CMMC requirements start in one place, and it is not where most contractors expect. Before you touch a tool, a policy template, or a vendor pitch, you have to answer a single question: what Controlled Unclassified Information (CUI) do you actually have?
Not what a prime implies you might have. Not everything that has ever touched a government contract. The specific data, on the specific systems, tied to the specific contract language that creates the obligation in the first place.
Most contractors and subcontractors across the Defense Industrial Base (DIB) cannot answer that question with any precision, and they tend to miss it in one of two directions. Some believe they have no CUI, and they are wrong. Others believe everything they touch is CUI, so they scope their entire network into the compliance boundary because nobody ever told them otherwise. Both mistakes cost real money. The first one fails an assessment outright. The second one pays for a security program two or three times larger than the contractor ever needed to build, chasing controls around data that was never CUI to begin with.
What the mandate actually says
Since 2017, the Department of War, primarily through the Defense Federal Acquisition Regulation Supplement (DFARS), has required any contractor that processes, stores, or transmits CUI on behalf of the government to implement the 110 security controls in NIST SP 800-171, published by the National Institute of Standards and Technology (NIST). The Cybersecurity Maturity Model Certification (CMMC) program did not invent that requirement. It exists to verify it.
CMMC is the mechanism. NIST SP 800-171 is the standard. Confusing the two is where most contractors get lost, because a CMMC assessment, whatever form it takes at a given CMMC level and phase, is checking one thing: whether the security requirements in NIST SP 800-171 are actually in place. It is not a separate standard with its own rules layered on top.
Even with a reform task force inside the Department of War revisiting how CMMC phases in and how the reviews are conducted, the underlying security requirements have not moved. Know what CUI you have. Protect it to the NIST SP 800-171 standard. That part of the mandate has not changed since 2017, and it is not going to change because the paperwork around it does.
What “protect it” actually means
NIST SP 800-171’s 110 controls sort into fourteen families: access control, incident response, configuration management, media protection, physical protection, and so on down the list. Most contractors we work with are already running a version of several of these security requirements. Antivirus software, access management tools, and basic incident response steps are common across the Defense Industrial Base.
The gap is rarely a missing tool. It is a missing System Security Plan describing what you run, why you run it, and how you know it is still running months later. Federal Contract Information (FCI), the lower-sensitivity category that applies more broadly across the DIB, carries its own, shorter set of basic safeguarding requirements, and the two categories are easy to conflate if you have not scoped your CUI first.
Why this matters now
Waiting for the phase-in schedule or the assessment mechanism to settle is not a strategy. The CUI-identification work, and the control implementation behind it, is the same work regardless of who eventually checks it or when.
This is also why we do not build CMMC as a one-time deliverable. A Watch Bill and a Logbook do not care whether the reviewer is a self-assessment checklist, a third-party assessor, or the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). They document what is actually true, on an ongoing basis, which is the only version of “ready” that survives a change in the assessment mechanism.
It is also why we do not sell CMMC as a managed IT contract. Midwatch is not a general-purpose MSP. It exists specifically to hold CUI and FCI inside a boundary built to this standard, which is a narrower and more defensible job than “manage the network.”
The takeaway for contractors
Start with the CUI. Not the tool list. Not the phase-in date. Not which office ends up doing the review. Contractors and subcontractors who can name their CUI, and can show what they are doing to protect it, are ready no matter which door the verification eventually comes through.
We stand the watch for you. Come stand it with us.