Skip to content

FREQUENTLY ASKED QUESTIONS

CUI Discovery and CMMC Questions, Answered

Learn how Teramis helps organizations discover and validate Controlled Unclassified Information, support defensible CMMC scope, and monitor what changes over time.

FAQs

About Teramis

What is Teramis?

Teramis is a purpose-built CUI discovery, validation, reporting, and ongoing monitoring platform.

It helps organizations identify potential Controlled Unclassified Information across approved data environments, validate relevant findings, support CMMC boundary decisions, and monitor changes over time.

Who uses Teramis?

Teramis supports defense contractors, enterprise teams, government agencies, CMMC advisors, RPOs, MSPs, MSSPs, GRC providers, and technology partners that need stronger visibility into where CUI exists.

Does Teramis certify organizations for CMMC?

No. Teramis does not perform formal CMMC assessments, certify organizations, or guarantee assessment outcomes.

Teramis provides discovery findings, validation results, and other evidence that can support CMMC readiness, scoping, and boundary discussions.

CUI Discovery and Validation

How does Teramis help organizations discover CUI?

Teramis examines authorized data sources to identify content that may contain CUI. Findings can then be reviewed and validated to distinguish relevant CUI from unrelated content and false positives.

This provides a clearer picture of the organization's actual CUI footprint.

What types of data sources can Teramis examine?

Supported data sources can include Microsoft 365, file systems, email, endpoints, engineering repositories, CAD files, PDFs, scanned documents, archives, SharePoint, OneDrive, and other approved sources.

Exact source coverage, access requirements, and deployment options should be confirmed during technical planning.

Does Teramis make the final determination that information is CUI?

Teramis identifies and helps validate potential CUI findings. Authorized customer personnel and their advisors remain responsible for final classification, handling, legal, and compliance decisions.

How does Teramis help reduce false positives?

Teramis supports review, validation, and sampling workflows that help teams distinguish relevant CUI from unrelated findings.

This helps organizations avoid expanding their CMMC scope or acting on unvalidated scan results.

What access does Teramis need?

Teramis examines only the environments and data sources your organization expressly authorizes. Scope is defined before discovery begins.

Does our data leave our environment?

Teramis is deployed within the customer's security boundary, so scanning and analysis remain inside the customer-controlled environment. Sensitive files do not need to be uploaded to an external discovery service.

A multi-agent architecture supports distributed and complex environments, including situations where data exists across separate repositories, networks, business units, or Microsoft 365 tenants.

How accurate is Teramis?

Teramis uses review and sampling workflows to help confirm the accuracy of findings and distinguish relevant CUI from unrelated content or false positives. Accuracy depends on the environment, data sources, file types, and scope of the engagement.

CMMC Scope and Boundary Validation

Does Teramis decide an organization's CMMC boundary?

No. Teramis provides technical findings and evidence that compliance, security, IT, executive, and advisory teams can use when making boundary decisions.

The organization remains responsible for defining and approving its CMMC assessment scope.

What is CUI boundary validation?

CUI boundary validation compares the organization's documented boundary with findings from its approved data environments.

It helps identify systems, repositories, files, or users that may require additional review because the documented boundary and actual CUI footprint do not align.

Should CUI discovery happen before CMMC scoping?

CUI discovery provides the evidence needed to define or validate scope. Organizations can use validated findings to make more informed decisions about which systems, users, repositories, applications, and business processes belong within the CMMC boundary.

Ongoing Monitoring and Spillage

What does ongoing monitoring mean?

Ongoing monitoring uses recurring scans to identify new CUI findings, movement, potential spillage, and changes to the documented boundary over time.

Ongoing monitoring does not necessarily mean constant or real-time surveillance. Scan frequency and coverage depend on the approved deployment and monitoring plan.

What is CUI spillage?

CUI spillage occurs when Controlled Unclassified Information appears in a location, system, repository, or workflow that is not approved for handling it.

Teramis can help identify potential spillage, validate the finding, and document its location.

Can Teramis help after a suspected security incident?

Teramis can scan authorized portions of affected systems and repositories to help determine whether CUI may be present.

These findings can give counsel, incident response teams, and leadership a stronger factual basis for evaluating potential impact and reporting obligations.

Teramis does not perform incident response or digital forensics, determine whether a reportable breach occurred, establish whether data was accessed or exfiltrated, or make legal and notification decisions.

Technology and Partner Use

Is Teramis a replacement for DLP, eDiscovery, GRC, or access-governance tools?

No. Teramis is designed to complement existing security, governance, and compliance systems.

DLP tools can enforce data-movement policies, access-governance systems can manage permissions, and GRC platforms can organize compliance activity. Teramis adds CUI discovery, validation, and ongoing visibility.

Can CMMC partners use Teramis to support clients?

Yes. MSPs, MSSPs, CMMC advisors, RPOs, GRC providers, and other approved partners can use Teramis to strengthen client discovery, boundary validation, ongoing monitoring, and readiness services.

Teramis provides technical findings and evidence. Partners apply those findings within the services and guidance they provide.

Still Have Questions?

TALK WITH A CUI DISCOVERY EXPERT

Start With the CUI You Actually Have

Talk with Teramis about your environment, approved data sources, CMMC objectives, or ongoing monitoring goals.

Request a Demo Start a CUI Discovery Readiness Assessment


Section B, pending approval. This content stays hidden until the Remedius remediation capability language is approved for publication.

CUI Remediation and Remedius

What is Remedius?

Remedius is a remediation capability within the Teramis platform. It helps organizations take controlled action on validated CUI findings after authorized personnel approve the action and destination.

Can Teramis move or remediate CUI?

Yes. Through Remedius, Teramis supports authorized remediation of validated CUI findings within supported environments.

This can include moving CUI into authorized locations, preserving source folder structures, verifying successful transfers, reporting conflicts or failures, addressing unauthorized source copies, and producing manifests and logs that document what occurred.

Who decides which CUI findings are remediated?

The customer determines which findings require remediation, identifies the authorized destination, approves the action, and controls the remediation schedule.

Teramis and Remedius do not independently decide what data should be moved, deleted, or otherwise changed.

Can Teramis help with CUI migration?

Yes. Teramis can identify and validate the CUI that needs to move before an enclave or tenant migration.

Remedius can support authorized movement of validated CUI within supported environments, and Teramis can re-scan source locations afterward to help verify that the intended CUI was moved and identify anything that may remain.