Many contractors hear CMMC and imagine every laptop, jobsite router and cloud account will need to meet the full set of requirements. Often that is not true. Scoping is the process of deciding which systems actually handle controlled unclassified information, or CUI, and which do not. A well-drawn boundary can shrink the work, the cost and the audit surface dramatically.
It can also go wrong. Draw it too small and an assessor will redraw it for you. This post explains the basics for defense subcontractors and small primes.
Start With the Data, Not the Network
The right question is not "which computers do we have?" but "where does CUI enter, live and leave our company?" Trace the information.
- How does CUI reach you? Through email attachments, a prime's portal, shared drives or physical media?
- Where is it stored? Servers, laptops, cloud storage, project management tools?
- Who touches it? Engineers, project managers, estimators, administrative staff?
- Where does it go next? To subcontractors, suppliers or back to the customer?
Your contract and the markings on documents tell you what counts as CUI. If you are not sure, ask the contracting officer or your prime in writing. Guessing in either direction causes trouble.
The Types of Assets in Scope
Under the CMMC program, built on NIST SP 800-171, assets generally fall into categories based on their relationship to CUI.
Assets that process, store or transmit CUI
These are fully in scope. They must meet the applicable requirements.
Security protection assets
Systems that protect the in-scope environment, such as firewalls, identity providers, logging and endpoint security tools, are also in scope, even if they do not hold CUI themselves.
Contractor risk managed and specialized assets
Some devices, such as operational technology or test equipment, may not be able to meet every requirement. They are documented and managed under your risk approach rather than ignored.
Out-of-scope assets
Systems that cannot touch CUI and are separated from the ones that do can be out of scope. The separation must be real and demonstrable, not just an intention.
Enclave Thinking
Many small contractors benefit from building an enclave: a deliberately limited environment where all CUI lives. Instead of securing the entire company to the full standard, you secure a smaller set of people, devices and cloud services.
An enclave might include:
- A dedicated cloud environment for CUI storage and collaboration.
- A small number of managed laptops used by people who handle CUI.
- Defined, documented paths for moving data in and out.
- Logging and access control specific to that environment.
If you use an external cloud provider to store CUI, check what the provider's own authorization covers and which responsibilities remain yours. Cloud providers that handle CUI have their own requirements, and you need to understand how they fit into your assessment.
Common Scoping Mistakes
- Assuming email is out of scope. If CUI arrives or leaves by email, your email system is in the boundary.
- Forgetting personal and mobile devices. Phones that read CUI email count.
- Leaving CUI copies in unexpected places. Desktops, downloads folders, backups and old laptops often hold forgotten files.
- Ignoring service providers. Your IT provider, backup provider and any cloud vendor that touches CUI may be part of the story.
- Drawing a boundary on paper that does not match the network. If out-of-scope systems can reach in-scope ones freely, the separation is weak.
Document the Boundary
Your scope should appear in your system security plan: a written description of the boundary, a network diagram, a data flow diagram, an asset inventory and the roles of external providers. As of the date of this post, the CMMC program rule is in effect and the DFARS acquisition rule has begun phasing CMMC requirements into contracts, so primes are increasingly asking for this information. Having a clear boundary on paper makes those conversations much easier.
Validate Before You Commit
Before you finalize scope, test it.
- Search file shares, laptops and email for CUI-marked documents outside the intended boundary.
- Check that out-of-scope networks truly cannot reach the CUI environment.
- Confirm every person with access has a legitimate reason.
- Review each external provider and what it touches.
Getting Help
Scoping is the single decision that most affects what CMMC will cost you. Ironfield Cyber helps defense subcontractors map their CUI, design practical enclaves and document the boundary for assessment. If you are early in the process, a scoping workshop is a sensible first step.