
As Cybersecurity Maturity Model Certification (CMMC) gets codified into law with the publication of the 32 CFR Final Rule, defense contractors or Organizations Seeking Assessments (OSA) will need to stay compliant with the CMMC compliance requirements to ensure continued eligibility for Department of Defense (DoD) contracts. Understanding scoping requirements for CMMC Level 1, which focuses on the basic safeguarding of Federal Contract Information (FCI), can streamline compliance efforts and ensure a smooth certification journey.
In order to help OSAs prepare for the CMMC assessment, The DoD has released scoping guides for public use for all three levels of CMMC certification. In this blog, we will do a deep dive into the CMMC Level 1 scoping guidance, which helps contractors understand which assets fall within the scope of the self-assessment and which do not and simplifies the compliance process.
Before OSA’s engage in the Level 1 self-assessment process, they will need to accurately determine the boundaries of the assessment efforts. CMMC Level 1 scope focuses on assets that process, store, or transmit FCI. Contractors must understand that while higher levels of CMMC (Levels 2 and 3) involve more stringent requirements, Level 1 is designed to address basic safeguarding measures for assets within scope.
The CMMC Level 1 scope divides assets into three categories:
These are assets that handle FCI directly, as defined in 32 CFR 170.19(b), either through processing, storage, or transmission. Examples of in-scope assets include computers, storage systems, and networks that store, process, or transmit FCI. OSA’s must assess these assets to meet all Level 1 compliance requirements, ensuring that fundamental security practices are applied to protect FCI.
Assets that do not process, store, or transmit FCI are considered out-of-scope as defined in 32 CFR 170.19(b)(2). Examples of out-of-scope assets include internal systems that are completely isolated from any FCI handling operations. This differentiation allows organizations to exclude assets not involved in FCI handling and streamline the assessment process by focusing resources effectively.
These assets as defined in 32 CFR 170.19(b)(2)(ii), may interact with FCI but have inherent limitations in achieving full security compliance, thus excluded from the Level 1 self-assessment scope. Specialized assets include Internet of Things (IoT) and Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Furnished Equipment (GFE), Restricted Information Systems, and Test Equipment.
In order to effectively scope for Level 1 self-assessment, OSAs must take into consideration both the technical and human aspects of the organization. When identifying scope OSAs should evaluate the following components:
People: This includes employees, contractors, and any external personnel who interact with FCI. Recognizing the users that handle FCI is essential for satisfying CMMC Level 1 requirements like user identification and access control.
Technology: Organizations must assess all systems used to process, store, or transmit FCI, ensuring that any technology interacting with FCI meets Level 1 compliance criteria.
Facilities: The physical locations where FCI is handled, such as office locations, datacenters, or manufacturing plants, also need to be considered within Level 1 scope. OSAs should ensure these environments are secure and compliant with the Level 1 requirements.
External Service Providers: Any outsourced or third-party service providers involved in processing or storing FCI on behalf of the OSA must be included in the scope for Level of self-assessment. Ensuring external service providers align with CMMC requirements is crucial to maintaining compliance boundaries.
One of the challenges of compliance is managing changes within the organization. The CMMC Level 1 Scoping Guidance highlights that a new assessment may be required if there are significant changes to the assessment boundary or system architecture, such as network expansions or mergers and acquisitions. However, minor adjustments or operational changes within the existing assessment boundary, like adding or removing assets, do not require a new assessment, provided these changes remain consistent with the existing System Security Plan (SSP).
While the SSP is not mandatory for Level 1 self-assessments, it is recommended as a best practice to document the organization’s approach to managing FCI. This proactive documentation can simplify the assessment process and demonstrate an ongoing commitment to security.
The CMMC Level 1 Scoping Guidance helps OSAs to determine the Level 1 assessment boundary by clearly identifying which assets to include and which to exclude. Focusing on assets that directly interact with FCI allows organizations to define the assessment scope more accurately and prepare for the certification process without unnecessary complexity, laying a solid foundation for security and compliance.
Connect with our CMMC experts at Idenhaus today to discuss any questions you have about the process. We're always ready to tackle your pressing cybersecurity inquiries anytime you need us.