The biggest cost lever in CMMC Level 2 readiness is not a product. It is scope. Every system that stores, processes or transmits Controlled Unclassified Information, and every system that can affect the security of those systems, becomes part of your assessment. If CUI is allowed to spread across the whole company, the whole company is in scope.
Careful scoping can shrink the effort dramatically, but only if the boundary is real, documented and defended.
What scope means
Your assessment scope covers the assets in your environment that handle CUI, plus those that provide security protection for it. In practice, that usually includes:
- Computers, servers and cloud services that store or process CUI
- People who access it
- Networks and devices that connect to those systems
- Security tools protecting them, such as identity, logging and endpoint protection
- Facilities where CUI is accessed or stored, including paper and removable media
Assets with no connection to CUI and no ability to affect it may sit outside the boundary, provided the separation is solid and documented.
Two basic approaches
Enterprise-wide
Treat the whole company as in scope. This is simpler to explain and enforce, since everyone follows the same rules. It can be cost-effective for small companies where most staff touch CUI anyway.
Enclave
Create a dedicated, protected environment for CUI, often a secured cloud workspace or a separate network segment with controlled devices. Only the people who need CUI work inside it. The rest of the company remains outside the boundary.
An enclave suits companies where only a few people, projects or contracts involve CUI. Ask a qualified advisor how to handle it in your situation, since requirements for assets that interact with the enclave can be detailed.
Steps to define your boundary
- Identify CUI. Confirm with contracts and the prime which information is CUI. Do not guess.
- Map the data flow. Trace how CUI enters, where it is stored, who uses it, and where it leaves.
- List assets in the flow. Include laptops, servers, cloud tools, printers, phones, and removable media.
- Decide the approach. Choose enterprise-wide or enclave based on how widely CUI spreads and what you can sustain.
- Define the people. Determine who needs access and who does not, and remove access for the rest.
- Document the boundary. Capture it in your system security plan, with a network diagram and a data flow diagram.
- Enforce it. Use technical controls, not only policy, so CUI cannot drift outside.
Common scoping mistakes
- Unmanaged data sprawl. CUI in personal email, text threads, local downloads and old file shares makes the boundary meaningless.
- Forgotten assets. Printers, scanners, backup systems and mobile devices often handle CUI without being listed.
- Shared infrastructure. If the CUI environment shares identity systems or networks with the rest of the company, those pieces may fall in scope.
- External service providers. Cloud services and managed providers that touch CUI have their own responsibilities and must be considered.
- Vague documentation. An assessor will test whether your description matches reality.
- Contract surprises. New work with CUI can expand scope overnight.
Controls that protect the boundary
- Limit access by role and need, and review it regularly
- Use multi-factor authentication
- Control and encrypt devices that touch CUI
- Restrict removable media and unmanaged file sharing
- Log and monitor activity within the boundary
- Train staff on what CUI is and where it may go
Keep scoping alive
Scope changes. New projects, vendors, offices and software can all alter the boundary. Review it at least annually and whenever you take on new CUI work. Update the diagrams and system security plan accordingly.
A hypothetical example
Consider a hypothetical 120-person contractor in which eight employees handle CUI for a single federal contract. Treating the entire company as in scope would require extensive changes for every laptop and user. Creating a protected enclave for those eight people limits the effort. The company must still be careful with how data moves in and out, and keep the enclave's documentation accurate. The savings are real, but so is the discipline needed to keep CUI inside.
Get the scoping right early
Scoping is a decision with technical, financial and contractual consequences. Ironfield Cyber helps contractors map CUI flows, evaluate enclave and enterprise options and document the boundary for their system security plans. If you are planning for CMMC Level 2, a scoping workshop is a sensible first step.