← Back to Blog

New CMMC Rule

Treatment of Controlled Unclassified Information (CUI) in Transit

XQ + Meerkat Position Paper

Authors:

Chris Haigh, Meerkat Cyber

Brian Wane , XQ Message, Inc

The newly introduced CMMC rule provides clarity on handling CUI during transmission. Specifically, the rule states that a common carrier’s information system is outside the contractor’s CMMC assessment scope, as long as CUI remains properly encrypted throughout transit.

Key Implications

This clarification means that effective endpoint encryption, such as XQ’s Zero Trust Data solution, ensures that any system storing or transmitting encrypted CUI is excluded from the CMMC assessment scope. This aligns with logical security principles, as properly encrypted CUI poses no meaningful risk.

Endpoint Encryption as a Compliance Strategy

By implementing robust endpoint encryption, contractors can:

  • Ensure CUI remains protected during transit and beyond.
  • Minimize the systems subject to CMMC assessment, simplifying compliance.
  • Reduce operational and regulatory burdens while maintaining security.

Logical Consistency and Compliance

It would be inconsistent to treat properly encrypted CUI as a security risk. Recognizing the effectiveness of endpoint encryption not only reinforces compliance efficiency but also promotes a clear, risk-based approach to data protection.

Summary

The new CMMC rule reinforces the critical role of endpoint encryption in securing CUI in transit. By utilizing XQ’s Zero Trust Data solution, contractors can confidently mitigate CUI transmission risks, streamline compliance, and strengthen their overall security posture.

References

Frequently asked questions

Is a common carrier's network in scope for a CMMC assessment when it transmits CUI?

No, under the CMMC rule a common carrier's information system is outside the contractor's Cybersecurity Maturity Model Certification (CMMC) assessment scope, as long as Controlled Unclassified Information (CUI) remains properly encrypted throughout transit. The rule clarifies how CUI is treated during transmission and reflects the logic that properly encrypted CUI poses no meaningful risk.

How can endpoint encryption reduce the number of systems in a CMMC assessment?

Endpoint encryption reduces CMMC assessment scope because systems that only store or transmit properly encrypted CUI fall outside that scope. By encrypting CUI at the endpoint, contractors keep it protected during transit and beyond, minimize the systems subject to assessment, and lower operational and regulatory burden while maintaining security. The position paper from XQ and Meerkat Cyber frames this as a clear, risk-based approach.

How does XQ help contractors protect CUI in transit?

XQ helps contractors protect CUI in transit through its Zero Trust Data solution, which provides endpoint encryption so CUI stays encrypted wherever it travels. According to the position paper by Chris Haigh of Meerkat Cyber and Brian Wane of XQ, this lets contractors mitigate CUI transmission risk, streamline compliance by keeping carrier systems out of scope, and strengthen their overall security posture.

Want the full technical detail behind this post?

Talk to the team