May 7, 2026

Migration Readiness, 12 questions to answer before moving CUI title page

Migration Readiness: 12 Questions to Answer Before You Move CUI

Moving Controlled Unclassified Information to a new environment—whether cloud or on-premises—is one of the highest-risk activities a defense contractor can undertake from a CMMC compliance perspective. Done well, it can reduce your assessment boundary and modernize your infrastructure. Done poorly, it can invalidate your compliance posture and expose you to contract risk. This checklist gives you 12 questions to answer before you move a single byte of CUI.

Data and Classification Readiness

Cloud Security Checklist icon

  1. Have you completed a full CUI inventory and do you know exactly where all CUI currently resides? This is non-negotiable. You cannot migrate what you haven’t found.
  2. Is all CUI properly categorized and labeled per your agency’s CUI registry requirements? Labeling policies need to be in place before migration, not after.
  3. Do you have a data map showing who has access to CUI and through what systems? Access control migration requires a complete picture of your current state.
  4. Are there any CUI categories with specific handling requirements (e.g., ITAR, EAR, Privacy) that need separate migration tracks? Regulatory overlaps require separate planning.

Infrastructure and Architecture Readiness

  1. Have you selected a FedRAMP High-authorized cloud environment (Azure Government, AWS GovCloud, or equivalent) for CUI workloads? Commercial cloud is not acceptable for CUI. Confirm your target environment’s authorization status.
  2. Has your target enclave architecture been designed and reviewed by a CMMC-qualified practitioner? Architecture design mistakes are much cheaper to fix before migration than after.
  3. Are identity and access management systems (including MFA and Conditional Access) configured in the destination environment before data migration? IAM must come before data, not after.
  4. Is encryption at rest and in transit configured using FIPS 140-2 validated algorithms in the destination environment? Encryption must be verified before CUI arrives.

Compliance and Documentation Readiness

  1. Has your System Security Plan been updated to reflect the target environment’s architecture? Your SSP must describe your environment as it will exist post-migration, not as it exists today.
  2. Have you identified and documented all CMMC controls that will change as a result of the migration? A control-by-control impact analysis is a best practice before major infrastructure changes.
  3. Is your managed services provider prepared to monitor the destination environment from day one of migration? Security monitoring should not have a gap during migration.
  4. Do you have a rollback plan if the migration creates unforeseen compliance issues? A documented rollback procedure is a risk management requirement, not a sign of pessimism.

Why This Checklist Matters for Your C3PAO Assessment

C3PAO assessors look closely at your migration history. Rushed or undocumented migrations leave evidence gaps that create findings. Contractors who can show a disciplined, documented migration process—with evidence that security controls were in place before CUI moved—consistently perform better in assessments.

VSO provides migration readiness assessments as part of our pre-engagement process. We work through this checklist with every new client before any infrastructure work begins.

Conclusion

Migration readiness isn’t about slowing down—it’s about moving fast without breaking your compliance posture. Answer these 12 questions confidently before you start, and your cloud migration will be a compliance accelerant rather than a compliance crisis.

🟢 Download the full VSO Migration Readiness Checklist (PDF) for a complete version of this framework, including evidence requirements for each item. [Gated PDF — capture email to download] — CMMC Managed Services | Contact VSO

Frequently Asked Questions

Does migrating to GCC-High automatically make us CMMC compliant?

No. GCC-High provides a compliant infrastructure foundation, but CMMC compliance requires that you properly configure and operate that infrastructure. The environment is compliant; your configuration may not be.

How often should defense contractors update their CUI inventory?

At minimum annually, and any time you add new contract requirements, new systems, or new personnel with CUI access. Continuous CUI discovery tools can automate much of this process.

What should we do if we discover undocumented CUI during migration preparation?

Stop and document. Undocumented CUI is both a compliance finding and a data handling risk. Work with your CMMC MSP to classify it, update your SSP, and determine whether any prior handling was non-compliant.

How long should we maintain logs from the pre-migration environment?

CMMC requires audit log retention for at least 90 days for active analysis, with longer-term retention recommended for incident response purposes. Many contractors retain migration-era logs for 1–3 years.

Can we migrate in phases rather than all at once?

Yes, and phased migration is generally recommended. Migrate non-CUI workloads first to test your process, then migrate CUI in controlled batches with full documentation of each phase.

Author Thom Walters

Share This Story, Choose Your Platform!