CMMC Compliance CUI Protection for AEC Contractors and Subcontractors
CMMC compliance is no longer a future consideration for architecture, engineering, and construction firms. It is a condition of award for DoD contracts. If your firm handles Controlled Unclassified Information (CUI) or Federal Contract Information (FCI), you must demonstrate CMMC certification to bid. Otherwise, you risk losing work to competitors who are already compliant.
For AEC decision-makers, the stakes are clear: federal projects represent significant revenue streams. But CMMC compliance introduces new complexity, including scoping CUI, implementing NIST controls, managing subcontractor flow downs, and preparing for assessments. The window to act is narrowing.
CMMC enforcement is active. Solicitations now specify compliance requirements, and contracting officers verify status through the Supplier Performance Risk System (SPRS). Contractors and subcontractors alike must review flowdown obligations immediately. Cybersecurity is not an IT back-office function. For AEC firms, it is a strategic imperative that directly impacts your ability to win and deliver on DoD contracts.
Let’s jump in and learn:
- Main Takeaways
- What CMMC Compliance Requires from DoD Contractors and Subcontractors in AEC
- Understanding CUI: What It Is, How It Is Classified, and Who Must Protect It on Construction Projects
- CMMC Levels Explained: Scope, Assessment Requirements, and What Contractors Need to Achieve Level 2
- How EgnyteGov Provides a Secure Data Enclave for CMMC Compliance and CUI Protection
- Steps AEC Contractors and Subcontractors Can Take Now to Prepare for a CMMC Assessment
- Conclusion
Main Takeaways
- cybersecurity protection for contractors and subcontractors.
- CMMC compliance for AEC contractors applies when DoD work involves protected information. Architecture, engineering, and construction firms must demonstrate compliance to remain eligible for federal projects.
- CMMC Level 2 covers Controlled Unclassified Information (CUI) and requires implementation of 110 NIST SP 800-171 Rev. 2 requirements. The contract determines whether a self-assessment or C3PAO assessment is needed.
- CUI protection affects project drawings, specifications, BIM files, site plans, and security-related documentation. Not every federal project file is CUI—check contract markings and clauses.
- EgnyteGov provides a secure data enclave with granular access control, encryption, audit trails, and compliance mapping to help contractors protect CUI and Federal Contract Information (FCI).
- Subcontractors must review flowdown clauses before sharing protected data. CMMC subcontractor requirements flow down through the supply chain.
What CMMC Compliance Requires from DoD Contractors and Subcontractors in AEC
CMMC compliance is the DoD framework for assessing cybersecurity protection in contractor information systems. For AEC firms, it means proving contract data stays protected.
As of 2026:
- Solicitations can specify CMMC compliance requirements.
- The solicitation states the required level CMMC and assessment type.
- Contracting officers verify status through SPRS.
- Primes and subcontractors should review flowdown obligations.
For DoD contractor compliance, this is not a one-time checkbox. Firms must maintain continuous compliance, regularly monitor systems, update security practices, and stay assessment-ready through ongoing training and documentation.
Understanding CUI: What It Is, How It Is Classified, and Who Must Protect It on Construction Projects
Controlled Unclassified Information (CUI) is government information requiring safeguarding, but is not classified. CUI protection follows contractual and governmental requirements.
Potential AEC examples include:
- Facility drawings and engineering specifications
- Site plans, surveys, geotechnical data, and BIM files
- Security-related facility information and access documentation
- Procurement or technical information for a DoD contract
Not every federal project file is CUI. Contractors must confirm markings, clauses, and instructions. For federal contractor document management, distinguishing CUI from FCI matters. FCI is broader than Controlled Unclassified Information: it is nonpublic information provided or generated for the government under the terms of the contract.
CMMC Levels Explained: Scope, Assessment Requirements, and What Contractors Need to Achieve Level 2
The required level depends on the contract and the type of data that’s being protected. CMMC Level 2 is the key level for organizations protecting CUI.
Level | Focus | Assessment |
Level 1 | FCI; 15 security requirements | Annual self-assessment |
Level 2 | CUI; 110 requirements that are derived from NIST SP 800-171 Rev. 2 | Self-assessment or C3PAO assessment, as specified by contract |
Level 3 | Certain highly sensitive CUI; All CMMC Level 2 requirements, plus 24 selected NIST SP 800-172 requirements | DIBCAC assessment |
For CMMC Level 2, firms must implement requirements and maintain evidence. Final status is generally current for three years. CMMC certification depends on the contract, so review the solicitation carefully.
How EgnyteGov Provides a Secure Data Enclave for CMMC Compliance and CUI Protection
A secure data enclave is a controlled environment for authorized users to store, access, and collaborate on sensitive information. EgnyteGov provides this foundation for CUI or FCI security.
The EgnyteGov CMMC solutions include:
- Controlled CUI environments
- Granular access control
- Encryption, Single Sign-On (SSO), and Multi-Factor Authentication (MFA) capabilities
- CUI discovery and labeling
- Audit trails
- Compliance mapping and evidence management capabilities, with Compliance Center and Compliance Agent
The EgnyteGov solutions can reduce assessment scope when properly configured, so implementation is performed in conjunction with Egnyte’s Professional Services team. Contractors still need policies, procedures, and controls, and there will always be CMMC requirements that are owned by your organization. The CUI data enclave approach is a practical way to segment sensitive DoD work from commercial operations, simplifying compliance and reducing cost.
Steps AEC Contractors and Subcontractors Can Take Now to Prepare for a CMMC Assessment
Use this checklist to make CMMC compliance actionable:
- Scope CUI: Map where it enters, moves, and leaves.
- Define the boundary: Identify systems and repositories that handle protected information.
- Review the solicitation: Confirm CMMC level, assessment type, and flowdown clauses.
- Close gaps: Assess against NIST SP 800-171 Rev. 2 requirements. Conduct a gap analysis to identify missing controls.
- Tighten access: Use least-privileged permissions, MFA, and controlled sharing.
- Preserve compliance evidence: Maintain logs and documentation for assessments.
- Govern subcontractors: Confirm downstream parties meet applicable requirements.
For federal contractor document management, centralizing controls can simplify evidence gathering and limit uncontrolled copies. Engaging an experienced technology partner will likely reduce your time to compliance.
Conclusion
CMMC compliance is now a critical condition of award for DoD contracts. For AEC firms, this means taking action now to protect Controlled Unclassified Information, meet CMMC Level 2 requirements, and validate DoD contractor compliance across the supply chain.
EgnyteGov provides the secure data enclave and compliance mapping needed to help contractors reduce assessment scope and protect CUI and/or FCI. But compliance also depends on your policies, procedures, and people.
Don't wait. Start scoping your CUI, reviewing solicitations, and closing gaps today. The firms that act now will be the ones winning federal contracts tomorrow.
Frequently Asked Questions
CMMC is the DoD framework for verifying cybersecurity protection that’s required by contract. It can apply to AEC primes and subcontractors when their DoD contract requires CMMC for systems that handle FCI or CUI. This can include architecture firms, engineering consultants, construction contractors, specialty trades, and suppliers. The contract determines the CMMC level and assessment type. Review the solicitation rather than assuming every DoD project requires the same certification.
Controlled Unclassified Information is non-classified government information that requires safeguarding under law, regulation, or government-wide policy. On AEC projects, it may include facility drawings, site surveys, technical specifications, BIM files, security-related information, and contract-generated content. Not every project file is CUI. Firms should use contract requirements, markings, and guidance to determine scope. Strong CUI protection requires controlled access and documented handling across project workflows.
CMMC compliance has three levels. Level 1 covers FCI and requires 15 security requirements with an annual self-assessment. Level 2 covers CUI and includes 110 NIST SP 800-171 Rev. 2 requirements. Depending on the contract, it can require a self-assessment or a C3PAO assessment. Level 3 adds 24 selected NIST SP 800-172 requirements and requires a DIBCAC assessment. Contractors should follow the level and assessment type that are stated in relevant contracts.
CMMC compliance requirements can flow down when subcontractors need to protect FCI or CUI under contract. The prime should identify applicable clauses and communicate the required level and assessment type. A subcontractor should determine which systems are in scope and verify its status before handling protected data. CMMC compliance is therefore not a prime-only responsibility. However, primes must review every subcontract before granting access to protected content and confirm data exchanges with each subcontractor before sharing protected data.
EgnyteGov provides a secure data enclave with access control, encryption, Multi-Factor Authentication (MFA), and automated discovery, all of which are designed to help contractors protect CUI and FCI. It holds FedRAMP Moderate Equivalency for DoD engagements and supports compliance mapping and audit logging. The EgnyteGov CMMC solutions can reduce assessment scope when properly configured, so implementation is performed in conjunction with Egnyte’s Professional Services team. Contractors still own their policies, procedures, and evidence, while EgnyteGov provides the technological foundation to centralize and simplify compliance.
Egnyte has experts ready to answer your questions. For more than a decade, Egnyte has helped more than 23,000+ customers with millions of users worldwide.
Additional Resources

CMMC Compliance for Contractors
Protect CUI and support CMMC Level 2 compliance efforts.

CMMC Compliance Product Tour
Explore compliance workflows and CUI protection features.

Public Sector Content Governance
Secure sensitive government data with governed collaboration.