How to Build a CUI Data Flow Diagram for CMMC

A CUI data flow diagram for CMMC is a map of exactly how controlled unclassified information enters, moves through, is stored in, and leaves your systems, drawn so a Third-Party Assessment Organization can compare it against the way your network actually operates. Build it by inventorying every asset that touches CUI, drawing an authorization boundary around them, and tracing the data from the moment it arrives through processing, storage, transmission, and destruction, with the security control on each path labeled. Done well, the diagram sets the scope of your assessment and anchors your System Security Plan. Done poorly, it becomes the first place an assessor finds a gap.

What the Diagram Has to Show

Every CUI data flow diagram needs an authorization boundary that separates the protected environment from the rest of your corporate network. Inside that boundary, heightened security controls apply. Outside it, nothing should have access to CUI, and the diagram has to make the separation visually unambiguous.

Inside the boundary, four things need to appear:

  • Data stores. Servers, databases, file shares, backup systems, and physical storage such as filing cabinets where CUI sits at rest.
  • Processing systems. Workstations, applications, and services that actively work with CUI. Name the specific software that touches the data.
  • Transmission paths. The network routes data takes between components, with the security mechanism on each path labeled, whether that is an encrypted tunnel, a VPN, or a secure file transfer protocol.
  • External entities. Federal agencies, prime contractors, subcontractors, and cloud providers that send or receive CUI. Every entry and exit point must be clearly marked.

The diagram is the visual companion to the written system boundary in your System Security Plan, which should describe the boundary, the operational environment, connections to other systems, and how security requirements are met.1National Institute of Standards and Technology. NIST Special Publication 1318 If the SSP says encrypted email is the only authorized way to send CUI outside the boundary, the diagram should show that path and no other outbound CUI route.

The regulatory reason this matters: DFARS 252.204-7012 requires contractors to implement NIST SP 800-171 on any system that processes, stores, or transmits covered defense information.2eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting NIST 800-171 control 3.1.3 tells you to control the flow of CUI according to approved authorizations. You cannot show control over a flow you have not documented.

Inventory Before You Draw

Drawing before you gather documentation is the fastest way to produce something that fails an assessment. Start with the CUI Registry maintained by the National Archives and Records Administration to identify the specific categories of CUI your organization handles.3National Archives. CUI Registry Defense-related categories include Controlled Technical Information, DoD Critical Infrastructure Security Information, and Naval Nuclear Propulsion Information, among others. Each category may carry different handling requirements, and you need to know which ones apply before you can map controls onto the diagram.

Review your active federal contracts next. The contract language tells you what types of CUI you receive, which DFARS clauses apply, and what the government expects your security posture to look like. Pull your existing SSP if you have one; it likely describes your system boundary and many of the components you need to diagram.

Then build a complete inventory of everything that touches CUI:

  • Hardware. Server names and locations, network devices, workstations, mobile devices, removable media, and printers authorized to handle CUI.
  • Software. Applications, operating systems, encryption tools, and collaboration platforms.
  • Cloud services. Any external cloud provider used to store, process, or transmit CUI, with the authorization status of each.
  • Personnel. Roles and permissions documenting who can access specific datasets and through which systems.

Inventorying systems and understanding how data moves into, within, and out of them determines the scope of NIST 800-171 requirements that apply.1National Institute of Standards and Technology. NIST Special Publication 1318 Skip this step and you end up with a diagram that looks complete but is missing entire data paths.

Building the Diagram Step by Step

Start at the point of ingestion, where CUI first enters your environment. That might be a secure file transfer from a government agency, an encrypted email from a prime contractor, or a download from a government portal. Mark this entry point clearly and label the transmission method and the encryption protecting the data in transit.

From ingestion, trace the data through each internal system it touches. Use directional lines showing which way data moves. If CUI arrives by secure file transfer, gets processed on a workstation, and then gets saved to a database, three connected nodes with two directional lines capture that flow. Label each connection with the protocol or method in use. Include the firewalls and routers along the path. Those are your security protection assets, and assessors need to see them.

When data reaches a storage point, show whether it stays there or moves further. Backup processes matter here. If CUI is replicated to a backup server or archived to long-term storage, those secondary paths need their own flow lines and labels. This is where diagrams get complex, and it is where auditors catch the most gaps.

For outbound transmission, show the path from the internal system through the authorization boundary to the recipient. If you send CUI to a subcontractor, the diagram should show the transmission method and identify the external entity by name or role. The same applies to CUI sent back to a government agency.

Finally, account for destruction. When CUI reaches the end of its retention period, the diagram should show the path to destruction, whether that means secure digital wiping, physical shredding, or degaussing. It is easy to forget and is frequently missing from diagrams that otherwise look thorough. Distinct colors or line styles for different data states (in transit, at rest, being destroyed) make the diagram easier for an assessor to follow.

Cloud Services on the Diagram

If you use an external cloud provider to store, process, or transmit covered defense information, DFARS 252.204-7012 requires the provider to meet security requirements equivalent to the FedRAMP Moderate baseline.2eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting The provider must also comply with the same incident reporting, malicious software handling, and media preservation requirements that apply to you.

Cloud services cannot sit on the diagram as generic boxes outside the authorization boundary. Show which cloud components handle CUI, what data moves to and from the cloud environment, and how that transmission is secured. If your provider has a FedRAMP Moderate authorization or has been assessed as meeting equivalent requirements, document that status alongside the cloud components or in supporting documentation.4Department of Defense Chief Information Officer. FedRAMP Authorization and Equivalency

This is where smaller contractors get caught out. A standard commercial Microsoft 365 or AWS tenant and a GovCloud tenant with FedRAMP authorization are not the same thing, even from the same vendor. The specific configuration and licensing tier matters, and the diagram has to reflect the one you actually use.

The Four Asset Categories That Must Appear

Your diagram defines the scope of your CMMC assessment. The CMMC Scoping Guide for Level 2 breaks the environment into four asset categories, and every one has to appear on the network diagram.5Department of Defense Chief Information Officer. CMMC Scoping Guide Level 2

  • CUI Assets. Systems and components that process, store, or transmit CUI. These are the core of the diagram and are subject to all applicable NIST 800-171 requirements.
  • Security Protection Assets. Systems that provide security functions to the CUI environment, such as firewalls, intrusion detection systems, and authentication servers. They do not handle CUI directly but protect the assets that do.
  • Contractor Risk Managed Assets. Systems that could interact with CUI but are not intended to, because policies and access controls prevent it. A general-purpose workstation on the same network segment, blocked from CUI repositories by access controls, fits here.
  • Specialized Assets. Equipment that handles CUI but cannot be fully secured under standard NIST 800-171 controls, such as IoT devices, operational technology, government-furnished equipment, and test equipment.

Assessors use the diagram and asset inventory to facilitate scoping discussions before the assessment even begins.5Department of Defense Chief Information Officer. CMMC Scoping Guide Level 2 If a category is missing, it becomes an immediate finding. Many organizations diagram the CUI assets meticulously and forget the security protection assets that make their access controls work.

CUI Basic vs. CUI Specified

One distinction changes what controls show up on the diagram. Federal regulations divide CUI into two subsets. CUI Basic is the default: when the authorizing law or regulation does not spell out particular handling instructions, the uniform controls in 32 CFR Part 2002 and the CUI Registry apply. CUI Specified is different: the authorizing law or regulation contains specific handling controls that go beyond or differ from the CUI Basic baseline, and the Registry identifies which categories carry them.6eCFR. 32 CFR 2002.4 – Definitions Export-controlled technical data under ITAR is one example, carrying restrictions well beyond CUI Basic safeguards. Where the flows on your diagram carry Specified CUI, the labeled controls on those paths need to reflect the stricter requirements.

What Assessors Do With It

A CMMC Level 2 certification assessment is conducted by an accredited C3PAO. Assessors use two primary methods when evaluating your data flow diagram: examining the documentation and interviewing your personnel to confirm the documentation matches operational reality.7Department of Defense Chief Information Officer. CMMC Assessment Guide Level 2

They look for evidence that your organization has identified and documented the flow of CUI across systems and network, that the documented flow accurately reflects the actual technical implementation, and that unauthorized paths or processes are not in use. A diagram showing CUI moving only through encrypted channels loses credibility quickly if an interview with IT staff turns up an unencrypted email forwarding rule.

Common documentation reviewed alongside the diagram includes policies, procedures, training materials, and system and network diagrams.7Department of Defense Chief Information Officer. CMMC Assessment Guide Level 2 Drafts do not count. Documents must be in final form to serve as evidence. Every NIST 800-171 requirement assessed must receive a finding of MET or NOT APPLICABLE for you to reach Final Level 2 status. Requirements scored NOT MET can go on a Plan of Action and Milestones, but you then have 180 days to fix them and pass a closeout assessment; if you miss that window, conditional status expires and standard contractual remedies apply.8Federal Register. Cybersecurity Maturity Model Certification (CMMC) Program

Keeping the Diagram Current

A diagram is only useful when it reflects the environment as it exists today. Validating it means comparing the visual map against actual network traffic observed by your IT staff. Technical personnel should verify that data moves through the documented paths and does not leak through side channels: a shared drive someone created as a shortcut, an unapproved collaboration tool, a personal device syncing files.

Update the diagram when any of the following happen:

  • Hardware, software, or a cloud service is added to or removed from the CUI environment.
  • A new subcontractor is onboarded who will receive CUI.
  • Your federal contract scope changes or a new CUI category is added.
  • Network architecture changes, including firewall rule modifications or new VPN configurations.
  • Organizational changes alter who has access to CUI systems.

CMMC Level 2 self-assessments are required every three years, with an annual affirmation of continued compliance in between.8Federal Register. Cybersecurity Maturity Model Certification (CMMC) Program Each annual affirmation is a certification that your security posture, including your data flow documentation, still matches reality. Letting the diagram go stale and then affirming compliance creates exposure that reaches well beyond a failed assessment.