One of the most consequential decisions in preparing for CMMC or any NIST SP 800-171 effort is deciding what is in scope. Every system that stores, processes, or transmits controlled unclassified information, and the systems that protect or connect to them, falls within the assessment boundary. The bigger the boundary, the more you must secure, document, and defend.
Contractors generally face two approaches: bring the entire company environment up to standard, or build a smaller enclave where controlled information lives and work stays contained. Neither is universally better. Here is how to weigh them.
What scope means
Scope covers the people, processes, technology, and facilities involved with controlled information. This includes endpoints, servers, cloud services, network equipment, email, collaboration tools, and the security tools that protect them. Systems that can reach the controlled environment without strong separation may be pulled into scope too.
Because the rules and guidance on scoping are detailed, confirm your specific boundary with a qualified assessor or consultant. The comparison below is a general framework.
Option one: company-wide approach
You apply the required controls across your whole environment.
Advantages
- Simpler operations. Everyone uses the same systems and standards.
- Fewer decisions about where information may go.
- Fewer chances for controlled information to spill into the wrong place.
- Easier for employees, who do not need to switch environments.
Drawbacks
- Higher cost, since every device, account, and system must meet requirements.
- A larger assessment, with more evidence to gather and defend.
- Greater impact on staff who never handle controlled information but must follow stricter rules.
- Harder to retrofit if your environment is sprawling or has many legacy systems.
This approach tends to suit smaller companies with a limited number of systems, or those where most employees work with controlled information.
Option two: a dedicated enclave
You create a bounded environment, physically or logically separate, for work involving controlled information. Only designated people and systems operate inside it. Many enclave strategies use a separate cloud tenant or managed environment built for these requirements.
Advantages
- Smaller scope, which can lower cost and effort.
- Clearer boundaries and a more focused assessment.
- Less disruption for staff outside the enclave.
- A good fit when only a few projects or people handle controlled information.
Drawbacks
- Employees must work in two environments, which creates friction and risk of mistakes.
- Strong discipline is needed to prevent controlled information from leaving the enclave through email, personal devices, or file sharing.
- Connections between the enclave and the rest of the business must be carefully controlled and documented.
- Poorly designed enclaves can still pull other systems into scope.
Questions to decide
- How many people and projects handle controlled information? A handful favors an enclave. Most of the company favors a broader approach.
- How much does the rest of the business depend on shared tools? Heavy integration makes separation harder.
- What is your current environment like? A messy network with many legacy systems may be more affordable to wall off than to remediate.
- How likely is growth in controlled work? If you expect more contracts, a company-wide foundation may pay off later.
- What can staff realistically follow? A design people work around is worse than a simpler one.
Design tips for an enclave
- Define precisely which data types belong inside, and train staff to recognize them.
- Control entry and exit points, including email, file transfer, and removable media.
- Use dedicated accounts and strong authentication for enclave access.
- Keep devices used in the enclave managed and hardened.
- Document the boundary clearly with diagrams and an asset list.
- Review it regularly, because scope tends to creep.
Watch for scope creep
Scope expands quietly when someone connects a personal laptop, adds a new cloud app, or forwards a file to a coworker outside the enclave. Build periodic checks into your routine, and include boundary questions in change management.
Get the decision documented
Whichever path you choose, record the reasoning, the boundary description, and the approval from leadership. This documentation becomes part of your system security plan and helps explain your choices to assessors and customers.
Where Ironfield Cyber fits
Ironfield Cyber helps defense subcontractors compare scoping options, estimate the work involved, and design practical boundaries. We coordinate with your assessor and counsel, and we are happy to walk through the tradeoffs for your company.