CMMC for Transportation & Logistics: What Defense-Contract Carriers Need to Know
CMMC for transportation and logistics companies is a real compliance requirement, not another generic cybersecurity checklist. It applies when your trucks, warehouses, or dispatch operations touch a Department of War contract. The Department of War was formerly called the Department of Defense, or DoD. Cybersecurity Maturity Model Certification, or CMMC, is that framework. It verifies your company has the right security controls for defense-related information.
Suppose you move household goods, freight, or shipment data under a DoD contract. CMMC may already apply to your business. This is true whether you are a moving company, a freight carrier, a broker, or a third-party logistics (3PL) provider. It has nothing to do with your ELD system, telematics platform, or general ransomware defenses on their own. Those are real concerns. They are simply a separate topic from CMMC, and we cover that side in our guide to trucking industry cybersecurity.
This guide focuses on the DoD-contract side only: where CMMC already applies to transportation and logistics, and where it doesn’t yet.
The Clearest Example: USTRANSCOM’s Defense Personal Property Program
The clearest place CMMC already reaches this industry is the Defense Personal Property Program (DP3). U.S. Transportation Command, or USTRANSCOM, runs DP3. It manages military household-goods and personal-property moves nationwide.

If your company is a Transportation Service Provider (TSP) in this program, CMMC is not hypothetical. It is already a condition of doing business.
Non-Temporary Storage (NTS) TSPs, and their subcontractors, must meet a specific bar. Any of them that possess FCI or CUI must complete a CMMC Level 1 self-assessment. They must then affirm that assessment in the Supplier Performance Risk System, or SPRS. That affirmation keeps them eligible for shipment awards.
In plain terms, for a household-goods mover or NTS provider:
- If you move military household goods or personal property under DP3, you likely already touch FCI.
- Losing SPRS-eligible status means losing shipment awards. It is not just a paperwork problem.
- The Level 1 self-assessment requirement is active now. It does not wait on a future CMMC phase.
One note for your own compliance calendar: program cycles and specific affirmation windows shift over time. Confirm the current date against your Tender of Service directly. Do not rely on a generic date from an outside guide, including this one.
Beyond Household Goods: When a Load Makes You a Subcontractor
DP3 is not the only door CMMC uses to reach transportation and logistics. Any motor carrier, freight broker, or 3PL can be pulled in too.

Suppose you move cargo or shipment data for a DoD prime contractor, or for a DoD component directly. You are likely handling FCI. That is true even if you never think of your company as a technology business. A freight invoice and a defense contract obligation are not mutually exclusive.
The flow-down mechanism has two layers. DFARS 252.204-7021 extends that same logic to the CMMC certification requirement itself. If a prime’s contract requires a specific CMMC level, that requirement flows down to you as the subcontractor. It does not stop at the prime.
This is the trap that catches carriers off guard. A company that sees itself as a vendor, filling a load and sending an invoice, can still be a CMMC-obligated subcontractor under the contract’s own terms. The prime’s paperwork decides that, not your self-description.
If your company builds parts to a prime’s drawings and specs instead of moving freight, this page is not the right fit. See our guide to CMMC for manufacturers instead.
FCI vs. CUI: The Test for a Carrier’s Shipment Data
Not every load carries the same weight under CMMC. Whether your data is FCI or CUI decides which level applies to you.

Federal Contract Information (FCI) is basic information created for, or received under, a government contract. It is not meant for public release. For a carrier, that could be as simple as a load number or shipment reference tied to a DoD contract.
Controlled Unclassified Information (CUI) is more sensitive. For a carrier, that means manifests, routing details, or cargo information that is export-controlled or otherwise CUI-marked. The moment your shipment data crosses that line, you are handling CUI, not just FCI.
Handling CUI moves you to CMMC Level 2. That level is built on the 110 security requirements of NIST SP 800-171. Level 2 is verified either by your own annual self-assessment, or by a third-party assessment from a C3PAO every three years. Which path applies depends on what your contract requires.
CMMC Level 2 covers 110, built on NIST SP 800-171.
| Category | What it looks like for a carrier | CMMC level it triggers |
|---|---|---|
| CUI (Controlled Unclassified Information) | Manifests, routing details, or cargo data that is export-controlled or CUI-marked | Level 2, self-assessment or C3PAO third-party assessment against NIST SP 800-171 |
The practical test for your own operation is short. If the cargo or its paperwork is export-controlled or CUI-marked, you are handling CUI. If it’s just a load number or shipment reference, you are likely still at the FCI-only, Level 1 tier.
The Three CMMC Levels, Applied to Transportation
Not every carrier faces the same bar. The level that applies to you depends on what kind of data you handle, not on your company’s size or fleet count.
| CMMC Level | Applies to (transportation) | Requirement basis | Assessment type |
|---|---|---|---|
| Level 2 (Advanced) | Carriers and TSPs that handle CUI, such as manifests, routing details, or export-controlled cargo data | 110 security requirements of NIST SP 800-171 | Self-assessment, or third-party assessment by a C3PAO every 3 years, depending on contract |
Most carriers and 3PLs sit at Level 1. That covers straightforward loads with basic contract data attached. TSPs handling manifests or export-controlled cargo details are pushed to Level 2. Level 3 almost never touches a transportation company. It’s reserved for a small slice of the most sensitive DoD programs.
The Flow-Down Trap: How a Prime’s Requirement Becomes Yours
CMMC doesn’t stop at the company that signs the prime contract. It travels down the supply chain, contract by contract, to everyone who touches CUI along the way.

CMMC certification works the same way. A prime cannot lawfully award CUI-relevant subcontract work to a company that hasn’t met the required level.
This matters for TSP networks specifically. A large TSP awarded a DP3 shipment often relies on a network of local moving agents to actually pack, load, and haul the freight. If that TSP’s CMMC obligation covers CUI, the obligation follows the work down to those agents too. The same logic applies to a freight broker placing loads with owner-operators or regional carriers under a defense contract.
What this means in practice for a subcontracted carrier:
- Your own CMMC status can determine whether a prime or TSP is willing to subcontract work to you at all.
- A single non-compliant link in the chain can put the prime’s own contract eligibility at risk, not just yours.
- “We’re just hauling freight” isn’t a legal shield. The contract’s own terms decide whether you’re in scope, not your job description.
If you’re unsure whether your specific subcontract carries a flow-down CMMC clause, that answer is in the contract itself. Read our companion guide on CMMC flow-down requirements for how to spot the clause and what it obligates you to do.
Where Things Stand in 2026: Phase II Paused, Phase I Still Active
CMMC rolled out in phases, and the phases matter right now more than usual. One is paused. The other is not.
On July 13, 2026, the Small Business Administration announced that the Department of War suspended CMMC Phase II, which had been set to take effect November 10, 2026.
| Phase | Status as of this writing | What it means for carriers and TSPs |
|---|---|---|
| Phase I (Level 1 and Level 2 self-assessment) | Active, unchanged | Continue meeting self-assessment obligations and SPRS affirmation now |
| Phase II (mandatory third-party C3PAO certification for higher-risk contracts) | Suspended as of July 13, 2026 | No new C3PAO certification deadline currently in force |
SBA cited real numbers behind the suspension.
For a carrier or TSP, the practical reading is simple. Level 1 and Level 2 self-assessment obligations are the real, active requirement today. The heavier third-party certification track is on hold, not cancelled, and it can resume on a future timeline.
What CMMC Is Not: A Different Problem Than Fleet Cybersecurity
It’s worth being direct about scope. CMMC has nothing to do with your telematics platform, your ELD compliance, or ransomware protection for your dispatch software on their own.
Those are real risks. A dispatch system held hostage by ransomware can shut down a fleet just as fast as a lost contract. But that’s a general fleet-cybersecurity problem, not a DoD contract obligation.
CMMC applies specifically when your company handles FCI or CUI under a defense contract, whether as a DP3 TSP, a subcontracted carrier, or a broker moving DoD freight. It is a contractual requirement, not a general best-practices framework. A fully CMMC-compliant carrier can still get hit by ransomware on an unrelated system, and a carrier with excellent fleet cybersecurity can still be out of compliance with CMMC if it has never done a Level 1 self-assessment.
See Where You Stand
Free 2-minute CMMC Risk-Check: answer a few plain-English questions about your fleet, dispatch, and shipment-data systems, then get your readiness level and the gaps to close. No sign-up required to see your result.
Take the free CMMC risk assessment
How LeadingIT Supports Transportation and Logistics Companies
For a carrier, broker, or TSP working toward Level 1 or Level 2, the technical backbone an assessment actually checks looks like this:
- Access control and unique-user authentication with multifactor authentication (MFA) across dispatch, TMS, and shipment-data systems
- Encryption of FCI and CUI at rest and in transit
- Centralized audit logging across the systems that touch shipment or manifest data
- Configuration management and regular patching
- Security awareness training for dispatch, warehouse, and office staff
- Incident response planning that matches DFARS reporting timelines
- The documentation an assessor or a prime’s flow-down audit will ask to see: a system security plan and a POA&M
LeadingIT helps carrier and TSP clients scope which systems actually touch FCI or CUI, so the compliance boundary doesn’t balloon to the whole company. From there, LeadingIT implements the required NIST SP 800-171 controls as part of ongoing managed IT, and maintains the evidence trail needed for an SPRS score submission or a future C3PAO assessment. For the done-for-you path, see LeadingIT’s compliance and managed IT services for defense-contract transportation companies.
Related Guides
- What Is NIST SP 800-171? A Plain-English Guide
- What Is a C3PAO? A Guide to CMMC Assessors
- CMMC for Manufacturers: What Defense Suppliers Need to Know
- What Is CUI? Controlled Unclassified Information for Defense Suppliers
Frequently Asked Questions
It can, but only when the trucking company handles federal contract information or controlled unclassified information under a Department of War contract. A motor carrier moving DoD cargo or shipment data for a prime contractor is likely handling FCI at minimum. General trucking operations with no defense contract involved are not subject to CMMC.
DP3 is USTRANSCOM’s program for managing military household-goods and personal-property moves. Non-Temporary Storage Transportation Service Providers in DP3 that possess FCI or CUI must complete a CMMC Level 1 self-assessment and affirm it in the Supplier Performance Risk System to stay eligible for shipment awards.
FCI is basic contract-related information not meant for public release, such as a load number or shipment reference. CUI is more sensitive: manifests, routing details, or cargo data that is export-controlled or otherwise CUI-marked. Handling only FCI keeps a carrier at Level 1. Handling CUI moves a carrier to Level 2.
No. The Department of War suspended CMMC Phase II as of July 13, 2026, ahead of its planned November 10, 2026 effective date. Phase I self-assessment obligations for Level 1 and Level 2 remain active and unchanged.
A freight broker moving cargo or shipment data for a DoD prime contractor is handling FCI at minimum, and CUI if the cargo or manifests are export-controlled. That pulls the broker into the same flow-down obligations as a carrier, regardless of whether the broker thinks of itself as a technology company.
A Certified Third-Party Assessment Organization, or C3PAO, is an organization authorized to conduct official CMMC Level 2 certification assessments.<details> <summary>How is CMMC different from general trucking cybersecurity?</summary> <p>CMMC is a contractual requirement tied specifically to handling FCI or CUI under a DoD contract. General trucking cybersecurity, covering telematics, ELD systems, and ransomware protection for dispatch software, is a separate and equally real concern. A carrier can be fully CMMC-compliant and still face a ransomware incident on an unrelated system.
Ready to Find Out Where You Stand?
CMMC obligations for transportation companies are narrow but real, and they’re easy to miss until a prime or a TSP asks for proof. If your company moves freight, household goods, or shipment data under a defense contract, get a clear read on your status before it holds up a bid. See LeadingIT’s compliance and managed IT services for defense-contract transportation companies, or book a call to walk through your specific contracts.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
