← All insights

Current cybersecurity development

NIST’s New CUI Assessment Primer: What Small Defense Contractors Should Do First

NIST published SP 1352 on September 16, 2026 to help small businesses understand foundational SP 800-171 assessment concepts and prepare for assessment work.

Central Florida aerospace supplier team organizing CUI assessment evidence on a secure U.S. production floor.

A new small-business assessment resource

On September 16, 2026, NIST published Special Publication 1352, a small-business primer for assessing security requirements for Controlled Unclassified Information under NIST SP 800-171A Revision 3. NIST says the guide is intended for owners and employees managing SP 800-171 implementation, self-assessment, or preparation for external assessors.

For Central Florida defense manufacturers, engineering firms, technology providers, and subcontractors, the publication is a timely prompt to organize evidence before treating assessment as a last-minute questionnaire.

Confirm whether CUI is actually in scope

Begin with contracts, flow-down clauses, customer instructions, and systems that create, receive, process, store, or transmit CUI. Do not label every company system in scope without analysis, but do not omit connected services or administrative paths that can affect protected environments. Coordinate scope with the contracting and legal teams.

Map requirements to evidence

For each applicable requirement, identify the implementation owner, system component, policy or procedure, technical configuration, and evidence that shows the control operates. Evidence may include configuration exports, access reviews, training records, tickets, logs, test results, and approved plans. A policy statement alone may not demonstrate implementation.

Separate gaps from explanations

If a requirement is not fully implemented, record the gap, affected assets, interim protection, owner, target date, and dependency. Avoid creating evidence after the fact or describing an intended future state as current. Accurate preparation helps leadership prioritize resources and reduces confusion during assessment.

Prepare people as well as documents

Identify who can explain identity, configuration, incident response, media protection, vendor services, and system boundaries. Rehearse concise answers grounded in evidence. Preserve versions of documents and exports so the assessment record reflects the environment at the relevant time.

Use the primer as orientation, not a certification shortcut

SP 1352 provides a high-level overview; it does not replace contractual direction, SP 800-171, SP 800-171A, or assessor requirements. Use it to build assessment literacy, then obtain qualified guidance for the organization's actual obligations.

Human-reviewed draft; verify contract clauses, current NIST publications, CMMC requirements, and assessor expectations before publication.

Sources