Most standard contract forms, RFQs, SAM.gov notices, and award documents are not CUI.
However, attachments associated with these contract documents may contain CUI. Each document should be marked appropriately.
Examples of contract documents that MAY contain CUI are research and engineering data, engineering drawings, technical reports, technical data packages, design analysis, specification, test reports, technical order, cybersecurity plans, IP addresses, nodes, links.
Proc. Notes L40, L41, and L42 may be included in solicitations that will eventually require a CMMC level associated with CUI.
|
Proc. Note
|
Title
|
|
L40
|
CMMC Level 2 Self-Assessment Requirement
|
|
L41
|
Cybersecurity Maturity Model Certification (CMMC) Level 2 Certified Third-Party Assessment Organization (C3PAO) Requirement
|
|
L42
|
Cybersecurity Maturity Model Certification (CMMC) Level 3 Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Assessment Requirement
|
Standard Text Objects may be included in solicitations requiring level 2 self-assessment or (C3PAO) certification levels.
|
Standard Text Object
|
Title
|
|
RD004
|
Cybersecurity Maturity Model Certification (CMMC) Level 2 Self-Assessment Phase-In Requirement (November 10, 2025 – November 10, 2028)
|
|
RD005
|
Cybersecurity Maturity Model Certification (CMMC) Level 2 Certified Third-Party Assessment Organization (C3PAO) Phase-In Requirement (November 10, 2025 – November 10, 2028)
|
Reference: DoW CUI Program Controlled Technical Information