CMMC Scoping: Define the Boundary Before It Defines Your Cost
CMMC scoping is the process of identifying which systems, people, and facilities fall inside your CMMC assessment boundary. Get it right and you assess only what handles CUI. Get it wrong and every laptop, server, and cloud account in the company becomes assessable.
Last Updated: August 20, 2026
What Is CMMC Scoping?
CMMC scoping is the formal exercise of drawing the boundary around every asset that stores, processes, or transmits Controlled Unclassified Information (CUI) or Federal Contract Information (FCI), plus every asset that protects those systems. The Department of Defense publishes official scoping guidance for each CMMC level, and your assessor will use it to decide what gets examined. Everything inside the boundary is fair game for the assessment. Everything outside it must be justifiably separated.
Scoping is step zero of any CMMC program. It happens before the gap assessment, before remediation, and long before a C3PAO walks in the door. The reason is simple economics: assessment effort, remediation cost, and ongoing compliance overhead all scale with the number of in-scope assets. A defense contractor that scopes carelessly can end up paying to bring hundreds of endpoints up to NIST SP 800-171 standards when a well-designed boundary would have required a few dozen.
Key Takeaways
- CMMC scoping determines which assets are assessed. The DoD's Level 2 scoping guidance defines five asset categories, each with different assessment treatment.
- Scope drives cost. Shrinking the boundary with segmentation or a CUI enclave is usually the single biggest cost lever in a CMMC program.
- You cannot scope what you have not mapped. A CUI data flow map and asset inventory come first.
- External service providers, cloud platforms, and MSPs can pull themselves into your scope. Their role must be documented before the assessment.
- Petronella Technology Group, a CyberAB Registered Provider Organization (RPO #1449), runs scoping workshops that produce the asset inventory, data flow diagrams, and boundary documentation your assessor expects.
The team at Petronella Technology Group has been securing regulated businesses and defense contractors since 2002, and scoping conversations start nearly every CMMC engagement we take on. Craig Petronella, CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, covers scoping decisions and SPRS scoring at length in the book because they shape everything that follows. If you are earlier in your CMMC journey, start with our CMMC compliance services overview or our plain-English guide to the CMMC levels.
Scope Is the Biggest Cost Lever in CMMC
Every practice in NIST SP 800-171 applies to in-scope assets. Multi-factor authentication, FIPS-validated encryption, audit logging, configuration baselines, physical protection: each control has to be implemented, documented, and evidenced for the systems inside your boundary. Double the in-scope asset count and you roughly double the implementation surface, the evidence collection burden, and the time an assessor spends examining your environment.
This is why two companies with identical headcount can have wildly different CMMC budgets. A 60-person machine shop that confines CUI to a segmented enclave of 12 workstations and one file server has a small, defensible boundary. A 60-person shop where engineers email CUI drawings to anyone, store them on personal shares, and sync them to unmanaged phones has effectively scoped in the entire company, including the phones.
Scoping decisions also interact with your SPRS score. The self-assessment you submit under DFARS 252.204-7020 covers the same boundary a future assessment will, so an inflated scope depresses your score today and raises your certification cost tomorrow. Contractors who map data flows first, shrink the boundary second, and only then start remediation consistently spend less at every subsequent stage, which is the sequence our CMMC gap assessment follows.
The Five CMMC Level 2 Asset Categories
The DoD's Level 2 scoping guidance sorts every asset in your environment into one of five categories. The category determines how the asset is treated during a CMMC assessment, what documentation it needs, and how much it costs you. Classifying assets correctly, and being able to defend the classification, is the heart of CMMC scoping.
| Asset Category | Definition | Assessment Treatment |
|---|---|---|
| CUI Assets | Systems that process, store, or transmit CUI | Assessed against all applicable NIST SP 800-171 requirements |
| Security Protection Assets | Assets that provide security functions to the CUI environment (SIEM, MFA, EDR, firewalls) | Assessed against the requirements relevant to the protection they provide |
| Contractor Risk Managed Assets | Assets that could, but are not intended to, handle CUI because policy and practice prevent it | Documented in the SSP and asset inventory; managed through your risk-based policies rather than examined against every practice |
| Specialized Assets | IoT, IIoT, operational technology, government-furnished equipment, restricted information systems, and test equipment | Documented in the SSP and managed through risk-based policies; not assessed against every practice |
| Out-of-Scope Assets | Assets that cannot process, store, or transmit CUI and provide no security protection to assets that do | Not assessed; separation must be real and justifiable |
CUI Assets: The Core of Your Boundary
File servers holding technical drawings, engineering workstations, ERP modules with contract data, email systems that carry CUI attachments, and the cloud tenants behind them. These assets face the full weight of the framework, so the goal of scoping is to make this set as small as your operations allow.
Security Protection Assets: Protection Pulls You In
Your SIEM, your identity provider, your endpoint detection platform, your backup infrastructure. They may never touch a CUI file, but because the CUI environment depends on them, they are in scope for the controls they deliver. This category is where external providers and management tools often surprise contractors.
Contractor Risk Managed Assets: Policy Does the Work
A front-office PC that could technically reach the CUI share but is blocked by policy, group membership, and network controls. CRMAs stay out of the deep end only if your separation story holds up. If an assessor finds CUI on one, your classification, and your boundary, collapses.
Specialized and Out-of-Scope: Document or Separate
CNC machines, shop-floor OT, lab test rigs, and government-furnished equipment get risk-based handling, but only if they appear in your SSP and asset inventory. Out-of-scope assets need demonstrable separation: physical, logical, or both. "We just don't put CUI there" is a hope, not a boundary.
Not Sure Which Category Your Assets Fall Into?
Petronella Technology Group runs a structured scoping workshop that classifies every asset, maps your CUI flows, and documents the boundary in the format assessors expect. You leave with a defensible scope, not a guess.
Scoping Differences Across CMMC Levels 1, 2, and 3
Each CMMC level has its own scoping guidance, and the differences matter when you are deciding what to bid on and what to build.
Level 1 scoping revolves around Federal Contract Information rather than CUI. The boundary covers assets that process, store, or transmit FCI, and the 15 basic safeguarding requirements of FAR 52.204-21 apply to them. There are no asset categories at Level 1: an asset either handles FCI or it does not. Many small subcontractors discover their entire office network handles FCI because contract emails and invoices travel everywhere, which is an argument for tidying data flows even at Level 1.
Level 2 scoping introduces the five asset categories above, because CUI demands finer distinctions. It also introduces the concepts that make scope reduction possible: separation techniques, security protection assets, and documented risk-based handling for equipment that cannot meet every control. Level 2 is where enclave architectures earn their keep, and where our clients spend most of their scoping effort. If Level 2 certification is on your horizon, our CMMC Level 2 certification services page walks through the full journey from scoping to C3PAO assessment.
Level 3 scoping builds on a Level 2 certified boundary and layers selected NIST SP 800-172 enhanced requirements on top for contractors supporting the DoD's most sensitive programs. If Level 3 may apply to you, the scoping conversation needs to happen alongside your prime contractor early, because architecture choices made for Level 2 can help or hurt you at Level 3.
You Cannot Scope What You Cannot Recognize: Finding Your CUI
Every scoping mistake we see traces back to the same root: the organization never firmly established what CUI it holds. Controlled Unclassified Information is information the government creates or possesses, or that a contractor creates or handles for the government, that requires safeguarding under law, regulation, or government-wide policy. The National Archives maintains the official CUI Registry of categories, and in the defense world the common ones are controlled technical information, export-controlled data, and certain procurement and program information.
In practice, recognition is messier than the definitions suggest. Properly marked documents arrive with CUI banners and designation indicators, and those are the easy cases. The hard cases are the drawings a prime emailed in 2019 with no markings at all, the legacy folder structures where CUI and commercial work are interleaved, and the technical data your own engineers generate under a contract that carries a DFARS 252.204-7012 clause. Unmarked does not mean uncontrolled, and assuming otherwise quietly poisons the whole scoping exercise.
Our scoping workshops therefore begin with contract review rather than a network scan. The clauses in your prime contracts and flow-downs establish whether you should be receiving or generating CUI at all, and interviews with the engineers, program managers, and quality staff who handle government work reveal where it actually accumulates. Only after that inventory exists does asset categorization begin. When clients ask why we do not just run a discovery tool and call it a day, the answer is that tools find patterns, not obligations: a scanner cannot read your contract, and your assessor certainly will.
How Petronella Technology Group Scopes a CMMC Environment
Scoping done well is a short, intense project with a concrete paper trail. Here is the sequence we run, refined across CMMC engagements since the framework's earliest days. Craig Petronella has held the CMMC Registered Practitioner credential since 2020, and our entire team is CMMC-RP certified.
CUI Identification and Data Flow Mapping
We start with your contracts, not your network. DFARS clauses, CDRLs, and prime flow-downs tell us what CUI you actually receive or create. Then we trace where it enters, where it lives, who touches it, and where it leaves: email, file shares, ERP, CAD systems, cloud tenants, removable media, and the shop floor.
Asset Inventory and Categorization
Every asset that appears in a data flow gets classified into one of the five categories, with the rationale written down. This inventory becomes an appendix to your System Security Plan, and ComplianceArmor®, our compliance documentation platform, keeps it current as your environment changes.
Boundary Design and Scope Reduction
With flows and assets on the table, we look for the smallest boundary your operations can live with. Options range from VLAN segmentation and access restructuring to a purpose-built CMMC enclave that concentrates CUI in a hardened environment while the rest of the business runs unchanged.
External Provider and Cloud Review
We inventory every MSP, cloud service, and external service provider that touches the boundary, verify FedRAMP status where CUI rides on a cloud offering under DFARS 252.204-7012, and document shared responsibilities so nobody's assumptions become your finding.
Boundary Documentation and Assessment Prep
The final package includes the network diagram, data flow diagrams, categorized asset inventory, and scoping narrative your assessor will ask for on day one. From there, most clients move straight into a gap assessment against the scoped boundary.
Seven CMMC Scoping Mistakes That Inflate Cost or Sink Assessments
- Scoping the network instead of the data. The boundary follows CUI, not your subnet diagram. Contractors who start from network maps routinely miss CUI in email, SaaS tools, and backups.
- Declaring assets out of scope without separation. An out-of-scope claim requires demonstrable physical or logical separation. Flat networks make every out-of-scope claim fragile.
- Forgetting security protection assets. The backup server, the domain controller, and the MSP's remote management tool protect the CUI environment, so they are in scope even though they never store a drawing.
- Ignoring the people and facilities dimensions. Scope is not only hardware. The employees who handle CUI and the rooms where it is printed, discussed, or stored belong in the boundary documentation too.
- Letting collaboration tools sprawl. If CUI lands in chat exports, ticketing systems, or personal cloud drives, those platforms just joined your boundary. Data hygiene is scope hygiene.
- Treating the MSP as invisible. If a service provider administers in-scope systems, their access and tooling are part of your assessment story. Ask them hard questions now, not during the assessment.
- Scoping once and never again. New contracts, new tools, and new hires all move CUI. A boundary documented in 2024 and untouched since is a finding waiting to happen. Continuous monitoring of scope belongs in your program, and it is a core feature of ComplianceArmor®.
DIY Scoping vs. Generic IT Consultant vs. Petronella Technology Group
| Factor | DIY | Generic IT Consultant | Petronella Technology Group |
|---|---|---|---|
| CMMC-specific expertise | Reading the scoping guides yourself while running the business | Strong on networking, often new to asset categories and CUI handling | CyberAB Registered Provider Organization (RPO #1449); entire team CMMC-RP certified |
| Scope reduction strategy | Usually defaults to "everything is in scope" | May segment networks without tying segments to CUI flows | Boundary design driven by data flow mapping, including enclave architecture where it pays off |
| Documentation output | Ad hoc spreadsheets | Varies by consultant | Assessor-ready asset inventory, data flow diagrams, and scoping narrative maintained in ComplianceArmor® |
| Continuity after scoping | You own every next step | Often ends at the report | Same team carries you through gap assessment, remediation, and C3PAO preparation |
| Track record | Not applicable | Varies | In business since 2002, BBB A+ rated since 2003, rated 4.7 across 92 verified TrustIndex reviews |
Scoping is one of the few CMMC activities where a short engagement with the right specialist changes the cost of everything downstream. It is also one of the easiest places to get quietly wrong, because errors surface months later, in front of an assessor.
Get a Boundary an Assessor Will Respect
A scoping workshop with Petronella Technology Group typically takes days, not months, and the deliverables slot directly into your System Security Plan. We promise straight answers about what belongs in scope and what does not.
Who Needs CMMC Scoping Help
Scoping support delivers the most value for organizations in the defense industrial base that are early in their CMMC journey or facing a deadline they did not plan for:
- Defense subcontractors seeing CMMC Level 2 requirements in new flow-downs from their primes
- Machine shops and manufacturers whose OT and shop-floor equipment complicate the boundary
- Engineering firms with CUI living in CAD files, simulation data, and project shares
- Contractors weighing an enclave build against bringing the whole environment into scope
- Companies whose MSP manages everything and nobody has documented who is responsible for what
- Level 1 contractors bidding on work that will bring CUI, and Level 2 obligations, with it
We work with defense contractors and manufacturers across North Carolina, from Raleigh and Durham across the Triangle, and nationwide. Because Petronella Technology Group also delivers managed IT and cybersecurity services, the scoping design we hand you is one our own engineers would be willing to operate.
CMMC Scoping: Frequently Asked Questions
What is CMMC scoping in simple terms?
CMMC scoping is deciding, and documenting, which parts of your business get assessed. Anything that stores, processes, or transmits CUI, or protects the systems that do, is inside the assessment boundary. Everything else must be genuinely separated to stay outside it.
What are the five CMMC asset categories?
The Level 2 scoping guidance defines CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Each category receives different treatment during an assessment, from full examination against NIST SP 800-171 down to documentation review.
Does my whole company have to be in scope for CMMC?
No. If CUI is confined to a well-separated environment, only that environment and the assets protecting it are assessed. That is the logic behind enclave architectures: concentrate CUI in a hardened segment so the rest of the business stays out of scope.
How does an enclave reduce CMMC scope?
An enclave isolates CUI storage, processing, and access behind strict logical boundaries. Users enter the enclave to work with CUI instead of CUI spreading to every desktop. Done properly, it can shrink the assessed environment dramatically. Our CMMC enclave services page covers the architecture in detail.
Are cloud services like Microsoft 365 in scope?
If CUI touches a cloud service, that service is part of your scope, and under DFARS 252.204-7012 a cloud offering holding CUI needs to meet FedRAMP Moderate or equivalent requirements. This is why many defense contractors use government community cloud offerings for CUI workloads. Verify before you migrate, not after.
Is my MSP in scope for my CMMC assessment?
If a managed service provider administers in-scope systems or provides security services to them, the provider's access, tooling, and responsibilities become part of your assessment story and must be documented, typically in a shared responsibility matrix. Ask your MSP now how they support CMMC clients. Petronella Technology Group answers that question for a living.
What documents come out of a scoping exercise?
A categorized asset inventory, CUI data flow diagrams, a network diagram showing the assessment boundary, and a scoping narrative that explains the rationale. These feed directly into your System Security Plan and are among the first artifacts an assessor requests.
When should scoping happen relative to a gap assessment?
Scoping comes first. A gap assessment measures your controls against the requirements for in-scope assets, so an undefined boundary makes gap results unreliable and usually oversized. Scope, then assess, then remediate: that order protects your budget.
Start Your CMMC Program With a Defensible Scope
Talk with the Petronella Technology Group team about your contracts, your CUI flows, and the boundary that fits your business. Free consultation, straight answers, and a clear path from scoping to certification.