News

CMMC Asset Scoping: How to Categorize Your IT Environment for Level 2 Compliance

January 6, 2026
white text on a blue background

Quick Answer

Every asset within your CMMC assessment boundary must fit into one of five categories defined in the Level 2 Scoping Guide (DoD CIO, December 2021) and 32 CFR §170.19(c)(1), Table 3: CUI Assets (directly process, store, or transmit Controlled Unclassified Information or Security Protection Data), Security Protection Assets (SPAs) (provide security functions protecting CUI), Contractor Risk Managed Assets (CRMAs) (can access CUI but aren't designed to process it), Specialized Assets (OT/IoT/GFE with limited assessment), and Out-of-Scope Assets (physically or logically separated from the CUI environment). You propose the boundary; assessors can challenge scopes that leave obvious gaps.

Here's what most defense contractors miss about CMMC asset scoping: you're the one proposing the boundary, not the C3PAO assessor who shows up to evaluate your environment. Draw that line too wide and you'll waste resources securing systems that don't need it. Draw it too narrow and you'll create gaps that assessors will challenge and that put your certification at risk. Our CMMC compliance services help organizations navigate exactly this boundary-setting process from the start.

This article explains how CMMC Level 2 asset categories work in practice and shows you how thoughtful scoping keeps you compliant without pulling your entire IT infrastructure into the assessment. The framework draws directly from 32 CFR §170.19 and the CMMC final rule, which established the regulatory requirements now binding on every DoD contractor. By the end, you'll know exactly what counts for CMMC and what can legitimately stay outside your CMMC assessment scope.

If you're still assessing whether CMMC Level 2 requirements are now enforceable for your organization, the short answer is yes. The final rule took effect November 10, 2025. Scoping decisions you make today have real consequences for your certification timeline and cost.

What Are the 5 CMMC Level 2 Asset Categories?

The Level 2 Scoping Guide and 32 CFR §170.19 give you five buckets for CMMC asset classification. Every asset within your assessment boundary goes into one of these categories. Getting this right determines your total compliance cost, your assessment timeline, and whether you'll actually pass.

What Are CUI Assets in CMMC?

CUI Assets are the people, systems, applications, or devices that actually handle Controlled Unclassified Information (CUI) or Security Protection Data (SPD). If an asset is actively designed to contain, process, store, or transmit CUI or SPD, it belongs here.

Common CUI Asset examples include:

File servers and storage accounts holding CUI

Virtual desktops or workstations where users open and manipulate CUI

Email systems used to send or receive CUI

Collaboration platforms (e.g., GCC High SharePoint or Teams) hosting CUI documents

Code that belongs to or processes CUI on behalf of the U.S. Government

Personnel who possess or handle CUI (subject-matter experts, project managers, floor managers)

Printers, 3D printers, or scanners regularly used to produce physical forms of CUI

A practical rule of thumb: if an asset is explicitly designed to contain, process, or transmit CUI, it belongs here. Many Organizations Seeking Certification (OSCs) overlook printers and scanners, assuming no hard drive means out of scope. Not so. If a device regularly produces or handles CUI, it's a CUI Asset.

Assessors will not proceed with the audit unless CUI Assets are clearly documented in asset and user inventories, shown in network diagrams, and adequately addressed in the SSP. Incomplete inventories can get an assessment canceled, sending your organization back to the end of a months-long queue. CUI Assets are assessed against all 110 controls and 320 objectives — the core purpose of CMMC.

How Do Security Protection Assets (SPAs) Work?

Security Protection Assets (SPAs) provide the security functions that protect the CUI environment. Typical examples include:

External service providers or managed service providers (MSPs)

Firewalls and VPN gateways guarding the enclave perimeter

Identity providers and MFA services used for CUI access

SIEM/SOAR tools aggregating logs from in-scope systems

Endpoint protection platforms monitoring CUI endpoints (e.g., Intune)

Wireless access points servicing CUI systems in hybrid or enterprise environments

SPAs must be listed in the asset inventory, described in the SSP (including their purpose and security function), and shown in network and data-flow diagrams. They're assessed against only those practices relevant to the security capability they provide. For example, a cloud-based identity provider may be evaluated on authentication, logging, and configuration management, but not on media sanitization.

SPAs underscore one of the most common scoping mistakes, covered extensively in 5 Common CMMC Pitfalls Small Businesses Should Avoid: many organizations assume MSPs are out of scope because they operate outside the OSC's organizational boundary. Under DFARS 252.204-7012 and external service provider obligations, that assumption is wrong. If an MSP interacts with the CUI environment — and most do, routinely working on email and file shares — they're in scope. Even a single instance of processing CUI during routine maintenance is enough.

For this reason, OSCs are strongly advised to seek MSPs that are already CMMC Level 2 certified or are firmly scheduled for assessment. Their tools, scanning mechanisms, and troubleshooting procedures will have been evaluated against security expectations for federal environments.

What Qualifies as a Contractor Risk Managed Asset (CRMA)?

Contractor Risk Managed Assets (CRMAs) exist in the gray zone, and they're often the source of debate between OSCs and assessors. The formal definition: assets that can, but are not intended to, process, store, or transmit CUI because of security policies, procedures, and practices in place — and that aren't required to be physically or logically separated from CUI assets.

A working definition: a CRMA is an asset that interacts with CUI or the CUI environment but isn't designed to store, transmit, process, or protect it. Both SPAs and CRMAs interact with CUI — the crucial distinction is that SPAs actively protect CUI and the environment, while CRMAs do not. Common CRMA examples:

A remote desktop application installed on endpoints to access a VDI that hosts CUI

An MSP's remote monitoring and management (RMM) tool or access path into the client's environment

A shared ticketing system between the CUI environment and the MSP

Internal line-of-business applications that could technically receive CUI but are governed by strict DLP rules that prohibit it

CRMAs are still in the Level 2 CMMC scope but are not assessed against the full control set. Instead, they're primarily addressed under Practice 3.12.4, which requires OSCs to inventory them, diagram them, and explain their treatment in the SSP. For organizations pursuing CMMC Level 3, CRMAs that fall within Level 3 scope are treated as full CUI Assets.

CRMA status is a risk bet: you're asserting that governance, technical controls, and user training are strong enough to preclude active flow of CUI in practice. If that assertion is weak or poorly documented, assessors may push to reclassify CRMAs as CUI Assets. The stakes around proper classification rose significantly since CMMC D-Day: November 10, 2025, when the final rule became effective and compliance obligations became legally enforceable.

What Are Specialized Assets Under CMMC?

Specialized Assets are a catch-all for systems that are difficult or impractical to evaluate against the full control set:

Operational Technology (OT) / Industrial Control Systems (ICS)

IoT devices and embedded sensors

Government Furnished Equipment (GFE)

Test equipment or lab systems with limited interfaces

HVAC and environmental control devices

For Level 2, Specialized Assets that process CUI — or protect assets that do — are in scope, but they undergo limited checks by the C3PAO. The emphasis is on confirming they're known, documented (location, function, and connectivity), and that reasonable safeguards exist given their constraints. "Limited checks" does not mean they can be ignored. OSCs still need to demonstrate that these devices are segmented, monitored, and managed. Assessors will verify that Specialized Assets are segregated from the access paths used by CUI Assets.

What Qualifies as an Out-of-Scope Asset?

Everything else belongs here — but only if the decision is justified and provable. Out-of-Scope Assets are those that:

Cannot process, store, or transmit CUI

Do not provide security protections for CUI Assets

Are physically or logically separated from CUI assets and SPAs

The regulations offer a helpful example: an endpoint hosting a VDI client configured so that no CUI can be processed, stored, or transmitted outside the keyboard/video/mouse stream may be treated as out of scope.

"Out of scope" does not mean "ignored." You must be able to explain why a given asset cannot reasonably encounter CUI and how you've engineered and enforced that separation. The separation techniques that make out-of-scope status defensible will be covered in a follow-up article in this series.

How to Scope Your CMMC Assessment: A 4-Step Framework

Knowing the definitions is the easy part. Applying them consistently is the real work. A practical CMMC scoping effort typically follows four steps.

Step 1: Understand Your Contracts and Data Types

Start by identifying which contracts involve only Federal Contract Information (FCI) and which involve CUI. Contracts touching only FCI fall under CMMC Level 1. For a primer on that boundary, see our CMMC Level 1 scoping guidance. Contracts involving CUI require Level 2 — and possibly Level 3 — compliance.

Work with program managers and contracting officers to define precisely what constitutes CUI under each contract (e.g., technical drawings, specifications, export-controlled data). This step prevents the common scenario where "everything feels like CUI" and scope expands unnecessarily.

Step 2: Map Your Data Flows

Trace how CUI enters the organization — through portals, email, secure file shares, DoD systems, and people. Then map where users access and work with that CUI (VDI, Teams/SharePoint, PLM tools, specialized applications), and identify downstream systems such as backups and log aggregation platforms.

These maps form the backbone of your SSP and network diagrams, and they naturally surface CUI Assets, SPAs, CRMAs, and Specialized Assets. Skipping this step almost always results in gaps that assessors identify during the review.

Step 3: Classify Each Asset

For each asset in your inventory, work through this decision tree:

Does it actively process, store, or transmit CUI? → CUI Asset

Does it provide a security function protecting CUI Assets? → SPA

Can it technically access CUI but isn't intended to do so, and doesn't provide a security function? → CRMA

Is it OT/IoT/GFE or other hard-to-assess technology in the CUI environment? → Specialized Asset

None of the above, and separated from CUI and SPAs? → Out-of-Scope Asset

Document the rationale for each classification. That narrative often becomes some of the most valuable evidence during an assessment — it demonstrates deliberate, risk-informed decision-making rather than guesswork.

Step 4: Record Scope in Your SSP and Diagrams

Label each item in the asset inventory as a CUI Asset, SPA, CRMA, Specialized Asset, or Out-of-Scope. Use consistent color-coding. Create flow diagrams showing how CUI moves across the environment and network diagrams showing where assets reside and which network resources they use. Reflect all of this in the SSP, including how CRMAs are constrained and how Specialized Assets are segregated.

A practical rule: map your environment so clearly that a non-specialist could follow your classification logic without additional explanation. For step-by-step certification planning beyond scoping, see How Do I Become CMMC Certified? — a companion resource that walks through the end-to-end process.

Make Scoping a Design Decision, Not a Paperwork Chore

CMMC scoping can easily devolve into taxonomy debates over whether a particular system is a CRMA, SPA, or Specialized Asset. At its best, however, scoping is a design exercise in how CUI should exist in your organization.

If you architect a tight enclave with well-defined CUI Assets and carefully selected SPAs, you reduce your attack surface and simplify your assessment.

If you rely heavily on CRMAs, you're betting that governance, DLP, and user discipline will keep CUI in its proper channels — something a Level 2 assessor may choose to test.

If you neglect Specialized and Out-of-Scope Assets, you risk creating blind spots that both attackers and assessors are trained to find.

Done well, CMMC scoping does more than satisfy a regulation. It produces a living map of how sensitive data and security controls interact across your environment — a strategic tool that guides investment, informs incident response, and makes future audits and technology refreshes far less painful.

The CMMC assessment boundary also defines where sensitive government data is handled, stored, or transmitted. A well-drawn, documented boundary protects your organization from:

Failed audits caused by unidentified CUI exposure

Costly re-assessments triggered by architectural or boundary changes

Liability for potential data spillage outside the defined enclave

A clear assessment boundary supports smarter allocation of cybersecurity resources. Instead of spreading defenses thinly across all systems, organizations can concentrate investments where CUI resides, prioritize improvements that directly affect contract eligibility, and demonstrate to the DoD a mature, risk-based compliance approach. This is one of the Top 10 Reasons to Become CMMC Certified — the competitive positioning benefits alone can justify the investment.

As CMMC is a business game changer for defense contractors, defining the assessment boundary is vital not just for technical compliance — it's a business optimization exercise that determines your total cost of compliance, your level of risk exposure, and your ability to bid effectively in the defense industrial base market.

If you'd like expert guidance defining your CMMC assessment boundary from the ground up, Idenhaus CMMC cybersecurity services are designed to take organizations from initial scoping through C3PAO assessment support.

Frequently Asked Questions About CMMC Asset Scoping

What is the difference between a CUI Asset and a Security Protection Asset?

A CUI Asset actively processes, stores, or transmits Controlled Unclassified Information — think file servers, email systems, or virtual desktops where employees open CUI documents. A Security Protection Asset (SPA), by contrast, provides the security functions that protect those CUI Assets — think firewalls, SIEM tools, identity providers, and endpoint protection platforms. Both are in scope for Level 2 assessment, but they're evaluated differently.

Can an MSP be out of scope for CMMC?

Generally, no. If an MSP interacts with your CUI environment — which most do through routine maintenance of email, file shares, and endpoints — they're in scope as a Security Protection Asset. Organizations seeking CMMC Level 2 certification should work with MSPs that are themselves certified or on a clear path to certification.

What happens if I scope my assessment too narrowly?

Assessors are trained to look for gaps. If your proposed scope excludes systems that clearly touch CUI, a C3PAO can challenge the boundary and require you to expand it before the assessment proceeds. In some cases this can delay certification by months and significantly increase remediation costs.

Do Specialized Assets have to meet all 110 CMMC controls?

No. Specialized Assets — OT, IoT, GFE, and similar systems — undergo limited checks rather than full assessment against all controls. However, they must still be inventoried, documented, and demonstrably segregated from CUI Assets. "Limited checks" does not mean "ignored."

What is CMMC and why does it apply to my organization?

If your company holds DoD contracts that involve Controlled Unclassified Information or Federal Contract Information, CMMC compliance is now a legal requirement under 32 CFR Part 170, effective November 10, 2025. See What is CMMC? for a full overview of the program, its levels, and who it covers.

How do I start the CMMC certification process?

How Do I Become CMMC Certified? walks through the end-to-end process, from selecting a C3PAO and completing a readiness assessment to preparing your System Security Plan and scheduling your formal evaluation.

Where can I find answers to other common CMMC questions?

For a broader overview of CMMC 2.0 requirements, assessment timelines, and contractor obligations, see CMMC 2.0 Top 10 Questions Answered. For current data on how many organizations have been assessed and where the certification queue stands, see CMMC by the Numbers: Where Things Stand. For a full picture of how the ecosystem fits together — including the role of RPOs, C3PAOs, and the CAICO — see Understanding the CMMC 2.0 Compliance Ecosystem.

The Bottom Line on CMMC Asset Scoping

The CMMC boundary you draw today determines not just your certification timeline but your long-term security posture and operational efficiency. Choose deliberately. Document thoroughly. And remember that you're designing a defensible security architecture, not just filling out paperwork to satisfy an assessor.

In the next article in this series, we'll examine the practical logical and physical separation techniques you can use to enforce these boundaries and keep CUI exactly where it belongs.

Ready to define your scope with confidence? Idenhaus CMMC Services provide end-to-end support from initial scoping through C3PAO assessment. Contact us to get started.

More News

Subscribe To Our Newsletter

Please send me the following content from Idenhaus:*
Select as many boxes as you'd like!
Idenhaus needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.