CMMC Scoping: Deciding Which Systems Actually Hold CUI

Scoping drives the cost of CMMC readiness. Learn how to map where CUI lives, what is in scope, and how to shrink the boundary without cutting corners.

3 min readBy Ironfield Cyber Team

The single biggest lever on the cost of CMMC readiness is not a tool or a consultant. It is scope. Every system that stores, processes, or transmits Controlled Unclassified Information, plus the systems that protect them, falls into your assessment boundary. A smaller, well-defined boundary means fewer laptops to harden, fewer users to train, and fewer controls to document.

For defense subcontractors, scoping is also where most early mistakes happen. Firms either assume everything is in scope and overspend, or assume almost nothing is and discover the gap late.

Start With the Data, Not the Network

CUI is information, not a technology. Begin by finding it. Your contract and any flow-down clauses should tell you what categories of CUI you are expected to handle, and the prime or contracting officer can clarify when the language is vague.

Ask these questions:

  • Which contracts involve CUI, and what specific documents or data come with them?
  • Who receives that data, and by what route: email, a portal, a shared drive, a flash drive?
  • Where does it get stored, copied, printed, or forwarded afterward?
  • Who outside your company touches it, such as engineers, suppliers, or software vendors?

Follow one piece of CUI from the moment it arrives to the moment it is deleted. That path is your data flow, and it shows you the real boundary.

Identify the Asset Categories

Under the CMMC scoping approach, assets are sorted by their relationship to CUI. In general terms:

  • CUI assets store, process, or transmit CUI. They get the full set of requirements.
  • Security protection assets provide security functions for the CUI environment, such as identity systems, firewalls, and logging tools. They are in scope too.
  • Contractor risk managed assets and specialized assets (for example, certain OT or test equipment) have their own treatment and need documented reasoning.
  • Out-of-scope assets have no path to CUI and are separated from it.

Check the official CMMC scoping guidance for the level you are pursuing. The details matter, and your assessor will use that guidance, not a summary.

Shrink the Boundary on Purpose

Once you know where CUI lives, you can often contain it. Common approaches:

  1. Create a dedicated enclave. A separate, controlled environment for CUI work, with its own accounts, devices, and storage, keeps the rest of the company out of scope.
  2. Restrict who needs CUI. If only six people truly need it, only their endpoints and accounts need to be hardened to the full standard.
  3. Use a compliant cloud service. Hosting CUI in an environment that meets the required security baseline can be simpler than building it on your own servers. Confirm the provider's responsibilities in writing.
  4. Stop the leaks. Email forwarding, personal cloud sync, and local copies on laptops widen scope quickly. Block them.

Document Every Decision

Scoping is only defensible if it is written down. Maintain:

  • A network and data-flow diagram showing the CUI boundary
  • An asset inventory tagged by category
  • A short narrative explaining why out-of-scope systems are out of scope
  • A record of who is authorized to handle CUI

These feed directly into your System Security Plan. An assessor will test your boundary, so the diagram must match reality, not a sketch from two years ago.

Common Scoping Mistakes

  • Treating the whole domain as in scope when only a small team handles CUI
  • Forgetting the identity provider, backup system, or remote access tool that protects the enclave
  • Ignoring managed service providers and cloud vendors that have access
  • Letting the boundary drift as new staff and devices are added

Review scope at least annually and whenever a new contract with CUI is awarded.

Where We Fit

Ironfield Cyber helps defense contractors map CUI flows, design an enclave that fits how their people actually work, and document the boundary for assessment. If you are unsure what is in scope at your company, a short scoping conversation is usually the most valuable first step.