When a general contractor or specialty trade learns that a defense-related contract will require CMMC, the first reaction is often to picture securing every laptop, phone and server in the company. In many cases that is not necessary. The most valuable early decision is scoping: deciding which people, systems and facilities actually touch the information the program is designed to protect.
Why scoping comes first
CMMC 2.0 is the Department of Defense program for verifying that contractors protect sensitive unclassified information. The program rule under 32 CFR Part 170 took effect in December 2024, and the acquisition rule that puts requirements into contracts under DFARS took effect on November 10, 2025, with requirements phased in over time. Level 2 aligns with the 110 security requirements of NIST SP 800-171.
Those requirements apply to systems that process, store or transmit Controlled Unclassified Information (CUI), plus the systems that protect them. Everything else may be out of scope. A smaller scope means a smaller assessment, lower cost and fewer things to maintain.
Step one: find your CUI
CUI is information the government designates for protection. In construction it can include certain drawings, specifications, facility layouts, and project documents for sensitive installations. Contracts and the contracting officer should identify it, often through markings or contract clauses. If you are unsure, ask the prime contractor or contracting officer in writing rather than guessing.
Trace where CUI goes:
- Where does it arrive: email, a portal, a shared drive, a project platform?
- Who opens it: estimators, project managers, superintendents, subcontractors?
- Where is it stored, printed or copied: laptops, file servers, cloud storage, USB drives, phones?
- Who do you send it to?
Step two: classify your assets
Once you know the data flows, sort your assets into categories the program recognizes in general terms.
- CUI assets: systems that handle CUI directly.
- Security protection assets: systems that protect those, such as identity providers, firewalls and logging tools.
- Contractor risk managed assets: systems that are not intended to handle CUI but are not separated from it.
- Out-of-scope assets: systems with no access to CUI and properly separated.
Review the official scoping guidance published for the program to confirm how each category is treated, since details matter.
Step three: consider an enclave
For many small and mid-sized contractors, the practical answer is a CUI enclave: a dedicated, tightly controlled environment where CUI lives, separate from the rest of the company. Options include a protected section of a cloud platform built for government use or a small set of dedicated machines. The rest of your business, including field tablets, general email and jobsite Wi-Fi, stays outside.
An enclave works only if people respect the boundary. Document who has access, how files enter and leave, and what is prohibited, such as forwarding CUI to personal email or saving it to a personal phone.
Common scoping mistakes
- Assuming all of Microsoft 365 is in scope or out of scope without checking where CUI actually flows.
- Forgetting the people side: estimators who email drawings to themselves at home.
- Ignoring managed service providers and cloud vendors who touch the environment. They can become part of your scope.
- Failing to document the boundary. Assessors want a clear, written scope and network diagram.
What to produce
Aim for four documents before you spend money on controls:
- A list of contracts with CUI and the data types involved.
- A data flow diagram of how CUI moves.
- An asset inventory marked by category.
- A written scope statement explaining what is in and out and why.
Getting help
Scoping is where most of the savings, and most of the mistakes, happen. Ironfield Cyber helps defense subcontractors map CUI, design right-sized boundaries and prepare documentation. If a prime has handed you a flow-down clause and you are not sure where to start, a scoping conversation is the right first step.