When a defense subcontractor first reads the CMMC requirements, the instinct is to treat the whole company as in scope. That instinct is expensive. The most effective step in preparing for CMMC Level 2 is deciding, carefully and on paper, which systems actually touch Controlled Unclassified Information and which do not.
Scoping is not a trick to avoid requirements. Assessors expect a clear, defensible boundary, and they will test it. But a smaller boundary means fewer systems to harden, fewer users to train, and less evidence to collect. The 32 CFR Part 170 program rule has been in effect since December 16, 2024, and with the DFARS acquisition rule effective since November 10, 2025, contract requirements are now phasing in, so this work has real deadlines behind it.
Start With the Data, Not the Network
CMMC Level 2 protects CUI, so scoping begins with a simple question: where does CUI enter, live, move, and leave your company?
Trace the flow
Walk through a typical contract. CUI might arrive by email from a prime contractor, a secure file transfer, or a portal. It might be saved to a project folder, printed in the shop, or opened on a laptop in the field. List every place it lands, including backups, email archives, and personal drives where someone saved a copy "just in case."
Ask people, not just systems
Interview estimators, engineers, project managers, and shop leads. Ask what they receive from customers and where they keep it. You will almost always discover copies in places nobody documented.
The Categories Assessors Look At
NIST SP 800-171 and the CMMC scoping guidance sort assets into categories. In plain terms:
- Assets that process, store, or transmit CUI. These are in scope and must meet all applicable requirements.
- Security protection assets. The tools that protect the in-scope environment, such as firewalls, identity systems, and logging tools, are also assessed.
- Contractor risk managed assets. Systems that could touch CUI but are not meant to, and that you manage through documented policy.
- Specialized assets. Items such as operational technology or test equipment have their own treatment.
- Out-of-scope assets. Systems that are properly separated and cannot reach CUI.
Do not memorize the labels. What matters is that each device, application, and person is placed in a category and that you can explain why.
Ways to Shrink the Boundary
Create a dedicated enclave
Many small contractors keep CUI in one controlled environment, such as a separate, hardened set of laptops and a segregated cloud workspace, instead of securing the whole company. Users who handle CUI work inside that enclave; everyone else does not touch it.
Use a compliant cloud service carefully
Placing CUI in a cloud platform can reduce on-premises scope, but the provider must meet the applicable requirements, and you remain responsible for how you configure and use it. Ask the vendor for their responsibility documentation and confirm it in writing. Do not assume that a popular platform is automatically suitable.
Limit who handles CUI
Fewer users means fewer accounts, fewer devices, and less training overhead. Define a list of authorized people tied to specific contracts.
Separate networks
Network segmentation can keep the CUI environment apart from guest Wi-Fi, shop equipment, and general office traffic. Document the separation and test it.
Common Scoping Mistakes
- Declaring the boundary too small without evidence. If a shared printer, backup server, or email system touches CUI, it is in scope whether or not you listed it.
- Forgetting people. Employees, contractors, and managed service providers with access to the in-scope environment are part of the picture.
- Ignoring backups and logs. A backup copy of CUI is still CUI.
- Forgetting remote work. Laptops that leave the building belong in the diagram.
- Leaving scope undocumented. If it is only in someone's head, it will not survive an assessment.
Document the Boundary
Produce a short package: a data flow diagram, an asset list with category assignments, a list of authorized users, and a written explanation of each separation control. This becomes the backbone of your system security plan. Review it whenever you win a new contract, add a system, or change a vendor.
Where Ironfield Cyber Fits
Scoping is a business decision with technical consequences, and it is easier with an outside set of eyes. Ironfield Cyber can help a defense subcontractor map CUI flows, test a proposed boundary, and decide whether an enclave makes sense before you spend money on hardening the wrong systems.