Before you write a single policy or turn on a single control, there's a decision that quietly determines how hard — and how expensive — your entire CMMC effort will be: what's in scope? Draw that boundary well and you might only have to secure a handful of systems. Draw it badly and you've just signed up to lock down your whole company.
Here's the short version: CMMC scoping is deciding which of your assets are part of the assessment, based on how each one relates to CUI. Every device, account, and cloud service falls into one of five categories, and where it lands decides whether it gets assessed against all 110 controls, some of them, or none at all. Getting this right is the highest-leverage move a small contractor can make.
What Is CMMC Scoping?
Scoping is the act of separating your environment into what's being assessed and what isn't. The official rules live in the DoD's CMMC Level 2 Scoping Guide and in the regulation at 32 CFR 170.19. Both describe the same idea: identify everything that touches your Controlled Unclassified Information (CUI), and everything that protects it, and treat that as your assessment boundary.
The reason this matters so much is simple. A CMMC Level 2 assessor doesn't examine "your company" — they examine your defined scope. If your scope is tight and well-documented, the assessment is focused and predictable. If it's vague or sprawling, the assessor has more to look at, more places for findings to hide, and every hour of that costs you.
Assessors have said it plainly: the first questions in a CMMC engagement should be about your CUI and how it flows — not about your technology. If the conversation starts with tools instead of data, the scope is being built backwards.
That's why scoping starts with a question that has nothing to do with firewalls: where does CUI actually enter our business, where does it live, and where does it go? Answer that honestly and the categories below almost sort themselves.
The 5 CMMC Asset Categories
Every asset in your environment — laptops, servers, cloud apps, network gear, even the printers — belongs to exactly one of these five categories. This is the heart of scoping.
| Category | What it is | How it's treated |
|---|---|---|
| CUI Assets | Anything that processes, stores, or transmits CUI — file servers, the laptops people open CUI on, your CUI-holding cloud storage. | Must meet all 110 NIST SP 800-171 controls. Fully assessed. |
| Security Protection Assets (SPA) | Assets that provide a security function to the scope — firewall, SIEM, EDR, identity/access management — whether or not they touch CUI themselves. | Assessed against the controls relevant to the protection they provide. |
| Contractor Risk Managed Assets (CRMA) | Assets capable of handling CUI but that you've decided won't — kept away from CUI by policy and configuration rather than physical separation. | Documented in the SSP and risk-managed. Not fully assessed unless controls or documentation fall short. |
| Specialized Assets | Gear that can't fully run the controls: IoT devices, operational technology, government-furnished equipment, test equipment, restricted systems. | Documented and shown to be managed; not held to every control. |
| Out-of-Scope Assets | Assets with no CUI, no connection to the CUI environment, and no security role — a marketing laptop on a separate network, for example. | Not assessed at all — if the separation is real and provable. |
Why the Boundary Is the Whole Game
Notice the pattern in that table: the more assets you push into the CUI Assets bucket, the more of your environment has to satisfy all 110 controls. The goal of good scoping isn't to cheat the rules — it's to arrange your business so CUI lives in as few places as possible, which honestly reduces both your risk and your workload.
This is where most small contractors go wrong. CUI arrives by email, gets saved to a general file share, opened on everyone's laptop, and copied into three other tools. Now every one of those is a CUI Asset, and the scope is the entire company. The security work balloons, the SSP gets enormous, and the assessment gets expensive.
How to Shrink Your Scope: The Enclave
The single most effective scoping move for a small business is a CUI enclave — a segmented, isolated zone (logical or physical) where you deliberately confine all CUI. Access is restricted, it's separated from the rest of your network, and CUI never leaves it.
Done well, an enclave means the 110 controls only have to be applied to that small zone, not your whole shop. Everything outside — general email, accounting, the marketing website — can stay out of scope because it never touches CUI.
| CUI everywhere (no enclave) | CUI in an enclave | |
|---|---|---|
| In-scope assets | Most of the company | A small, defined zone |
| Controls to apply | 110 controls across everything | 110 controls in one place |
| Assessment effort & cost | High — more to examine | Lower — focused boundary |
| Ongoing burden | Every device stays compliant | Only the enclave does |
One more thing scoping surfaces: your outside providers. If your MSP administers systems inside your boundary, they're part of your scope, and their controls get examined too. That's covered in does my MSP need to be CMMC compliant.
Map your scope before you build
CMMC Map walks you through where CUI enters, lives, and moves — then helps you define a tight boundary and documents it straight into your System Security Plan.
Start Your Free 7-Day TrialWhere Scoping Gets Written Down
Scoping isn't a mental exercise — it has to be documented, and the document is your System Security Plan. The SSP records your boundary, your data flows, and which category each asset falls into. When a C3PAO shows up, that scope definition is the map they assess against. A fuzzy scope in the SSP is one of the fastest ways to stall an assessment before it really begins.
The Bottom Line
Scoping is the decision that shapes everything after it — your controls, your documentation, your assessment cost, and how much of your day-to-day operation has to change. Start from your CUI, sort every asset into one of the five categories, confine CUI to as small an enclave as your work allows, and write it all down in the SSP. Do that first, and the rest of CMMC becomes a far smaller, far more predictable project.