Staffing firms CMMC compliance questions are landing in our inbox more than almost any other topic this year, and for good reason. Recruiting and staffing agencies that place workers on defense programs occupy a strange middle ground. You are not machining parts or writing weapons software, yet your recruiters may handle resumes with security clearance details, personnel data tied to defense programs, and contract documents from prime contractors. So does the Cybersecurity Maturity Model Certification actually apply to you?
The honest answer is that it depends on the data you touch, not the service you provide. This post walks through how to figure out your obligation and what to do about it.
The short answer
If your firm stores, processes, or transmits Federal Contract Information or Controlled Unclassified Information in support of a DoD contract, CMMC applies to you, regardless of the fact that you provide people rather than products. If your placements are purely commercial and no federal contract data crosses your systems, it does not.
The official DoD CMMC program page confirms the framework covers contractors and subcontractors at every tier of the supply chain. Staffing agreements with defense primes are subcontracts, which is exactly where many firms get caught off guard.
How CMMC reaches staffing firms through flow-down
CMMC obligations travel down the supply chain through contract clauses. Under DFARS 252.204-7021, prime contractors must ensure that every subcontractor holds the appropriate CMMC status before awarding a subcontract that involves FCI or CUI. Primes cannot simply vouch for you. You need your own status.
In practice, this means your staffing agreement with a defense prime will increasingly include CMMC language. Some firms discover the requirement only when a long-standing client asks for their compliance status during a contract renewal, with little time to respond. We covered how flow-down works in more detail in our CMMC subcontractor guide.
Level 1 or Level 2: which one applies to you
The level depends on data sensitivity. Level 1 applies when you handle only Federal Contract Information, meaning information provided by or generated for the government under contract that is not intended for public release. Basic examples in staffing include contract numbers, statements of work, and rate schedules from a defense prime. Level 1 requires an annual self-assessment against 15 basic safeguarding practices.
Level 2 applies when you handle Controlled Unclassified Information. This level requires implementing all 110 controls in NIST SP 800-171, and for most defense-related contracts it means an independent assessment by a certified third party. With C3PAO certification becoming mandatory for new Level 2 awards on November 10, 2026, and assessor backlogs already growing, timing matters. Our plain-language comparison of CMMC Level 1 vs Level 2 can help you place yourself.
What CUI looks like in staffing work
Staffing executives often assume CUI means blueprints and technical drawings. It is broader than that. In a staffing context, CUI can include:
- Personnel rosters and staffing plans tied to a specific defense program
- Candidate records containing clearance levels, adjudication details, or program access information
- Onboarding documents that reference controlled program details or facility access procedures
- Emails and shared files from a prime that carry CUI markings
If any of this sits in your applicant tracking system, your email, or your recruiters' laptops, you are storing CUI. The National Archives CUI Registry maintains the official categories if you want to check specific document types.
Five questions to determine your obligation
- Do any of your client agreements support a DoD prime or higher-tier subcontractor?
- Do those agreements contain DFARS 252.204-7012, 7019, 7020, or 7021 clauses? Check the fine print.
- Do your systems store candidate or personnel data connected to a defense program?
- Have you received any documents from clients marked CUI or with distribution statements?
- Has a client asked about your SPRS score or CMMC status in the last year?
If you answered yes to the first question and any other, you should assume CMMC applies and verify your level rather than wait for a client to force the issue.
Waiting carries real costs. Primes are already screening subcontractors by SPRS score and CMMC status during teaming decisions, so non-compliant staffing firms simply stop appearing on bid teams. There is no warning letter, just fewer requests. And because certification and remediation take months, a firm that starts only when a client demands proof usually cannot respond in time. The firms that keep their defense placements through 2027 will be the ones that verified their obligations in 2026.
Find Out Exactly Where You Stand
The CGA CMMC Gap Assessment Grant provides a $5,000 in-kind professional assessment against all 110 NIST SP 800-171 controls — fully funded, no cost to your firm.
Apply for the Grant →How to fund your gap assessment
The gap between where most staffing firms stand and full NIST SP 800-171 compliance is real but manageable, and you do not have to fund the first step yourself. The CMMC Gap Assessment Grant from Cyber Grants Alliance provides a $5,000 in-kind assessment that evaluates your firm against all 110 controls and delivers a remediation roadmap.
For a staffing firm, the assessment typically focuses on your applicant tracking system, email environment, and remote recruiter workstations, which are the places CUI actually lives in your business. You come out knowing exactly what to fix and in what order.
Apply for the grant before your next contract renewal puts the question to you on someone else's timeline.