" /> Sharing CUI With Non-CMMC Vendors: Redaction and Segmentation | ITSECOPS
Guide

How Do We Share Work With Vendors That Are Not CMMC Level 2 by Redacting or Segmenting CUI?

Updated · Sep 2026 By ITSECOPS Free · No signup

CMMC questions from the field · Sharing work with vendors that are not CMMC Level 2 (or Level 1) · Updated September 2026

You have two legitimate options and one illegitimate one. Option A: share the CUI and flow the obligations down, in which case the vendor needs at least CMMC Level 2 (Self) and the DFARS 252.204-7012 clause (32 CFR 170.23(a)(2)). Option B: give the vendor a work package that contains no CUI at all, in which case the vendor needs only Level 1 if it handles FCI, or nothing under CMMC if it handles neither (32 CFR 170.23(a)(1); DoD FAQ C-Q2). DoD explicitly leaves that choice to you: “it is up to the prime contractor to determine the information that needs to be shared with a subcontractor,” and “The DoD encourages prime contractors to work with subcontractors to lessen the burden of flowing down CUI requirements.” The illegitimate option is pretending. Removing the contract number does not un-CUI a drawing (“CUI is CUI and shall be safeguarded accordingly,” DCSA CUI FAQ), a redacted copy is a new document that must contain zero CUI, and only the designating agency can decontrol the original (32 CFR 2002.18).

Decide the option before you touch the document

Question Option A: flow the CUI down Option B: redact or segment so no CUI reaches the vendor
When it fits The vendor genuinely needs the controlled content to do the work: build-to-print machining, design engineering, test labs receiving drawings or data The vendor needs scope, schedule, commercial-item requirements, facilities, staffing, or generic services, not the controlled technical content
Vendor requirement DFARS 252.204-7012 and 7021 flowed down “without alteration” (7012(m)(1)); CMMC Level 2 (Self) minimum, Level 2 (C3PAO) if your contract requires it (32 CFR 170.23(a)(2)-(4)); an affirmation in SPRS before subcontract award (7021(d)(4), (f)(2)) FAR 52.204-21 and CMMC Level 1 (Self) if the vendor will hold FCI; no CMMC status if the vendor holds neither FCI nor CUI
Your obligation Verify status before award: “ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate” (7021(f)(2)); document the vendor in your SSP Prove the package contains no CUI, keep the record of what was removed, and keep the vendor out of your CUI boundary
What it cannot do Cannot be skipped by NDA alone; an NDA is not a safeguarding standard Cannot hand a designer a hollowed-out spec and expect design work; if they need the CTI, use Option A

The golden rule of redaction

Removing CUI creates a new document. You are not decontrolling the government’s original; you cannot. Decontrol is executed by “the originator of the information, the original classification authority (OCA) if identified in a security classification guide, or designated offices for decontrolling CUI” (DoDI 5200.48 para 3.3.a(2)). The original stays CUI and stays inside your enclave. What leaves is a derivative that was authored to contain only non-CUI information, and it is non-CUI only when every item of CUI is gone and what remains does not independently qualify.

DFARS 252.204-7012(m)(1) states the test in the prime’s own words: “The Contractor shall determine if the information required for subcontractor performance retains its identity as covered defense information and will require protection under this clause, and, if necessary, consult with the Contracting Officer.” That sentence is your authority to redact, your standard for doing it, and your escape hatch when unsure.

Redaction procedure that survives an assessment

  1. Start from portion marks. If the source is portion-marked, remove every (CUI) portion and keep the (U) portions (DoDI 5200.48 para 3.4.b). If it is only banner-marked, you are analysing content by category and guessing the boundaries: flag it, and query the contracting officer or prime (see unmarked CUI).
  2. Remove by category, not by instinct. Controlled Technical Information (drawings, models, specifications, tolerances, materials, performance parameters, test data), anything with a Distribution Statement B to F or an export-control notice, government cost data, source selection information, facility and network security detail, PII, and operational or threat information.
  3. Keep what is uncontrolled. Solicitation administration, public standards and clause references, high-level purpose statements that reveal no controlled parameters, commercial-item requirements, boilerplate terms.
  4. Run the aggregation check. Read the residual document as a whole. If a competent reader could reconstruct controlled technical information from the fragments left, redact more. DoDI 5200.48 para 5.3.c requires contractors to monitor CUI “for aggregation and compilation,” and the same logic applies in reverse to what you release.
  5. Remove content for real. Delete text and flatten the file; a black box over selectable text is not a redaction. Strip metadata, embedded objects and revision history.
  6. Do not put a CUI banner on the result. A document with no CUI must not be marked CUI (32 CFR 2002.4(o)). Add a plain statement: “Sanitized derivative of [reference], contains no CUI, prepared [date] for supplier solicitation.”
  7. Second-person approval and a log. The redactor does not self-approve. A trained reviewer confirms the output, and a record of what was removed stays on the CUI side. That log is your AC.L2-3.1.3 evidence.
  8. Store it outside the enclave, deliberately. Non-CUI derivatives live in a labelled non-CUI location so they are never confused with the source.

Segmentation: keeping vendors outside the CUI boundary

Redaction handles documents. Segmentation handles systems and people. NIST SP 800-171 Rev 2 states that organisations “may limit the scope of the security requirements by isolating the designated system components in a separate CUI security domain,” using “physical separation, logical separation, or a combination of both.” The CMMC Level 2 Scoping Guide turns that into an assessment category: assets “physically or logically separated from CUI assets” are out of scope, and “An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset.”

Three patterns work in practice:

  • Separate collaboration space. A non-CUI SharePoint site or project tool where sanitized packages, schedules and commercial correspondence live. Vendors get accounts there and nowhere else.
  • Read-only, KVM-only access for the few who must see CUI. A vendor engineer who needs to view a drawing can do so through VDI or a browser-isolated session inside your enclave, with copy, print and download disabled. The vendor’s own laptop stays out of scope; the vendor’s person is still bound by the flow-down, so this is Option A with a smaller footprint, not Option B.
  • Physical separation for shop-floor partners. Printed, controlled copies signed out and back, or a dedicated workstation on your premises.

One trap: a vendor that receives no CUI but administers your systems or your security tooling is still inside your assessment. “In a scenario where IT support is handled by an MSP and where security protection data is handled by an MSSP, both the MSP and the MSSP qualify as ESPs and will be assessed as part of the Organization Seeking Assessment’s assessment scope” (DoD FAQ E-Q4; 32 CFR 170.19(c)(2), Table 4). Cloud services that store or process CUI must meet FedRAMP Moderate or equivalent (7012(b)(2)(ii)(D)). Redaction does not help with either.

Contract paperwork for each option

Vendor receives Flow down CMMC status to verify before award Reference
CUI DFARS 252.204-7012 (including paragraph (m)) and 252.204-7021 (including paragraph (f)), the CUI markings and dissemination controls, and a written agreement to handle CUI per 32 CFR 2002 Level 2 (Self) minimum; Level 2 (C3PAO) where your contract requires it; affirmation in SPRS 32 CFR 170.23(a)(2)-(4); 7021(d)(4), (f); 32 CFR 2002.16(a)(5)-(6)
FCI only FAR 52.204-21; 7021 if the subcontract carries a CMMC level Level 1 (Self) 32 CFR 170.23(a)(1); DoD FAQ C-Q2
Neither Ordinary commercial terms and NDA None under CMMC 90 FR 43560 preamble: no requirement “for a CMMC assessment” where no FCI or CUI is processed, stored or transmitted

Two further rules. You cannot add limited dissemination controls of your own to make a document “vendor-safe” or “vendor-unsafe”: “Only the designating agency may apply limited dissemination controls to CUI” (32 CFR 2002.16(b)(4)(iii)). And export control is a separate regime: a sanitized package that removes CUI may still contain ITAR or EAR technical data, and a redaction procedure built for CMMC does not clear it for foreign-national access.

Sources and clauses

  • 32 CFR 170.23: Level 1 for FCI-only subcontractors; Level 2 (Self) minimum, Level 2 (C3PAO) where required, for subcontractors that process, store or transmit CUI
  • 32 CFR 170.19(c): out-of-scope assets, VDI KVM-only endpoints, Table 4 external service provider rules
  • DFARS 252.204-7012: (b)(2)(ii)(D) FedRAMP Moderate for cloud, (m) subcontract flow-down and the “retains its identity as covered defense information” test
  • DFARS 252.204-7021 (NOV 2025): (d)(1)(ii) consult 32 CFR 170.23, (d)(4) subcontractor affirmations, (f) flow-down and pre-award status check
  • 32 CFR 2002.16: lawful government purpose, agreements with non-executive-branch entities, only the designating agency applies limited dissemination controls
  • 32 CFR 2002.18: decontrol by the designating agency; decontrolled CUI must be clearly indicated when reused
  • DoDI 5200.48, 6 March 2020: para 3.3.a(2) decontrol authority, 3.4.b portion marking, 3.7.b lawful government purpose and dissemination to contractors, 4.2 limited dissemination controls, 5.3.c aggregation
  • DoD CIO CMMC FAQ, Rev 2.3, July 2026: B-Q6 flow-down, C-Q2 FCI-only companies, E-Q1 to E-Q5 cloud and service providers
  • DCSA CUI FAQ, Version 3, May 2025: de-identifying does not remove CUI status; prime responsibility for subcontractor compliance; verifying a vendor can safeguard CUI
  • 90 FR 43560, 10 September 2025: “it is up to the prime contractor to determine the information that needs to be shared with a subcontractor”
  • 89 FR 83092, 15 October 2024: “The DoD encourages prime contractors to work with subcontractors to lessen the burden of flowing down CUI requirements”
  • NIST SP 800-171 Rev 2: section 1.1 on isolating CUI in a separate security domain; 3.1.3 information flow control
  • CMMC Level 2 Scoping Guide v2.13, September 2024: out-of-scope assets and logical/physical separation

This page is general information, not legal advice. ITSECOPS is not affiliated with the Department of Defense. Contract-specific questions belong with your contracting officer.

Answered by Gaurav Sengar, CISA

Cybersecurity expert with 12+ years across cybersecurity, IT operations and compliance. He has helped several defense suppliers and their subcontractors reach CMMC readiness, from scoping and SPRS scoring to POA&M closeout.

FAQ

Can I send CUI to a vendor that only has CMMC Level 1?

No. A subcontractor that will process, store or transmit CUI needs Level 2 (Self) at minimum under 32 CFR 170.23(a)(2), and DFARS 252.204-7021(f)(2) requires you to verify that status before award. Either bring the vendor to Level 2 or give it a package with no CUI.

If I remove the contract number and program name, is the drawing still CUI?

Yes. DCSA’s CUI FAQ is direct: de-identifying does not change the status, “CUI is CUI and shall be safeguarded accordingly.” Controlled Technical Information is controlled because of what it is, not because of the label on it.

Can a prime decontrol CUI so subcontractors do not need Level 2?

No. Decontrol belongs to the designating agency (32 CFR 2002.18; DoDI 5200.48 para 3.3.a(2)). A prime can create a new derivative that contains no CUI, which is different from decontrolling the original.

Does an NDA make a vendor eligible to receive CUI?

No. An NDA governs confidentiality between companies. Receiving CUI requires the DFARS 252.204-7012 flow-down, NIST SP 800-171 safeguarding and the applicable CMMC status. The NDA is a useful addition, not a substitute.

Need a redaction and segmentation procedure your assessor and your prime will both accept?

Book a session with Gaurav Sengar: vendor-by-vendor data mapping, a redaction workflow with second-person approval and logging, segmentation design for out-of-scope partners, and the flow-down paperwork for each tier.

BOOK A CMMC SESSION

Need help applying this to your environment?

We turn compliance guides into shipped controls. Talk to an engineer.

Book a consultation