Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CMMC scoping explained

CMMC Scoping: A Clear Guide to the 5 Asset Categories

CMMC scoping decides the size of your assessment before a single requirement is tested. Under 32 CFR 170.19 the CMMC Assessment Scope must be specified before any self-assessment or certification assessment, and at Level 2 it is built from five asset categories with different documentation and assessment treatment: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope Assets. Get the categories right and a 2,000-endpoint company can be assessed on a 40-system enclave; get them wrong and the assessor either expands the scope on the day or, worse, certifies a boundary that does not contain the CUI. This guide sets out the five categories as the rule defines them, the Level 1 and Level 3 variations, how external service providers fall in, and the decisions that shrink scope legitimately.

CMMC scoping: the five Level 2 asset categories and how each is assessed
Four in-scope categories with different assessment treatment, one out-of-scope category that must be justified.

What CMMC scoping is

The rule defines the CMMC Assessment Scope as “the set of all assets in the OSA’s environment that will be assessed against CMMC security requirements”, and says it “must be specified prior to assessment”. Assets here means people, technology, facilities and external service providers — the rule tells Level 1 assessors to consider all four. Scope is not the whole company unless the whole company handles CUI; it is the boundary within which CUI, and the things that protect CUI, live.

The scope is recorded three ways at Level 2: in the asset inventory, in the System Security Plan (with each asset category’s treatment described), and in a network diagram of the assessment scope. All three are inputs to the assessment and the SSP is itself requirement CA.L2-3.12.4 — one of the six requirements that can never go on a POA&M.

The five CMMC scoping categories at Level 2

Table 3 to 32 CFR 170.19(c)(1) defines the categories. Four are in scope; one is not.

Category Definition (32 CFR 170.19) OSA must Assessor will
CUI Assets Assets that process, store or transmit CUI Inventory; document treatment in the SSP; show on the network diagram; prepare for assessment Assess against all 110 Level 2 requirements
Security Protection Assets Assets that provide security functions or capabilities to the assessment scope Inventory; SSP; network diagram; prepare for assessment Assess against the Level 2 requirements relevant to the capabilities provided
Contractor Risk Managed Assets Assets that can, but are not intended to, process, store or transmit CUI because of security policy, procedures and practices; need not be separated from CUI assets Inventory; SSP; network diagram; prepare for assessment Review the SSP; if sufficiently documented, do not assess further; a limited check if documentation raises questions, which may not materially extend the assessment
Specialized Assets Assets that can handle CUI but cannot be fully secured: IoT, IIoT, OT, GFE, restricted information systems, test equipment Inventory; SSP; show they are managed under risk-based policies and practices; network diagram Review the SSP; do not assess against other requirements
Out-of-Scope Assets Assets that cannot process, store or transmit CUI and do not protect CUI assets; physically or logically separated Prepare to justify the inability to handle CUI None

CUI Assets

The core. Anything that touches CUI is assessed against everything. The category is broader than the file server: the laptops that open the files, the email system that carries them, the printer that prints them, the backup that copies them, the collaboration tool the program team uses. CUI Assets are found by following the data, and the discovery exercise — where does CUI enter, where does it go, where does it rest — is the first scoping task.

Security Protection Assets

Whatever protects the CUI Assets, whether or not it handles CUI itself: the firewall, the identity provider, the SIEM, the endpoint protection console, the vulnerability scanner, the MFA service. They are assessed only against the requirements relevant to the capability they provide, but they are in scope, and a cloud-hosted one pulls its provider into scope as an external service provider.

Contractor Risk Managed Assets

The category that makes a shared network defensible. An asset that could handle CUI but is not intended to — a workstation on the same VLAN used by a non-program team, say — can be a CRMA if the SSP documents the policies and practices that keep CUI off it. The assessor reviews the SSP and, if satisfied, does not assess the asset. If the documentation “or other findings raise questions”, the assessor can run a limited check, but the rule caps it: the checks “shall not materially increase the assessment duration nor the assessment cost”. The category rewards clear, specific SSP treatment and punishes vague assertions.

Specialized Assets

Devices that handle CUI but cannot be fully secured to the 110 requirements — a CNC controller, a piece of test equipment, government-furnished hardware. They are inventoried and described, must be shown to be managed under the contractor’s risk-based practices, and are not assessed against the other requirements. The relief is real, but it disappears at Level 3, where requirement SI.L3-3.14.3e requires specialized assets to be included in the enhanced requirements or segregated.

Out-of-Scope Assets

Assets that cannot handle CUI and do not protect CUI assets, because they are physically or logically separated from the systems that do, or are inherently unable. The rule gives one example: an endpoint hosting a VDI client configured to allow nothing beyond keyboard, video and mouse to reach it. Two rules bound the category: an asset that falls into any in-scope category cannot be out of scope, and the OSA must be prepared to justify the exclusion.

External service providers

Table 4 to 170.19(c)(2)(i) settles the most common scoping argument. If an external service provider processes, stores or transmits CUI and is a cloud service provider, it must meet the FedRAMP requirements in DFARS 252.204-7012; if it is not a CSP, its services are in your assessment scope and assessed as part of your assessment. If the ESP handles Security Protection Data but not CUI — a managed SIEM, an MSSP — its services are assessed as Security Protection Assets, CSP or not. A provider that handles neither is not an ESP under CMMC. The relationship must be documented in the SSP and in the ESP’s service description and customer responsibility matrix, and the ESP may voluntarily undergo its own CMMC assessment to reduce the effort during yours.

CMMC scoping at Level 1 and Level 3

Level 1 (32 CFR 170.19(b)) Level 2 (170.19(c)) Level 3 (170.19(d))
In scope Systems that process, store or transmit FCI CUI Assets, SPAs, CRMAs, Specialized Assets CUI Assets (including what Level 2 calls CRMAs), SPAs irrespective of CUI handling, Specialized Assets
Contractor Risk Managed Assets No such category In scope; SSP review only if well documented Treated as CUI Assets: limited Level 2 check, full Level 3 assessment
Specialized Assets Not in scope; not assessed In scope; SSP review only Subject to requirement 3.14.3e: include or segregate
Out of scope Systems without FCI; KVM-only VDI endpoints; no documentation required Justify the inability to handle CUI Justify the inability to handle CUI

Level 1 is simpler — FCI systems in, everything else out, specialized assets excluded. Level 3 is stricter in the two places Level 2 gave relief. An organization planning to grow from Level 2 to Level 3 should scope Level 2 as if the CRMA relief did not exist. Our guides to CMMC Level 1 and CMMC Level 3 cover the two ends.

Five scoping decisions that shrink the assessment legitimately

  1. Build an enclave. Put CUI, and only CUI work, inside a segmented environment with its own identity, endpoints and services. Everything outside becomes Out-of-Scope with a defensible justification. This is the single largest cost lever in CMMC.
  2. Use VDI the way the rule describes. A KVM-only VDI client is the rule’s own example of an out-of-scope endpoint. Clipboard, drive mapping and printing must actually be disabled, and the configuration must be evidenced.
  3. Document CRMAs specifically. Name the assets, the policy that keeps CUI off them, the technical control that enforces it and the check that verifies it. That is what “sufficiently documented” means.
  4. Push CUI to FedRAMP-authorized services. A CSP meeting the 7012 FedRAMP requirement carries its own assessment; your scope holds the customer responsibilities in the CRM, not the provider’s infrastructure.
  5. Retire the CUI you do not need. Every copy in every system extends scope. A data map that finds three legacy archives is worth more than any control.

Frequently asked questions

What are the CMMC scoping asset categories?
At Level 2: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope Assets, defined in Table 3 to 32 CFR 170.19(c)(1). Level 1 uses FCI systems in, specialized and non-FCI assets out; Level 3 collapses CRMAs into CUI Assets.

Are Contractor Risk Managed Assets assessed?
Only by SSP review if they are sufficiently documented. If the documentation raises questions the assessor may run a limited check that must not materially increase the assessment’s duration or cost.

Is our cloud provider in scope?
If it handles CUI it must meet the FedRAMP requirements in DFARS 252.204-7012. If it handles security protection data only, its services are assessed as Security Protection Assets. Either way the relationship is documented in the SSP and a customer responsibility matrix.

Can a VDI endpoint be out of scope?
Yes, if the VDI client is configured to allow nothing beyond keyboard, video and mouse — the rule’s own example. The configuration has to be real and evidenced.

Where is the scope recorded?
In the asset inventory, the System Security Plan and a network diagram of the assessment scope, all of which the assessor reviews; the scope is also submitted to SPRS with the assessment results.

Where this leaves you

CMMC scoping is a data-flow exercise followed by five sorting decisions. Find every place CUI enters, moves and rests; put those assets and the things that protect them in scope; document the assets that could but do not handle CUI with enough specificity that the assessor never needs the limited check; inventory the specialized assets; and justify every exclusion. Then draw the diagram — because it is the first thing the assessor asks for.

References

More on CMMC

The CUI Scoping and Boundary Definition Guide, the CUI Asset Inventory and Data Flow Diagram Guide, the Assessment Scope Determination Procedure, the SSP template and the Cloud Service Provider Security Requirements Guide are in the CMMC Documentation Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.