The defense department has updated the CMMC FAQs for the second time in 3 months. In lieu of rulemaking updates the CMMC FAQs are the best place for updated guidance. This week we’re exploring DoD’s answers regarding everything from encryption to enclaves to VDI endpoints.
Transcript
[Music]
All right, folks. It is January of 2026. Happy New Year. The Department of Defense has updated the CMMC frequently asked questions twice since November of 2025. The FAQs are becoming the center of gravity for guidance updates in lieu of major rulemaking nowadays. Ironically, there are seven new answers for people to chew on. We had nothing to do with that, and that’s what we’re going to talk about today.
There were some gifts left under the tree by the Department of Defense prior to Christmas with FAQs that dropped during the holiday season. Maybe these were lost in the mail, maybe they went DHL or whatever it may be, but now they’re here. Some of the questions I’ve been getting in the couple of days since they dropped have been whether these updates mean changes to the program itself. That’s a huge misconception. These aren’t changes to the program. These are points of clarification offered from an authoritative stance. A lot of people will say the guidance is always changing and there’s a lot of turnaround in the program, but the department doesn’t see it that way. They say this is what we meant all along. People will kind of see how that works out as we go through the answers they provided. If you haven’t checked out the FAQs, that really does seem to be the best place for new guidance until we get to updated rulemaking in the future. As everybody knows, rulemaking is a process that takes a really long time. You can get to the official FAQs from the DoD CIO’s website, and we’ll put a link below so you can check those out.
The FAQ document itself is not very long, about a dozen pages. It’s split up into sections A through E. They talk about general questions about CMMC, questions about the CMMC model, questions about assessments and how those run, questions about specific implementations, although that’s sometimes a little squishy, and then questions about external service providers. I’m sure the document will expand over time, but that’s currently the structure of the FAQ document online. It’s pretty straightforward from top to bottom. Everybody should be reading it at a minimum because this is the closest you’re going to get to specific guidance from the folks in the CIO office, since they’re the ones putting out the updates in the FAQ. This is as close to the reactor as we can get currently, and that’s what everybody should be paying attention to.
On November 17th of 2025, they updated four answers in the FAQ document. The first one is Section B, Question 8: Is encrypted CUI still considered CUI? According to the DoD, yes. Encrypted CUI is still considered CUI because encryption is not considered to be a method of decontrolling controlled unclassified information under 32 CFR 2002, the official federal CUI regulation. There are guidelines about what constitutes proper decontrol, meaning taking something from CUI to no longer being CUI, and encrypting data is not a method of decontrol. Therefore, encrypted CUI is still considered to be CUI even though it is encrypted. This has been a heavy point of debate in the ecosystem over the past couple of months, and this clarification makes clear that this isn’t just opinion. It’s grounded in the regulation that underpins the program. They’ll build on this answer in subsequent questions about what happens in the cloud and certain implementations, but the key takeaway is that CUI remains CUI until it is properly decontrolled.
The second updated question is Section C, Question 8: What is the difference between an operational plan of action and a plan of action and milestones, often referred to as a POAM? According to the DoD, there is effectively a distinction between what we might call CMMC POAMs and regular POAMs. CMMC POAMs are the open items that must be closed within 180 days of your CMMC assessment, per the guidance in 32 CFR 170.21. A subset of one-point requirements are allowed to be open findings at the end of your CMMC assessment, but they must be closed out within 180 days. You receive a conditional status with open items, and to achieve final status, those items must be closed and tracked on an official CMMC POAM. In contrast, what many would consider a regular POAM, as required by NIST SP 800-171 and rooted in 800-53, refers to measures implemented to manage risks or vulnerabilities such as applying patches, addressing temporary deficiencies, or performing routine system maintenance. NIST does not formally distinguish between certification POAMs and operational POAMs; this distinction is something the DoD has created. For defense contractors, however, the distinction matters. Think of it as the difference between items identified during a CMMC assessment that must be closed within 180 days and your broader ongoing POAM activities under NIST 800-171.
The third updated question is Section E, Question 2: Can a non-FedRAMP Moderate cloud service offering store encrypted CUI data? Since encrypted CUI is still considered CUI, the answer follows logically. According to the DoD, no. The cloud service must meet security requirements equivalent to the FedRAMP Moderate baseline. That can mean FedRAMP-authorized services or FedRAMP-equivalent services, but the requirement remains. Just because CUI is encrypted does not remove the obligation for FedRAMP Moderate-level protections in the cloud under DFARS 7012. There are no carve-outs here based solely on encryption.
The fourth updated question is Section E, Question 7: Is the endpoint used to access a VDI required to be in scope for NIST SP 800-171 when implementing controls to protect CUI, or can the endpoint be considered out of scope if CUI remains entirely in the VDI instance? According to the DoD, the endpoint can be considered out of scope, provided that CUI remains entirely within the VDI. Scoping is a primary driver of cost, complexity, assessment time, and assessment expense. The more scope can be minimized, the cheaper and faster assessments become, and the lower the risk exposure. This is a significant clarification for common architectures like VDIs, where logical boundaries and data flow controls can limit assessment scope.
On January 5th of 2026, the DoD updated three more questions. The fifth question, Section C, Question 10, addresses whether CMMC assessments are required for organizations that handle only hard copy CUI. According to the DoD, no. CMMC assessment requirements address cybersecurity-related risk to CUI and apply only when CUI is processed or transmitted on a contractor-owned information technology system. Organizations that handle only hard copy CUI are not required to complete a CMMC assessment. This has sparked considerable debate. There are physical protection and media protection control families within CMMC requirements, and hard copy CUI can still be viewed, copied, photographed, or otherwise mishandled in physical environments. Yet the DoD’s position is that CMMC assessments focus on cybersecurity risk to CUI in IT systems.
The sixth question, Section C, Question 11, asks whether encryption alone can create logical separation for a network within a CMMC assessment scope. The answer is no. Properly implemented encryption provides necessary confidentiality protection, but it does not by itself prevent data transfer or enforce the security boundary of a network. Since encrypted CUI is still CUI, encryption alone does not establish a logical boundary for scoping purposes. This is particularly relevant for solution providers that heavily emphasize encryption as the primary mechanism for compliance. Contractors should be mindful of this clarification when evaluating services that position encryption as the end-all solution for meeting NIST SP 800-171 and CMMC requirements.
The seventh and final updated question is Section C, Question 12: Are enterprise networking components part of an enclave’s assessment scope when that enclave does not have a direct internet connection? According to the DoD, no. If the enclave is otherwise logically separated from the greater enterprise network, and properly encrypted CUI transmission does not extend beyond that enclave, then the CMMC assessment scope does not extend to enterprise networking components. This is another significant clarification because it can limit scope. As always, contractors should leverage clear logical separation and strong data flow controls to minimize assessment scope and cost.
Of all the updated answers, the hard copy CUI clarification has generated the most discussion. The DoD grants risk-based concessions in many areas. For example, commercial off-the-shelf procurements handling CUI may not be subject to these requirements, and certain POAM items can remain open for up to 180 days. The DoD makes risk tolerance decisions across the program, including which controls from NIST SP 800-172 are included at Level 3. In the hard copy context, the DoD has chosen not to require a CMMC assessment when no IT system processes or transmits CUI. The tension arises because if hard copy protections matter in environments with IT systems, it raises questions about consistency in environments without them. From a resource perspective, it may make sense not to expend limited assessment capacity on hard copy-only environments. However, the distinction has sparked debate about how and when physical security controls should be assessed.
These seven updated questions cover a wide range of topics, from encryption to cloud requirements to assessment scoping. The document is short, but the breadth of issues addressed is significant. This will not be the last FAQ update of the year, and likely not even of the quarter. External service provider guidance remains an open question area, and further clarifications are likely. If you have thoughts on these updates, if there are questions you want clarified, or if you think something is missing, the debate is ongoing. We’ll continue to watch for updates and talk about them when they come out. We’ll see you next week.
[Music]
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.



