and a very low score without a credible plan to close the gap raises real questions. The practical target for most small contractors isn't a perfect 110; it's a defensible, improving number backed by a POA&M with real dates.
Submit your score in the Supplier Performance Risk System through your company's PIWS account, and keep the underlying System Security Plan (SSP) that generated it. Assessors and contracting officers can and do ask to see the SSP that supports the number — a score with no SSP behind it is a red flag, not a shortcut.
Building a POA&M a Five-Person Team Can Actually Run
A Plan of Action and Milestones (POA&M) is where good intentions go to die if you make it too big. The failure mode we see constantly: a 60-page POA&M with 80 open items, no owner assigned, and a single deadline of 'next year.' Nobody works from that document, so nothing closes.
Build it differently. For each open control, write one line: the control number, what's missing in plain language, who owns it, and a realistic date within the next 90 days. Group controls into three waves — access control and MFA first, boundary and logging second, documentation and policy third. This ordering matches how assessors and contracting officers actually weigh risk, and it lets you show real, verifiable progress at each wave instead of a wall of red status flags.
Keep the POA&M as a living document reviewed monthly, not a one-time compliance exercise. Assign one person as the accountable owner even if the work is shared — ambiguity kills POA&Ms faster than budget does. And don't let perfect be the enemy of documented: an interim control with a written compensating measure and a closure date is far more credible to an assessor than silence.
Where This Fits Into a Real Federal Contracting Practice
CMMC Level 2 assessments (self or third-party, depending on your contract's CUI sensitivity) are coming into contracts on a rolling basis, and the DoD has signaled that flow-down to subcontractors will tighten over time. Small contractors who treat this as a compliance checkbox tend to redo the work twice. Small contractors who build a right-sized, well-documented security posture once tend to win more re-competes, because their SSP and POA&M become boilerplate they can reuse across proposals.
At VAERESOURCE, we build CUI environments and compliance documentation the same way we build data and AI systems for government clients: scoped tightly to what's actually required, with auditable logs, fail-closed access controls, and a human accountable for every control in the SSP — not a vendor dashboard that generates a score nobody can explain. A NIST 800-171 program only holds up under a real assessment if the people who built it can walk an assessor through every decision. That's the standard we hold our own work to, and it's the standard we help small contractors reach without needing an enterprise-sized IT budget to get there.
Building AI or data systems your agency can trust?
VAERESOURCE is an SBA-certified SDVOSB/VOSB/WOSB data-engineering and trusted-AI firm for federal, state, and local missions. See our services.
Start a conversation →