Explore UAB

Research security guidance

Cybersecurity Maturity Model Certification (CMMC)

What UAB researchers need to know when planning work under a U.S. Department of Defense contract or subcontract.

What is CMMC?

The Cybersecurity Maturity Model Certification program is the Department of Defense framework for assessing how contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on nonfederal systems.

CMMC requirements began appearing in applicable DoD solicitations and contracts on Nov. 10, 2025, and are being introduced through a four-phase implementation.

Does CMMC apply to your project?

A project may be in scope when all or part of the work is performed under an applicable DoD contract or subcontract and UAB systems will process, store or transmit FCI or CUI.

Signs the project may be in scope

  • The work is under a DoD contract or subcontract.
  • The solicitation or agreement includes applicable DFARS cybersecurity or CMMC clauses.
  • UAB will receive, create, process, store or transmit FCI.
  • The project involves government-designated CUI.
  • A sponsor, prime contractor or flow-down agreement specifies a required CMMC status.

Signs the project may be outside scope

  • The work is not performed under a covered DoD contract or subcontract.
  • No FCI or CUI will be processed, stored or transmitted on UAB systems.
  • The solicitation and agreement do not include an applicable CMMC requirement.
  • The work is limited to publicly available information.

Fundamental research status is not, by itself, a blanket CMMC exemption. Confirm the project’s information and contract requirements with OSP.

Key concepts: FCI and CUI

Identifying the information that the project will handle is one of the first steps in determining the required CMMC status and assessment scope.

Generally associated with Level 1

Federal Contract Information (FCI)

Information provided by or generated for the federal government under a contract to develop or deliver a product or service that is not intended for public release.

Examples may include:

  • Nonpublic contract deliverables
  • Project schedules and performance information
  • Nonpublic technical or pricing information

Generally associated with Level 2 or Level 3

Controlled Unclassified Information (CUI)

Government-created or government-owned information that requires safeguarding or dissemination controls under an applicable law, regulation or government-wide policy.

Categories may include:

  • Export-controlled information
  • Sensitive personally identifiable information
  • Proprietary business information
  • Other information identified in the federal CUI Registry

The three CMMC levels

The DoD specifies the required CMMC status in the solicitation or contract. The information type alone does not tell you whether a Level 2 project requires self-assessment or third-party certification.

Foundational

Level 1

  • Protects FCI
  • 15 basic safeguarding requirements
  • Annual self-assessment submitted in SPRS
  • Affirmation of compliance

Advanced

Level 2

  • Protects CUI
  • 110 requirements from NIST SP 800-171 Revision 2
  • Self-assessment or C3PAO certification assessment, as specified by the DoD
  • Assessment every three years with annual affirmation

Expert

Level 3

  • Applies to selected high-priority CUI programs
  • Requires Final Level 2 C3PAO status first
  • Adds selected NIST SP 800-172 requirements
  • Government-led assessment every three years

Top tasks for researchers

Start during proposal development. CMMC affects the contract, the technical environment, project procedures, staffing and budget.

  1. Review the solicitation and agreement

    Ask OSP to identify applicable clauses and flow-down requirements, including DFARS 252.204-7012 and 252.204-7021 when present.

  2. Identify the information

    Determine whether the project will receive, generate or share FCI or government-designated CUI. Document the sponsor’s designation rather than relying on sensitivity alone.

  3. Engage support early

    Coordinate with OSP, UAB IT Information Security and other research security partners before submission so that compliance needs can be evaluated and planned.

  4. Use only approved environments

    Do not place FCI or CUI in standard collaboration, storage, email, research computing or AI services unless that specific service and use case have been approved.

  5. Plan the budget and project procedures

    Work with OSP and your research administrator to determine whether security, assessment and compliance costs may be included. Build required procedures, training and documentation into the project plan.

  6. Maintain evidence

    Keep current system security plans, procedures, inventories, diagrams, training records and other evidence needed to support assessments and annual affirmations.

CMMC implementation timeline

The phased rollout expands the types of CMMC requirements included in applicable DoD solicitations and contracts. The exact requirement for a project still comes from its procurement documents.

  1. Phase 1

    Nov. 10, 2025-Nov. 9, 2026

    Level 1 and Level 2 self-assessment requirements begin for applicable solicitations and contracts. DoD may require Level 2 C3PAO certification in selected procurements.

  2. Phase 2

    Nov. 10, 2026-Nov. 9, 2027

    Level 2 C3PAO certification is added for applicable solicitations and contracts. DoD may begin including Level 3 requirements in selected procurements.

  3. Phase 3

    Nov. 10, 2027-Nov. 9, 2028

    Level 2 C3PAO certification and Level 3 requirements expand across applicable awards and option periods as described in the rule.

  4. Phase 4

    Beginning Nov. 10, 2028

    Full implementation begins, with CMMC requirements included in all applicable DoD solicitations and contracts, including applicable option periods.

Frequently asked questions

Does CMMC apply to university research?

It can. Universities are in scope when they perform covered DoD contract or subcontract work and process, store or transmit FCI or CUI on contractor information systems.

How do I know whether my project requires CMMC?

Review the solicitation, agreement and any flow-down terms with OSP. The project team must also determine what information will be handled and which systems will be in scope.

Does all CUI require a third-party Level 2 assessment?

No. Level 2 may require either a self-assessment or a certification assessment by a CMMC Third-Party Assessment Organization. The DoD specifies the required status for the procurement.

Is fundamental research automatically exempt?

No blanket exemption should be assumed. Openly publishable fundamental research may avoid CUI restrictions in some circumstances, but OSP must evaluate the actual solicitation, agreement, information and clauses.

Can I use my usual storage, email or collaboration tools?

Only when the specific system and use case are approved for the information involved. Do not assume that a standard UAB service is approved for FCI or CUI.

What happens if the required CMMC status is not in place?

UAB may be ineligible for the award, subcontract or option period, and contractual remedies may apply if a required status expires during performance.

Resources and support

CMMC planning is a shared responsibility. Bring in contract, research security and technical partners before the proposal is submitted.

Office of Sponsored Programs

Contract, subcontract, proposal and clause guidance.

Visit OSP for sponsored programs guidance

UAB IT Information Security

Security requirements, system planning and approved technical environments.

Visit Information Security

Research Security and Export Control

Research security, export-control and related CUI questions.

Visit Research Security