Reviewed 2026-09-20. Use the current solicitation, contract, 32 CFR Part 170, applicable DFARS clauses, and qualified contracting and security advisers as the authoritative basis for a decision.
CMMC levels, in plain language
CMMC requirements depend on the information and contract in scope. Under the current rule, Level 1 uses an annual self-assessment and does not permit plans of action and milestones. Level 2 may require either a self-assessment or an assessment by a CMMC Third-Party Assessment Organization, as specified by the solicitation; its assessment cycle is generally three years with annual affirmation, and limited conditional status can require closing permitted items within 180 days. Level 3 is assessed by the Defense Industrial Base Cybersecurity Assessment Center, requires a final Level 2 C3PAO status first, and also uses a three-year cycle with annual affirmation.
The Department of Defense CMMC program page and current DFARS 252.204 provisions provide primary program and contracting sources.
CUI is a boundary question before it is a feature question
The National Archives describes controlled unclassified information as government information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy. The CUI Registry glossary and category list are the starting points; the responsible contracting and security owners still need to determine what applies to the exact records and agreement.
For a manufacturing workflow, inventory the part and order identifiers, drawings, specifications, routings, work instructions, supplier records, quality evidence, attachments, exports, messages, backups, logs, support artifacts, and AI inputs that might enter the boundary. Then identify every user, device, service, provider, interface, and recovery path that can reach them.
Architecture evidence to request
- System boundary: dated diagrams showing environments, network zones, identity, data stores, integrations, administrators, support paths, providers, and exports.
- Access: proposed roles and attributes, approval authority, denied-access behavior, privilege review, session controls, and customer administration.
- Records and audit: which events are logged, what context is retained, who can retrieve or export evidence, and how integrity and retention are tested.
- AI and providers: permitted tasks and data, model and provider identity, processing location, retention and training terms, human approval, monitoring, and disablement.
- Operations: configuration, release, vulnerability, incident, backup, restore, continuity, change, and evidence-review responsibilities.
What to demonstrate with manufacturing work
- Open a representative job using authorized synthetic data and the exact roles proposed for production.
- Attempt access from a user, device, or role that should be denied; confirm the operational and retained evidence.
- Change a controlled requirement and trace approval, affected work, quality status, supplier handoff, and release.
- Exercise an unavailable provider or integration, a corrected record, a restore scenario, and the approved manual or stop path.
- Retrieve the evidence package an assessor and the customer’s accountable owners would need, tied to the proposed release and environment.
How to evaluate Cortrova
Ask Cortrova to map each applicable requirement to the proposed product behavior, customer procedure, external control, evidence, test, exception, and accountable owner. That mapping is how an alignment claim should be evaluated. Access rules, audit-integrity mechanisms, approval gates, deployment boundaries, integrations, and AI providers are evaluation areas, not universal release claims. They must be demonstrated and accepted for the exact customer scope.
Current NIST guidance includes NIST SP 800-171 Revision 3. The CMMC assessment requirements and the contract may incorporate a different revision or assessment procedure, so do not substitute the newest publication for the text actually made applicable to the solicitation.