CUI Scope Indicator
Your compliance cost is determined before remediation ever begins. The single biggest driver is scope — how many systems, users, and vendors touch your CUI environment. Answer the questions below to get your scope complexity rating and a plain-language breakdown of what it means for your timeline and budget.
Answer the questions below to understand your CUI environment complexity and what it means for your compliance path. Takes about 3 minutes.
Based on your answer, your organization likely falls under CMMC Level 1, which applies to contractors who handle Federal Contract Information (FCI) but not CUI. Level 1 has a narrower set of requirements — 15 practices focused on basic cyber hygiene — and does not require a third-party assessment.
This worksheet is scoped for CMMC Level 2 environments where CUI is present. Using it for a Level 1 context would overstate your compliance burden and may send you down the wrong path.
If you're unsure whether you handle CUI, that's actually a common and important question. We'd encourage you to explore our CUI quiz for a quick starting point, or schedule time with an ISI advisor to talk through your specific obligations.