A practical guide for scoping CUI, producing assessor-ready evidence, and closing last-mile blind spots

The CMMC standard was developed to govern cybersecurity practices within the defense industry. Businesses that support the Department of Defense, whether directly or indirectly, and that handle controlled unclassified information (CUI) have to be CMMC certified to win defense contracts.
Navigating the CMMC’s intricate requirements is already a daunting task, but getting ready for an actual assessment multiplies that difficulty tenfold. Teams tasked with verifying that CUI remains within designated perimeters must contend with data scattered across various VPNs, VDI setups, SaaS applications, and unmanaged web browsers.
This article walks through audit preparation for the three progressive levels of CMMC compliance. You'll see how to confirm assessment scope, build an evidence habit, close last-mile blind spots, and run a dress rehearsal before a formal review.
CUI is sensitive data, which could include PII, ePHI, and data elements from more than 20 categories. Due to this broad definition, many industries outside of the DoD also rely on the standard to demonstrate their ability to securely handle sensitive data. The CMMC Program final rule is the baseline teams should plan against as requirements show up in solicitations and contracts.
The CMMC’s three-tier framework measures an organization’s ability to protect sensitive information. Each escalating level corresponds to specific types of data and distinct assessment methods:
.png)
Assessors test whether your implemented controls match the CMMC’s System Security Plan (SSP), whether your required Plans of Action and Milestones (POA&Ms) are thorough and accurate, and whether you can document adequate policies and processes around data access, monitoring, media protection, and incident response.
The wrong prep path can waste months of team time, so the critical first step is to confirm the exact requirements specified in your prime contract awards and flow-downs to subcontractors. Everything after that amounts to building evidence that your organization meets these requirements.
Inventory where FCI and CUI enter, where they are stored, which roles touch them, and which subcontractors receive flow-down obligations.
Include paths that security stacks often undercount: personal devices on "bring your own device" (BYOD) programs, partners using third-party contractor access, and web apps where users can export files or paste text into unmanaged tools. Navigating the challenges of contractor and third-party access shows up across DIB supply chains, and assessors know the pattern.
Note: If a system cannot be shown to process, store, or transmit in-scope data, you need to create a clear rationale for keeping it outside the CMMC assessment’s scope. This rationale statement still needs to document owners, authentication, logging, and data-handling rules before you debate control wording.
.png)
Successful CMMC certs are built on proactive data governance. Decide early which artifacts prove each control family, who owns them, and how often they are updated.
This evidence usually includes:
Browser activity deserves special attention. Traditional stacks often cannot see what happens inside a session, which is why using your browser as an auditing support tool has become part of modern audit prep. Policy-focused logging of high-risk events is some of the most solid compliance evidence you can present to auditors.
Work with CUI increasingly happens in SaaS and web apps, and assessors will definitely audit the last mile of data access to check that your organization follows Zero Trust Network Access (ZTNA) policies of “never trust, always verify.”
Expect questions like:
If the current answer depends on a network DLP appliance catching every case, prepare for follow-ups. Network and endpoint controls rarely see the full story once data is rendered in a browser tab. You can get ahead of this audit pitfall by protecting sensitive CUI at its most vulnerable point: the browser.
CMMC Compliance: A Browser-Based Approach lays out why protecting CUI at the point of use reduces the number of systems you must prove for everyday web work. Teams modernizing federal zero trust face the same last-mile problem: users will find ways around overly restrictive controls that block their ability to do their jobs — and these bypasses show up in audits.
By the midpoint of prep, most teams need a concrete way to shrink scope and deepen evidence for web and SaaS work. That is where Island belongs in the plan.
The Island Enterprise Browser gives IT and security a governed environment for enterprise work, with policy, identity, and visibility built into the place users already spend their day. Paired with Island Data Protection, you can set boundaries on copy, paste, download, print, and risky destinations without routing every workflow through a remote desktop.
For CMMC prep, that combination helps in three practical ways:
If your team is still defining what an enterprise browser is, treat it as an audit-enabling control plane for the last mile.
Schedule an internal walkthrough that mimics assessor behavior. Pick control families that usually trip teams: access control, audit and accountability, media protection, system and communications protection, and incident response.
For each control family, require the owner to:
Give every gap identified its own ticket with an owner and due date, and make sure these tickets are closed well before assessment time.
Pro tip: Rehearse subcontractor flow-down questions as carefully as internal ones. If a partner company handles CUI and cannot show aligned controls, your own CMMC compliance is incomplete.
Use the rehearsal to decide where Island should be mandatory for CUI roles versus optional for general browsing.
CMMC audit prep succeeds when scope exactly matches contractual requirements, evidence is routine, and last-mile data handling is visible. It helps when you can demonstrate literacy with the CMMC framework itself, but at the end of the day assessors only care about the operational proof you provide.
Start with level and assessment type, map FCI and CUI with subcontractors included, and practice producing artifacts before anyone external asks. Where web and SaaS work dominate, put governance in the environment people use so the story you tell matches the sessions you can show.
If you're mapping CUI workflows and want a clearer last-mile control story for assessors, we're happy to walk through how Island applies in your environment. Schedule a demo to see access, data protection, and auditability in practice.
It depends on the CMMC level and what your contracts and flow-downs require. Confirm the assessment type in the solicitation language and with contracts counsel before you schedule a third party. The higher the CMMC certification level you aspire to, the earlier you need to build in traceability and visibility for any CUI work performed in your org (or by a subcontracting org).
The SSP should describe the in-scope environment, boundaries, and how controls are implemented. Day-of evidence is the live proof: logs, access reviews, configuration screenshots, tickets, and training records that match the plan. If the SSP and the live system disagree, assessors will notice.
Yes: if they can reach FCI or CUI, they are part of the audit. Device ownership does not remove the obligation to control access and data handling. Plan third-party contractor access and BYOD paths with the same clarity you use for corporate endpoints.
Yes, when they are accurate, time-bound, and allowed for the assessment type you face. A POA&M is not a substitute for required implemented controls. Use it to track residual risk with owners and dates, rather than papering over missing fundamentals.
Yes, because much CUI exposure happens after a user is already authenticated in a web app. Network logs rarely show copy, paste, download, or paste-into-AI events. Policy-focused browser logging produces artifacts closer to those actions, which is the point of using your browser as an auditing support tool.
Use Island for roles that handle CUI in SaaS and web apps when you want consistent access policy, data protection, and session evidence without expanding VDI. Pair the Island Enterprise Browser with Island Data Protection, then document that path in the SSP so assessors see a coherent control strategy and follow-through.